{
  "query": {
    "exploited": "1",
    "page": "26"
  },
  "count": 20,
  "total": 1734,
  "page": 26,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T20:46:13.413Z",
    "kev": "2026-10-06T21:45:15.930Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T21:46:16.004Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=26",
    "next": "https://spydr.io/threats.json?exploited=1&page=27"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-3272",
      "url": "https://spydr.io/cve/CVE-2024-3272",
      "published": "2024-04-04T01:15:50.123Z",
      "modified": "2026-06-17T07:43:41.427Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98038,
      "epss_percentile": 0.9991,
      "exploited": true,
      "kev": {
        "added": "2024-04-11",
        "due": "2024-05-02",
        "action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "D-Link"
      ],
      "products": [
        "D-Link DNS-320L",
        "D-Link DNS-325",
        "D-Link DNS-327L",
        "D-Link DNS-340L",
        "dlink dns-320l_firmware",
        "dlink dns-325_firmware",
        "dlink dns-327l_firmware",
        "dlink dns-340l_firmware"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced."
    },
    {
      "id": "CVE-2024-29059",
      "url": "https://spydr.io/cve/CVE-2024-29059",
      "published": "2024-03-23T00:15:09.150Z",
      "modified": "2026-06-17T07:22:20.537Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.98624,
      "epss_percentile": 0.99923,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft .NET Framework 4.8",
        "Microsoft .NET Framework 3.5 AND 4.8",
        "Microsoft .NET Framework 3.5 AND 4.7.2",
        "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
        "Microsoft .NET Framework 3.5 AND 4.8.1",
        "Microsoft .NET Framework 4.6.2",
        "Microsoft .NET Framework 3.5 AND 4.6/4.6.2",
        "Microsoft .NET Framework 2.0 Service Pack 2",
        "Microsoft .NET Framework 3.0 Service Pack 2",
        "Microsoft .NET Framework 3.5",
        "Microsoft .NET Framework 3.5.1"
      ],
      "cwes": [
        "CWE-209"
      ],
      "description": ".NET Framework Information Disclosure Vulnerability"
    },
    {
      "id": "CVE-2024-20767",
      "url": "https://spydr.io/cve/CVE-2024-20767",
      "published": "2024-03-18T12:15:06.870Z",
      "modified": "2026-06-17T07:07:49.320Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "adobe.com",
      "epss": 0.98514,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2024-12-16",
        "due": "2025-01-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet."
    },
    {
      "id": "CVE-2024-26169",
      "url": "https://spydr.io/cve/CVE-2024-26169",
      "published": "2024-03-12T17:15:56.173Z",
      "modified": "2026-06-17T07:17:15.207Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04014,
      "epss_percentile": 0.9028,
      "exploited": true,
      "kev": {
        "added": "2024-06-13",
        "due": "2024-07-04",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Windows Error Reporting Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-48788",
      "url": "https://spydr.io/cve/CVE-2023-48788",
      "published": "2024-03-12T15:15:46.973Z",
      "modified": "2026-06-17T06:34:58.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98446,
      "epss_percentile": 0.99918,
      "exploited": true,
      "kev": {
        "added": "2024-03-25",
        "due": "2024-04-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiClientEMS",
        "fortinet forticlient_enterprise_management_server"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets."
    },
    {
      "id": "CVE-2024-23296",
      "url": "https://spydr.io/cve/CVE-2024-23296",
      "published": "2024-03-05T20:16:01.553Z",
      "modified": "2026-06-17T07:12:32.137Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01411,
      "epss_percentile": 0.71803,
      "exploited": true,
      "kev": {
        "added": "2024-03-06",
        "due": "2024-03-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS",
        "apple ipad_os",
        "apple iphone_os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited."
    },
    {
      "id": "CVE-2024-23225",
      "url": "https://spydr.io/cve/CVE-2024-23225",
      "published": "2024-03-05T20:16:01.370Z",
      "modified": "2026-06-17T07:12:20.443Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01481,
      "epss_percentile": 0.73097,
      "exploited": true,
      "kev": {
        "added": "2024-03-06",
        "due": "2024-03-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS",
        "apple ipad_os",
        "apple iphone_os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited."
    },
    {
      "id": "CVE-2024-27199",
      "url": "https://spydr.io/cve/CVE-2024-27199",
      "published": "2024-03-04T18:15:09.377Z",
      "modified": "2026-06-17T07:19:25.110Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "NVD",
      "epss": 0.99991,
      "epss_percentile": 0.99986,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "JetBrains"
      ],
      "products": [
        "JetBrains TeamCity"
      ],
      "cwes": [
        "CWE-23",
        "CWE-22"
      ],
      "description": "In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible"
    },
    {
      "id": "CVE-2024-27198",
      "url": "https://spydr.io/cve/CVE-2024-27198",
      "published": "2024-03-04T18:15:09.040Z",
      "modified": "2026-06-17T07:19:24.987Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99938,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2024-03-07",
        "due": "2024-03-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "JetBrains"
      ],
      "products": [
        "JetBrains TeamCity"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible"
    },
    {
      "id": "CVE-2024-1212",
      "url": "https://spydr.io/cve/CVE-2024-1212",
      "published": "2024-02-21T18:15:50.417Z",
      "modified": "2026-07-13T19:49:31.120Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95388,
      "epss_percentile": 0.99868,
      "exploited": true,
      "kev": {
        "added": "2024-11-18",
        "due": "2024-12-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software",
        "kemptechnologies"
      ],
      "products": [
        "Progress Software LoadMaster",
        "kemptechnologies loadmaster"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution."
