{
  "query": {
    "exploited": "1",
    "page": "77"
  },
  "count": 20,
  "total": 1739,
  "page": 77,
  "limit": 20,
  "updated": {
    "cves": "2026-10-09T00:50:36.126Z",
    "kev": "2026-10-09T01:50:38.055Z",
    "epss": "2026-10-09T01:01:36.165Z",
    "breaches": "2026-10-09T00:49:35.859Z",
    "posts": "2026-10-09T01:50:38.405Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=77",
    "next": "https://spydr.io/threats.json?exploited=1&page=78"
  },
  "coverage": {
    "cves_published_since": "2026-06-11",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2016-3718",
      "url": "https://spydr.io/cve/CVE-2016-3718",
      "published": "2016-05-05T18:59:08.960Z",
      "modified": "2026-06-17T00:46:15.097Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.76741,
      "epss_percentile": 0.99536,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "imagemagick",
        "canonical",
        "oracle",
        "suse",
        "opensuse"
      ],
      "products": [
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for ibm z systems eus",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for power little endian",
        "redhat enterprise linux for power little endian eus",
        "redhat enterprise linux hpc node",
        "redhat enterprise linux hpc node eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux server supplementary eus",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "imagemagick",
        "canonical ubuntu linux",
        "oracle linux",
        "oracle solaris"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image."
    },
    {
      "id": "CVE-2016-3715",
      "url": "https://spydr.io/cve/CVE-2016-3715",
      "published": "2016-05-05T18:59:04.727Z",
      "modified": "2026-06-17T00:46:14.567Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.75307,
      "epss_percentile": 0.99504,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "imagemagick",
        "canonical",
        "oracle",
        "suse",
        "opensuse"
      ],
      "products": [
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for ibm z systems eus",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for power little endian",
        "redhat enterprise linux for power little endian eus",
        "redhat enterprise linux hpc node",
        "redhat enterprise linux hpc node eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux server supplementary eus",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "imagemagick",
        "canonical ubuntu linux",
        "oracle linux",
        "oracle solaris"
      ],
      "cwes": [
        "CWE-552"
      ],
      "description": "The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image."
    },
    {
      "id": "CVE-2016-3714",
      "url": "https://spydr.io/cve/CVE-2016-3714",
      "published": "2016-05-05T18:59:03.273Z",
      "modified": "2026-06-17T00:46:14.277Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97485,
      "epss_percentile": 0.99901,
      "exploited": true,
      "kev": {
        "added": "2024-09-09",
        "due": "2024-09-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "imagemagick",
        "canonical",
        "debian",
        "opensuse",
        "suse"
      ],
      "products": [
        "imagemagick",
        "canonical ubuntu_linux",
        "debian_linux",
        "opensuse",
        "opensuse leap",
        "suse_linux_enterprise_server"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka \"ImageTragick.\""
    },
    {
      "id": "CVE-2016-3081",
      "url": "https://spydr.io/cve/CVE-2016-3081",
      "published": "2016-04-26T14:59:02.207Z",
      "modified": "2026-10-08T18:17:11.817Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.93352,
      "epss_percentile": 0.99838,
      "exploited": true,
      "kev": {
        "added": "2026-10-08",
        "due": "2026-10-11",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache",
        "oracle"
      ],
      "products": [
        "apache struts",
        "oracle siebel e-billing"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions."
    },
    {
      "id": "CVE-2016-3427",
      "url": "https://spydr.io/cve/CVE-2016-3427",
      "published": "2016-04-21T11:00:21.667Z",
      "modified": "2026-06-17T00:45:40.273Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92334,
      "epss_percentile": 0.99822,
      "exploited": true,
      "kev": {
        "added": "2023-05-12",
        "due": "2023-06-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "canonical",
        "debian",
        "netapp",
        "apache",
        "redhat",
        "suse",
        "opensuse"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "oracle jrockit",
        "oracle linux",
        "canonical ubuntu linux",
        "debian linux",
        "netapp e-series santricity management plug-ins",
        "netapp e-series santricity storage manager",
        "netapp e-series santricity web services",
        "netapp oncommand balance",
        "netapp oncommand cloud manager",
        "netapp oncommand insight",
        "netapp oncommand performance manager",
        "netapp oncommand report",
        "netapp oncommand shift",
        "netapp oncommand unified manager",
        "netapp oncommand workflow automation",
        "netapp storagegrid",
        "netapp vasa provider for clustered data ontap",
        "netapp virtual storage console"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX."
    },
    {
      "id": "CVE-2016-0167",
      "url": "https://spydr.io/cve/CVE-2016-0167",
      "published": "2016-04-12T23:59:30.430Z",
      "modified": "2026-06-17T00:37:02.890Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05683,
      "epss_percentile": 0.92797,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0165."
    },
    {
      "id": "CVE-2016-0165",
      "url": "https://spydr.io/cve/CVE-2016-0165",
      "published": "2016-04-12T23:59:28.303Z",
      "modified": "2026-06-17T00:37:02.613Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13732,
      "epss_percentile": 0.96418,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0167."
