{
  "query": {
    "exploited": "1",
    "page": "31"
  },
  "count": 20,
  "total": 1734,
  "page": 31,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T00:46:23.556Z",
    "kev": "2026-10-07T01:46:10.380Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T01:47:10.349Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=31",
    "next": "https://spydr.io/threats.json?exploited=1&page=32"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-38035",
      "url": "https://spydr.io/cve/CVE-2023-38035",
      "published": "2023-08-21T17:15:47.457Z",
      "modified": "2026-06-17T06:09:16.930Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9995,
      "epss_percentile": 0.99974,
      "exploited": true,
      "kev": {
        "added": "2023-08-22",
        "due": "2023-09-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti MobileIron Sentry"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration."
    },
    {
      "id": "CVE-2023-36847",
      "url": "https://spydr.io/cve/CVE-2023-36847",
      "published": "2023-08-17T20:15:10.553Z",
      "modified": "2026-06-17T06:07:13.203Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.83455,
      "epss_percentile": 0.99678,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3."
    },
    {
      "id": "CVE-2023-36846",
      "url": "https://spydr.io/cve/CVE-2023-36846",
      "published": "2023-08-17T20:15:10.457Z",
      "modified": "2026-06-17T06:07:12.957Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.93473,
      "epss_percentile": 0.99839,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3."
    },
    {
      "id": "CVE-2023-36845",
      "url": "https://spydr.io/cve/CVE-2023-36845",
      "published": "2023-08-17T20:15:10.360Z",
      "modified": "2026-06-17T06:07:12.753Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "juniper.net",
      "epss": 0.9507,
      "epss_percentile": 0.99862,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-473"
      ],
      "description": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2."
    },
    {
      "id": "CVE-2023-36844",
      "url": "https://spydr.io/cve/CVE-2023-36844",
      "published": "2023-08-17T20:15:10.267Z",
      "modified": "2026-06-17T06:07:12.573Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.89958,
      "epss_percentile": 0.99792,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-473"
      ],
      "description": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2."
    },
    {
      "id": "CVE-2023-35082",
      "url": "https://spydr.io/cve/CVE-2023-35082",
      "published": "2023-08-15T16:15:11.633Z",
      "modified": "2026-06-17T06:04:23.757Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99996,
      "exploited": true,
      "kev": {
        "added": "2024-01-18",
        "due": "2024-02-08",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti EPMM"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier."
    },
    {
      "id": "CVE-2022-48503",
      "url": "https://spydr.io/cve/CVE-2022-48503",
      "published": "2023-08-14T23:15:10.490Z",
      "modified": "2026-06-17T05:15:33.720Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03213,
      "epss_percentile": 0.87789,
      "exploited": true,
      "kev": {
        "added": "2025-10-20",
        "due": "2025-11-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple tvOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-129"
      ],
      "description": "The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution."
    },
    {
      "id": "CVE-2023-38180",
      "url": "https://spydr.io/cve/CVE-2023-38180",
      "published": "2023-08-08T19:15:10.367Z",
      "modified": "2026-08-10T16:18:37.320Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "microsoft.com",
      "epss": 0.14016,
      "epss_percentile": 0.96463,
      "exploited": true,
      "kev": {
        "added": "2023-08-09",
        "due": "2023-08-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft .NET 6.0",
        "Microsoft .NET 7.0",
        "Microsoft ASP.NET Core 2.1",
        "Microsoft Visual Studio 2022 version 17.2",
        "Microsoft Visual Studio 2022 version 17.4",
        "Microsoft Visual Studio 2022 version 17.6"
      ],
      "cwes": [
        "CWE-400"
      ],
      "description": ".NET and Visual Studio Denial of Service Vulnerability"
    },
    {
      "id": "CVE-2023-38950",
      "url": "https://spydr.io/cve/CVE-2023-38950",
      "published": "2023-08-03T23:15:11.117Z",
      "modified": "2026-07-09T13:57:25.203Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.92468,
      "epss_percentile": 0.99824,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zkteco"
      ],
      "products": [
        "zkteco biotime"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime."
