{
  "query": {
    "exploited": "1",
    "page": "62"
  },
  "count": 20,
  "total": 1734,
  "page": 62,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T12:49:09.674Z",
    "kev": "2026-10-08T12:50:09.232Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T12:49:09.674Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=62",
    "next": "https://spydr.io/threats.json?exploited=1&page=63"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-18187",
      "url": "https://spydr.io/cve/CVE-2019-18187",
      "published": "2019-10-28T20:15:11.003Z",
      "modified": "2026-06-17T02:24:26.050Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.25125,
      "epss_percentile": 0.97883,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro"
      ],
      "products": [
        "Trend Micro OfficeScan"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication."
    },
    {
      "id": "CVE-2019-11043",
      "url": "https://spydr.io/cve/CVE-2019-11043",
      "published": "2019-10-28T15:15:13.863Z",
      "modified": "2026-06-17T02:12:11.767Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9978,
      "epss_percentile": 0.99955,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PHP"
      ],
      "products": [
        "PHP"
      ],
      "cwes": [
        "CWE-120",
        "CWE-787"
      ],
      "description": "In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution."
    },
    {
      "id": "CVE-2019-3010",
      "url": "https://spydr.io/cve/CVE-2019-3010",
      "published": "2019-10-16T18:15:34.293Z",
      "modified": "2026-06-17T02:35:02.800Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13399,
      "epss_percentile": 0.96331,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Solaris Operating System"
      ],
      "cwes": [],
      "description": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2019-16278",
      "url": "https://spydr.io/cve/CVE-2019-16278",
      "published": "2019-10-14T17:15:09.427Z",
      "modified": "2026-06-17T02:22:03.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99033,
      "epss_percentile": 0.99931,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nazgul"
      ],
      "products": [
        "nazgul nostromo_nhttpd"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request."
    },
    {
      "id": "CVE-2019-2215",
      "url": "https://spydr.io/cve/CVE-2019-2215",
      "published": "2019-10-11T19:15:10.947Z",
      "modified": "2026-06-17T02:33:27.307Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72105,
      "epss_percentile": 0.9942,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "debian",
        "canonical",
        "netapp",
        "huawei"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095"
    },
    {
      "id": "CVE-2019-1322",
      "url": "https://spydr.io/cve/CVE-2019-1322",
      "published": "2019-10-10T14:15:16.190Z",
      "modified": "2026-06-17T02:28:22.690Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19205,
      "epss_percentile": 0.97269,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340."
    },
    {
      "id": "CVE-2019-1315",
      "url": "https://spydr.io/cve/CVE-2019-1315",
      "published": "2019-10-10T14:15:15.737Z",
      "modified": "2026-06-17T02:28:21.600Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03478,
      "epss_percentile": 0.88766,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342."
    },
    {
      "id": "CVE-2019-16928",
      "url": "https://spydr.io/cve/CVE-2019-16928",
      "published": "2019-09-27T21:15:10.017Z",
      "modified": "2026-06-17T02:22:58.967Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41638,
      "epss_percentile": 0.9865,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "exim",
        "canonical",
        "debian",
        "fedoraproject"
      ],
      "products": [
        "exim",
        "canonical ubuntu linux",
        "debian linux",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command."
    },
    {
      "id": "CVE-2019-16920",
      "url": "https://spydr.io/cve/CVE-2019-16920",
      "published": "2019-09-27T12:15:10.017Z",
      "modified": "2026-06-17T02:22:57.810Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99996,
      "epss_percentile": 0.99989,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-655 firmware",
        "dlink dir-866l firmware",
        "dlink dir-652 firmware",
        "dlink dhp-1565 firmware",
        "dlink dir-855l firmware",
        "dlink dap-1533 firmware",
        "dlink dir-862l firmware",
        "dlink dir-615 firmware",
        "dlink dir-835 firmware",
        "dlink dir-825 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a \"PingTest\" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825."
    },
    {
      "id": "CVE-2019-16759",
      "url": "https://spydr.io/cve/CVE-2019-16759",
      "published": "2019-09-24T22:15:13.183Z",
      "modified": "2026-06-17T02:22:44.363Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99728,
      "epss_percentile": 0.99952,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vbulletin"
      ],
      "products": [
        "vbulletin"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request."
    },
    {
      "id": "CVE-2019-1367",
      "url": "https://spydr.io/cve/CVE-2019-1367",
      "published": "2019-09-23T20:15:13.447Z",
      "modified": "2026-06-17T02:28:28.333Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.52449,
      "epss_percentile": 0.98938,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 9",
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 11 on Windows Server 2012",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221."
    },
    {
      "id": "CVE-2019-16057",
      "url": "https://spydr.io/cve/CVE-2019-16057",
      "published": "2019-09-16T12:15:10.910Z",
      "modified": "2026-06-17T02:21:36.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86491,
      "epss_percentile": 0.99734,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dns-320 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection."
    },
    {
      "id": "CVE-2019-16256",
      "url": "https://spydr.io/cve/CVE-2019-16256",
      "published": "2019-09-12T13:15:10.327Z",
      "modified": "2026-06-17T02:22:00.793Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04949,
      "epss_percentile": 0.91936,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "trustedconnectivityalliance"
      ],
      "products": [
        "trustedconnectivityalliance s@t browser"
      ],
      "cwes": [],
      "description": "Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker."
    },
    {
      "id": "CVE-2019-1297",
      "url": "https://spydr.io/cve/CVE-2019-1297",
      "published": "2019-09-11T22:15:18.773Z",
      "modified": "2026-06-17T02:28:19.593Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21805,
      "epss_percentile": 0.97586,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Excel",
        "Microsoft Office",
        "Microsoft Office 365 ProPlus"
      ],
      "cwes": [],
      "description": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2019-1253",
      "url": "https://spydr.io/cve/CVE-2019-1253",
      "published": "2019-09-11T22:15:16.337Z",
      "modified": "2026-06-17T02:28:14.563Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11616,
      "epss_percentile": 0.95946,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303."
    },
    {
      "id": "CVE-2019-1215",
      "url": "https://spydr.io/cve/CVE-2019-1215",
      "published": "2019-09-11T22:15:14.587Z",
      "modified": "2026-06-17T02:28:05.677Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19254,
      "epss_percentile": 0.97274,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303."
    },
    {
      "id": "CVE-2019-1214",
      "url": "https://spydr.io/cve/CVE-2019-1214",
      "published": "2019-09-11T22:15:14.523Z",
      "modified": "2026-06-17T02:28:05.463Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01419,
      "epss_percentile": 0.71998,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-15949",
      "url": "https://spydr.io/cve/CVE-2019-15949",
      "published": "2019-09-05T17:15:12.327Z",
      "modified": "2026-06-17T02:21:24.097Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77039,
      "epss_percentile": 0.99541,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root."
    },
    {
      "id": "CVE-2019-13608",
      "url": "https://spydr.io/cve/CVE-2019-13608",
      "published": "2019-08-29T19:15:13.227Z",
      "modified": "2026-06-17T02:17:04.013Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.30041,
      "epss_percentile": 0.98172,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix storefront server"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks."
    },
    {
      "id": "CVE-2019-15752",
      "url": "https://spydr.io/cve/CVE-2019-15752",
      "published": "2019-08-28T21:15:10.880Z",
      "modified": "2026-06-17T02:21:00.877Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48628,
      "epss_percentile": 0.98843,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "docker",
        "apache"
      ],
      "products": [
        "docker",
        "apache geode"
      ],
      "cwes": [
        "CWE-732"
      ],
      "description": "Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\\DockerDesktop\\version-bin\\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
