{
  "query": {
    "exploited": "1",
    "page": "66"
  },
  "count": 20,
  "total": 1734,
  "page": 66,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T16:49:18.208Z",
    "kev": "2026-10-08T16:50:18.245Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T16:49:18.208Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=66",
    "next": "https://spydr.io/threats.json?exploited=1&page=67"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-9978",
      "url": "https://spydr.io/cve/CVE-2019-9978",
      "published": "2019-03-24T15:29:00.243Z",
      "modified": "2026-06-17T02:44:58.130Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.72946,
      "epss_percentile": 0.99442,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "warfareplugins"
      ],
      "products": [
        "warfareplugins social warfare",
        "warfareplugins social warfare pro"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro."
    },
    {
      "id": "CVE-2019-7238",
      "url": "https://spydr.io/cve/CVE-2019-7238",
      "published": "2019-03-21T17:29:01.180Z",
      "modified": "2026-06-17T02:40:18.367Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77146,
      "epss_percentile": 0.99543,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sonatype"
      ],
      "products": [
        "sonatype nexus repository manager"
      ],
      "cwes": [],
      "description": "Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control."
    },
    {
      "id": "CVE-2019-1003030",
      "url": "https://spydr.io/cve/CVE-2019-1003030",
      "published": "2019-03-08T21:29:00.343Z",
      "modified": "2026-06-17T02:09:34.493Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97058,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Jenkins project"
      ],
      "products": [
        "Jenkins project Jenkins Pipeline: Groovy Plugin"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM."
    },
    {
      "id": "CVE-2019-1003029",
      "url": "https://spydr.io/cve/CVE-2019-1003029",
      "published": "2019-03-08T21:29:00.297Z",
      "modified": "2026-06-17T02:09:34.290Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7444,
      "epss_percentile": 0.99484,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Jenkins project"
      ],
      "products": [
        "Jenkins project Jenkins Script Security Plugin"
      ],
      "cwes": [],
      "description": "A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM."
    },
    {
      "id": "CVE-2018-18809",
      "url": "https://spydr.io/cve/CVE-2018-18809",
      "published": "2019-03-07T22:29:00.323Z",
      "modified": "2026-06-17T01:47:56.560Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.79064,
      "epss_percentile": 0.99591,
      "exploited": true,
      "kev": {
        "added": "2022-12-29",
        "due": "2023-01-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TIBCO Software Inc."
      ],
      "products": [
        "TIBCO Software Inc. TIBCO JasperReports Library",
        "TIBCO Software Inc. TIBCO JasperReports Library Community Edition",
        "TIBCO Software Inc. TIBCO JasperReports Library for ActiveMatrix BPM",
        "TIBCO Software Inc. TIBCO JasperReports Server",
        "TIBCO Software Inc. TIBCO JasperReports Server Community Edition",
        "TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM",
        "TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy",
        "TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0."
    },
    {
      "id": "CVE-2019-0676",
      "url": "https://spydr.io/cve/CVE-2019-0676",
      "published": "2019-03-05T23:29:02.613Z",
      "modified": "2026-06-17T02:08:40.863Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.0811,
      "epss_percentile": 0.94691,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [],
      "description": "An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'."
    },
    {
      "id": "CVE-2019-0604",
      "url": "https://spydr.io/cve/CVE-2019-0604",
      "published": "2019-03-05T23:29:00.757Z",
      "modified": "2026-06-17T02:08:31.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99913,
      "epss_percentile": 0.99968,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Server",
        "Microsoft SharePoint Foundation",
        "Microsoft SharePoint Enterprise Server"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594."
    },
    {
      "id": "CVE-2019-6223",
      "url": "https://spydr.io/cve/CVE-2019-6223",
      "published": "2019-03-05T16:29:02.060Z",
      "modified": "2026-06-17T02:38:50.217Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.02629,
      "epss_percentile": 0.85049,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS"
      ],
      "cwes": [],
      "description": "A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer."
    },
    {
      "id": "CVE-2019-9082",
      "url": "https://spydr.io/cve/CVE-2019-9082",
      "published": "2019-02-24T18:29:00.207Z",
      "modified": "2026-06-17T02:43:02.110Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97419,
      "epss_percentile": 0.999,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "thinkphp",
        "opensourcebms",
        "zzzcms"
      ],
      "products": [
        "thinkphp",
        "opensourcebms open source background management system",
        "zzzcms zzzphp"
      ],
      "cwes": [
        "CWE-94",
        "CWE-306"
      ],
      "description": "ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command."
