{
  "query": {
    "exploited": "1",
    "page": "22"
  },
  "count": 20,
  "total": 1734,
  "page": 22,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T16:45:50.826Z",
    "kev": "2026-10-06T17:44:53.087Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T17:45:53.188Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=22",
    "next": "https://spydr.io/threats.json?exploited=1&page=23"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-8957",
      "url": "https://spydr.io/cve/CVE-2024-8957",
      "published": "2024-09-17T21:15:13.423Z",
      "modified": "2026-06-17T08:23:37.947Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.79703,
      "epss_percentile": 0.996,
      "exploited": true,
      "kev": {
        "added": "2024-11-04",
        "due": "2024-11-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PTZOptics"
      ],
      "products": [
        "PTZOptics PT30X-SDI",
        "PTZOptics PT30X-NDI",
        "ptzoptics pt30x-sdi_firmware",
        "ptzoptics pt30x-ndi_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices."
    },
    {
      "id": "CVE-2024-8956",
      "url": "https://spydr.io/cve/CVE-2024-8956",
      "published": "2024-09-17T20:15:07.287Z",
      "modified": "2026-06-17T08:23:37.827Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.58787,
      "epss_percentile": 0.99084,
      "exploited": true,
      "kev": {
        "added": "2024-11-04",
        "due": "2024-11-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PTZOptics"
      ],
      "products": [
        "PTZOptics PT30X-SDI",
        "PTZOptics PT30X-NDI",
        "ptzoptics pt30x-sdi_firmware",
        "ptzoptics pt30x-ndi-xx-g2_firmware"
      ],
      "cwes": [
        "CWE-306",
        "CWE-287"
      ],
      "description": "PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file."
    },
    {
      "id": "CVE-2024-38813",
      "url": "https://spydr.io/cve/CVE-2024-38813",
      "published": "2024-09-17T18:15:04.127Z",
      "modified": "2026-06-17T07:41:05.720Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.17355,
      "epss_percentile": 0.97037,
      "exploited": true,
      "kev": {
        "added": "2024-11-20",
        "due": "2024-12-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "broadcom"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation",
        "broadcom vmware_center_server",
        "broadcom vmware_cloud_foundation"
      ],
      "cwes": [
        "CWE-250",
        "CWE-273"
      ],
      "description": "The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet."
    },
    {
      "id": "CVE-2024-38812",
      "url": "https://spydr.io/cve/CVE-2024-38812",
      "published": "2024-09-17T18:15:03.920Z",
      "modified": "2026-06-17T07:41:05.577Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54571,
      "epss_percentile": 0.98992,
      "exploited": true,
      "kev": {
        "added": "2024-11-20",
        "due": "2024-12-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "broadcom"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation",
        "broadcom vmware_vcenter_server",
        "broadcom vmware_cloud_foundation"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution."
    },
    {
      "id": "CVE-2024-8190",
      "url": "https://spydr.io/cve/CVE-2024-8190",
      "published": "2024-09-10T21:15:14.697Z",
      "modified": "2026-06-17T08:22:05.230Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88535,
      "epss_percentile": 0.99771,
      "exploited": true,
      "kev": {
        "added": "2024-09-13",
        "due": "2024-10-04",
        "action": "As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability."
    },
    {
      "id": "CVE-2024-43461",
      "url": "https://spydr.io/cve/CVE-2024-43461",
      "published": "2024-09-10T17:15:33.410Z",
      "modified": "2026-08-10T16:19:10.537Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.54486,
      "epss_percentile": 0.98988,
      "exploited": true,
      "kev": {
        "added": "2024-09-16",
        "due": "2024-10-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-451"
      ],
      "description": "Windows MSHTML Platform Spoofing Vulnerability"
    },
    {
      "id": "CVE-2024-38226",
      "url": "https://spydr.io/cve/CVE-2024-38226",
      "published": "2024-09-10T17:15:25.267Z",
      "modified": "2026-08-10T16:19:04.130Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02667,
      "epss_percentile": 0.85236,
      "exploited": true,
      "kev": {
        "added": "2024-09-10",
        "due": "2024-10-01",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office 2019",
        "Microsoft Office LTSC 2021",
        "Microsoft Publisher 2016"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Microsoft Publisher Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-38217",
      "url": "https://spydr.io/cve/CVE-2024-38217",
      "published": "2024-09-10T17:15:24.640Z",
      "modified": "2026-08-10T16:19:03.400Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.10026,
      "epss_percentile": 0.95489,
      "exploited": true,
      "kev": {
        "added": "2024-09-10",
        "due": "2024-10-01",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-38014",
      "url": "https://spydr.io/cve/CVE-2024-38014",
      "published": "2024-09-10T17:15:20.320Z",
      "modified": "2026-08-10T16:19:01.613Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.06263,
      "epss_percentile": 0.93368,
      "exploited": true,
      "kev": {
        "added": "2024-09-10",
        "due": "2024-10-01",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Windows Installer Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-40711",
      "url": "https://spydr.io/cve/CVE-2024-40711",
      "published": "2024-09-07T17:15:13.260Z",
      "modified": "2026-06-17T07:46:23.383Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90369,
      "epss_percentile": 0.99798,
      "exploited": true,
      "kev": {
        "added": "2024-10-17",
        "due": "2024-11-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Veeam"
      ],
      "products": [
        "Veeam Backup and Recovery",
        "veeam backup_\\&_replication"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE)."
