{
  "query": {
    "exploited": "1",
    "page": "28"
  },
  "count": 20,
  "total": 1734,
  "page": 28,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T22:46:18.712Z",
    "kev": "2026-10-06T22:45:18.551Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T22:46:18.712Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=28",
    "next": "https://spydr.io/threats.json?exploited=1&page=29"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-6448",
      "url": "https://spydr.io/cve/CVE-2023-6448",
      "published": "2023-12-05T18:15:12.643Z",
      "modified": "2026-06-17T06:50:46.670Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02072,
      "epss_percentile": 0.80816,
      "exploited": true,
      "kev": {
        "added": "2023-12-11",
        "due": "2023-12-18",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Unitronics"
      ],
      "products": [
        "Unitronics VisiLogic"
      ],
      "cwes": [
        "CWE-1188",
        "CWE-798"
      ],
      "description": "Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system."
    },
    {
      "id": "CVE-2023-33107",
      "url": "https://spydr.io/cve/CVE-2023-33107",
      "published": "2023-12-05T03:15:14.860Z",
      "modified": "2026-06-17T06:00:58.287Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00739,
      "epss_percentile": 0.53062,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm 315_5g_iot_modem_firmware",
        "qualcomm apq8017_firmware",
        "qualcomm apq8064au_firmware",
        "qualcomm aqt1000_firmware",
        "qualcomm ar8031_firmware",
        "qualcomm ar8035_firmware",
        "qualcomm c-v2x_9150_firmware",
        "qualcomm csra6620_firmware",
        "qualcomm csra6640_firmware",
        "qualcomm csrb31024_firmware",
        "qualcomm fastconnect_6200_firmware",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm flight_rb5_5g_platform_firmware",
        "qualcomm mdm9250_firmware",
        "qualcomm mdm9650_firmware",
        "qualcomm msm8108_firmware"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call."
    },
    {
      "id": "CVE-2023-33106",
      "url": "https://spydr.io/cve/CVE-2023-33106",
      "published": "2023-12-05T03:15:14.673Z",
      "modified": "2026-06-17T06:00:56.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00788,
      "epss_percentile": 0.54744,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm ar8035_firmware",
        "qualcomm csra6620_firmware",
        "qualcomm csra6640_firmware",
        "qualcomm fastconnect_6200_firmware",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm flight_rb5_5g_platform_firmware",
        "qualcomm qam8255p_firmware",
        "qualcomm qam8295p_firmware",
        "qualcomm qam8650p_firmware",
        "qualcomm qam8775p_firmware",
        "qualcomm qca6174a_firmware",
        "qualcomm qca6391_firmware",
        "qualcomm qca6426_firmware",
        "qualcomm qca6436_firmware",
        "qualcomm qca6574_firmware",
        "qualcomm qca6574a_firmware"
      ],
      "cwes": [
        "CWE-823",
        "CWE-119"
      ],
      "description": "Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND."
    },
    {
      "id": "CVE-2023-33063",
      "url": "https://spydr.io/cve/CVE-2023-33063",
      "published": "2023-12-05T03:15:12.067Z",
      "modified": "2026-06-17T06:00:38.380Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00672,
      "epss_percentile": 0.50455,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm 315_5g_iot_modem_firmware",
        "qualcomm apq8017_firmware",
        "qualcomm aqt1000_firmware",
        "qualcomm ar8031_firmware",
        "qualcomm ar8035_firmware",
        "qualcomm ar9380_firmware",
        "qualcomm c-v2x_9150_firmware",
        "qualcomm csr8811_firmware",
        "qualcomm csra6620_firmware",
        "qualcomm csra6640_firmware",
        "qualcomm csrb31024_firmware",
        "qualcomm fastconnect_6200_firmware",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm flight_rb5_5g_platform_firmware",
        "qualcomm immersive_home_214_platform_firmware",
        "qualcomm immersive_home_216_platform_firmware"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Memory corruption in DSP Services during a remote call from HLOS to DSP."
    },
    {
      "id": "CVE-2023-42917",
      "url": "https://spydr.io/cve/CVE-2023-42917",
      "published": "2023-11-30T23:15:07.280Z",
      "modified": "2026-06-17T06:24:49.733Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09295,
      "epss_percentile": 0.95243,
      "exploited": true,
      "kev": {
        "added": "2023-12-04",
        "due": "2023-12-25",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple macOS",
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1."
    },
    {
      "id": "CVE-2023-42916",
      "url": "https://spydr.io/cve/CVE-2023-42916",
      "published": "2023-11-30T23:15:07.223Z",
      "modified": "2026-06-17T06:24:49.510Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.17823,
      "epss_percentile": 0.97095,
      "exploited": true,
      "kev": {
        "added": "2023-12-04",
        "due": "2023-12-25",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple macOS",
        "Apple iOS and iPadOS",
        "apple iphone_os",
        "apple ipados"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1."
    },
    {
      "id": "CVE-2023-6345",
      "url": "https://spydr.io/cve/CVE-2023-6345",
      "published": "2023-11-29T12:15:07.077Z",
      "modified": "2026-06-17T06:50:34.617Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.16468,
      "epss_percentile": 0.96908,
      "exploited": true,
      "kev": {
        "added": "2023-11-30",
        "due": "2023-12-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-49105",
      "url": "https://spydr.io/cve/CVE-2023-49105",
      "published": "2023-11-21T22:15:08.613Z",
      "modified": "2026-08-28T12:21:09.753Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.42919,
      "epss_percentile": 0.98686,
      "exploited": true,
      "kev": {
        "added": "2026-08-27",
        "due": "2026-08-30",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "owncloud"
      ],
      "products": [
        "owncloud server"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0."
