{
  "query": {
    "exploited": "1",
    "page": "27"
  },
  "count": 20,
  "total": 1734,
  "page": 27,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T20:46:13.413Z",
    "kev": "2026-10-06T21:45:15.930Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T21:46:16.004Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=27",
    "next": "https://spydr.io/threats.json?exploited=1&page=28"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-21893",
      "url": "https://spydr.io/cve/CVE-2024-21893",
      "published": "2024-01-31T18:15:47.437Z",
      "modified": "2026-08-04T05:16:30.353Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99999,
      "exploited": true,
      "kev": {
        "added": "2024-01-31",
        "due": "2024-02-02",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti ICS",
        "Ivanti IPS",
        "ivanti connect_secure",
        "ivanti policy_secure"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication."
    },
    {
      "id": "CVE-2024-1086",
      "url": "https://spydr.io/cve/CVE-2024-1086",
      "published": "2024-01-31T13:15:10.827Z",
      "modified": "2026-08-07T19:59:58.823Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28058,
      "epss_percentile": 0.98062,
      "exploited": true,
      "kev": {
        "added": "2024-05-30",
        "due": "2024-06-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux Kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660."
    },
    {
      "id": "CVE-2024-23897",
      "url": "https://spydr.io/cve/CVE-2024-23897",
      "published": "2024-01-24T18:15:09.370Z",
      "modified": "2026-06-17T07:13:49.330Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99995,
      "exploited": true,
      "kev": {
        "added": "2024-08-19",
        "due": "2024-09-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Jenkins Project",
        "jenkins"
      ],
      "products": [
        "Jenkins Project Jenkins",
        "jenkins"
      ],
      "cwes": [
        "CWE-22",
        "CWE-27"
      ],
      "description": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system."
    },
    {
      "id": "CVE-2024-23222",
      "url": "https://spydr.io/cve/CVE-2024-23222",
      "published": "2024-01-23T01:15:11.500Z",
      "modified": "2026-06-17T07:12:19.937Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10593,
      "epss_percentile": 0.95671,
      "exploited": true,
      "kev": {
        "added": "2024-01-23",
        "due": "2024-02-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version."
    },
    {
      "id": "CVE-2024-0769",
      "url": "https://spydr.io/cve/CVE-2024-0769",
      "published": "2024-01-21T08:15:07.550Z",
      "modified": "2026-06-17T06:54:13.300Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82714,
      "epss_percentile": 0.99662,
      "exploited": true,
      "kev": {
        "added": "2025-06-25",
        "due": "2025-07-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "D-Link"
      ],
      "products": [
        "D-Link DIR-859",
        "dlink dir-859_firmware"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced."
    },
    {
      "id": "CVE-2023-6549",
      "url": "https://spydr.io/cve/CVE-2023-6549",
      "published": "2024-01-17T21:15:11.690Z",
      "modified": "2026-06-17T06:50:58.160Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.57633,
      "epss_percentile": 0.99062,
      "exploited": true,
      "kev": {
        "added": "2024-01-17",
        "due": "2024-02-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cloud Software Group"
      ],
      "products": [
        "Cloud Software Group NetScaler ADC"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read"
    },
    {
      "id": "CVE-2023-6548",
      "url": "https://spydr.io/cve/CVE-2023-6548",
      "published": "2024-01-17T20:15:50.627Z",
      "modified": "2026-06-17T06:50:58.003Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03191,
      "epss_percentile": 0.87693,
      "exploited": true,
      "kev": {
        "added": "2024-01-17",
        "due": "2024-01-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cloud Software Group",
        "citrix"
      ],
      "products": [
        "Cloud Software Group NetScaler ADC",
        "Cloud Software Group NetScaler Gateway",
        "citrix netscaler_application_delivery_controller",
        "citrix netscaler_gateway"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface."
    },
    {
      "id": "CVE-2024-0519",
      "url": "https://spydr.io/cve/CVE-2024-0519",
      "published": "2024-01-16T22:15:37.753Z",
      "modified": "2026-06-17T06:53:41.133Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03802,
      "epss_percentile": 0.8971,
      "exploited": true,
      "kev": {
        "added": "2024-01-17",
        "due": "2024-02-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787",
        "CWE-125"
      ],
      "description": "Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-22527",
      "url": "https://spydr.io/cve/CVE-2023-22527",
      "published": "2024-01-16T05:15:08.290Z",
      "modified": "2026-06-17T05:35:38.480Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99984,
      "epss_percentile": 0.99982,
      "exploited": true,
      "kev": {
        "added": "2024-01-24",
        "due": "2024-02-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin."
    },
    {
      "id": "CVE-2024-21887",
      "url": "https://spydr.io/cve/CVE-2024-21887",
      "published": "2024-01-12T17:15:10.017Z",
      "modified": "2026-08-04T05:16:30.193Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99999,
      "exploited": true,
      "kev": {
        "added": "2024-01-10",
        "due": "2024-01-22",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti ICS",
        "Ivanti IPS"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance."
