{
  "query": {
    "exploited": "1",
    "page": "29"
  },
  "count": 20,
  "total": 1734,
  "page": 29,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T22:46:18.712Z",
    "kev": "2026-10-06T23:45:20.765Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T23:46:20.864Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=29",
    "next": "https://spydr.io/threats.json?exploited=1&page=30"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-34048",
      "url": "https://spydr.io/cve/CVE-2023-34048",
      "published": "2023-10-25T18:17:27.897Z",
      "modified": "2026-06-17T06:02:47.860Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99428,
      "epss_percentile": 0.99942,
      "exploited": true,
      "kev": {
        "added": "2024-01-22",
        "due": "2024-02-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation (VMware vCenter Server)",
        "vmware cloud_foundation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution."
    },
    {
      "id": "CVE-2023-20273",
      "url": "https://spydr.io/cve/CVE-2023-20273",
      "published": "2023-10-25T18:17:23.017Z",
      "modified": "2026-06-17T05:30:12.820Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89634,
      "epss_percentile": 0.99786,
      "exploited": true,
      "kev": {
        "added": "2023-10-23",
        "due": "2023-10-27",
        "action": "Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS XE Software"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges."
    },
    {
      "id": "CVE-2023-5631",
      "url": "https://spydr.io/cve/CVE-2023-5631",
      "published": "2023-10-18T15:15:08.727Z",
      "modified": "2026-06-17T06:48:58.673Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.75873,
      "epss_percentile": 0.99516,
      "exploited": true,
      "kev": {
        "added": "2023-10-26",
        "due": "2023-11-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Roundcube"
      ],
      "products": [
        "Roundcubemail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code."
    },
    {
      "id": "CVE-2023-45727",
      "url": "https://spydr.io/cve/CVE-2023-45727",
      "published": "2023-10-18T10:15:08.643Z",
      "modified": "2026-06-17T06:29:25.203Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.03542,
      "epss_percentile": 0.88943,
      "exploited": true,
      "kev": {
        "added": "2024-12-03",
        "due": "2024-12-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "North Grid Corporation",
        "northgrid"
      ],
      "products": [
        "North Grid Corporation Proself Enterprise/Standard Edition",
        "North Grid Corporation Proself Gateway Edition",
        "North Grid Corporation Proself Mail Sanitize Edition",
        "northgrid proself"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker."
    },
    {
      "id": "CVE-2023-20198",
      "url": "https://spydr.io/cve/CVE-2023-20198",
      "published": "2023-10-16T16:15:10.023Z",
      "modified": "2026-06-17T05:29:47.117Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99571,
      "epss_percentile": 0.99946,
      "exploited": true,
      "kev": {
        "added": "2023-10-16",
        "due": "2023-10-20",
        "action": "Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS XE Software"
      ],
      "cwes": [
        "CWE-420"
      ],
      "description": "Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343."
    },
    {
      "id": "CVE-2023-41763",
      "url": "https://spydr.io/cve/CVE-2023-41763",
      "published": "2023-10-10T18:15:18.150Z",
      "modified": "2026-06-17T06:22:45.340Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.90353,
      "epss_percentile": 0.99798,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Skype for Business Server 2015 CU13",
        "Microsoft Skype for Business Server 2019 CU7"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Skype for Business Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-36584",
      "url": "https://spydr.io/cve/CVE-2023-36584",
      "published": "2023-10-10T18:15:14.280Z",
      "modified": "2026-06-17T06:06:36.723Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.03055,
      "epss_percentile": 0.87168,
      "exploited": true,
      "kev": {
        "added": "2023-11-16",
        "due": "2023-12-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-36563",
      "url": "https://spydr.io/cve/CVE-2023-36563",
      "published": "2023-10-10T18:15:13.003Z",
      "modified": "2026-06-17T06:06:32.857Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.20719,
      "epss_percentile": 0.97475,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Microsoft WordPad Information Disclosure Vulnerability"
    },
    {
      "id": "CVE-2023-4966",
      "url": "https://spydr.io/cve/CVE-2023-4966",
      "published": "2023-10-10T14:15:10.977Z",
      "modified": "2026-07-31T04:16:44.230Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99997,
      "exploited": true,
      "kev": {
        "added": "2023-10-18",
        "due": "2023-11-08",
        "action": "Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix NetScaler ADC",
        "Citrix NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server."
    },
    {
      "id": "CVE-2023-44487",
      "url": "https://spydr.io/cve/CVE-2023-44487",
      "published": "2023-10-10T14:15:10.883Z",
      "modified": "2026-08-11T19:37:30.880Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99998,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ietf",
        "Siemens"
      ],
      "products": [
        "ietf http",
        "Siemens RUGGEDCOM APE1808",
        "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
        "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
        "Siemens SINEC NMS",
        "Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
      ],
      "cwes": [
        "CWE-400"
      ],
      "description": "The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023."
