{
  "query": {
    "exploited": "1",
    "page": "24"
  },
  "count": 20,
  "total": 1734,
  "page": 24,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T18:46:01.823Z",
    "kev": "2026-10-06T19:45:10.728Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T19:46:10.731Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=24",
    "next": "https://spydr.io/threats.json?exploited=1&page=25"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-38080",
      "url": "https://spydr.io/cve/CVE-2024-38080",
      "published": "2024-07-09T17:15:43.410Z",
      "modified": "2026-06-17T07:39:22.737Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.07115,
      "epss_percentile": 0.94077,
      "exploited": true,
      "kev": {
        "added": "2024-07-09",
        "due": "2024-07-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Windows Hyper-V Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-39891",
      "url": "https://spydr.io/cve/CVE-2024-39891",
      "published": "2024-07-02T18:15:03.447Z",
      "modified": "2026-06-17T07:42:58.630Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01669,
      "epss_percentile": 0.76009,
      "exploited": true,
      "kev": {
        "added": "2024-07-23",
        "due": "2024-08-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "twilio"
      ],
      "products": [
        "twilio authy_2-factor_authentication"
      ],
      "cwes": [
        "CWE-203"
      ],
      "description": "In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)"
    },
    {
      "id": "CVE-2024-38475",
      "url": "https://spydr.io/cve/CVE-2024-38475",
      "published": "2024-07-01T19:15:04.883Z",
      "modified": "2026-06-17T07:40:21.380Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.99957,
      "epss_percentile": 0.99975,
      "exploited": true,
      "kev": {
        "added": "2025-05-01",
        "due": "2025-05-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache",
        "netapp"
      ],
      "products": [
        "Apache Software Foundation Apache HTTP Server",
        "apache http_server",
        "netapp ontap_9"
      ],
      "cwes": [
        "CWE-116"
      ],
      "description": "Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag \"UnsafePrefixStat\" can be used to opt back in once ensuring the substitution is appropriately constrained."
    },
    {
      "id": "CVE-2024-20399",
      "url": "https://spydr.io/cve/CVE-2024-20399",
      "published": "2024-07-01T17:15:04.383Z",
      "modified": "2026-06-17T07:06:56.067Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04306,
      "epss_percentile": 0.90872,
      "exploited": true,
      "kev": {
        "added": "2024-07-02",
        "due": "2024-07-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco NX-OS Software",
        "cisco nx-os"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode"
    },
    {
      "id": "CVE-2024-36401",
      "url": "https://spydr.io/cve/CVE-2024-36401",
      "published": "2024-07-01T16:15:04.120Z",
      "modified": "2026-06-17T07:36:38.833Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99813,
      "epss_percentile": 0.99958,
      "exploited": true,
      "kev": {
        "added": "2024-07-15",
        "due": "2024-08-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "geoserver"
      ],
      "products": [
        "geoserver"
      ],
      "cwes": [
        "CWE-95",
        "CWE-94"
      ],
      "description": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed."
    },
    {
      "id": "CVE-2024-4885",
      "url": "https://spydr.io/cve/CVE-2024-4885",
      "published": "2024-06-25T20:15:12.970Z",
      "modified": "2026-06-17T08:03:06.323Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99288,
      "epss_percentile": 0.99937,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software Corporation",
        "progress"
      ],
      "products": [
        "Progress Software Corporation WhatsUp Gold",
        "progress whatsup_gold"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\\nmconsole privileges."
    },
    {
      "id": "CVE-2024-37085",
      "url": "https://spydr.io/cve/CVE-2024-37085",
      "published": "2024-06-25T15:15:12.377Z",
      "modified": "2026-06-17T07:37:43.940Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.2677,
      "epss_percentile": 0.97981,
      "exploited": true,
      "kev": {
        "added": "2024-07-30",
        "due": "2024-08-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware ESXi",
        "VMware Cloud Foundation"
      ],
      "cwes": [
        "CWE-287",
        "CWE-305"
      ],
      "description": "VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD."
    },
    {
      "id": "CVE-2024-37079",
      "url": "https://spydr.io/cve/CVE-2024-37079",
      "published": "2024-06-18T06:15:11.350Z",
      "modified": "2026-06-17T07:37:43.330Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22377,
      "epss_percentile": 0.97637,
      "exploited": true,
      "kev": {
        "added": "2026-01-23",
        "due": "2026-02-13",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution."
    },
    {
      "id": "CVE-2024-6047",
      "url": "https://spydr.io/cve/CVE-2024-6047",
      "published": "2024-06-17T06:15:09.237Z",
      "modified": "2026-06-17T08:17:10.453Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "cert.org.tw",
      "epss": 0.10072,
      "epss_percentile": 0.95513,
      "exploited": true,
      "kev": {
        "added": "2025-05-07",
        "due": "2025-05-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GeoVision"
      ],
      "products": [
        "GeoVision GV_DSP_LPR_V2",
        "GeoVision GV_IPCAMD_GV_BX1500",
        "GeoVision GV_IPCAMD_GV_CB220",
        "GeoVision GV_IPCAMD_GV_EBL1100",
        "GeoVision GV_IPCAMD_GV_EFD1100",
        "GeoVision GV_IPCAMD_GV_FD2410",
        "GeoVision GV_IPCAMD_GV_FD3400",
        "GeoVision GV_IPCAMD_GV_FE3401",
        "GeoVision GV_IPCAMD_GV_FE420",
        "GeoVision GV-VS14_VS14",
        "GeoVision GV_VS03",
        "GeoVision GV_VS2410",
        "GeoVision GV_VS28XX",
        "GeoVision GV_VS216XX",
        "GeoVision GV VS04A",
        "GeoVision GV VS04H",
        "GeoVision GVLX 4 V2",
        "GeoVision GVLX 4 V3",
        "GeoVision GV_IPCAMD_GV_BX130",
        "GeoVision GV_GM8186_VS14"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device."
