{
  "query": {
    "exploited": "1",
    "page": "76"
  },
  "count": 20,
  "total": 1739,
  "page": 76,
  "limit": 20,
  "updated": {
    "cves": "2026-10-09T00:50:36.126Z",
    "kev": "2026-10-09T01:50:38.055Z",
    "epss": "2026-10-09T01:01:36.165Z",
    "breaches": "2026-10-09T00:49:35.859Z",
    "posts": "2026-10-09T01:50:38.405Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=76",
    "next": "https://spydr.io/threats.json?exploited=1&page=77"
  },
  "coverage": {
    "cves_published_since": "2026-06-11",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2016-3393",
      "url": "https://spydr.io/cve/CVE-2016-3393",
      "published": "2016-10-14T02:59:30.290Z",
      "modified": "2026-06-17T00:45:36.537Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.68465,
      "epss_percentile": 0.99322,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 10 1607",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web site, aka \"Windows Graphics Component RCE Vulnerability.\""
    },
    {
      "id": "CVE-2016-3298",
      "url": "https://spydr.io/cve/CVE-2016-3298",
      "published": "2016-10-14T02:59:13.893Z",
      "modified": "2026-06-17T00:45:27.033Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.33332,
      "epss_percentile": 0.98337,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer",
        "microsoft windows 7",
        "microsoft windows server 2008",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka \"Internet Explorer Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2016-6415",
      "url": "https://spydr.io/cve/CVE-2016-6415",
      "published": "2016-09-19T01:59:06.167Z",
      "modified": "2026-06-17T00:50:59.430Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.87687,
      "epss_percentile": 0.99758,
      "exploited": true,
      "kev": {
        "added": "2023-05-19",
        "due": "2023-06-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco ios",
        "cisco ios xe",
        "cisco ios xr"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN."
    },
    {
      "id": "CVE-2016-3351",
      "url": "https://spydr.io/cve/CVE-2016-3351",
      "published": "2016-09-14T10:59:24.357Z",
      "modified": "2026-08-14T05:16:53.547Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.26483,
      "epss_percentile": 0.97966,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer",
        "microsoft edge"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka \"Microsoft Browser Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2016-4657",
      "url": "https://spydr.io/cve/CVE-2016-4657",
      "published": "2016-08-25T21:59:02.150Z",
      "modified": "2026-06-17T00:47:58.727Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.66788,
      "epss_percentile": 0.99276,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site."
    },
    {
      "id": "CVE-2016-4656",
      "url": "https://spydr.io/cve/CVE-2016-4656",
      "published": "2016-08-25T21:59:01.087Z",
      "modified": "2026-06-17T00:47:58.547Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23626,
      "epss_percentile": 0.9776,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app."
    },
    {
      "id": "CVE-2016-4655",
      "url": "https://spydr.io/cve/CVE-2016-4655",
      "published": "2016-08-25T21:59:00.133Z",
      "modified": "2026-06-17T00:47:58.357Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.33353,
      "epss_percentile": 0.9834,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os"
      ],
      "cwes": [],
      "description": "The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app."
    },
    {
      "id": "CVE-2016-6367",
      "url": "https://spydr.io/cve/CVE-2016-6367",
      "published": "2016-08-18T18:59:01.463Z",
      "modified": "2026-06-17T00:50:54.407Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22583,
      "epss_percentile": 0.97666,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco adaptive security appliance software"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA."
    },
    {
      "id": "CVE-2016-6366",
      "url": "https://spydr.io/cve/CVE-2016-6366",
      "published": "2016-08-18T18:59:00.117Z",
      "modified": "2026-06-17T00:50:54.163Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87565,
      "epss_percentile": 0.99757,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco pix firewall software",
        "cisco adaptive security appliance software",
        "cisco asa 1000v cloud firewall software"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON."
    },
    {
      "id": "CVE-2016-3309",
      "url": "https://spydr.io/cve/CVE-2016-3309",
      "published": "2016-08-09T21:59:16.113Z",
      "modified": "2026-06-17T00:45:28.227Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.20467,
      "epss_percentile": 0.97453,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 10 1607",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311."
