{
  "query": {
    "exploited": "1",
    "page": "34"
  },
  "count": 20,
  "total": 1734,
  "page": 34,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T04:47:17.455Z",
    "kev": "2026-10-07T04:46:17.408Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T04:47:17.455Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=34",
    "next": "https://spydr.io/threats.json?exploited=1&page=35"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-29492",
      "url": "https://spydr.io/cve/CVE-2023-29492",
      "published": "2023-04-11T05:15:07.393Z",
      "modified": "2026-06-17T05:50:13.017Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0269,
      "epss_percentile": 0.85401,
      "exploited": true,
      "kev": {
        "added": "2023-04-13",
        "due": "2023-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "novisurvey"
      ],
      "products": [
        "novisurvey novi_survey"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data."
    },
    {
      "id": "CVE-2023-28206",
      "url": "https://spydr.io/cve/CVE-2023-28206",
      "published": "2023-04-10T19:15:07.273Z",
      "modified": "2026-06-17T05:47:06.300Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23215,
      "epss_percentile": 0.97718,
      "exploited": true,
      "kev": {
        "added": "2023-04-10",
        "due": "2023-05-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-28205",
      "url": "https://spydr.io/cve/CVE-2023-28205",
      "published": "2023-04-10T19:15:07.237Z",
      "modified": "2026-06-17T05:47:06.097Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.27076,
      "epss_percentile": 0.98,
      "exploited": true,
      "kev": {
        "added": "2023-04-10",
        "due": "2023-05-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple Safari",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-26083",
      "url": "https://spydr.io/cve/CVE-2023-26083",
      "published": "2023-04-06T16:15:07.843Z",
      "modified": "2026-06-17T05:42:38.457Z",
      "score": 3.3,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01218,
      "epss_percentile": 0.67646,
      "exploited": true,
      "kev": {
        "added": "2023-04-07",
        "due": "2023-04-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm 5th gen gpu architecture kernel driver",
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-401"
      ],
      "description": "Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata."
    },
    {
      "id": "CVE-2023-1671",
      "url": "https://spydr.io/cve/CVE-2023-1671",
      "published": "2023-04-04T10:15:07.197Z",
      "modified": "2026-06-17T05:28:29.373Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99992,
      "exploited": true,
      "kev": {
        "added": "2023-11-16",
        "due": "2023-12-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sophos"
      ],
      "products": [
        "Sophos Web Appliance"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code."
    },
    {
      "id": "CVE-2022-43939",
      "url": "https://spydr.io/cve/CVE-2022-43939",
      "published": "2023-04-03T19:15:07.047Z",
      "modified": "2026-06-17T05:07:31.013Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92266,
      "epss_percentile": 0.99821,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Hitachi Vantara"
      ],
      "products": [
        "Hitachi Vantara Pentaho Business Analytics Server"
      ],
      "cwes": [
        "CWE-647"
      ],
      "description": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented."
    },
    {
      "id": "CVE-2022-43769",
      "url": "https://spydr.io/cve/CVE-2022-43769",
      "published": "2023-04-03T18:15:07.703Z",
      "modified": "2026-06-17T05:07:17.553Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9767,
      "epss_percentile": 0.99903,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Hitachi Vantara"
      ],
      "products": [
        "Hitachi Vantara Pentaho Business Analytics Server"
      ],
      "cwes": [
        "CWE-74",
        "CWE-94"
      ],
      "description": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream."
    },
    {
      "id": "CVE-2023-20963",
      "url": "https://spydr.io/cve/CVE-2023-20963",
      "published": "2023-03-24T20:15:10.010Z",
      "modified": "2026-06-17T05:31:19.720Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01465,
      "epss_percentile": 0.72825,
      "exploited": true,
      "kev": {
        "added": "2023-04-13",
        "due": "2023-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-295"
      ],
      "description": "In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519"
    },
    {
      "id": "CVE-2022-42948",
      "url": "https://spydr.io/cve/CVE-2022-42948",
      "published": "2023-03-24T14:15:09.927Z",
      "modified": "2026-06-17T05:05:39.117Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02706,
      "epss_percentile": 0.85493,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "helpsystems"
      ],
      "products": [
        "helpsystems cobalt strike"
      ],
      "cwes": [
        "CWE-116"
      ],
      "description": "Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI."
