{
  "query": {
    "exploited": "1",
    "page": "32"
  },
  "count": 20,
  "total": 1734,
  "page": 32,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T02:47:12.621Z",
    "kev": "2026-10-07T02:46:12.406Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T02:47:12.620Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=32",
    "next": "https://spydr.io/threats.json?exploited=1&page=33"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-35311",
      "url": "https://spydr.io/cve/CVE-2023-35311",
      "published": "2023-07-11T18:15:17.177Z",
      "modified": "2026-06-17T06:04:38.140Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.15522,
      "epss_percentile": 0.96723,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office LTSC 2021",
        "Microsoft Office 2019",
        "Microsoft Outlook 2016",
        "Microsoft Outlook 2013",
        "Microsoft Outlook 2013 Service Pack 1"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "Microsoft Outlook Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-32049",
      "url": "https://spydr.io/cve/CVE-2023-32049",
      "published": "2023-07-11T18:15:13.430Z",
      "modified": "2026-06-17T05:57:57.393Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04156,
      "epss_percentile": 0.90585,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-32046",
      "url": "https://spydr.io/cve/CVE-2023-32046",
      "published": "2023-07-11T18:15:13.313Z",
      "modified": "2026-06-17T05:57:57.037Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.10049,
      "epss_percentile": 0.95504,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows MSHTML Platform Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-24489",
      "url": "https://spydr.io/cve/CVE-2023-24489",
      "published": "2023-07-10T22:15:09.197Z",
      "modified": "2026-06-17T05:39:22.423Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97343,
      "epss_percentile": 0.99898,
      "exploited": true,
      "kev": {
        "added": "2023-08-16",
        "due": "2023-09-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix ShareFile Storage Zones Controller"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller."
    },
    {
      "id": "CVE-2023-34192",
      "url": "https://spydr.io/cve/CVE-2023-34192",
      "published": "2023-07-06T16:15:10.047Z",
      "modified": "2026-06-17T06:03:05.923Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77266,
      "epss_percentile": 0.99545,
      "exploited": true,
      "kev": {
        "added": "2025-02-25",
        "due": "2025-03-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function."
    },
    {
      "id": "CVE-2023-21237",
      "url": "https://spydr.io/cve/CVE-2023-21237",
      "published": "2023-06-28T18:15:16.560Z",
      "modified": "2026-06-17T05:32:08.713Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00266,
      "epss_percentile": 0.16885,
      "exploited": true,
      "kev": {
        "added": "2024-03-05",
        "due": "2024-03-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android",
        "google android"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912"
    },
    {
      "id": "CVE-2023-32439",
      "url": "https://spydr.io/cve/CVE-2023-32439",
      "published": "2023-06-23T18:15:13.813Z",
      "modified": "2026-06-17T05:58:50.663Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23968,
      "epss_percentile": 0.97782,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple Safari",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-32435",
      "url": "https://spydr.io/cve/CVE-2023-32435",
      "published": "2023-06-23T18:15:13.767Z",
      "modified": "2026-06-17T05:58:50.090Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22951,
      "epss_percentile": 0.97695,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple Safari"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7."
    },
    {
      "id": "CVE-2023-32434",
      "url": "https://spydr.io/cve/CVE-2023-32434",
      "published": "2023-06-23T18:15:13.720Z",
      "modified": "2026-06-17T05:58:49.887Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.51517,
      "epss_percentile": 0.98916,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7."
