{
  "query": {
    "exploited": "1",
    "page": "53"
  },
  "count": 20,
  "total": 1734,
  "page": 53,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T02:48:45.529Z",
    "kev": "2026-10-08T03:49:47.849Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T03:48:47.954Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=53",
    "next": "https://spydr.io/threats.json?exploited=1&page=54"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-1647",
      "url": "https://spydr.io/cve/CVE-2021-1647",
      "published": "2021-01-12T20:15:30.727Z",
      "modified": "2026-06-17T03:32:13.953Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.39392,
      "epss_percentile": 0.98574,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft System Center Endpoint Protection",
        "Microsoft System Center 2012 R2 Endpoint Protection",
        "Microsoft Security Essentials",
        "Microsoft System Center 2012 Endpoint Protection",
        "Microsoft Windows Defender"
      ],
      "cwes": [],
      "description": "Microsoft Defender Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2021-3129",
      "url": "https://spydr.io/cve/CVE-2021-3129",
      "published": "2021-01-12T15:15:16.453Z",
      "modified": "2026-06-17T04:04:43.133Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99943,
      "epss_percentile": 0.99973,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "facade"
      ],
      "products": [
        "facade ignition"
      ],
      "cwes": [],
      "description": "Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2."
    },
    {
      "id": "CVE-2020-16017",
      "url": "https://spydr.io/cve/CVE-2020-16017",
      "published": "2021-01-08T19:15:12.727Z",
      "modified": "2026-06-17T02:57:38.610Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0273,
      "epss_percentile": 0.85641,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page."
    },
    {
      "id": "CVE-2020-16013",
      "url": "https://spydr.io/cve/CVE-2020-16013",
      "published": "2021-01-08T19:15:12.460Z",
      "modified": "2026-06-17T02:57:38.160Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02756,
      "epss_percentile": 0.85815,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2020-17519",
      "url": "https://spydr.io/cve/CVE-2020-17519",
      "published": "2021-01-05T12:15:12.680Z",
      "modified": "2026-06-17T02:59:04.010Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.97809,
      "epss_percentile": 0.99906,
      "exploited": true,
      "kev": {
        "added": "2024-05-23",
        "due": "2024-06-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache Flink",
        "apache flink"
      ],
      "cwes": [
        "CWE-552"
      ],
      "description": "A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master."
    },
    {
      "id": "CVE-2020-10148",
      "url": "https://spydr.io/cve/CVE-2020-10148",
      "published": "2020-12-29T22:15:12.327Z",
      "modified": "2026-06-17T02:47:26.413Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9198,
      "epss_percentile": 0.99819,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Orion Platform"
      ],
      "cwes": [
        "CWE-288",
        "CWE-306"
      ],
      "description": "The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected."
    },
    {
      "id": "CVE-2020-35730",
      "url": "https://spydr.io/cve/CVE-2020-35730",
      "published": "2020-12-28T20:15:13.150Z",
      "modified": "2026-06-17T03:14:12.273Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.3292,
      "epss_percentile": 0.9832,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "fedoraproject",
        "debian"
      ],
      "products": [
        "roundcube webmail",
        "fedoraproject fedora",
        "debian linux"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php."
    },
    {
      "id": "CVE-2020-29583",
      "url": "https://spydr.io/cve/CVE-2020-29583",
      "published": "2020-12-22T22:15:14.443Z",
      "modified": "2026-06-17T03:11:28.957Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90155,
      "epss_percentile": 0.99796,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zyxel"
      ],
      "products": [
        "zyxel usg20-vpn firmware",
        "zyxel usg20w-vpn firmware",
        "zyxel usg40 firmware",
        "zyxel usg40w firmware",
        "zyxel usg60 firmware",
        "zyxel usg60w firmware",
        "zyxel usg110 firmware",
        "zyxel usg210 firmware",
        "zyxel usg310 firmware",
        "zyxel usg1100 firmware",
        "zyxel usg1900 firmware",
        "zyxel usg2200 firmware",
        "zyxel zywall110 firmware",
        "zyxel zywall310 firmware",
        "zyxel zywall1100 firmware",
        "zyxel atp100 firmware",
        "zyxel atp100w firmware",
        "zyxel atp200 firmware",
        "zyxel atp500 firmware",
        "zyxel atp700 firmware"
      ],
      "cwes": [
        "CWE-522"
      ],
      "description": "Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges."
