{
  "query": {
    "exploited": "1",
    "page": "59"
  },
  "count": 20,
  "total": 1734,
  "page": 59,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T08:49:00.339Z",
    "kev": "2026-10-08T09:50:02.563Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T06:48:55.302Z",
    "posts": "2026-10-08T09:49:02.611Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=59",
    "next": "https://spydr.io/threats.json?exploited=1&page=60"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2020-0069",
      "url": "https://spydr.io/cve/CVE-2020-0069",
      "published": "2020-03-10T20:15:21.947Z",
      "modified": "2026-06-17T02:45:11.200Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0137,
      "epss_percentile": 0.71071,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "huawei"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754"
    },
    {
      "id": "CVE-2020-0041",
      "url": "https://spydr.io/cve/CVE-2020-0041",
      "published": "2020-03-10T20:15:21.383Z",
      "modified": "2026-06-17T02:45:07.270Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03145,
      "epss_percentile": 0.87531,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel"
    },
    {
      "id": "CVE-2016-11021",
      "url": "https://spydr.io/cve/CVE-2016-11021",
      "published": "2020-03-09T01:15:10.780Z",
      "modified": "2026-06-17T00:40:49.490Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.6887,
      "epss_percentile": 0.99333,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dcs-930l firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter."
    },
    {
      "id": "CVE-2020-10221",
      "url": "https://spydr.io/cve/CVE-2020-10221",
      "published": "2020-03-08T22:15:11.120Z",
      "modified": "2026-06-17T02:47:30.760Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77123,
      "epss_percentile": 0.99542,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rconfig"
      ],
      "products": [
        "rconfig"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter."
    },
    {
      "id": "CVE-2020-10189",
      "url": "https://spydr.io/cve/CVE-2020-10189",
      "published": "2020-03-06T17:15:12.383Z",
      "modified": "2026-06-17T02:47:27.960Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99941,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine desktop central"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets."
    },
    {
      "id": "CVE-2019-20500",
      "url": "https://spydr.io/cve/CVE-2019-20500",
      "published": "2020-03-05T15:15:11.253Z",
      "modified": "2026-06-17T02:30:35.163Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96713,
      "epss_percentile": 0.99885,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dwl-2600ap firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter."
    },
    {
      "id": "CVE-2020-9054",
      "url": "https://spydr.io/cve/CVE-2020-9054",
      "published": "2020-03-04T20:15:10.750Z",
      "modified": "2026-10-07T18:17:09.643Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99988,
      "epss_percentile": 0.99984,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ZyXEL"
      ],
      "products": [
        "ZyXEL NAS326",
        "ZyXEL NAS520",
        "ZyXEL NAS540",
        "ZyXEL NAS542",
        "ZyXEL NSA210",
        "ZyXEL NSA220",
        "ZyXEL NSA221",
        "ZyXEL NSA310",
        "ZyXEL NSA320",
        "ZyXEL NSA320S",
        "ZyXEL NSA325",
        "ZyXEL NSA325v2"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2"
    },
    {
      "id": "CVE-2019-17026",
      "url": "https://spydr.io/cve/CVE-2019-17026",
      "published": "2020-03-02T05:15:12.010Z",
      "modified": "2026-06-17T02:23:11.170Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.46311,
      "epss_percentile": 0.98788,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox ESR",
        "Mozilla Thunderbird",
        "Mozilla Firefox"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1."
    },
    {
      "id": "CVE-2020-6418",
      "url": "https://spydr.io/cve/CVE-2020-6418",
      "published": "2020-02-27T23:15:12.623Z",
      "modified": "2026-06-17T03:23:18.510Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.78808,
      "epss_percentile": 0.99584,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2020-3837",
      "url": "https://spydr.io/cve/CVE-2020-3837",
      "published": "2020-02-27T21:15:16.630Z",
      "modified": "2026-06-17T03:19:07.070Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14839,
      "epss_percentile": 0.96614,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2020-1938",
      "url": "https://spydr.io/cve/CVE-2020-1938",
      "published": "2020-02-24T22:15:12.057Z",
      "modified": "2026-08-25T16:28:27.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9927,
      "epss_percentile": 0.99937,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache"
      ],
      "products": [
        "Apache Tomcat"
      ],
      "cwes": [],
      "description": "When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations."
