{
  "query": {
    "exploited": "1",
    "page": "63"
  },
  "count": 20,
  "total": 1734,
  "page": 63,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T12:49:09.674Z",
    "kev": "2026-10-08T12:50:09.232Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T12:49:09.674Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=63",
    "next": "https://spydr.io/threats.json?exploited=1&page=64"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-15107",
      "url": "https://spydr.io/cve/CVE-2019-15107",
      "published": "2019-08-16T03:15:11.387Z",
      "modified": "2026-08-06T05:16:35.140Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9971,
      "epss_percentile": 0.99951,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "webmin"
      ],
      "products": [
        "webmin"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability."
    },
    {
      "id": "CVE-2019-0344",
      "url": "https://spydr.io/cve/CVE-2019-0344",
      "published": "2019-08-14T14:15:16.463Z",
      "modified": "2026-06-17T02:08:12.500Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07079,
      "epss_percentile": 0.94058,
      "exploited": true,
      "kev": {
        "added": "2024-09-30",
        "due": "2024-10-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP SE",
        "sap"
      ],
      "products": [
        "SAP SE SAP Commerce Cloud (virtualjdbc extension)",
        "sap commerce_cloud"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection."
    },
    {
      "id": "CVE-2019-11581",
      "url": "https://spydr.io/cve/CVE-2019-11581",
      "published": "2019-08-09T20:15:11.270Z",
      "modified": "2026-06-17T02:13:12.170Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84621,
      "epss_percentile": 0.99701,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Jira Server and Data Center"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability."
    },
    {
      "id": "CVE-2019-0193",
      "url": "https://spydr.io/cve/CVE-2019-0193",
      "published": "2019-08-01T14:15:13.113Z",
      "modified": "2026-06-17T02:07:55.447Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83547,
      "epss_percentile": 0.99681,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache"
      ],
      "products": [
        "Apache Solr"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's \"dataConfig\" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property \"enable.dih.dataConfigParam\" to true."
    },
    {
      "id": "CVE-2019-11708",
      "url": "https://spydr.io/cve/CVE-2019-11708",
      "published": "2019-07-23T14:15:15.327Z",
      "modified": "2026-06-17T02:13:28.273Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55874,
      "epss_percentile": 0.99023,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox ESR",
        "Mozilla Firefox",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2."
    },
    {
      "id": "CVE-2019-11707",
      "url": "https://spydr.io/cve/CVE-2019-11707",
      "published": "2019-07-23T14:15:15.233Z",
      "modified": "2026-06-17T02:13:28.073Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.37696,
      "epss_percentile": 0.98507,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox ESR",
        "Mozilla Firefox",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2."
    },
    {
      "id": "CVE-2019-1579",
      "url": "https://spydr.io/cve/CVE-2019-1579",
      "published": "2019-07-19T22:15:11.557Z",
      "modified": "2026-10-02T04:18:01.077Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.46239,
      "epss_percentile": 0.98784,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "paloaltonetworks"
      ],
      "products": [
        "Palo Alto Networks GlobalProtect Portal/Gateway Interface"
      ],
      "cwes": [
        "CWE-134"
      ],
      "description": "Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code."
    },
    {
      "id": "CVE-2019-13272",
      "url": "https://spydr.io/cve/CVE-2019-13272",
      "published": "2019-07-17T13:15:10.687Z",
      "modified": "2026-06-17T02:16:26.033Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.52199,
      "epss_percentile": 0.98933,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "debian",
        "fedoraproject",
        "canonical",
        "redhat",
        "netapp"
      ],
      "products": [
        "linux kernel",
        "debian linux",
        "fedoraproject fedora",
        "canonical ubuntu linux",
        "redhat enterprise linux",
        "redhat enterprise linux for arm 64",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for real time",
        "redhat enterprise linux for real time for nfv",
        "redhat enterprise linux for real time for nfv tus",
        "redhat enterprise linux for real time tus",
        "netapp aff a700s firmware",
        "netapp h410c firmware",
        "netapp h610s firmware",
        "netapp active iq unified manager",
        "netapp e-series performance analyzer",
        "netapp e-series santricity os controller",
        "netapp hci management node",
        "netapp service processor",
        "netapp solidfire"
      ],
      "cwes": [],
      "description": "In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments."