    },
    {
      "id": "CVE-2023-26360",
      "url": "https://spydr.io/cve/CVE-2023-26360",
      "published": "2023-03-23T20:15:15.263Z",
      "modified": "2026-06-17T05:43:10.340Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "score_source": "adobe.com",
      "epss": 0.97339,
      "epss_percentile": 0.99897,
      "exploited": true,
      "kev": {
        "added": "2023-03-15",
        "due": "2023-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-26359",
      "url": "https://spydr.io/cve/CVE-2023-26359",
      "published": "2023-03-23T20:15:15.167Z",
      "modified": "2026-06-17T05:43:10.197Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.16988,
      "epss_percentile": 0.96993,
      "exploited": true,
      "kev": {
        "added": "2023-08-21",
        "due": "2023-09-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-28434",
      "url": "https://spydr.io/cve/CVE-2023-28434",
      "published": "2023-03-22T21:15:18.427Z",
      "modified": "2026-06-17T05:47:43.610Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07917,
      "epss_percentile": 0.94572,
      "exploited": true,
      "kev": {
        "added": "2023-09-19",
        "due": "2023-10-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "minio"
      ],
      "products": [
        "minio"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`."
    },
    {
      "id": "CVE-2023-28432",
      "url": "https://spydr.io/cve/CVE-2023-28432",
      "published": "2023-03-22T21:15:18.257Z",
      "modified": "2026-06-17T05:47:42.203Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.83957,
      "epss_percentile": 0.99688,
      "exploited": true,
      "kev": {
        "added": "2023-04-21",
        "due": "2023-05-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "minio"
      ],
      "products": [
        "minio"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z."
    },
    {
      "id": "CVE-2023-0386",
      "url": "https://spydr.io/cve/CVE-2023-0386",
      "published": "2023-03-22T21:15:18.090Z",
      "modified": "2026-06-17T05:25:25.427Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0788,
      "epss_percentile": 0.94555,
      "exploited": true,
      "kev": {
        "added": "2025-06-17",
        "due": "2025-07-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "debian",
        "netapp",
        "canonical",
        "linux"
      ],
      "products": [
        "Kernel"
      ],
      "cwes": [
        "CWE-282"
      ],
      "description": "A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system."
    },
    {
      "id": "CVE-2023-25280",
      "url": "https://spydr.io/cve/CVE-2023-25280",
      "published": "2023-03-16T01:15:46.780Z",
      "modified": "2026-06-17T05:41:01.463Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97864,
      "epss_percentile": 0.99908,
      "exploited": true,
      "kev": {
        "added": "2024-09-30",
        "due": "2024-10-21",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir820la1_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp."
    },
    {
      "id": "CVE-2023-28461",
      "url": "https://spydr.io/cve/CVE-2023-28461",
      "published": "2023-03-15T23:15:10.070Z",
      "modified": "2026-08-05T05:16:37.477Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.68079,
      "epss_percentile": 0.9931,
      "exploited": true,
      "kev": {
        "added": "2024-11-25",
        "due": "2024-12-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arraynetworks"
      ],
      "products": [
        "arraynetworks arrayos_ag"
      ],
      "cwes": [
        "CWE-287",
        "CWE-306"
      ],
      "description": "Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated \"a new Array AG release with the fix will be available soon.\""
    },
    {
      "id": "CVE-2023-1389",
      "url": "https://spydr.io/cve/CVE-2023-1389",
      "published": "2023-03-15T23:15:09.403Z",
      "modified": "2026-06-17T05:27:50.687Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99992,
      "exploited": true,
      "kev": {
        "added": "2023-05-01",
        "due": "2023-05-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tp-link"
      ],
      "products": [
        "TP-Link Archer AX21 (AX1800)"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request."
    },
    {
      "id": "CVE-2023-24880",
      "url": "https://spydr.io/cve/CVE-2023-24880",
      "published": "2023-03-14T17:15:17.683Z",
      "modified": "2026-06-17T05:40:10.753Z",
      "score": 4.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.78005,
      "epss_percentile": 0.99566,
      "exploited": true,
      "kev": {
        "added": "2023-03-14",
        "due": "2023-04-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-23397",
      "url": "https://spydr.io/cve/CVE-2023-23397",
      "published": "2023-03-14T17:15:13.263Z",
      "modified": "2026-06-17T05:37:01.380Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97159,
      "epss_percentile": 0.99894,
      "exploited": true,
      "kev": {
        "added": "2023-03-14",
        "due": "2023-04-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office LTSC 2021",
        "Microsoft Outlook 2016",
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office 2019",
        "Microsoft Outlook 2013 Service Pack 1"
      ],
      "cwes": [
        "CWE-20",
        "CWE-294"
      ],
      "description": "Microsoft Outlook Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-27532",
      "url": "https://spydr.io/cve/CVE-2023-27532",
      "published": "2023-03-10T22:15:10.557Z",
      "modified": "2026-06-17T05:45:24.980Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.81326,
      "epss_percentile": 0.9963,
      "exploited": true,
      "kev": {
        "added": "2023-08-22",
        "due": "2023-09-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veeam"
      ],
      "products": [
        "Veeam Backup & Replication"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