    },
    {
      "id": "CVE-2020-3153",
      "url": "https://spydr.io/cve/CVE-2020-3153",
      "published": "2020-02-19T20:15:15.113Z",
      "modified": "2026-08-12T05:17:29.713Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.28307,
      "epss_percentile": 0.98077,
      "exploited": true,
      "kev": {
        "added": "2022-10-24",
        "due": "2022-11-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco AnyConnect Secure Mobility Client"
      ],
      "cwes": [
        "CWE-427"
      ],
      "description": "A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system."
    },
    {
      "id": "CVE-2020-7796",
      "url": "https://spydr.io/cve/CVE-2020-7796",
      "published": "2020-02-18T22:15:10.013Z",
      "modified": "2026-06-17T03:25:27.790Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84418,
      "epss_percentile": 0.99696,
      "exploited": true,
      "kev": {
        "added": "2026-02-17",
        "due": "2026-03-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled."
    },
    {
      "id": "CVE-2020-0688",
      "url": "https://spydr.io/cve/CVE-2020-0688",
      "published": "2020-02-11T22:15:15.900Z",
      "modified": "2026-06-17T02:46:21.387Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99962,
      "epss_percentile": 0.99976,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013",
        "Microsoft Exchange Server 2019 Cumulative Update 3",
        "Microsoft Exchange Server 2016 Cumulative Update 14",
        "Microsoft Exchange Server 2016 Cumulative Update 15",
        "Microsoft Exchange Server 2019 Cumulative Update 4",
        "Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'."
    },
    {
      "id": "CVE-2020-0683",
      "url": "https://spydr.io/cve/CVE-2020-0683",
      "published": "2020-02-11T22:15:15.650Z",
      "modified": "2026-06-17T02:46:20.557Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07605,
      "epss_percentile": 0.94399,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows 10 Version 1909 for 32-bit Systems",
        "Microsoft Windows 10 Version 1909 for x64-based Systems",
        "Microsoft Windows 10 Version 1909 for ARM64-based Systems",
        "Microsoft Windows Server, version 1909 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686."
    },
    {
      "id": "CVE-2020-0674",
      "url": "https://spydr.io/cve/CVE-2020-0674",
      "published": "2020-02-11T22:15:14.883Z",
      "modified": "2026-06-17T02:46:19.067Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86863,
      "epss_percentile": 0.99743,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 10",
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Internet Explorer 11 on Windows Server 2012",
        "Microsoft Internet Explorer 9"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767."
    },
    {
      "id": "CVE-2020-0618",
      "url": "https://spydr.io/cve/CVE-2020-0618",
      "published": "2020-02-11T22:15:13.400Z",
      "modified": "2026-08-15T04:17:46.010Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99046,
      "epss_percentile": 0.99931,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SQL Server",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)",
        "Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2019-19356",
      "url": "https://spydr.io/cve/CVE-2019-19356",
      "published": "2020-02-07T23:15:10.013Z",
      "modified": "2026-06-17T02:26:33.677Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28168,
      "epss_percentile": 0.98069,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netis-systems"
      ],
      "products": [
        "netis-systems wf2419 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing."
    },
    {
      "id": "CVE-2019-18988",
      "url": "https://spydr.io/cve/CVE-2019-18988",
      "published": "2020-02-07T16:15:10.033Z",
      "modified": "2026-06-17T02:25:42.777Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04707,
      "epss_percentile": 0.91572,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "teamviewer"
      ],
      "products": [
        "teamviewer"
      ],
      "cwes": [
        "CWE-521"
      ],
      "description": "TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least OptionsPasswordAES in the current version of the product. If an attacker were to know this key, they could decrypt protect information stored in the registry or configuration files of TeamViewer. With versions before v9.x , this allowed for attackers to decrypt the Unattended Access password to the system (which allows for remote login to the system as well as headless file browsing). The latest version still uses the same key for OptionPasswordAES but appears to have changed how the Unattended Access password is stored. While in most cases an attacker requires an existing session on a system, if the registry/configuration keys were stored off of the machine (such as in a file share or online), an attacker could then decrypt the required password to login to the system."
    },
    {
      "id": "CVE-2020-8655",
      "url": "https://spydr.io/cve/CVE-2020-8655",
      "published": "2020-02-07T00:15:09.613Z",
      "modified": "2026-06-17T03:26:42.707Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.60075,
      "epss_percentile": 0.99114,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "eyesofnetwork"
      ],
      "products": [
        "eyesofnetwork"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root via a crafted NSE script for nmap 7."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
