{
  "query": {
    "exploited": "1",
    "page": "75"
  },
  "count": 20,
  "total": 1739,
  "page": 75,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T22:50:31.810Z",
    "kev": "2026-10-08T23:50:33.345Z",
    "epss": "2026-10-08T19:01:23.474Z",
    "breaches": "2026-10-09T00:49:35.859Z",
    "posts": "2026-10-08T23:50:33.664Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=75",
    "next": "https://spydr.io/threats.json?exploited=1&page=76"
  },
  "coverage": {
    "cves_published_since": "2026-06-11",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-5638",
      "url": "https://spydr.io/cve/CVE-2017-5638",
      "published": "2017-03-11T02:59:00.150Z",
      "modified": "2026-06-17T01:20:54.013Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99994,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Struts"
      ],
      "cwes": [
        "CWE-755"
      ],
      "description": "The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string."
    },
    {
      "id": "CVE-2017-6334",
      "url": "https://spydr.io/cve/CVE-2017-6334",
      "published": "2017-03-06T02:59:00.433Z",
      "modified": "2026-06-17T01:22:10.303Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7264,
      "epss_percentile": 0.99433,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear dgn2200 series firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077."
    },
    {
      "id": "CVE-2017-0037",
      "url": "https://spydr.io/cve/CVE-2017-0037",
      "published": "2017-02-26T23:59:00.150Z",
      "modified": "2026-06-17T00:56:57.983Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.80386,
      "epss_percentile": 0.99615,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Internet Browser"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element."
    },
    {
      "id": "CVE-2017-6077",
      "url": "https://spydr.io/cve/CVE-2017-6077",
      "published": "2017-02-22T23:59:00.190Z",
      "modified": "2026-06-17T01:21:45.350Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.68712,
      "epss_percentile": 0.99328,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear dgn2200 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request."
    },
    {
      "id": "CVE-2016-10174",
      "url": "https://spydr.io/cve/CVE-2016-10174",
      "published": "2017-01-30T04:59:00.157Z",
      "modified": "2026-06-17T00:39:12.707Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83328,
      "epss_percentile": 0.99674,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear d6100 firmware",
        "netgear d7000 firmware",
        "netgear d7800 firmware",
        "netgear jnr1010v2 firmware",
        "netgear jnr3300 firmware",
        "netgear jwnr2010v5 firmware",
        "netgear r2000 firmware",
        "netgear r6100 firmware",
        "netgear r6220 firmware",
        "netgear r7500 firmware",
        "netgear r7500v2 firmware",
        "netgear wndr3700v4 firmware",
        "netgear wndr3800 firmware",
        "netgear wndr4300 firmware",
        "netgear wndr4300v2 firmware",
        "netgear wndr4500v3 firmware",
        "netgear wndr4700 firmware",
        "netgear wnr1000v2 firmware",
        "netgear wnr1000v4 firmware",
        "netgear wnr2000v3 firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution."
    },
    {
      "id": "CVE-2016-5198",
      "url": "https://spydr.io/cve/CVE-2016-5198",
      "published": "2017-01-19T05:59:00.213Z",
      "modified": "2026-06-17T00:48:57.617Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34164,
      "epss_percentile": 0.98369,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "redhat"
      ],
      "products": [
        "Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page."
    },
    {
      "id": "CVE-2017-5521",
      "url": "https://spydr.io/cve/CVE-2017-5521",
      "published": "2017-01-17T09:59:00.333Z",
      "modified": "2026-06-17T01:20:39.923Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89245,
      "epss_percentile": 0.9978,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear r6200 firmware",
        "netgear r6300 firmware",
        "netgear vegn2610 firmware",
        "netgear ac1450 firmware",
        "netgear wnr1000v3 firmware",
        "netgear wndr3700v3 firmware",
        "netgear wndr4000 firmware",
        "netgear wndr4500 firmware",
        "netgear d6400 firmware",
        "netgear d6220 firmware",
        "netgear d6300 firmware",
        "netgear d6300b firmware",
        "netgear dgn2200bv4 firmware"
      ],
      "cwes": [],
      "description": "An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions."
    },
    {
      "id": "CVE-2016-10033",
      "url": "https://spydr.io/cve/CVE-2016-10033",
      "published": "2016-12-30T19:59:00.137Z",
      "modified": "2026-06-17T00:38:55.477Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99714,
      "epss_percentile": 0.99952,
      "exploited": true,
      "kev": {
        "added": "2025-07-07",
        "due": "2025-07-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "phpmailer project",
        "wordpress",
        "joomla"
      ],
      "products": [
        "phpmailer project phpmailer",
        "wordpress",
        "joomla!"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \\\" (backslash double quote) in a crafted Sender property."