    },
    {
      "id": "CVE-2016-0162",
      "url": "https://spydr.io/cve/CVE-2016-0162",
      "published": "2016-04-12T23:59:26.410Z",
      "modified": "2026-06-17T00:37:02.340Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.22012,
      "epss_percentile": 0.97611,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka \"Internet Explorer Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2016-0151",
      "url": "https://spydr.io/cve/CVE-2016-0151",
      "published": "2016-04-12T23:59:15.890Z",
      "modified": "2026-06-17T00:37:00.880Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.62943,
      "epss_percentile": 0.99181,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2012"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka \"Windows CSRSS Security Feature Bypass Vulnerability.\""
    },
    {
      "id": "CVE-2016-3976",
      "url": "https://spydr.io/cve/CVE-2016-3976",
      "published": "2016-04-07T23:59:10.797Z",
      "modified": "2026-06-17T00:46:39.947Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.47252,
      "epss_percentile": 0.9881,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971."
    },
    {
      "id": "CVE-2016-1019",
      "url": "https://spydr.io/cve/CVE-2016-1019",
      "published": "2016-04-07T10:59:01.447Z",
      "modified": "2026-10-01T20:17:16.080Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22316,
      "epss_percentile": 0.97635,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player desktop runtime",
        "adobe flash player",
        "adobe air desktop runtime",
        "adobe air sdk",
        "adobe air sdk & compiler"
      ],
      "cwes": [],
      "description": "Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016."
    },
    {
      "id": "CVE-2016-1646",
      "url": "https://spydr.io/cve/CVE-2016-1646",
      "published": "2016-03-29T10:59:00.160Z",
      "modified": "2026-06-17T00:42:19.940Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.4811,
      "epss_percentile": 0.9883,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "debian",
        "canonical",
        "google",
        "suse",
        "opensuse",
        "redhat"
      ],
      "products": [
        "debian linux",
        "canonical ubuntu linux",
        "google chrome",
        "suse package hub",
        "opensuse leap",
        "opensuse",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code."
    },
    {
      "id": "CVE-2016-1010",
      "url": "https://spydr.io/cve/CVE-2016-1010",
      "published": "2016-03-12T15:59:25.090Z",
      "modified": "2026-06-17T00:41:06.880Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19333,
      "epss_percentile": 0.97284,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted products are end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "samsung"
      ],
      "products": [
        "adobe flash player",
        "adobe air",
        "adobe air sdk",
        "samsung x14j firmware",
        "adobe flash player desktop runtime",
        "adobe air desktop runtime",
        "adobe air sdk & compiler"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993."
    },
    {
      "id": "CVE-2016-0099",
      "url": "https://spydr.io/cve/CVE-2016-0099",
      "published": "2016-03-09T11:59:09.590Z",
      "modified": "2026-06-17T00:36:55.360Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.37045,
      "epss_percentile": 0.98484,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka \"Secondary Logon Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2016-2388",
      "url": "https://spydr.io/cve/CVE-2016-2388",
      "published": "2016-02-16T15:59:02.103Z",
      "modified": "2026-06-17T00:43:57.187Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.52206,
      "epss_percentile": 0.98934,
      "exploited": true,
      "kev": {
        "added": "2022-06-09",
        "due": "2022-06-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846."
    },
    {
      "id": "CVE-2016-2386",
      "url": "https://spydr.io/cve/CVE-2016-2386",
      "published": "2016-02-16T15:59:00.133Z",
      "modified": "2026-06-17T00:43:56.867Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.71522,
      "epss_percentile": 0.99405,
      "exploited": true,
      "kev": {
        "added": "2022-06-09",
        "due": "2022-06-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079."
    },
    {
      "id": "CVE-2016-0752",
      "url": "https://spydr.io/cve/CVE-2016-0752",
      "published": "2016-02-16T02:59:06.783Z",
      "modified": "2026-06-17T00:38:09.067Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.95537,
      "epss_percentile": 0.9987,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rubyonrails",
        "opensuse",
        "suse",
        "debian",
        "redhat"
      ],
      "products": [
        "rubyonrails rails",
        "opensuse leap",
        "opensuse",
        "suse linux enterprise module for containers",
        "debian linux",
        "redhat software collections"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname."
    },
    {
      "id": "CVE-2016-0984",
      "url": "https://spydr.io/cve/CVE-2016-0984",
      "published": "2016-02-10T20:59:32.563Z",
      "modified": "2026-06-17T00:38:36.370Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54544,
      "epss_percentile": 0.98995,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted products are end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player",
        "adobe flash player desktop runtime",
        "adobe air desktop runtime",
        "adobe air sdk",
        "adobe air sdk & compiler"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983."
    },
    {
      "id": "CVE-2016-0040",
      "url": "https://spydr.io/cve/CVE-2016-0040",
      "published": "2016-02-10T11:59:06.440Z",
      "modified": "2026-06-17T00:36:50.320Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24467,
      "epss_percentile": 0.97825,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows server 2008",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka \"Windows Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2016-0034",
      "url": "https://spydr.io/cve/CVE-2016-0034",
      "published": "2016-01-13T05:59:22.657Z",
      "modified": "2026-08-14T05:16:53.100Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.69397,
      "epss_percentile": 0.99346,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted products are end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft silverlight"
      ],
      "cwes": [],
      "description": "Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka \"Silverlight Runtime Remote Code Execution Vulnerability.\""
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
