{
  "query": {
    "exploited": "1",
    "page": "33"
  },
  "count": 20,
  "total": 1734,
  "page": 33,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T02:47:12.621Z",
    "kev": "2026-10-07T03:46:14.963Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T03:47:15.195Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=33",
    "next": "https://spydr.io/threats.json?exploited=1&page=34"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-3079",
      "url": "https://spydr.io/cve/CVE-2023-3079",
      "published": "2023-06-05T22:15:12.383Z",
      "modified": "2026-06-17T06:13:18.817Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3211,
      "epss_percentile": 0.98275,
      "exploited": true,
      "kev": {
        "added": "2023-06-07",
        "due": "2023-06-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-34362",
      "url": "https://spydr.io/cve/CVE-2023-34362",
      "published": "2023-06-02T14:15:09.487Z",
      "modified": "2026-06-17T06:03:28.760Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99934,
      "epss_percentile": 0.99971,
      "exploited": true,
      "kev": {
        "added": "2023-06-02",
        "due": "2023-06-23",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "progress"
      ],
      "products": [
        "progress moveit_transfer",
        "progress moveit_cloud"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions."
    },
    {
      "id": "CVE-2023-32315",
      "url": "https://spydr.io/cve/CVE-2023-32315",
      "published": "2023-05-26T23:15:16.643Z",
      "modified": "2026-06-17T05:58:33.247Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99993,
      "exploited": true,
      "kev": {
        "added": "2023-08-24",
        "due": "2023-09-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "igniterealtime"
      ],
      "products": [
        "igniterealtime Openfire"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice."
    },
    {
      "id": "CVE-2023-2868",
      "url": "https://spydr.io/cve/CVE-2023-2868",
      "published": "2023-05-24T19:15:09.363Z",
      "modified": "2026-06-17T05:53:39.770Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87691,
      "epss_percentile": 0.99758,
      "exploited": true,
      "kev": {
        "added": "2023-05-26",
        "due": "2023-06-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Barracuda"
      ],
      "products": [
        "Barracuda Email Security Gateway"
      ],
      "cwes": [
        "CWE-20",
        "CWE-77"
      ],
      "description": "A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances."
    },
    {
      "id": "CVE-2023-33246",
      "url": "https://spydr.io/cve/CVE-2023-33246",
      "published": "2023-05-24T15:15:09.553Z",
      "modified": "2026-06-17T06:01:24.160Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96568,
      "epss_percentile": 0.99882,
      "exploited": true,
      "kev": {
        "added": "2023-09-06",
        "due": "2023-09-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache RocketMQ"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x ."
    },
    {
      "id": "CVE-2023-33010",
      "url": "https://spydr.io/cve/CVE-2023-33010",
      "published": "2023-05-24T13:15:09.640Z",
      "modified": "2026-06-17T06:00:17.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29024,
      "epss_percentile": 0.98118,
      "exploited": true,
      "kev": {
        "added": "2023-06-05",
        "due": "2023-06-26",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ATP series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel USG FLEX 50(W) firmware",
        "Zyxel USG20(W)-VPN firmware",
        "Zyxel VPN series firmware",
        "Zyxel ZyWALL/USG series firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device."
    },
    {
      "id": "CVE-2023-33009",
      "url": "https://spydr.io/cve/CVE-2023-33009",
      "published": "2023-05-24T13:15:09.560Z",
      "modified": "2026-06-17T06:00:16.810Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.28144,
      "epss_percentile": 0.98065,
      "exploited": true,
      "kev": {
        "added": "2023-06-05",
        "due": "2023-06-26",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ATP series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel USG FLEX 50(W) firmware",
        "Zyxel USG20(W)-VPN firmware",
        "Zyxel VPN series firmware",
        "Zyxel ZyWALL/USG series firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device."
    },
    {
      "id": "CVE-2023-29336",
      "url": "https://spydr.io/cve/CVE-2023-29336",
      "published": "2023-05-09T18:15:13.840Z",
      "modified": "2026-06-17T05:49:49.897Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.41185,
      "epss_percentile": 0.98632,
      "exploited": true,
      "kev": {
        "added": "2023-05-09",
        "due": "2023-05-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-24955",
      "url": "https://spydr.io/cve/CVE-2023-24955",
      "published": "2023-05-09T18:15:13.317Z",
      "modified": "2026-06-17T05:40:22.183Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.84974,
      "epss_percentile": 0.99708,
      "exploited": true,
      "kev": {
        "added": "2024-03-26",
        "due": "2024-04-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Microsoft SharePoint Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-21492",
      "url": "https://spydr.io/cve/CVE-2023-21492",
      "published": "2023-05-04T21:15:10.070Z",
      "modified": "2026-06-17T05:32:48.390Z",
      "score": 4.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.02554,
      "epss_percentile": 0.8455,
      "exploited": true,
      "kev": {
        "added": "2023-05-19",
        "due": "2023-06-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-532"
      ],
      "description": "Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR."