    },
    {
      "id": "CVE-2020-29574",
      "url": "https://spydr.io/cve/CVE-2020-29574",
      "published": "2020-12-11T17:15:13.480Z",
      "modified": "2026-08-15T04:17:56.567Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04658,
      "epss_percentile": 0.91499,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sophos"
      ],
      "products": [
        "sophos cyberoamos"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely."
    },
    {
      "id": "CVE-2020-17530",
      "url": "https://spydr.io/cve/CVE-2020-17530",
      "published": "2020-12-11T02:15:10.883Z",
      "modified": "2026-06-17T02:59:05.640Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95931,
      "epss_percentile": 0.99875,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-917"
      ],
      "description": "Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25."
    },
    {
      "id": "CVE-2020-17144",
      "url": "https://spydr.io/cve/CVE-2020-17144",
      "published": "2020-12-10T00:15:16.120Z",
      "modified": "2026-06-17T02:58:45.903Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.36514,
      "epss_percentile": 0.98459,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Microsoft Exchange Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2020-27950",
      "url": "https://spydr.io/cve/CVE-2020-27950",
      "published": "2020-12-08T21:15:13.967Z",
      "modified": "2026-06-17T03:09:55.770Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.1652,
      "epss_percentile": 0.96922,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-665"
      ],
      "description": "A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory."
    },
    {
      "id": "CVE-2020-27932",
      "url": "https://spydr.io/cve/CVE-2020-27932",
      "published": "2020-12-08T21:15:13.903Z",
      "modified": "2026-06-17T03:09:53.783Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10337,
      "epss_percentile": 0.95601,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2020-27930",
      "url": "https://spydr.io/cve/CVE-2020-27930",
      "published": "2020-12-08T21:15:13.827Z",
      "modified": "2026-06-17T03:09:53.467Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22009,
      "epss_percentile": 0.97608,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution."
    },
    {
      "id": "CVE-2020-4006",
      "url": "https://spydr.io/cve/CVE-2020-4006",
      "published": "2020-11-23T22:15:12.663Z",
      "modified": "2026-06-17T03:19:25.140Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.17302,
      "epss_percentile": 0.97038,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware Identity Manager (vIDM), VMware Identity Manager Connector (vIDM Connector), VMware Cloud Foundation, vRealize Suite Lifecycle Manager"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability."
    },
    {
      "id": "CVE-2020-13671",
      "url": "https://spydr.io/cve/CVE-2020-13671",
      "published": "2020-11-20T16:15:15.433Z",
      "modified": "2026-06-17T02:53:32.867Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3535,
      "epss_percentile": 0.98412,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Drupal"
      ],
      "products": [
        "Drupal Core"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74."
    },
    {
      "id": "CVE-2020-28949",
      "url": "https://spydr.io/cve/CVE-2020-28949",
      "published": "2020-11-19T19:15:11.937Z",
      "modified": "2026-06-17T03:10:53.810Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84554,
      "epss_percentile": 0.99698,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "php",
        "debian",
        "fedoraproject",
        "drupal"
      ],
      "products": [
        "php archive tar",
        "debian linux",
        "fedoraproject fedora",
        "drupal"
      ],
      "cwes": [],
      "description": "Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed."
    },
    {
      "id": "CVE-2020-17087",
      "url": "https://spydr.io/cve/CVE-2020-17087",
      "published": "2020-11-11T07:15:18.997Z",
      "modified": "2026-06-17T02:58:39.083Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.05431,
      "epss_percentile": 0.92502,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1803",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1"
      ],
      "cwes": [
        "CWE-131"
      ],
      "description": "Windows Kernel Local Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2020-13927",
      "url": "https://spydr.io/cve/CVE-2020-13927",
      "published": "2020-11-10T16:15:11.807Z",
      "modified": "2026-06-17T02:53:54.840Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99778,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "Apache Airflow"
      ],
      "cwes": [
        "CWE-306",
        "CWE-1188",
        "CWE-1056"
      ],
      "description": "The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default"
    },
    {
      "id": "CVE-2020-16846",
      "url": "https://spydr.io/cve/CVE-2020-16846",
      "published": "2020-11-06T08:15:13.283Z",
      "modified": "2026-06-17T02:58:07.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99585,
      "epss_percentile": 0.99946,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "saltstack",
        "debian",
        "fedoraproject",
        "opensuse"
      ],
      "products": [
        "saltstack salt",
        "debian linux",
        "fedoraproject fedora",
        "opensuse leap"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