    },
    {
      "id": "CVE-2016-7262",
      "url": "https://spydr.io/cve/CVE-2016-7262",
      "published": "2016-12-20T06:59:00.373Z",
      "modified": "2026-06-17T00:52:53.020Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.57733,
      "epss_percentile": 0.99066,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft excel",
        "microsoft excel viewer",
        "microsoft office compatibility pack"
      ],
      "cwes": [],
      "description": "Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka \"Microsoft Office Security Feature Bypass Vulnerability.\""
    },
    {
      "id": "CVE-2016-7892",
      "url": "https://spydr.io/cve/CVE-2016-7892",
      "published": "2016-12-15T06:59:56.313Z",
      "modified": "2026-06-17T00:53:43.090Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.18786,
      "epss_percentile": 0.97215,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution."
    },
    {
      "id": "CVE-2016-6277",
      "url": "https://spydr.io/cve/CVE-2016-6277",
      "published": "2016-12-14T16:59:00.350Z",
      "modified": "2026-06-17T00:50:44.547Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99803,
      "epss_percentile": 0.99957,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear d6220 firmware",
        "netgear d6400 firmware",
        "netgear r6250 firmware",
        "netgear r6400 firmware",
        "netgear r6700 firmware",
        "netgear r6900 firmware",
        "netgear r7000 firmware",
        "netgear r7100lg firmware",
        "netgear r7300dst firmware",
        "netgear r7900 firmware",
        "netgear r8000 firmware"
      ],
      "cwes": [
        "CWE-352"
      ],
      "description": "NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/."
    },
    {
      "id": "CVE-2016-9563",
      "url": "https://spydr.io/cve/CVE-2016-9563",
      "published": "2016-11-23T02:59:06.370Z",
      "modified": "2026-06-17T00:56:14.847Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.24226,
      "epss_percentile": 0.97807,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909."
    },
    {
      "id": "CVE-2016-8562",
      "url": "https://spydr.io/cve/CVE-2016-8562",
      "published": "2016-11-18T21:59:02.033Z",
      "modified": "2026-06-17T00:54:31.297Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0361,
      "epss_percentile": 0.8918,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "siemens"
      ],
      "products": [
        "siemens simatic cp 1543-1 firmware",
        "siemens siplus net cp 1543-1 firmware"
      ],
      "cwes": [],
      "description": "A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service."
    },
    {
      "id": "CVE-2016-5195",
      "url": "https://spydr.io/cve/CVE-2016-5195",
      "published": "2016-11-10T21:59:00.197Z",
      "modified": "2026-06-17T00:48:56.647Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83524,
      "epss_percentile": 0.9968,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "canonical",
        "linux",
        "redhat",
        "debian",
        "fedoraproject",
        "paloaltonetworks",
        "netapp"
      ],
      "products": [
        "canonical ubuntu linux",
        "linux kernel",
        "redhat enterprise linux",
        "redhat enterprise linux aus",
        "redhat enterprise linux eus",
        "redhat enterprise linux long life",
        "redhat enterprise linux tus",
        "debian linux",
        "fedoraproject fedora",
        "paloaltonetworks pan-os",
        "netapp cloud backup",
        "netapp hci storage nodes",
        "netapp oncommand balance",
        "netapp oncommand performance manager",
        "netapp oncommand unified manager for clustered data ontap",
        "netapp ontap select deploy administration utility",
        "netapp snapprotect",
        "netapp solidfire"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka \"Dirty COW.\""
    },
    {
      "id": "CVE-2016-7256",
      "url": "https://spydr.io/cve/CVE-2016-7256",
      "published": "2016-11-10T07:00:10.537Z",
      "modified": "2026-06-17T00:52:52.403Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64591,
      "epss_percentile": 0.99224,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 10 1607",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows server 2016",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka \"Open Type Font Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2016-7255",
      "url": "https://spydr.io/cve/CVE-2016-7255",
      "published": "2016-11-10T07:00:09.460Z",
      "modified": "2026-09-10T04:17:32.400Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.80968,
      "epss_percentile": 0.99625,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 10 1607",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows server 2016",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2016-7201",
      "url": "https://spydr.io/cve/CVE-2016-7201",
      "published": "2016-11-10T06:59:16.810Z",
      "modified": "2026-06-17T00:52:46.620Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.80004,
      "epss_percentile": 0.99608,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft edge"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243."
    },
    {
      "id": "CVE-2016-7200",
      "url": "https://spydr.io/cve/CVE-2016-7200",
      "published": "2016-11-10T06:59:15.733Z",
      "modified": "2026-06-17T00:52:46.430Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82779,
      "epss_percentile": 0.99664,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft edge"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243."
    },
    {
      "id": "CVE-2016-7855",
      "url": "https://spydr.io/cve/CVE-2016-7855",
      "published": "2016-11-01T22:59:00.167Z",
      "modified": "2026-06-17T00:53:36.470Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.25198,
      "epss_percentile": 0.9789,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016."
    },
    {
      "id": "CVE-2016-7193",
      "url": "https://spydr.io/cve/CVE-2016-7193",
      "published": "2016-10-14T02:59:38.013Z",
      "modified": "2026-06-17T00:52:45.730Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.57582,
      "epss_percentile": 0.99063,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office",
        "microsoft office compatibility pack",
        "microsoft word",
        "microsoft word viewer"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted RTF document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