    },
    {
      "id": "CVE-2023-35081",
      "url": "https://spydr.io/cve/CVE-2023-35081",
      "published": "2023-08-03T18:15:11.303Z",
      "modified": "2026-06-17T06:04:23.637Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.63577,
      "epss_percentile": 0.99195,
      "exploited": true,
      "kev": {
        "added": "2023-07-31",
        "due": "2023-08-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti EPMM"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance."
    },
    {
      "id": "CVE-2023-37580",
      "url": "https://spydr.io/cve/CVE-2023-37580",
      "published": "2023-07-31T16:15:10.327Z",
      "modified": "2026-06-17T06:08:30.210Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.49083,
      "epss_percentile": 0.98855,
      "exploited": true,
      "kev": {
        "added": "2023-07-27",
        "due": "2023-08-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client."
    },
    {
      "id": "CVE-2023-38606",
      "url": "https://spydr.io/cve/CVE-2023-38606",
      "published": "2023-07-27T00:15:16.173Z",
      "modified": "2026-06-17T06:10:49.160Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.02899,
      "epss_percentile": 0.86503,
      "exploited": true,
      "kev": {
        "added": "2023-07-26",
        "due": "2023-08-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple tvOS",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple watchOS"
      ],
      "cwes": [],
      "description": "This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1."
    },
    {
      "id": "CVE-2023-37450",
      "url": "https://spydr.io/cve/CVE-2023-37450",
      "published": "2023-07-27T00:15:15.497Z",
      "modified": "2026-06-17T06:08:14.593Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1895,
      "epss_percentile": 0.9723,
      "exploited": true,
      "kev": {
        "added": "2023-07-13",
        "due": "2023-08-03",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple tvOS",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple watchOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-35078",
      "url": "https://spydr.io/cve/CVE-2023-35078",
      "published": "2023-07-25T07:15:10.897Z",
      "modified": "2026-08-05T05:16:38.037Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99998,
      "exploited": true,
      "kev": {
        "added": "2023-07-25",
        "due": "2023-08-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication."
    },
    {
      "id": "CVE-2023-38203",
      "url": "https://spydr.io/cve/CVE-2023-38203",
      "published": "2023-07-20T16:15:12.180Z",
      "modified": "2026-06-17T06:09:39.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.97074,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-3519",
      "url": "https://spydr.io/cve/CVE-2023-3519",
      "published": "2023-07-19T18:15:11.513Z",
      "modified": "2026-08-05T05:16:39.130Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99749,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2023-07-19",
        "due": "2023-08-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix NetScaler ADC",
        "Citrix NetScaler Gateway"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Unauthenticated remote code execution"
    },
    {
      "id": "CVE-2023-29300",
      "url": "https://spydr.io/cve/CVE-2023-29300",
      "published": "2023-07-12T16:15:11.733Z",
      "modified": "2026-06-17T05:49:44.993Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.99991,
      "epss_percentile": 0.99986,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-29298",
      "url": "https://spydr.io/cve/CVE-2023-29298",
      "published": "2023-07-12T16:15:11.623Z",
      "modified": "2026-06-17T05:49:44.727Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.9979,
      "epss_percentile": 0.99955,
      "exploited": true,
      "kev": {
        "added": "2023-07-20",
        "due": "2023-08-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-36884",
      "url": "https://spydr.io/cve/CVE-2023-36884",
      "published": "2023-07-11T19:15:09.623Z",
      "modified": "2026-08-10T16:18:30.637Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.98932,
      "epss_percentile": 0.99928,
      "exploited": true,
      "kev": {
        "added": "2023-07-17",
        "due": "2023-08-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Windows Search Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-36874",
      "url": "https://spydr.io/cve/CVE-2023-36874",
      "published": "2023-07-11T18:15:20.733Z",
      "modified": "2026-06-17T06:07:16.410Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.42564,
      "epss_percentile": 0.98674,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows Error Reporting Service Elevation of Privilege Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