    },
    {
      "id": "CVE-2024-32896",
      "url": "https://spydr.io/cve/CVE-2024-32896",
      "published": "2024-06-13T21:15:54.080Z",
      "modified": "2026-06-17T07:30:38.333Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02985,
      "epss_percentile": 0.86876,
      "exploited": true,
      "kev": {
        "added": "2024-06-13",
        "due": "2024-07-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-670",
        "CWE-783"
      ],
      "description": "there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation."
    },
    {
      "id": "CVE-2024-34102",
      "url": "https://spydr.io/cve/CVE-2024-34102",
      "published": "2024-06-13T09:15:10.380Z",
      "modified": "2026-06-17T07:32:54.930Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.99994,
      "epss_percentile": 0.99988,
      "exploited": true,
      "kev": {
        "added": "2024-07-17",
        "due": "2024-08-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Commerce"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2024-35250",
      "url": "https://spydr.io/cve/CVE-2024-35250",
      "published": "2024-06-11T17:16:02.650Z",
      "modified": "2026-07-20T16:16:51.603Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.25222,
      "epss_percentile": 0.97886,
      "exploited": true,
      "kev": {
        "added": "2024-12-16",
        "due": "2025-01-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-30088",
      "url": "https://spydr.io/cve/CVE-2024-30088",
      "published": "2024-06-11T17:15:56.810Z",
      "modified": "2026-08-04T05:16:30.547Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.68202,
      "epss_percentile": 0.99314,
      "exploited": true,
      "kev": {
        "added": "2024-10-15",
        "due": "2024-11-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "Windows Kernel Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-36971",
      "url": "https://spydr.io/cve/CVE-2024-36971",
      "published": "2024-06-10T09:15:09.127Z",
      "modified": "2026-06-17T07:37:30.630Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02701,
      "epss_percentile": 0.85463,
      "exploited": true,
      "kev": {
        "added": "2024-08-07",
        "due": "2024-08-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux",
        "linux_kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order. Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three ->negative_advice() existing methods must perform the sk_dst_reset() themselves. Note the check against NULL dst is centralized in __dst_negative_advice(), there is no need to duplicate it in various callbacks. Many thanks to Clement Lecigne for tracking this issue. This old bug became visible after the blamed commit, using UDP sockets."
    },
    {
      "id": "CVE-2024-4577",
      "url": "https://spydr.io/cve/CVE-2024-4577",
      "published": "2024-06-09T20:15:09.550Z",
      "modified": "2026-06-17T08:02:11.493Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99987,
      "epss_percentile": 0.99984,
      "exploited": true,
      "kev": {
        "added": "2024-06-12",
        "due": "2024-07-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PHP Group"
      ],
      "products": [
        "PHP Group PHP"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use \"Best-Fit\" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc."
    },
    {
      "id": "CVE-2024-4610",
      "url": "https://spydr.io/cve/CVE-2024-4610",
      "published": "2024-06-07T12:15:09.077Z",
      "modified": "2026-06-17T08:02:15.760Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00764,
      "epss_percentile": 0.53943,
      "exploited": true,
      "kev": {
        "added": "2024-06-12",
        "due": "2024-07-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Arm Ltd",
        "arm"
      ],
      "products": [
        "Arm Ltd Bifrost GPU Kernel Driver",
        "Arm Ltd Valhall GPU Kernel Driver",
        "arm bifrost_gpu_kernel_driver",
        "arm valhall_gpu_kernel_driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0."
    },
    {
      "id": "CVE-2024-37383",
      "url": "https://spydr.io/cve/CVE-2024-37383",
      "published": "2024-06-07T04:15:30.463Z",
      "modified": "2026-06-17T07:38:15.543Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.73296,
      "epss_percentile": 0.9945,
      "exploited": true,
      "kev": {
        "added": "2024-10-24",
        "due": "2024-11-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube"
      ],
      "products": [
        "roundcube webmail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes."
    },
    {
      "id": "CVE-2024-28995",
      "url": "https://spydr.io/cve/CVE-2024-28995",
      "published": "2024-06-06T09:15:14.167Z",
      "modified": "2026-06-17T07:22:13.360Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99614,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2024-07-17",
        "due": "2024-08-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Serv-U"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine."
    },
    {
      "id": "CVE-2024-29824",
      "url": "https://spydr.io/cve/CVE-2024-29824",
      "published": "2024-05-31T18:15:11.177Z",
      "modified": "2026-06-17T07:23:11.330Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99938,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2024-10-02",
        "due": "2024-10-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti EPM",
        "ivanti endpoint_manager"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code."
    },
    {
      "id": "CVE-2024-23692",
      "url": "https://spydr.io/cve/CVE-2024-23692",
      "published": "2024-05-31T10:15:09.330Z",
      "modified": "2026-08-11T04:17:15.300Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99485,
      "epss_percentile": 0.99944,
      "exploited": true,
      "kev": {
        "added": "2024-07-09",
        "due": "2024-07-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Rejetto"
      ],
      "products": [
        "Rejetto HTTP File Server"
      ],
      "cwes": [
        "CWE-1336",
        "CWE-94"
      ],
      "description": "Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
