{
  "query": {
    "exploited": "1",
    "page": "23"
  },
  "count": 20,
  "total": 1734,
  "page": 23,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T18:46:01.823Z",
    "kev": "2026-10-06T18:45:08.577Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T18:46:01.823Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=23",
    "next": "https://spydr.io/threats.json?exploited=1&page=24"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-7593",
      "url": "https://spydr.io/cve/CVE-2024-7593",
      "published": "2024-08-13T19:15:16.940Z",
      "modified": "2026-06-17T08:20:30.860Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99991,
      "exploited": true,
      "kev": {
        "added": "2024-09-24",
        "due": "2024-10-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti vTM",
        "ivanti virtual_traffic_manager"
      ],
      "cwes": [
        "CWE-287",
        "CWE-303"
      ],
      "description": "Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel."
    },
    {
      "id": "CVE-2024-38213",
      "url": "https://spydr.io/cve/CVE-2024-38213",
      "published": "2024-08-13T18:15:30.750Z",
      "modified": "2026-06-17T07:39:41.937Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "microsoft.com",
      "epss": 0.13626,
      "epss_percentile": 0.96379,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-38193",
      "url": "https://spydr.io/cve/CVE-2024-38193",
      "published": "2024-08-13T18:15:28.230Z",
      "modified": "2026-06-17T07:39:39.247Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.28739,
      "epss_percentile": 0.98097,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-38189",
      "url": "https://spydr.io/cve/CVE-2024-38189",
      "published": "2024-08-13T18:15:27.733Z",
      "modified": "2026-06-17T07:39:38.820Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.08194,
      "epss_percentile": 0.94727,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office 2019",
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Project 2016",
        "Microsoft Office LTSC 2021"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Microsoft Project Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-38178",
      "url": "https://spydr.io/cve/CVE-2024-38178",
      "published": "2024-08-13T18:15:26.220Z",
      "modified": "2026-06-17T07:39:37.397Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.4138,
      "epss_percentile": 0.98639,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Scripting Engine Memory Corruption Vulnerability"
    },
    {
      "id": "CVE-2024-38107",
      "url": "https://spydr.io/cve/CVE-2024-38107",
      "published": "2024-08-13T18:15:10.963Z",
      "modified": "2026-06-17T07:39:26.377Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01635,
      "epss_percentile": 0.75515,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows 11 Version 24H2"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Power Dependency Coordinator Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-38106",
      "url": "https://spydr.io/cve/CVE-2024-38106",
      "published": "2024-08-13T18:15:10.713Z",
      "modified": "2026-06-17T07:39:26.217Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.06337,
      "epss_percentile": 0.93444,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 11 Version 24H2"
      ],
      "cwes": [
        "CWE-591"
      ],
      "description": "Windows Kernel Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-41710",
      "url": "https://spydr.io/cve/CVE-2024-41710",
      "published": "2024-08-12T19:15:16.850Z",
      "modified": "2026-06-17T07:48:05.950Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41646,
      "epss_percentile": 0.98648,
      "exploited": true,
      "kev": {
        "added": "2025-02-12",
        "due": "2025-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel 6940_sip_firmware",
        "mitel 6905_sip_firmware",
        "mitel 6910_sip_firmware",
        "mitel 6915_sip_firmware",
        "mitel 6920_sip_firmware",
        "mitel 6920w_sip_firmware",
        "mitel 6930w_sip_firmware",
        "mitel 6940w_sip_firmware",
        "mitel 6970_conference_firmware"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system."
    },
    {
      "id": "CVE-2024-27443",
      "url": "https://spydr.io/cve/CVE-2024-27443",
      "published": "2024-08-12T15:15:20.283Z",
      "modified": "2026-06-17T07:19:54.627Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.23632,
      "epss_percentile": 0.97755,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zimbra"
      ],
      "products": [
        "zimbra collaboration"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code."
    },
    {
      "id": "CVE-2024-7694",
      "url": "https://spydr.io/cve/CVE-2024-7694",
      "published": "2024-08-12T13:38:58.553Z",
      "modified": "2026-06-17T08:20:44.183Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "cert.org.tw",
      "epss": 0.01792,
      "epss_percentile": 0.77677,
      "exploited": true,
      "kev": {
        "added": "2026-02-17",
        "due": "2026-03-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeamT5"
      ],
      "products": [
        "TeamT5 ThreatSonar Anti-Ransomware"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server."
