{
  "query": {
    "exploited": "1",
    "page": "56"
  },
  "count": 20,
  "total": 1734,
  "page": 56,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T06:48:55.607Z",
    "kev": "2026-10-08T06:49:55.245Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T06:48:55.302Z",
    "posts": "2026-10-08T06:48:55.607Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=56",
    "next": "https://spydr.io/threats.json?exploited=1&page=57"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2020-14644",
      "url": "https://spydr.io/cve/CVE-2020-14644",
      "published": "2020-07-15T18:15:29.457Z",
      "modified": "2026-06-17T02:55:13.130Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94548,
      "epss_percentile": 0.99854,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation WebLogic Server",
        "oracle weblogic_server"
      ],
      "cwes": [],
      "description": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2020-1350",
      "url": "https://spydr.io/cve/CVE-2020-1350",
      "published": "2020-07-14T23:15:13.087Z",
      "modified": "2026-06-17T03:01:10.590Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96721,
      "epss_percentile": 0.99885,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows Server, version 2004 (Server Core installation)"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2020-1147",
      "url": "https://spydr.io/cve/CVE-2020-1147",
      "published": "2020-07-14T23:15:12.057Z",
      "modified": "2026-06-17T03:00:34.930Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93966,
      "epss_percentile": 0.99845,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server",
        "Microsoft SharePoint Server",
        "Microsoft Visual Studio 2019",
        "Microsoft Visual Studio 2019 version 16.6 (includes 16.0 - 16.5)",
        "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
        "Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)",
        "Microsoft .NET Core",
        "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2",
        "Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems",
        "Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems",
        "Microsoft .NET Framework 4.8 on Windows Server, version 1803 (Server Core Installation)",
        "Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems",
        "Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems",
        "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems",
        "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems",
        "Microsoft .NET Framework 4.8 on Windows Server 2016",
        "Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)",
        "Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1",
        "Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1",
        "Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems"
      ],
      "cwes": [],
      "description": "A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2020-1040",
      "url": "https://spydr.io/cve/CVE-2020-1040",
      "published": "2020-07-14T23:15:11.683Z",
      "modified": "2026-06-17T03:00:17.990Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07393,
      "epss_percentile": 0.94275,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043."
    },
    {
      "id": "CVE-2020-6287",
      "url": "https://spydr.io/cve/CVE-2020-6287",
      "published": "2020-07-14T13:15:13.000Z",
      "modified": "2026-06-17T03:23:00.330Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94719,
      "epss_percentile": 0.99857,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP SE"
      ],
      "products": [
        "SAP SE SAP NetWeaver AS JAVA (LM Configuration Wizard)"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check."
    },
    {
      "id": "CVE-2020-10987",
      "url": "https://spydr.io/cve/CVE-2020-10987",
      "published": "2020-07-13T19:15:12.207Z",
      "modified": "2026-06-17T02:48:48.630Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7981,
      "epss_percentile": 0.99604,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tenda"
      ],
      "products": [
        "tenda ac15 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter."
    },
    {
      "id": "CVE-2020-8196",
      "url": "https://spydr.io/cve/CVE-2020-8196",
      "published": "2020-07-10T16:15:12.407Z",
      "modified": "2026-06-17T03:26:02.043Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.26333,
      "epss_percentile": 0.97958,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP"
      ],
      "cwes": [
        "CWE-284",
        "CWE-287"
      ],
      "description": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users."
    },
    {
      "id": "CVE-2020-8195",
      "url": "https://spydr.io/cve/CVE-2020-8195",
      "published": "2020-07-10T16:15:12.327Z",
      "modified": "2026-06-17T03:26:01.840Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.33029,
      "epss_percentile": 0.98324,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP"
      ],
      "cwes": [
        "CWE-20",
        "CWE-22"
      ],
      "description": "Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users."
    },
    {
      "id": "CVE-2020-8193",
      "url": "https://spydr.io/cve/CVE-2020-8193",
      "published": "2020-07-10T16:15:12.157Z",
      "modified": "2026-06-17T03:26:01.560Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.88411,
      "epss_percentile": 0.9977,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP"
      ],
      "cwes": [
        "CWE-284",
        "CWE-287"
      ],
      "description": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints."
    },
    {
      "id": "CVE-2020-9377",
      "url": "https://spydr.io/cve/CVE-2020-9377",
      "published": "2020-07-09T13:15:10.653Z",
      "modified": "2026-06-17T03:27:50.537Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21338,
      "epss_percentile": 0.97548,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-610 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer"
    },
    {
      "id": "CVE-2020-15505",
      "url": "https://spydr.io/cve/CVE-2020-15505",
      "published": "2020-07-07T02:15:10.613Z",
      "modified": "2026-06-17T02:56:45.497Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99737,
      "epss_percentile": 0.99953,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mobileiron"
      ],
      "products": [
        "mobileiron core",
        "mobileiron enterprise connector",
        "mobileiron monitor and reporting database",
        "mobileiron sentry"
      ],
      "cwes": [
        "CWE-706"
      ],
      "description": "A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors."