    },
    {
      "id": "CVE-2023-29552",
      "url": "https://spydr.io/cve/CVE-2023-29552",
      "published": "2023-04-25T16:15:09.537Z",
      "modified": "2026-06-17T05:50:32.263Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.63975,
      "epss_percentile": 0.99205,
      "exploited": true,
      "kev": {
        "added": "2023-11-08",
        "due": "2023-11-29",
        "action": "Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netapp",
        "suse",
        "vmware",
        "service location protocol project"
      ],
      "products": [
        "netapp smi-s provider",
        "suse manager server",
        "suse linux enterprise server",
        "vmware esxi",
        "service location protocol project service location protocol"
      ],
      "cwes": [],
      "description": "The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor."
    },
    {
      "id": "CVE-2023-28771",
      "url": "https://spydr.io/cve/CVE-2023-28771",
      "published": "2023-04-25T02:15:08.743Z",
      "modified": "2026-06-17T05:48:44.217Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.99284,
      "epss_percentile": 0.99937,
      "exploited": true,
      "kev": {
        "added": "2023-05-31",
        "due": "2023-06-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ZyWALL/USG series firmware",
        "Zyxel VPN series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel ATP series firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device."
    },
    {
      "id": "CVE-2023-27524",
      "url": "https://spydr.io/cve/CVE-2023-27524",
      "published": "2023-04-24T16:15:07.843Z",
      "modified": "2026-06-17T05:45:23.917Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97405,
      "epss_percentile": 0.99899,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Superset"
      ],
      "cwes": [
        "CWE-1188"
      ],
      "description": "Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable."
    },
    {
      "id": "CVE-2023-27351",
      "url": "https://spydr.io/cve/CVE-2023-27351",
      "published": "2023-04-20T16:15:07.723Z",
      "modified": "2026-10-01T19:17:14.823Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.78052,
      "epss_percentile": 0.99567,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut NG"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226."
    },
    {
      "id": "CVE-2023-27350",
      "url": "https://spydr.io/cve/CVE-2023-27350",
      "published": "2023-04-20T16:15:07.653Z",
      "modified": "2026-06-17T05:44:50.950Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99995,
      "exploited": true,
      "kev": {
        "added": "2023-04-21",
        "due": "2023-05-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut NG"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987."
    },
    {
      "id": "CVE-2023-2136",
      "url": "https://spydr.io/cve/CVE-2023-2136",
      "published": "2023-04-19T04:15:31.607Z",
      "modified": "2026-06-17T05:51:32.013Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05739,
      "epss_percentile": 0.92845,
      "exploited": true,
      "kev": {
        "added": "2023-04-21",
        "due": "2023-05-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-2033",
      "url": "https://spydr.io/cve/CVE-2023-2033",
      "published": "2023-04-14T19:15:09.453Z",
      "modified": "2026-06-17T05:51:14.400Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.40798,
      "epss_percentile": 0.98619,
      "exploited": true,
      "kev": {
        "added": "2023-04-17",
        "due": "2023-05-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-20118",
      "url": "https://spydr.io/cve/CVE-2023-20118",
      "published": "2023-04-13T07:15:21.080Z",
      "modified": "2026-06-17T05:29:31.353Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54107,
      "epss_percentile": 0.98981,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device. Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds [\"#workarounds\"] section. {{value}} [\"%7b%7bvalue%7d%7d\"])}]]"
    },
    {
      "id": "CVE-2023-28252",
      "url": "https://spydr.io/cve/CVE-2023-28252",
      "published": "2023-04-11T21:15:25.137Z",
      "modified": "2026-06-17T05:47:14.567Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.48973,
      "epss_percentile": 0.98851,
      "exploited": true,
      "kev": {
        "added": "2023-04-11",
        "due": "2023-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-28229",
      "url": "https://spydr.io/cve/CVE-2023-28229",
      "published": "2023-04-11T21:15:23.387Z",
      "modified": "2026-06-17T05:47:11.090Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01671,
      "epss_percentile": 0.7604,
      "exploited": true,
      "kev": {
        "added": "2023-10-04",
        "due": "2023-10-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2"
      ],
      "cwes": [
        "CWE-591"
      ],
      "description": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