    },
    {
      "id": "CVE-2023-49103",
      "url": "https://spydr.io/cve/CVE-2023-49103",
      "published": "2023-11-21T22:15:08.277Z",
      "modified": "2026-06-17T06:35:22.550Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.78428,
      "epss_percentile": 0.99574,
      "exploited": true,
      "kev": {
        "added": "2023-11-30",
        "due": "2023-12-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "owncloud"
      ],
      "products": [
        "owncloud graph api"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure."
    },
    {
      "id": "CVE-2023-48365",
      "url": "https://spydr.io/cve/CVE-2023-48365",
      "published": "2023-11-15T22:15:28.027Z",
      "modified": "2026-06-17T06:34:06.873Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.47453,
      "epss_percentile": 0.98812,
      "exploited": true,
      "kev": {
        "added": "2025-01-13",
        "due": "2025-02-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qlik"
      ],
      "products": [
        "qlik sense"
      ],
      "cwes": [
        "CWE-444"
      ],
      "description": "Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265."
    },
    {
      "id": "CVE-2023-36424",
      "url": "https://spydr.io/cve/CVE-2023-36424",
      "published": "2023-11-14T18:15:45.990Z",
      "modified": "2026-06-17T06:06:15.630Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12184,
      "epss_percentile": 0.96057,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-36036",
      "url": "https://spydr.io/cve/CVE-2023-36036",
      "published": "2023-11-14T18:15:33.033Z",
      "modified": "2026-06-17T06:05:43.003Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1667,
      "epss_percentile": 0.96948,
      "exploited": true,
      "kev": {
        "added": "2023-11-14",
        "due": "2023-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-36033",
      "url": "https://spydr.io/cve/CVE-2023-36033",
      "published": "2023-11-14T18:15:32.677Z",
      "modified": "2026-06-17T06:05:42.567Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10945,
      "epss_percentile": 0.95777,
      "exploited": true,
      "kev": {
        "added": "2023-11-14",
        "due": "2023-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-822",
        "CWE-119"
      ],
      "description": "Windows DWM Core Library Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-36025",
      "url": "https://spydr.io/cve/CVE-2023-36025",
      "published": "2023-11-14T18:15:31.867Z",
      "modified": "2026-06-17T06:05:41.527Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88085,
      "epss_percentile": 0.99764,
      "exploited": true,
      "kev": {
        "added": "2023-11-14",
        "due": "2023-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012"
      ],
      "cwes": [],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-47246",
      "url": "https://spydr.io/cve/CVE-2023-47246",
      "published": "2023-11-10T06:15:30.510Z",
      "modified": "2026-07-31T04:16:43.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98851,
      "epss_percentile": 0.99927,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-12-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sysaid"
      ],
      "products": [
        "sysaid_on-premises"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023."
    },
    {
      "id": "CVE-2023-22518",
      "url": "https://spydr.io/cve/CVE-2023-22518",
      "published": "2023-10-31T15:15:08.573Z",
      "modified": "2026-06-17T05:35:37.490Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99996,
      "exploited": true,
      "kev": {
        "added": "2023-11-07",
        "due": "2023-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
    },
    {
      "id": "CVE-2023-46604",
      "url": "https://spydr.io/cve/CVE-2023-46604",
      "published": "2023-10-27T15:15:14.017Z",
      "modified": "2026-06-17T06:31:11.370Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99891,
      "epss_percentile": 0.99965,
      "exploited": true,
      "kev": {
        "added": "2023-11-02",
        "due": "2023-11-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache ActiveMQ",
        "Apache Software Foundation Apache ActiveMQ Legacy OpenWire Module"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue."
    },
    {
      "id": "CVE-2023-46748",
      "url": "https://spydr.io/cve/CVE-2023-46748",
      "published": "2023-10-26T21:15:08.177Z",
      "modified": "2026-06-17T06:31:32.820Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04468,
      "epss_percentile": 0.91173,
      "exploited": true,
      "kev": {
        "added": "2023-10-31",
        "due": "2023-11-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated"
    },
    {
      "id": "CVE-2023-46747",
      "url": "https://spydr.io/cve/CVE-2023-46747",
      "published": "2023-10-26T21:15:08.097Z",
      "modified": "2026-06-17T06:31:32.640Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96515,
      "epss_percentile": 0.99881,
      "exploited": true,
      "kev": {
        "added": "2023-10-31",
        "due": "2023-11-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-288",
        "CWE-306"
      ],
      "description": "Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated"
    },
    {
      "id": "CVE-2023-43208",
      "url": "https://spydr.io/cve/CVE-2023-43208",
      "published": "2023-10-26T17:15:09.033Z",
      "modified": "2026-06-17T06:25:15.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82708,
      "epss_percentile": 0.99661,
      "exploited": true,
      "kev": {
        "added": "2024-05-20",
        "due": "2024-06-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nextgen"
      ],
      "products": [
        "nextgen mirth connect"
      ],
      "cwes": [
        "CWE-78",
        "CWE-502"
      ],
      "description": "NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
