{
  "query": {
    "exploited": "1",
    "page": "69"
  },
  "count": 20,
  "total": 1739,
  "page": 69,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T18:49:28.664Z",
    "kev": "2026-10-08T18:50:22.717Z",
    "epss": "2026-10-08T19:01:23.474Z",
    "breaches": "2026-10-08T18:49:28.295Z",
    "posts": "2026-10-08T18:49:28.664Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=69",
    "next": "https://spydr.io/threats.json?exploited=1&page=70"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2018-4939",
      "url": "https://spydr.io/cve/CVE-2018-4939",
      "published": "2018-05-19T17:29:01.480Z",
      "modified": "2026-06-17T01:59:19.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61987,
      "epss_percentile": 0.99159,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution."
    },
    {
      "id": "CVE-2018-8174",
      "url": "https://spydr.io/cve/CVE-2018-8174",
      "published": "2018-05-09T19:29:02.917Z",
      "modified": "2026-08-13T05:17:19.187Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88332,
      "epss_percentile": 0.99769,
      "exploited": true,
      "kev": {
        "added": "2022-02-15",
        "due": "2022-08-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 7",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows RT 8.1",
        "Microsoft Windows Server 2008",
        "Microsoft Windows Server 2012",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2008 R2",
        "Microsoft Windows 10",
        "Microsoft Windows 10 Servers"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka \"Windows VBScript Engine Remote Code Execution Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2018-8120",
      "url": "https://spydr.io/cve/CVE-2018-8120",
      "published": "2018-05-09T19:29:01.277Z",
      "modified": "2026-08-13T05:17:18.967Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73434,
      "epss_percentile": 0.99456,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008",
        "Microsoft Windows 7",
        "Microsoft Windows Server 2008 R2"
      ],
      "cwes": [
        "CWE-404"
      ],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166."
    },
    {
      "id": "CVE-2018-0824",
      "url": "https://spydr.io/cve/CVE-2018-0824",
      "published": "2018-05-09T19:29:00.370Z",
      "modified": "2026-06-17T01:31:44.387Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73185,
      "epss_percentile": 0.99448,
      "exploited": true,
      "kev": {
        "added": "2024-08-05",
        "due": "2024-08-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows_10",
        "microsoft windows_7",
        "microsoft windows_8.1",
        "microsoft windows_rt_8.1",
        "microsoft windows_server_2008",
        "microsoft windows_server_2012",
        "microsoft windows_server_2016"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A remote code execution vulnerability exists in \"Microsoft COM for Windows\" when it fails to properly handle serialized objects, aka \"Microsoft COM for Windows Remote Code Execution Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2018-10562",
      "url": "https://spydr.io/cve/CVE-2018-10562",
      "published": "2018-05-04T03:29:00.287Z",
      "modified": "2026-06-17T01:34:10.407Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99949,
      "epss_percentile": 0.99973,
      "exploited": true,
      "kev": {
        "added": "2022-03-31",
        "due": "2022-04-21",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dasannetworks"
      ],
      "products": [
        "dasannetworks gpon router firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output."
    },
    {
      "id": "CVE-2018-10561",
      "url": "https://spydr.io/cve/CVE-2018-10561",
      "published": "2018-05-04T03:29:00.227Z",
      "modified": "2026-06-17T01:34:10.200Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92893,
      "epss_percentile": 0.9983,
      "exploited": true,
      "kev": {
        "added": "2022-03-31",
        "due": "2022-04-21",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dasannetworks"
      ],
      "products": [
        "dasannetworks gpon router firmware"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending \"?images\" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device."
    },
    {
      "id": "CVE-2018-2628",
      "url": "https://spydr.io/cve/CVE-2018-2628",
      "published": "2018-04-19T02:29:00.457Z",
      "modified": "2026-06-17T01:55:57.647Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99958,
      "epss_percentile": 0.99975,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation WebLogic Server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2018-5430",
      "url": "https://spydr.io/cve/CVE-2018-5430",
      "published": "2018-04-17T18:29:00.293Z",
      "modified": "2026-06-17T02:00:17.883Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48986,
      "epss_percentile": 0.98854,
      "exploited": true,
      "kev": {
        "added": "2022-12-29",
        "due": "2023-01-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TIBCO Software Inc."
      ],
      "products": [
        "TIBCO Software Inc. TIBCO JasperReports Server",
        "TIBCO Software Inc. TIBCO JasperReports Server Community Edition",
        "TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM",
        "TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy",
        "TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS"
      ],
      "cwes": [
        "CWE-22",
        "CWE-200"
      ],
      "description": "The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2."
