{
  "query": {
    "exploited": "1",
    "page": "67"
  },
  "count": 20,
  "total": 1734,
  "page": 67,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T16:49:18.208Z",
    "kev": "2026-10-08T17:50:20.616Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T17:49:20.867Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=67",
    "next": "https://spydr.io/threats.json?exploited=1&page=68"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2018-19323",
      "url": "https://spydr.io/cve/CVE-2018-19323",
      "published": "2018-12-21T23:29:00.730Z",
      "modified": "2026-10-01T21:17:13.657Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08364,
      "epss_percentile": 0.94831,
      "exploited": true,
      "kev": {
        "added": "2022-10-24",
        "due": "2022-11-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gigabyte"
      ],
      "products": [
        "gigabyte aorus graphics engine",
        "gigabyte app center",
        "gigabyte oc guru ii",
        "gigabyte xtreme gaming engine"
      ],
      "cwes": [],
      "description": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs)."
    },
    {
      "id": "CVE-2018-19322",
      "url": "https://spydr.io/cve/CVE-2018-19322",
      "published": "2018-12-21T23:29:00.650Z",
      "modified": "2026-08-13T05:17:16.757Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01816,
      "epss_percentile": 0.78026,
      "exploited": true,
      "kev": {
        "added": "2022-10-24",
        "due": "2022-11-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gigabyte"
      ],
      "products": [
        "gigabyte aorus graphics engine",
        "gigabyte app center",
        "gigabyte oc guru ii",
        "gigabyte xtreme gaming engine"
      ],
      "cwes": [
        "CWE-749"
      ],
      "description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges."
    },
    {
      "id": "CVE-2018-19321",
      "url": "https://spydr.io/cve/CVE-2018-19321",
      "published": "2018-12-21T23:29:00.573Z",
      "modified": "2026-08-13T05:17:16.560Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03701,
      "epss_percentile": 0.89436,
      "exploited": true,
      "kev": {
        "added": "2022-10-24",
        "due": "2022-11-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gigabyte"
      ],
      "products": [
        "gigabyte aorus graphics engine",
        "gigabyte app center",
        "gigabyte oc guru ii",
        "gigabyte xtreme gaming engine"
      ],
      "cwes": [],
      "description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges."
    },
    {
      "id": "CVE-2018-19320",
      "url": "https://spydr.io/cve/CVE-2018-19320",
      "published": "2018-12-21T23:29:00.493Z",
      "modified": "2026-08-13T05:17:16.323Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03597,
      "epss_percentile": 0.89135,
      "exploited": true,
      "kev": {
        "added": "2022-10-24",
        "due": "2022-11-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gigabyte"
      ],
      "products": [
        "gigabyte aorus graphics engine",
        "gigabyte app center",
        "gigabyte oc guru ii",
        "gigabyte xtreme gaming engine"
      ],
      "cwes": [],
      "description": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system."
    },
    {
      "id": "CVE-2018-8653",
      "url": "https://spydr.io/cve/CVE-2018-8653",
      "published": "2018-12-20T13:29:00.327Z",
      "modified": "2026-06-17T02:05:15.967Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29606,
      "epss_percentile": 0.98151,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 9",
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting Engine Memory Corruption Vulnerability.\" This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643."
    },
    {
      "id": "CVE-2018-8639",
      "url": "https://spydr.io/cve/CVE-2018-8639",
      "published": "2018-12-12T00:29:01.840Z",
      "modified": "2026-06-17T02:05:14.420Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22179,
      "epss_percentile": 0.9762,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 7",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows RT 8.1",
        "Microsoft Windows Server 2008",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2012",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2008 R2",
        "Microsoft Windows 10",
        "Microsoft Windows 10 Servers"
      ],
      "cwes": [
        "CWE-404"
      ],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641."
    },
    {
      "id": "CVE-2018-8611",
      "url": "https://spydr.io/cve/CVE-2018-8611",
      "published": "2018-12-12T00:29:00.933Z",
      "modified": "2026-06-17T02:05:11.560Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04196,
      "epss_percentile": 0.90681,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 7",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows RT 8.1",
        "Microsoft Windows Server 2008",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2012",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2008 R2",
        "Microsoft Windows 10",
        "Microsoft Windows 10 Servers"
      ],
      "cwes": [
        "CWE-404"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka \"Windows Kernel Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2018-20062",
      "url": "https://spydr.io/cve/CVE-2018-20062",
      "published": "2018-12-11T18:29:00.197Z",
      "modified": "2026-06-17T01:52:14.323Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9953,
      "epss_percentile": 0.99945,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "5none"
      ],
      "products": [
        "5none nonecms"
      ],
      "cwes": [],
      "description": "An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\\think\\Request/input&filter=phpinfo&data=1 query string."