    },
    {
      "id": "CVE-2024-20439",
      "url": "https://spydr.io/cve/CVE-2024-20439",
      "published": "2024-09-04T17:15:13.210Z",
      "modified": "2026-06-17T07:07:06.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9709,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2025-03-31",
        "due": "2025-04-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Smart License Utility"
      ],
      "cwes": [
        "CWE-912",
        "CWE-798"
      ],
      "description": "A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative account. An attacker could exploit this vulnerability by using the static credentials to login to the affected system. A successful exploit could allow the attacker to login to the affected system with administrative rights over the CSLU application API."
    },
    {
      "id": "CVE-2024-45195",
      "url": "https://spydr.io/cve/CVE-2024-45195",
      "published": "2024-09-04T09:15:04.397Z",
      "modified": "2026-06-17T07:53:46.637Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99983,
      "epss_percentile": 0.99982,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache OFBiz",
        "apache ofbiz"
      ],
      "cwes": [
        "CWE-425"
      ],
      "description": "Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue."
    },
    {
      "id": "CVE-2024-6670",
      "url": "https://spydr.io/cve/CVE-2024-6670",
      "published": "2024-08-29T22:15:05.573Z",
      "modified": "2026-06-17T08:18:27.307Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93,
      "epss_percentile": 0.99831,
      "exploited": true,
      "kev": {
        "added": "2024-09-16",
        "due": "2024-10-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software Corporation",
        "progress"
      ],
      "products": [
        "Progress Software Corporation WhatsUp Gold",
        "progress whatsupgold"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password."
    },
    {
      "id": "CVE-2024-40766",
      "url": "https://spydr.io/cve/CVE-2024-40766",
      "published": "2024-08-23T07:15:03.643Z",
      "modified": "2026-09-21T21:17:02.403Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.18379,
      "epss_percentile": 0.97153,
      "exploited": true,
      "kev": {
        "added": "2024-09-09",
        "due": "2024-09-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SonicOS"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions."
    },
    {
      "id": "CVE-2024-39717",
      "url": "https://spydr.io/cve/CVE-2024-39717",
      "published": "2024-08-22T19:15:09.173Z",
      "modified": "2026-06-17T07:42:31.890Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04006,
      "epss_percentile": 0.90247,
      "exploited": true,
      "kev": {
        "added": "2024-08-23",
        "due": "2024-09-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Versa",
        "versa-networks"
      ],
      "products": [
        "Versa Director",
        "versa-networks versa_director"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in."
    },
    {
      "id": "CVE-2024-28987",
      "url": "https://spydr.io/cve/CVE-2024-28987",
      "published": "2024-08-21T22:15:04.350Z",
      "modified": "2026-06-17T07:22:12.560Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.93299,
      "epss_percentile": 0.99836,
      "exploited": true,
      "kev": {
        "added": "2024-10-15",
        "due": "2024-11-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data."
    },
    {
      "id": "CVE-2024-7971",
      "url": "https://spydr.io/cve/CVE-2024-7971",
      "published": "2024-08-21T21:15:09.277Z",
      "modified": "2026-06-17T08:21:35.047Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21103,
      "epss_percentile": 0.97517,
      "exploited": true,
      "kev": {
        "added": "2024-08-26",
        "due": "2024-09-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2024-7965",
      "url": "https://spydr.io/cve/CVE-2024-7965",
      "published": "2024-08-21T21:15:08.947Z",
      "modified": "2026-06-17T08:21:34.043Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.18528,
      "epss_percentile": 0.97176,
      "exploited": true,
      "kev": {
        "added": "2024-08-28",
        "due": "2024-09-18",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787",
        "CWE-358"
      ],
      "description": "Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2024-7262",
      "url": "https://spydr.io/cve/CVE-2024-7262",
      "published": "2024-08-15T15:15:22.290Z",
      "modified": "2026-06-17T08:19:43.623Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X",
      "score_source": "eset.com",
      "epss": 0.02937,
      "epss_percentile": 0.86643,
      "exploited": true,
      "kev": {
        "added": "2024-09-03",
        "due": "2024-09-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Kingsoft"
      ],
      "products": [
        "Kingsoft WPS Office"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document"
    },
    {
      "id": "CVE-2024-28986",
      "url": "https://spydr.io/cve/CVE-2024-28986",
      "published": "2024-08-13T23:15:16.627Z",
      "modified": "2026-06-17T07:22:12.443Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "solarwinds.com",
      "epss": 0.84628,
      "epss_percentile": 0.997,
      "exploited": true,
      "kev": {
        "added": "2024-08-15",
        "due": "2024-09-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
