{
  "query": {
    "exploited": "1",
    "page": "64"
  },
  "count": 20,
  "total": 1734,
  "page": 64,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T12:49:09.674Z",
    "kev": "2026-10-08T13:50:11.773Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T13:49:11.704Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=64",
    "next": "https://spydr.io/threats.json?exploited=1&page=65"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-1064",
      "url": "https://spydr.io/cve/CVE-2019-1064",
      "published": "2019-06-12T14:29:04.273Z",
      "modified": "2026-06-17T02:27:44.930Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06886,
      "epss_percentile": 0.93902,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1703",
        "Microsoft Windows 10 Version 1803",
        "Microsoft Windows Server, version 1803 (Server Core Installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1709 for 32-bit Systems",
        "Microsoft Windows 10 Version 1709",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows AppX Deployment Service handles hard links."
    },
    {
      "id": "CVE-2010-5330",
      "url": "https://spydr.io/cve/CVE-2010-5330",
      "published": "2019-06-11T21:29:00.350Z",
      "modified": "2026-06-16T23:26:34.420Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39362,
      "epss_percentile": 0.98573,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ui"
      ],
      "products": [
        "ui airos"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected."
    },
    {
      "id": "CVE-2019-10149",
      "url": "https://spydr.io/cve/CVE-2019-10149",
      "published": "2019-06-05T14:29:11.293Z",
      "modified": "2026-06-17T02:10:21.590Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99961,
      "epss_percentile": 0.99975,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "exim"
      ],
      "products": [
        "exim"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution."
    },
    {
      "id": "CVE-2018-13382",
      "url": "https://spydr.io/cve/CVE-2018-13382",
      "published": "2019-06-04T21:29:00.373Z",
      "modified": "2026-06-17T01:39:18.570Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.81691,
      "epss_percentile": 0.99638,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, FortiProxy"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests"
    },
    {
      "id": "CVE-2018-13379",
      "url": "https://spydr.io/cve/CVE-2018-13379",
      "published": "2019-06-04T21:29:00.233Z",
      "modified": "2026-06-17T01:39:18.123Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99995,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, FortiProxy"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests."
    },
    {
      "id": "CVE-2019-11580",
      "url": "https://spydr.io/cve/CVE-2019-11580",
      "published": "2019-06-03T14:29:00.217Z",
      "modified": "2026-06-17T02:13:11.973Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95355,
      "epss_percentile": 0.99867,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Crowd"
      ],
      "cwes": [],
      "description": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability."
    },
    {
      "id": "CVE-2019-9875",
      "url": "https://spydr.io/cve/CVE-2019-9875",
      "published": "2019-05-31T21:29:06.187Z",
      "modified": "2026-06-17T02:44:46.273Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13795,
      "epss_percentile": 0.96427,
      "exploited": true,
      "kev": {
        "added": "2025-03-26",
        "due": "2025-04-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sitecore"
      ],
      "products": [
        "sitecore cms"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in an HTTP POST parameter."
    },
    {
      "id": "CVE-2019-9874",
      "url": "https://spydr.io/cve/CVE-2019-9874",
      "published": "2019-05-31T21:29:06.123Z",
      "modified": "2026-06-17T02:44:46.077Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83736,
      "epss_percentile": 0.99685,
      "exploited": true,
      "kev": {
        "added": "2025-03-26",
        "due": "2025-04-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sitecore"
      ],
      "products": [
        "sitecore cms",
        "sitecore experience platform"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN."
    },
    {
      "id": "CVE-2019-9670",
      "url": "https://spydr.io/cve/CVE-2019-9670",
      "published": "2019-05-29T22:29:01.507Z",
      "modified": "2026-06-17T02:44:09.363Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99986,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml."
    },
    {
      "id": "CVE-2018-13383",
      "url": "https://spydr.io/cve/CVE-2018-13383",
      "published": "2019-05-29T18:29:00.693Z",
      "modified": "2026-06-17T01:39:18.710Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.33647,
      "epss_percentile": 0.9835,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS and FortiProxy"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages."