    },
    {
      "id": "CVE-2023-42824",
      "url": "https://spydr.io/cve/CVE-2023-42824",
      "published": "2023-10-04T19:15:10.490Z",
      "modified": "2026-06-17T06:24:36.060Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01095,
      "epss_percentile": 0.6445,
      "exploited": true,
      "kev": {
        "added": "2023-10-05",
        "due": "2023-10-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6."
    },
    {
      "id": "CVE-2023-22515",
      "url": "https://spydr.io/cve/CVE-2023-22515",
      "published": "2023-10-04T14:15:10.440Z",
      "modified": "2026-06-17T05:35:37.127Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99223,
      "epss_percentile": 0.99936,
      "exploited": true,
      "kev": {
        "added": "2023-10-05",
        "due": "2023-10-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
    },
    {
      "id": "CVE-2023-4911",
      "url": "https://spydr.io/cve/CVE-2023-4911",
      "published": "2023-10-03T18:15:10.463Z",
      "modified": "2026-06-17T06:38:52.787Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.63769,
      "epss_percentile": 0.99202,
      "exploited": true,
      "kev": {
        "added": "2023-11-21",
        "due": "2023-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Red Hat",
        "Siemens"
      ],
      "products": [
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 8.6 Extended Update Support",
        "Red Hat Enterprise Linux 9",
        "Red Hat Enterprise Linux 9.0 Extended Update Support",
        "Red Hat Virtualization 4 for Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 6",
        "Red Hat Enterprise Linux 7",
        "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
        "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
        "Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges."
    },
    {
      "id": "CVE-2023-4211",
      "url": "https://spydr.io/cve/CVE-2023-4211",
      "published": "2023-10-01T18:15:09.927Z",
      "modified": "2026-06-17T06:37:19.410Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01098,
      "epss_percentile": 0.64539,
      "exploited": true,
      "kev": {
        "added": "2023-10-03",
        "due": "2023-10-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Arm Ltd"
      ],
      "products": [
        "Arm Ltd Midgard GPU Kernel Driver",
        "Arm Ltd Bifrost GPU Kernel Driver",
        "Arm Ltd Valhall GPU Kernel Driver",
        "Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory."
    },
    {
      "id": "CVE-2023-5217",
      "url": "https://spydr.io/cve/CVE-2023-5217",
      "published": "2023-09-28T16:15:10.980Z",
      "modified": "2026-06-17T06:48:06.467Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.49013,
      "epss_percentile": 0.98852,
      "exploited": true,
      "kev": {
        "added": "2023-10-02",
        "due": "2023-10-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome",
        "Google libvpx"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-20109",
      "url": "https://spydr.io/cve/CVE-2023-20109",
      "published": "2023-09-27T18:15:10.860Z",
      "modified": "2026-06-17T05:29:29.667Z",
      "score": 6.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02484,
      "epss_percentile": 0.84079,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS",
        "Cisco IOS XE Software"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details [\"#details\"] section of this advisory."
    },
    {
      "id": "CVE-2023-40044",
      "url": "https://spydr.io/cve/CVE-2023-40044",
      "published": "2023-09-27T15:18:57.307Z",
      "modified": "2026-06-17T06:15:55.110Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90355,
      "epss_percentile": 0.99798,
      "exploited": true,
      "kev": {
        "added": "2023-10-05",
        "due": "2023-10-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software Corporation"
      ],
      "products": [
        "Progress Software Corporation WS_FTP Server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system."
    },
    {
      "id": "CVE-2023-36851",
      "url": "https://spydr.io/cve/CVE-2023-36851",
      "published": "2023-09-27T15:18:54.877Z",
      "modified": "2026-06-17T06:07:13.967Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.01123,
      "epss_percentile": 0.65148,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2."
    },
    {
      "id": "CVE-2023-43770",
      "url": "https://spydr.io/cve/CVE-2023-43770",
      "published": "2023-09-22T06:15:10.090Z",
      "modified": "2026-06-17T06:26:24.770Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.6366,
      "epss_percentile": 0.99198,
      "exploited": true,
      "kev": {
        "added": "2024-02-12",
        "due": "2024-03-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "debian"
      ],
      "products": [
        "roundcube webmail",
        "debian_linux"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior."
    },
    {
      "id": "CVE-2023-41993",
      "url": "https://spydr.io/cve/CVE-2023-41993",
      "published": "2023-09-21T19:15:11.660Z",
      "modified": "2026-06-17T06:23:13.433Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24349,
      "epss_percentile": 0.97811,
      "exploited": true,
      "kev": {
        "added": "2023-09-25",
        "due": "2023-10-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple",
        "fedoraproject",
        "debian",
        "oracle",
        "netapp"
      ],
      "products": [
        "Apple macOS",
        "apple iphone_os",
        "apple ipad_os",
        "fedoraproject fedora",
        "debian_linux",
        "oracle graalvm",
        "oracle jdk",
        "oracle jre",
        "netapp cloud_insights_acquisition_unit",
        "netapp cloud_insights_storage_workload_security_agent",
        "netapp oncommand_insight",
        "netapp oncommand_workflow_automation"
      ],
      "cwes": [
        "CWE-754"
      ],
      "description": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