    },
    {
      "id": "CVE-2018-1273",
      "url": "https://spydr.io/cve/CVE-2018-1273",
      "published": "2018-04-11T13:29:00.290Z",
      "modified": "2026-08-26T05:18:03.100Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96956,
      "epss_percentile": 0.9989,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Spring by Pivotal"
      ],
      "products": [
        "Spring by Pivotal Spring Framework"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack."
    },
    {
      "id": "CVE-2018-7600",
      "url": "https://spydr.io/cve/CVE-2018-7600",
      "published": "2018-03-29T07:29:00.260Z",
      "modified": "2026-06-17T02:03:25.850Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99991,
      "epss_percentile": 0.99985,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "drupal",
        "debian"
      ],
      "products": [
        "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations."
    },
    {
      "id": "CVE-2018-0180",
      "url": "https://spydr.io/cve/CVE-2018-0180",
      "published": "2018-03-28T22:29:01.547Z",
      "modified": "2026-06-17T01:30:01.363Z",
      "score": 5.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.04935,
      "epss_percentile": 0.9192,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS"
      ],
      "cwes": [
        "CWE-399"
      ],
      "description": "Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599."
    },
    {
      "id": "CVE-2018-0179",
      "url": "https://spydr.io/cve/CVE-2018-0179",
      "published": "2018-03-28T22:29:01.467Z",
      "modified": "2026-06-17T01:30:01.100Z",
      "score": 5.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.04935,
      "epss_percentile": 0.9192,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS"
      ],
      "cwes": [
        "CWE-399"
      ],
      "description": "Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599."
    },
    {
      "id": "CVE-2018-0175",
      "url": "https://spydr.io/cve/CVE-2018-0175",
      "published": "2018-03-28T22:29:01.280Z",
      "modified": "2026-06-17T01:30:00.453Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03478,
      "epss_percentile": 0.88776,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS, IOS XE, and IOS XR"
      ],
      "cwes": [
        "CWE-119",
        "CWE-134"
      ],
      "description": "Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664."
    },
    {
      "id": "CVE-2018-0174",
      "url": "https://spydr.io/cve/CVE-2018-0174",
      "published": "2018-03-28T22:29:01.233Z",
      "modified": "2026-06-17T01:30:00.250Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.07608,
      "epss_percentile": 0.94406,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS and IOS XE"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuh91645."
    },
    {
      "id": "CVE-2018-0173",
      "url": "https://spydr.io/cve/CVE-2018-0173",
      "published": "2018-03-28T22:29:01.170Z",
      "modified": "2026-06-17T01:30:00.043Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.07608,
      "epss_percentile": 0.94406,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS and IOS XE"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754."
    },
    {
      "id": "CVE-2018-0172",
      "url": "https://spydr.io/cve/CVE-2018-0172",
      "published": "2018-03-28T22:29:01.110Z",
      "modified": "2026-06-17T01:29:59.830Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.0782,
      "epss_percentile": 0.9453,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS and IOS XE"
      ],
      "cwes": [
        "CWE-20",
        "CWE-787"
      ],
      "description": "A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow condition on the affected device, which will cause the device to reload and result in a DoS condition. Cisco Bug IDs: CSCvg62730."
    },
    {
      "id": "CVE-2018-0171",
      "url": "https://spydr.io/cve/CVE-2018-0171",
      "published": "2018-03-28T22:29:01.063Z",
      "modified": "2026-06-17T01:29:59.627Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99479,
      "epss_percentile": 0.99944,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS and IOS XE"
      ],
      "cwes": [
        "CWE-20",
        "CWE-787"
      ],
      "description": "A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186."
    },
    {
      "id": "CVE-2018-0167",
      "url": "https://spydr.io/cve/CVE-2018-0167",
      "published": "2018-03-28T22:29:00.907Z",
      "modified": "2026-06-17T01:29:59.147Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03354,
      "epss_percentile": 0.88365,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS, IOS XE, and IOS XR"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487."
    },
    {
      "id": "CVE-2018-0161",
      "url": "https://spydr.io/cve/CVE-2018-0161",
      "published": "2018-03-28T22:29:00.703Z",
      "modified": "2026-06-17T01:29:58.503Z",
      "score": 6.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.04116,
      "epss_percentile": 0.9052,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS"
      ],
      "cwes": [
        "CWE-399"
      ],
      "description": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541."
    },
    {
      "id": "CVE-2018-0159",
      "url": "https://spydr.io/cve/CVE-2018-0159",
      "published": "2018-03-28T22:29:00.593Z",
      "modified": "2026-06-17T01:29:58.153Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.0687,
      "epss_percentile": 0.93893,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS and IOS XE"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of specific IKEv1 packets. An attacker could exploit this vulnerability by sending crafted IKEv1 packets to an affected device during an IKE negotiation. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuj73916."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