    },
    {
      "id": "CVE-2018-7841",
      "url": "https://spydr.io/cve/CVE-2018-7841",
      "published": "2019-05-22T20:29:01.480Z",
      "modified": "2026-06-17T02:03:50.500Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72675,
      "epss_percentile": 0.99434,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "U.motion"
      ],
      "products": [
        "U.motion Builder software version 1.3.4"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered."
    },
    {
      "id": "CVE-2019-11634",
      "url": "https://spydr.io/cve/CVE-2019-11634",
      "published": "2019-05-22T17:29:00.227Z",
      "modified": "2026-08-12T05:17:21.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08091,
      "epss_percentile": 0.94679,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix receiver",
        "citrix workspace"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Citrix Workspace App before 1904 for Windows has Incorrect Access Control."
    },
    {
      "id": "CVE-2019-0903",
      "url": "https://spydr.io/cve/CVE-2019-0903",
      "published": "2019-05-16T19:29:02.303Z",
      "modified": "2026-06-17T02:09:09.837Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21713,
      "epss_percentile": 0.97581,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2019-0863",
      "url": "https://spydr.io/cve/CVE-2019-0863",
      "published": "2019-05-16T19:29:00.927Z",
      "modified": "2026-06-17T02:09:03.930Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05207,
      "epss_percentile": 0.92273,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-0708",
      "url": "https://spydr.io/cve/CVE-2019-0708",
      "published": "2019-05-16T19:29:00.427Z",
      "modified": "2026-06-17T02:08:44.017Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99999,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2018-14839",
      "url": "https://spydr.io/cve/CVE-2018-14839",
      "published": "2019-05-14T21:29:00.247Z",
      "modified": "2026-06-17T01:41:44.377Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89354,
      "epss_percentile": 0.99782,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "lg"
      ],
      "products": [
        "lg n1a1 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters."
    },
    {
      "id": "CVE-2019-3568",
      "url": "https://spydr.io/cve/CVE-2019-3568",
      "published": "2019-05-14T20:29:03.187Z",
      "modified": "2026-06-17T02:35:14.707Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.30076,
      "epss_percentile": 0.98175,
      "exploited": true,
      "kev": {
        "added": "2022-04-19",
        "due": "2022-05-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Facebook"
      ],
      "products": [
        "Facebook WhatsApp for Android",
        "Facebook WhatsApp Business for Android",
        "Facebook WhatsApp for iOS",
        "Facebook WhatsApp Business for iOS",
        "Facebook WhatsApp for Windows Phone",
        "Facebook WhatsApp for Tizen"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15."
    },
    {
      "id": "CVE-2019-11510",
      "url": "https://spydr.io/cve/CVE-2019-11510",
      "published": "2019-05-08T17:29:00.630Z",
      "modified": "2026-06-17T02:13:04.277Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 1,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti"
      ],
      "products": [
        "ivanti connect secure"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability ."
    },
    {
      "id": "CVE-2018-4063",
      "url": "https://spydr.io/cve/CVE-2018-4063",
      "published": "2019-05-06T19:29:00.637Z",
      "modified": "2026-06-17T01:58:18.623Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.27059,
      "epss_percentile": 0.98001,
      "exploited": true,
      "kev": {
        "added": "2025-12-12",
        "due": "2026-01-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sierrawireless"
      ],
      "products": [
        "Sierra Wireless"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability."
    },
    {
      "id": "CVE-2017-18368",
      "url": "https://spydr.io/cve/CVE-2017-18368",
      "published": "2019-05-02T17:29:00.287Z",
      "modified": "2026-06-17T01:12:42.023Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94425,
      "epss_percentile": 0.99851,
      "exploited": true,
      "kev": {
        "added": "2023-08-07",
        "due": "2023-08-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "billion",
        "zyxel"
      ],
      "products": [
        "billion 5200w-t firmware",
        "zyxel p660hn-t1a v2 firmware",
        "zyxel p660hn-t1a v1 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