    },
    {
      "id": "CVE-2023-32409",
      "url": "https://spydr.io/cve/CVE-2023-32409",
      "published": "2023-06-23T18:15:13.183Z",
      "modified": "2026-06-17T05:58:47.027Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.1653,
      "epss_percentile": 0.96925,
      "exploited": true,
      "kev": {
        "added": "2023-05-22",
        "due": "2023-06-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple tvOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-32373",
      "url": "https://spydr.io/cve/CVE-2023-32373",
      "published": "2023-06-23T18:15:12.007Z",
      "modified": "2026-06-17T05:58:42.273Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12172,
      "epss_percentile": 0.96054,
      "exploited": true,
      "kev": {
        "added": "2023-05-22",
        "due": "2023-06-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-28204",
      "url": "https://spydr.io/cve/CVE-2023-28204",
      "published": "2023-06-23T18:15:11.333Z",
      "modified": "2026-06-17T05:47:05.880Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.14292,
      "epss_percentile": 0.96512,
      "exploited": true,
      "kev": {
        "added": "2023-05-22",
        "due": "2023-06-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-2533",
      "url": "https://spydr.io/cve/CVE-2023-2533",
      "published": "2023-06-20T15:15:11.560Z",
      "modified": "2026-06-17T05:52:47.993Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28621,
      "epss_percentile": 0.98091,
      "exploited": true,
      "kev": {
        "added": "2025-07-28",
        "due": "2025-08-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut NG/MF"
      ],
      "cwes": [
        "CWE-352"
      ],
      "description": "A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes."
    },
    {
      "id": "CVE-2023-27992",
      "url": "https://spydr.io/cve/CVE-2023-27992",
      "published": "2023-06-19T12:15:09.433Z",
      "modified": "2026-06-17T05:46:20.047Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.82828,
      "epss_percentile": 0.99664,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel NAS326 firmware",
        "Zyxel NAS540 firmware",
        "Zyxel NAS542 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request."
    },
    {
      "id": "CVE-2023-29360",
      "url": "https://spydr.io/cve/CVE-2023-29360",
      "published": "2023-06-14T00:15:10.067Z",
      "modified": "2026-06-17T05:49:53.300Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.2162,
      "epss_percentile": 0.97569,
      "exploited": true,
      "kev": {
        "added": "2024-02-29",
        "due": "2024-03-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Microsoft Streaming Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-29357",
      "url": "https://spydr.io/cve/CVE-2023-29357",
      "published": "2023-06-14T00:15:09.903Z",
      "modified": "2026-06-17T05:49:52.747Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99984,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2024-01-10",
        "due": "2024-01-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Server 2019"
      ],
      "cwes": [
        "CWE-303"
      ],
      "description": "Microsoft SharePoint Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-20867",
      "url": "https://spydr.io/cve/CVE-2023-20867",
      "published": "2023-06-13T17:15:14.070Z",
      "modified": "2026-06-17T05:31:03.380Z",
      "score": 3.9,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.1353,
      "epss_percentile": 0.96355,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware Tools"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine."
    },
    {
      "id": "CVE-2023-27997",
      "url": "https://spydr.io/cve/CVE-2023-27997",
      "published": "2023-06-13T09:15:16.613Z",
      "modified": "2026-07-31T04:16:43.707Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85689,
      "epss_percentile": 0.99721,
      "exploited": true,
      "kev": {
        "added": "2023-06-13",
        "due": "2023-07-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS-6K7K",
        "Fortinet FortiProxy",
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests."
    },
    {
      "id": "CVE-2023-20887",
      "url": "https://spydr.io/cve/CVE-2023-20887",
      "published": "2023-06-07T15:15:09.190Z",
      "modified": "2026-06-17T05:31:07.117Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98281,
      "epss_percentile": 0.99915,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "Aria Operations for Networks (Formerly vRealize Network Insight)"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution."
    },
    {
      "id": "CVE-2023-33538",
      "url": "https://spydr.io/cve/CVE-2023-33538",
      "published": "2023-06-07T04:15:10.623Z",
      "modified": "2026-06-17T06:01:53.847Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41606,
      "epss_percentile": 0.98646,
      "exploited": true,
      "kev": {
        "added": "2025-06-16",
        "due": "2025-07-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tp-link"
      ],
      "products": [
        "tp-link tl-wr940n firmware",
        "tp-link tl-wr841n firmware",
        "tp-link tl-wr740n firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm ."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