    },
    {
      "id": "CVE-2020-5902",
      "url": "https://spydr.io/cve/CVE-2020-5902",
      "published": "2020-07-01T15:15:15.360Z",
      "modified": "2026-06-17T03:22:25.473Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 1,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "f5"
      ],
      "products": [
        "BIG-IP"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages."
    },
    {
      "id": "CVE-2020-15415",
      "url": "https://spydr.io/cve/CVE-2020-15415",
      "published": "2020-06-30T14:15:11.953Z",
      "modified": "2026-06-17T02:56:38.220Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8448,
      "epss_percentile": 0.99697,
      "exploited": true,
      "kev": {
        "added": "2024-09-30",
        "due": "2024-10-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "draytek"
      ],
      "products": [
        "draytek vigor3900_firmware",
        "draytek vigor2960_firmware",
        "draytek vigor300b_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472."
    },
    {
      "id": "CVE-2020-15069",
      "url": "https://spydr.io/cve/CVE-2020-15069",
      "published": "2020-06-29T18:15:12.313Z",
      "modified": "2026-06-17T02:55:59.830Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10674,
      "epss_percentile": 0.95701,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sophos"
      ],
      "products": [
        "sophos xg firewall firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x."
    },
    {
      "id": "CVE-2020-2021",
      "url": "https://spydr.io/cve/CVE-2020-2021",
      "published": "2020-06-29T15:15:12.733Z",
      "modified": "2026-06-17T03:11:38.983Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04362,
      "epss_percentile": 0.90988,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks PAN-OS"
      ],
      "cwes": [
        "CWE-347"
      ],
      "description": "When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. This issue cannot be exploited if SAML is not used for authentication. This issue cannot be exploited if the 'Validate Identity Provider Certificate' option is enabled (checked) in the SAML Identity Provider Server Profile. Resources that can be protected by SAML-based single sign-on (SSO) authentication are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces, Prisma Access In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies. There is no impact on the integrity and availability of the gateway, portal or VPN server. An attacker cannot inspect or tamper with sessions of regular users. In the worst case, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). In the case of PAN-OS and Panorama web interfaces, this issue allows an unauthenticated attacker with network access to the PAN-OS or Panorama web interfaces to log in as an administrator and perform administrative actions. In the worst-case scenario, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). If the web interfaces are only accessible to a restricted management network, then the issue is lowered to a CVSS Base Score of 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Palo Alto Networks is not aware of any malicious attempts to exploit this vulnerability."
    },
    {
      "id": "CVE-2020-11899",
      "url": "https://spydr.io/cve/CVE-2020-11899",
      "published": "2020-06-17T11:15:10.210Z",
      "modified": "2026-06-17T02:51:00.473Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "score_source": "NVD",
      "epss": 0.1842,
      "epss_percentile": 0.97168,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "treck",
        "dell"
      ],
      "products": [
        "treck tcp/ip",
        "dell wyse 5050 all-in-one firmware",
        "dell wyse 7030 firmware",
        "dell wyse 5030 firmware"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read."
    },
    {
      "id": "CVE-2020-0986",
      "url": "https://spydr.io/cve/CVE-2020-0986",
      "published": "2020-06-09T20:15:12.177Z",
      "modified": "2026-06-17T02:47:08.520Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.16277,
      "epss_percentile": 0.96877,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1909 for 32-bit Systems",
        "Microsoft Windows 10 Version 1909 for x64-based Systems",
        "Microsoft Windows 10 Version 1909 for ARM64-based Systems",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows 10 Version 2004 for 32-bit Systems",
        "Microsoft Windows Server, version 2004 (Server Core installation)",
        "Microsoft Windows 10 Version 2004 for ARM64-based Systems",
        "Microsoft Windows 10 Version 2004 for x64-based Systems"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316."
    },
    {
      "id": "CVE-2020-9819",
      "url": "https://spydr.io/cve/CVE-2020-9819",
      "published": "2020-06-09T17:15:13.377Z",
      "modified": "2026-06-17T03:28:37.767Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
      "score_source": "NVD",
      "epss": 0.02178,
      "epss_percentile": 0.81774,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple iOS-1",
        "Apple watchOS",
        "Apple watchOS-1"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption."
    },
    {
      "id": "CVE-2020-9818",
      "url": "https://spydr.io/cve/CVE-2020-9818",
      "published": "2020-06-09T17:15:13.317Z",
      "modified": "2026-06-17T03:28:37.607Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02286,
      "epss_percentile": 0.8266,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple iOS-1",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination."
    },
    {
      "id": "CVE-2020-13965",
      "url": "https://spydr.io/cve/CVE-2020-13965",
      "published": "2020-06-09T03:15:11.250Z",
      "modified": "2026-06-17T02:54:01.497Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.76596,
      "epss_percentile": 0.99532,
      "exploited": true,
      "kev": {
        "added": "2024-06-26",
        "due": "2024-07-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube"
      ],
      "products": [
        "roundcube webmail"
      ],
      "cwes": [
        "CWE-79",
        "CWE-80"
      ],
      "description": "An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