    },
    {
      "id": "CVE-2024-1709",
      "url": "https://spydr.io/cve/CVE-2024-1709",
      "published": "2024-02-21T16:15:50.420Z",
      "modified": "2026-06-17T07:04:50.557Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9998,
      "epss_percentile": 0.99981,
      "exploited": true,
      "kev": {
        "added": "2024-02-22",
        "due": "2024-02-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ConnectWise"
      ],
      "products": [
        "ConnectWise ScreenConnect"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems."
    },
    {
      "id": "CVE-2024-1708",
      "url": "https://spydr.io/cve/CVE-2024-1708",
      "published": "2024-02-21T16:15:50.233Z",
      "modified": "2026-06-17T07:04:50.430Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95436,
      "epss_percentile": 0.99869,
      "exploited": true,
      "kev": {
        "added": "2026-04-28",
        "due": "2026-05-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ConnectWise"
      ],
      "products": [
        "ConnectWise ScreenConnect"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems."
    },
    {
      "id": "CVE-2024-20953",
      "url": "https://spydr.io/cve/CVE-2024-20953",
      "published": "2024-02-17T02:15:49.520Z",
      "modified": "2026-06-17T07:08:14.457Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.03934,
      "epss_percentile": 0.90083,
      "exploited": true,
      "kev": {
        "added": "2025-02-24",
        "due": "2025-03-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation Agile PLM Framework",
        "oracle agile_plm_framework"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2024-23113",
      "url": "https://spydr.io/cve/CVE-2024-23113",
      "published": "2024-02-15T14:15:46.503Z",
      "modified": "2026-06-17T07:12:03.503Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61725,
      "epss_percentile": 0.99152,
      "exploited": true,
      "kev": {
        "added": "2024-10-09",
        "due": "2024-10-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiSwitchManager",
        "Fortinet FortiOS",
        "Fortinet FortiPAM",
        "Fortinet FortiProxy"
      ],
      "cwes": [
        "CWE-134"
      ],
      "description": "A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets."
    },
    {
      "id": "CVE-2024-21413",
      "url": "https://spydr.io/cve/CVE-2024-21413",
      "published": "2024-02-13T18:16:00.137Z",
      "modified": "2026-08-10T16:18:51.720Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.9466,
      "epss_percentile": 0.99856,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office 2016",
        "Microsoft Office 2019",
        "Microsoft Office LTSC 2021"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Microsoft Outlook Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-21412",
      "url": "https://spydr.io/cve/CVE-2024-21412",
      "published": "2024-02-13T18:15:59.903Z",
      "modified": "2026-08-10T16:18:51.517Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "score_source": "microsoft.com",
      "epss": 0.9941,
      "epss_percentile": 0.99942,
      "exploited": true,
      "kev": {
        "added": "2024-02-13",
        "due": "2024-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Internet Shortcut Files Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-21410",
      "url": "https://spydr.io/cve/CVE-2024-21410",
      "published": "2024-02-13T18:15:59.680Z",
      "modified": "2026-06-17T07:09:14.233Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.12561,
      "epss_percentile": 0.96134,
      "exploited": true,
      "kev": {
        "added": "2024-02-15",
        "due": "2024-03-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 13",
        "Microsoft Exchange Server 2019 Cumulative Update 14"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Microsoft Exchange Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-21351",
      "url": "https://spydr.io/cve/CVE-2024-21351",
      "published": "2024-02-13T18:15:51.333Z",
      "modified": "2026-08-10T16:18:42.753Z",
      "score": 7.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L",
      "score_source": "microsoft.com",
      "epss": 0.27798,
      "epss_percentile": 0.98046,
      "exploited": true,
      "kev": {
        "added": "2024-02-13",
        "due": "2024-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-21338",
      "url": "https://spydr.io/cve/CVE-2024-21338",
      "published": "2024-02-13T18:15:49.083Z",
      "modified": "2026-08-10T16:18:40.377Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.5981,
      "epss_percentile": 0.9911,
      "exploited": true,
      "kev": {
        "added": "2024-03-04",
        "due": "2024-03-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Windows Kernel Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-21762",
      "url": "https://spydr.io/cve/CVE-2024-21762",
      "published": "2024-02-09T09:15:08.087Z",
      "modified": "2026-08-04T05:16:30.003Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83428,
      "epss_percentile": 0.99677,
      "exploited": true,
      "kev": {
        "added": "2024-02-09",
        "due": "2024-02-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiProxy",
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