    },
    {
      "id": "CVE-2016-3643",
      "url": "https://spydr.io/cve/CVE-2016-3643",
      "published": "2016-06-17T15:59:02.257Z",
      "modified": "2026-06-17T00:46:07.770Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03674,
      "epss_percentile": 0.89365,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "solarwinds"
      ],
      "products": [
        "solarwinds virtualization manager"
      ],
      "cwes": [
        "CWE-264"
      ],
      "description": "SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by \"sudo cat /etc/passwd.\""
    },
    {
      "id": "CVE-2016-4171",
      "url": "https://spydr.io/cve/CVE-2016-4171",
      "published": "2016-06-16T14:59:51.017Z",
      "modified": "2026-06-17T00:47:02.337Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.20055,
      "epss_percentile": 0.97389,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016."
    },
    {
      "id": "CVE-2016-3235",
      "url": "https://spydr.io/cve/CVE-2016-3235",
      "published": "2016-06-16T01:59:36.983Z",
      "modified": "2026-06-17T00:45:20.667Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.43308,
      "epss_percentile": 0.98699,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft visio",
        "microsoft visio viewer"
      ],
      "cwes": [],
      "description": "Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka \"Microsoft Office OLE DLL Side Loading Vulnerability.\""
    },
    {
      "id": "CVE-2016-4523",
      "url": "https://spydr.io/cve/CVE-2016-4523",
      "published": "2016-06-09T10:59:04.073Z",
      "modified": "2026-06-17T00:47:42.740Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.31167,
      "epss_percentile": 0.98233,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "trihedral"
      ],
      "products": [
        "trihedral vtscada"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors."
    },
    {
      "id": "CVE-2016-4437",
      "url": "https://spydr.io/cve/CVE-2016-4437",
      "published": "2016-06-07T14:06:13.247Z",
      "modified": "2026-06-17T00:47:33.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93039,
      "epss_percentile": 0.99833,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache",
        "redhat"
      ],
      "products": [
        "apache aurora",
        "apache shiro",
        "redhat fuse",
        "redhat jboss middleware text-only advisories"
      ],
      "cwes": [
        "CWE-321"
      ],
      "description": "Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter."
    },
    {
      "id": "CVE-2016-3088",
      "url": "https://spydr.io/cve/CVE-2016-3088",
      "published": "2016-06-01T20:59:04.123Z",
      "modified": "2026-06-17T00:44:56.753Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98518,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "apache activemq"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request."
    },
    {
      "id": "CVE-2010-5326",
      "url": "https://spydr.io/cve/CVE-2010-5326",
      "published": "2016-05-13T10:59:00.173Z",
      "modified": "2026-06-16T23:26:33.823Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1777,
      "epss_percentile": 0.97096,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a \"Detour\" attack."
    },
    {
      "id": "CVE-2016-4117",
      "url": "https://spydr.io/cve/CVE-2016-4117",
      "published": "2016-05-11T01:59:46.137Z",
      "modified": "2026-09-10T04:17:30.760Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94354,
      "epss_percentile": 0.99851,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [],
      "description": "Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016."
    },
    {
      "id": "CVE-2016-0189",
      "url": "https://spydr.io/cve/CVE-2016-0189",
      "published": "2016-05-11T01:59:30.537Z",
      "modified": "2026-06-17T00:37:05.163Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94062,
      "epss_percentile": 0.99847,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft jscript",
        "microsoft vbscript",
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Scripting Engine Memory Corruption Vulnerability,\" a different vulnerability than CVE-2016-0187."
    },
    {
      "id": "CVE-2016-0185",
      "url": "https://spydr.io/cve/CVE-2016-0185",
      "published": "2016-05-11T01:59:26.097Z",
      "modified": "2026-06-17T00:37:04.663Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.69846,
      "epss_percentile": 0.99358,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka \"Windows Media Center Remote Code Execution Vulnerability.\""
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