    },
    {
      "id": "CVE-2018-17480",
      "url": "https://spydr.io/cve/CVE-2018-17480",
      "published": "2018-12-11T16:29:00.623Z",
      "modified": "2026-06-17T01:45:56.153Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3564,
      "epss_percentile": 0.98424,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
    },
    {
      "id": "CVE-2018-1000861",
      "url": "https://spydr.io/cve/CVE-2018-1000861",
      "published": "2018-12-10T14:29:01.417Z",
      "modified": "2026-06-17T01:33:11.847Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98326,
      "epss_percentile": 0.99916,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "jenkins",
        "redhat"
      ],
      "products": [
        "jenkins",
        "redhat openshift container platform"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way."
    },
    {
      "id": "CVE-2018-19410",
      "url": "https://spydr.io/cve/CVE-2018-19410",
      "published": "2018-11-21T16:29:00.347Z",
      "modified": "2026-06-17T01:49:15.640Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97939,
      "epss_percentile": 0.99909,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "paessler"
      ],
      "products": [
        "paessler prtg network monitor"
      ],
      "cwes": [],
      "description": "PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator)."
    },
    {
      "id": "CVE-2018-6065",
      "url": "https://spydr.io/cve/CVE-2018-6065",
      "published": "2018-11-14T15:29:01.250Z",
      "modified": "2026-06-17T02:01:16.080Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.60304,
      "epss_percentile": 0.99121,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2018-17463",
      "url": "https://spydr.io/cve/CVE-2018-17463",
      "published": "2018-11-14T15:29:00.297Z",
      "modified": "2026-06-17T01:45:53.927Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84564,
      "epss_percentile": 0.99699,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [],
      "description": "Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
    },
    {
      "id": "CVE-2018-8589",
      "url": "https://spydr.io/cve/CVE-2018-8589",
      "published": "2018-11-14T01:29:02.067Z",
      "modified": "2026-06-17T02:05:09.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03023,
      "epss_percentile": 0.87055,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008",
        "Microsoft Windows 7",
        "Microsoft Windows Server 2008 R2"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka \"Windows Win32k Elevation of Privilege Vulnerability.\" This affects Windows Server 2008, Windows 7, Windows Server 2008 R2."
    },
    {
      "id": "CVE-2018-8581",
      "url": "https://spydr.io/cve/CVE-2018-8581",
      "published": "2018-11-14T01:29:01.927Z",
      "modified": "2026-06-17T02:05:08.627Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.27355,
      "epss_percentile": 0.98016,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka \"Microsoft Exchange Server Elevation of Privilege Vulnerability.\" This affects Microsoft Exchange Server."
    },
    {
      "id": "CVE-2018-14667",
      "url": "https://spydr.io/cve/CVE-2018-14667",
      "published": "2018-11-06T22:29:00.193Z",
      "modified": "2026-06-17T01:41:24.937Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74202,
      "epss_percentile": 0.99479,
      "exploited": true,
      "kev": {
        "added": "2023-09-28",
        "due": "2023-10-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "[UNKNOWN]"
      ],
      "products": [
        "[UNKNOWN] RichFaces"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData."
    },
    {
      "id": "CVE-2018-14558",
      "url": "https://spydr.io/cve/CVE-2018-14558",
      "published": "2018-10-30T18:29:00.580Z",
      "modified": "2026-06-17T01:41:11.447Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0851,
      "epss_percentile": 0.94911,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tenda"
      ],
      "products": [
        "tenda ac7 firmware",
        "tenda ac9 firmware",
        "tenda ac10 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted goform/setUsbUnload request. This occurs because the \"formsetUsbUnload\" function executes a dosystemCmd function with untrusted input."
    },
    {
      "id": "CVE-2018-8453",
      "url": "https://spydr.io/cve/CVE-2018-8453",
      "published": "2018-10-10T13:29:02.557Z",
      "modified": "2026-08-13T05:17:19.440Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70042,
      "epss_percentile": 0.99363,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-07-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 7",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows RT 8.1",
        "Microsoft Windows Server 2008",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2012",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2008 R2",
        "Microsoft Windows 10",
        "Microsoft Windows 10 Servers"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2018-14634",
      "url": "https://spydr.io/cve/CVE-2018-14634",
      "published": "2018-09-25T21:29:00.390Z",
      "modified": "2026-06-17T01:41:20.410Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.0",
      "vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14689,
      "epss_percentile": 0.96589,
      "exploited": true,
      "kev": {
        "added": "2026-01-26",
        "due": "2026-02-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "The Linux Foundation"
      ],
      "products": [
        "The Linux Foundation kernel"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable."
    },
    {
      "id": "CVE-2018-15961",
      "url": "https://spydr.io/cve/CVE-2018-15961",
      "published": "2018-09-25T13:29:01.567Z",
      "modified": "2026-06-17T01:43:25.060Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9995,
      "epss_percentile": 0.99974,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