    },
    {
      "id": "CVE-2019-12991",
      "url": "https://spydr.io/cve/CVE-2019-12991",
      "published": "2019-07-16T18:15:13.117Z",
      "modified": "2026-06-17T02:15:52.457Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74052,
      "epss_percentile": 0.99475,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix netscaler sd-wan",
        "citrix sd-wan"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6)."
    },
    {
      "id": "CVE-2019-12989",
      "url": "https://spydr.io/cve/CVE-2019-12989",
      "published": "2019-07-16T18:15:12.930Z",
      "modified": "2026-06-17T02:15:52.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94957,
      "epss_percentile": 0.99862,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix netscaler sd-wan",
        "citrix sd-wan"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection."
    },
    {
      "id": "CVE-2019-1132",
      "url": "https://spydr.io/cve/CVE-2019-1132",
      "published": "2019-07-15T19:15:21.107Z",
      "modified": "2026-06-17T02:27:53.720Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09788,
      "epss_percentile": 0.95428,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-1130",
      "url": "https://spydr.io/cve/CVE-2019-1130",
      "published": "2019-07-15T19:15:21.047Z",
      "modified": "2026-08-12T05:17:23.177Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01719,
      "epss_percentile": 0.76753,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server",
        "Microsoft Windows",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129."
    },
    {
      "id": "CVE-2019-1129",
      "url": "https://spydr.io/cve/CVE-2019-1129",
      "published": "2019-07-15T19:15:20.967Z",
      "modified": "2026-06-17T02:27:53.220Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01782,
      "epss_percentile": 0.77591,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130."
    },
    {
      "id": "CVE-2019-1068",
      "url": "https://spydr.io/cve/CVE-2019-1068",
      "published": "2019-07-15T19:15:16.983Z",
      "modified": "2026-08-27T04:16:38.583Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.57273,
      "epss_percentile": 0.99054,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-08-29",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)",
        "Microsoft SQL Server",
        "Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)",
        "Microsoft SQL Server 2017 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2019-0880",
      "url": "https://spydr.io/cve/CVE-2019-0880",
      "published": "2019-07-15T19:15:15.687Z",
      "modified": "2026-06-17T02:09:06.100Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02289,
      "epss_percentile": 0.82679,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server",
        "Microsoft Windows",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2018-18325",
      "url": "https://spydr.io/cve/CVE-2018-18325",
      "published": "2019-07-03T17:15:10.250Z",
      "modified": "2026-06-17T01:47:00.017Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.7387,
      "epss_percentile": 0.9947,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dnnsoftware"
      ],
      "products": [
        "dnnsoftware dotnetnuke"
      ],
      "cwes": [
        "CWE-326"
      ],
      "description": "DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811."
    },
    {
      "id": "CVE-2018-15811",
      "url": "https://spydr.io/cve/CVE-2018-15811",
      "published": "2019-07-03T17:15:10.110Z",
      "modified": "2026-06-17T01:43:08.583Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.76143,
      "epss_percentile": 0.99524,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dnnsoftware"
      ],
      "products": [
        "dnnsoftware dotnetnuke"
      ],
      "cwes": [
        "CWE-326"
      ],
      "description": "DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters."
    },
    {
      "id": "CVE-2019-7256",
      "url": "https://spydr.io/cve/CVE-2019-7256",
      "published": "2019-07-02T19:15:11.147Z",
      "modified": "2026-06-17T02:40:19.833Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97081,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2024-03-25",
        "due": "2024-04-15",
        "action": "Contact the vendor for guidance on remediating firmware, per their advisory.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nortekcontrol"
      ],
      "products": [
        "nortekcontrol linear_emerge_essential_firmware",
        "nortekcontrol linear_emerge_elite_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Linear eMerge E3-Series devices allow Command Injections."
    },
    {
      "id": "CVE-2019-5786",
      "url": "https://spydr.io/cve/CVE-2019-5786",
      "published": "2019-06-27T17:15:13.770Z",
      "modified": "2026-06-17T02:38:12.210Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.61085,
      "epss_percentile": 0.99139,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page."
    },
    {
      "id": "CVE-2019-1069",
      "url": "https://spydr.io/cve/CVE-2019-1069",
      "published": "2019-06-12T14:29:04.337Z",
      "modified": "2026-08-12T05:17:22.517Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06117,
      "epss_percentile": 0.93249,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1703",
        "Microsoft Windows 10 Version 1803",
        "Microsoft Windows Server, version 1803 (Server Core Installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1709 for 32-bit Systems",
        "Microsoft Windows 10 Version 1709",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "microsoft windows_10"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