    },
    {
      "id": "CVE-2023-46805",
      "url": "https://spydr.io/cve/CVE-2023-46805",
      "published": "2024-01-12T17:15:09.530Z",
      "modified": "2026-10-01T21:17:17.487Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.99986,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2024-01-10",
        "due": "2024-01-22",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti ICS",
        "Ivanti IPS"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks."
    },
    {
      "id": "CVE-2023-7028",
      "url": "https://spydr.io/cve/CVE-2023-7028",
      "published": "2024-01-12T14:15:49.420Z",
      "modified": "2026-06-17T06:51:54.410Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94647,
      "epss_percentile": 0.99856,
      "exploited": true,
      "kev": {
        "added": "2024-05-01",
        "due": "2024-05-22",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GitLab"
      ],
      "products": [
        "GitLab"
      ],
      "cwes": [
        "CWE-640"
      ],
      "description": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address."
    },
    {
      "id": "CVE-2023-41974",
      "url": "https://spydr.io/cve/CVE-2023-41974",
      "published": "2024-01-10T22:15:49.240Z",
      "modified": "2026-06-17T06:23:10.837Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01955,
      "epss_percentile": 0.79615,
      "exploited": true,
      "kev": {
        "added": "2026-03-05",
        "due": "2026-03-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2022-48618",
      "url": "https://spydr.io/cve/CVE-2022-48618",
      "published": "2024-01-09T18:15:45.120Z",
      "modified": "2026-06-17T05:15:43.393Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00487,
      "epss_percentile": 0.39861,
      "exploited": true,
      "kev": {
        "added": "2024-01-31",
        "due": "2024-02-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple tvOS",
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple watchOS",
        "apple iphone_os",
        "apple ipados"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1."
    },
    {
      "id": "CVE-2022-2586",
      "url": "https://spydr.io/cve/CVE-2022-2586",
      "published": "2024-01-08T18:15:44.620Z",
      "modified": "2026-08-20T14:17:08.057Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10202,
      "epss_percentile": 0.95552,
      "exploited": true,
      "kev": {
        "added": "2024-06-26",
        "due": "2024-07-17",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "The Linux Kernel Organization",
        "linux"
      ],
      "products": [
        "The Linux Kernel Organization linux",
        "linux_kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted."
    },
    {
      "id": "CVE-2023-7101",
      "url": "https://spydr.io/cve/CVE-2023-7101",
      "published": "2023-12-24T22:15:07.983Z",
      "modified": "2026-06-17T06:52:04.040Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19106,
      "epss_percentile": 0.97252,
      "exploited": true,
      "kev": {
        "added": "2024-01-02",
        "due": "2024-01-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Douglas Wilson",
        "jmcnamara",
        "debian",
        "fedoraproject"
      ],
      "products": [
        "Douglas Wilson Spreadsheet::ParseExcel",
        "jmcnamara spreadsheet\\",
        "debian_linux",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-95",
        "CWE-94"
      ],
      "description": "Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic."
    },
    {
      "id": "CVE-2023-7024",
      "url": "https://spydr.io/cve/CVE-2023-7024",
      "published": "2023-12-21T23:15:11.213Z",
      "modified": "2026-06-17T06:51:53.730Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06671,
      "epss_percentile": 0.93711,
      "exploited": true,
      "kev": {
        "added": "2024-01-02",
        "due": "2024-01-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-47565",
      "url": "https://spydr.io/cve/CVE-2023-47565",
      "published": "2023-12-08T16:15:16.367Z",
      "modified": "2026-06-17T06:32:55.230Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73277,
      "epss_percentile": 0.99449,
      "exploited": true,
      "kev": {
        "added": "2023-12-21",
        "due": "2024-01-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. VioStor NVR"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later"
    },
    {
      "id": "CVE-2023-49897",
      "url": "https://spydr.io/cve/CVE-2023-49897",
      "published": "2023-12-06T07:15:41.883Z",
      "modified": "2026-06-17T06:36:40.620Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.50447,
      "epss_percentile": 0.98885,
      "exploited": true,
      "kev": {
        "added": "2023-12-21",
        "due": "2024-01-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FXC Inc."
      ],
      "products": [
        "FXC Inc. AE1021PE",
        "FXC Inc. AE1021"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product."
    },
    {
      "id": "CVE-2023-44221",
      "url": "https://spydr.io/cve/CVE-2023-44221",
      "published": "2023-12-05T21:15:07.150Z",
      "modified": "2026-06-17T06:27:09.827Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7625,
      "epss_percentile": 0.99525,
      "exploited": true,
      "kev": {
        "added": "2025-05-01",
        "due": "2025-05-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA100"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