    },
    {
      "id": "CVE-2024-7399",
      "url": "https://spydr.io/cve/CVE-2024-7399",
      "published": "2024-08-12T13:38:41.550Z",
      "modified": "2026-10-01T19:17:15.393Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91941,
      "epss_percentile": 0.99818,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Electronics"
      ],
      "products": [
        "Samsung Electronics MagicINFO 9 Server"
      ],
      "cwes": [
        "CWE-22",
        "CWE-434"
      ],
      "description": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority."
    },
    {
      "id": "CVE-2024-42009",
      "url": "https://spydr.io/cve/CVE-2024-42009",
      "published": "2024-08-05T19:15:38.220Z",
      "modified": "2026-06-17T07:48:37.930Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.82882,
      "epss_percentile": 0.99665,
      "exploited": true,
      "kev": {
        "added": "2025-06-09",
        "due": "2025-06-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube"
      ],
      "products": [
        "roundcube webmail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php."
    },
    {
      "id": "CVE-2024-38856",
      "url": "https://spydr.io/cve/CVE-2024-38856",
      "published": "2024-08-05T09:15:56.780Z",
      "modified": "2026-06-17T07:41:08.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99427,
      "epss_percentile": 0.99942,
      "exploited": true,
      "kev": {
        "added": "2024-08-27",
        "due": "2024-09-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache OFBiz",
        "apache ofbiz"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints)."
    },
    {
      "id": "CVE-2023-45249",
      "url": "https://spydr.io/cve/CVE-2023-45249",
      "published": "2024-07-24T14:15:04.867Z",
      "modified": "2026-06-17T06:28:32.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.53255,
      "epss_percentile": 0.98957,
      "exploited": true,
      "kev": {
        "added": "2024-07-29",
        "due": "2024-08-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Acronis"
      ],
      "products": [
        "Acronis Cyber Infrastructure"
      ],
      "cwes": [
        "CWE-1393"
      ],
      "description": "Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132."
    },
    {
      "id": "CVE-2024-21182",
      "url": "https://spydr.io/cve/CVE-2024-21182",
      "published": "2024-07-16T23:15:22.660Z",
      "modified": "2026-06-17T07:08:41.710Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "oracle.com",
      "epss": 0.74162,
      "epss_percentile": 0.99476,
      "exploited": true,
      "kev": {
        "added": "2026-06-01",
        "due": "2026-06-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation WebLogic Server"
      ],
      "cwes": [],
      "description": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."
    },
    {
      "id": "CVE-2024-5910",
      "url": "https://spydr.io/cve/CVE-2024-5910",
      "published": "2024-07-10T19:15:11.390Z",
      "modified": "2026-06-17T08:16:53.600Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.91684,
      "epss_percentile": 0.99814,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Expedition"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue."
    },
    {
      "id": "CVE-2024-5217",
      "url": "https://spydr.io/cve/CVE-2024-5217",
      "published": "2024-07-10T17:15:12.373Z",
      "modified": "2026-06-17T08:15:25.880Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "servicenow.com",
      "epss": 0.99628,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2024-07-29",
        "due": "2024-08-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ServiceNow"
      ],
      "products": [
        "ServiceNow Now Platform",
        "servicenow"
      ],
      "cwes": [
        "CWE-184",
        "CWE-697"
      ],
      "description": "ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible."
    },
    {
      "id": "CVE-2024-4879",
      "url": "https://spydr.io/cve/CVE-2024-4879",
      "published": "2024-07-10T17:15:12.117Z",
      "modified": "2026-06-17T08:03:05.523Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "servicenow.com",
      "epss": 0.99976,
      "epss_percentile": 0.99979,
      "exploited": true,
      "kev": {
        "added": "2024-07-29",
        "due": "2024-08-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ServiceNow"
      ],
      "products": [
        "ServiceNow Now Platform",
        "servicenow"
      ],
      "cwes": [
        "CWE-1287"
      ],
      "description": "ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible."
    },
    {
      "id": "CVE-2024-38112",
      "url": "https://spydr.io/cve/CVE-2024-38112",
      "published": "2024-07-09T17:15:47.860Z",
      "modified": "2026-06-17T07:39:26.777Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.84225,
      "epss_percentile": 0.99693,
      "exploited": true,
      "kev": {
        "added": "2024-07-09",
        "due": "2024-07-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-451"
      ],
      "description": "Windows MSHTML Platform Spoofing Vulnerability"
    },
    {
      "id": "CVE-2024-38094",
      "url": "https://spydr.io/cve/CVE-2024-38094",
      "published": "2024-07-09T17:15:46.090Z",
      "modified": "2026-06-17T07:39:24.640Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.50892,
      "epss_percentile": 0.98901,
      "exploited": true,
      "kev": {
        "added": "2024-10-22",
        "due": "2024-11-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Microsoft SharePoint Remote Code Execution Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