    },
    {
      "id": "CVE-2019-6340",
      "url": "https://spydr.io/cve/CVE-2019-6340",
      "published": "2019-02-21T21:29:00.343Z",
      "modified": "2026-06-17T02:39:02.497Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92017,
      "epss_percentile": 0.9982,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Drupal"
      ],
      "products": [
        "Drupal Core"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)"
    },
    {
      "id": "CVE-2019-8394",
      "url": "https://spydr.io/cve/CVE-2019-8394",
      "published": "2019-02-17T04:29:00.330Z",
      "modified": "2026-06-17T02:41:56.683Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.63336,
      "epss_percentile": 0.9919,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine servicedesk plus"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization."
    },
    {
      "id": "CVE-2018-20250",
      "url": "https://spydr.io/cve/CVE-2018-20250",
      "published": "2019-02-05T20:29:00.243Z",
      "modified": "2026-08-13T05:17:17.910Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96004,
      "epss_percentile": 0.99876,
      "exploited": true,
      "kev": {
        "added": "2022-02-15",
        "due": "2022-08-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Check Point Software Technologies Ltd."
      ],
      "products": [
        "Check Point Software Technologies Ltd. WinRAR"
      ],
      "cwes": [
        "CWE-36",
        "CWE-22"
      ],
      "description": "In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path."
    },
    {
      "id": "CVE-2018-20753",
      "url": "https://spydr.io/cve/CVE-2018-20753",
      "published": "2019-02-05T06:29:00.593Z",
      "modified": "2026-08-13T05:17:18.220Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29551,
      "epss_percentile": 0.98148,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "kaseya"
      ],
      "products": [
        "kaseya virtual system administrator"
      ],
      "cwes": [],
      "description": "Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild."
    },
    {
      "id": "CVE-2017-18362",
      "url": "https://spydr.io/cve/CVE-2017-18362",
      "published": "2019-02-05T06:29:00.233Z",
      "modified": "2026-08-13T05:17:15.457Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8682,
      "epss_percentile": 0.99742,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "connectwise"
      ],
      "products": [
        "connectwise manageditsync"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication."
    },
    {
      "id": "CVE-2019-1653",
      "url": "https://spydr.io/cve/CVE-2019-1653",
      "published": "2019-01-24T16:29:00.317Z",
      "modified": "2026-06-17T02:28:58.090Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99876,
      "epss_percentile": 0.99963,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to improper access controls for URLs. An attacker could exploit this vulnerability by connecting to an affected device via HTTP or HTTPS and requesting specific URLs. A successful exploit could allow the attacker to download the router configuration or detailed diagnostic information. Cisco has released firmware updates that address this vulnerability."
    },
    {
      "id": "CVE-2019-1652",
      "url": "https://spydr.io/cve/CVE-2019-1652",
      "published": "2019-01-24T15:29:00.953Z",
      "modified": "2026-06-17T02:28:57.913Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95923,
      "epss_percentile": 0.99874,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-20",
        "CWE-78"
      ],
      "description": "A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root. Cisco has released firmware updates that address this vulnerability."
    },
    {
      "id": "CVE-2018-13374",
      "url": "https://spydr.io/cve/CVE-2018-13374",
      "published": "2019-01-22T14:29:00.220Z",
      "modified": "2026-10-01T19:17:13.713Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.38088,
      "epss_percentile": 0.98524,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, fortiADC"
      ],
      "cwes": [
        "CWE-732"
      ],
      "description": "A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one."
    },
    {
      "id": "CVE-2018-15982",
      "url": "https://spydr.io/cve/CVE-2018-15982",
      "published": "2019-01-18T17:29:01.573Z",
      "modified": "2026-10-01T20:17:16.560Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89581,
      "epss_percentile": 0.99786,
      "exploited": true,
      "kev": {
        "added": "2022-02-15",
        "due": "2022-08-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation",
        "adobe flash player installer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution."
    },
    {
      "id": "CVE-2019-0543",
      "url": "https://spydr.io/cve/CVE-2019-0543",
      "published": "2019-01-08T21:29:00.517Z",
      "modified": "2026-06-17T02:08:20.077Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04718,
      "epss_percentile": 0.91587,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1607",
        "microsoft windows 10 1703",
        "microsoft windows 10 1709",
        "microsoft windows 10 1803",
        "microsoft windows 10 1809",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 1709",
        "microsoft windows server 1803",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows server 2016",
        "microsoft windows server 2019"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka \"Microsoft Windows Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2019-0541",
      "url": "https://spydr.io/cve/CVE-2019-0541",
      "published": "2019-01-08T21:29:00.470Z",
      "modified": "2026-06-17T02:08:19.707Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.53202,
      "epss_percentile": 0.98957,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office",
        "Microsoft Office Word Viewer",
        "Microsoft Internet Explorer 9",
        "Microsoft Internet Explorer 11",
        "Microsoft Excel Viewer",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka \"MSHTML Engine Remote Code Execution Vulnerability.\" This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
