{
  "query": {
    "exploited": "1",
    "page": "78"
  },
  "count": 20,
  "total": 1739,
  "page": 78,
  "limit": 20,
  "updated": {
    "cves": "2026-10-10T04:52:49.140Z",
    "kev": "2026-10-10T04:52:48.615Z",
    "epss": "2026-10-10T01:02:39.688Z",
    "breaches": "2026-10-10T00:52:39.619Z",
    "posts": "2026-10-10T04:52:49.140Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=78",
    "next": "https://spydr.io/threats.json?exploited=1&page=79"
  },
  "coverage": {
    "cves_published_since": "2026-06-12",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2015-7450",
      "url": "https://spydr.io/cve/CVE-2015-7450",
      "published": "2016-01-02T21:59:15.800Z",
      "modified": "2026-06-17T00:32:33.670Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97764,
      "epss_percentile": 0.99905,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ibm"
      ],
      "products": [
        "ibm sterling b2b integrator",
        "ibm sterling integrator",
        "ibm tivoli common reporting",
        "ibm watson content analytics",
        "ibm watson explorer analytical components",
        "ibm watson explorer annotation administration console",
        "ibm websphere application server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library."
    },
    {
      "id": "CVE-2015-8651",
      "url": "https://spydr.io/cve/CVE-2015-8651",
      "published": "2015-12-28T23:59:19.050Z",
      "modified": "2026-06-17T00:34:57.970Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.67698,
      "epss_percentile": 0.99303,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse",
        "hp"
      ],
      "products": [
        "adobe air sdk",
        "adobe air sdk & compiler",
        "adobe flash player",
        "adobe air",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "hp insight control",
        "hp insight control server provisioning",
        "hp matrix operating environment",
        "hp system management homepage",
        "hp systems insight manager",
        "hp version control repository manager"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors."
    },
    {
      "id": "CVE-2015-7755",
      "url": "https://spydr.io/cve/CVE-2015-7755",
      "published": "2015-12-19T14:59:01.453Z",
      "modified": "2026-06-17T00:33:04.553Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61139,
      "epss_percentile": 0.99143,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "juniper"
      ],
      "products": [
        "juniper screenos"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session."
    },
    {
      "id": "CVE-2015-6175",
      "url": "https://spydr.io/cve/CVE-2015-6175",
      "published": "2015-12-09T11:59:56.580Z",
      "modified": "2026-06-17T00:30:30.480Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05127,
      "epss_percentile": 0.92186,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507"
      ],
      "cwes": [],
      "description": "The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka \"Windows Kernel Memory Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2015-5287",
      "url": "https://spydr.io/cve/CVE-2015-5287",
      "published": "2015-12-07T18:59:02.230Z",
      "modified": "2026-08-27T04:16:38.280Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04962,
      "epss_percentile": 0.91972,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "oracle"
      ],
      "products": [
        "redhat automatic bug reporting tool",
        "oracle linux",
        "redhat enterprise linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux hpc node",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump."
    },
    {
      "id": "CVE-2015-5317",
      "url": "https://spydr.io/cve/CVE-2015-5317",
      "published": "2015-11-25T20:59:07.680Z",
      "modified": "2026-06-17T00:28:55.150Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.23003,
      "epss_percentile": 0.97706,
      "exploited": true,
      "kev": {
        "added": "2023-05-12",
        "due": "2023-06-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "jenkins",
        "redhat"
      ],
      "products": [
        "jenkins",
        "redhat openshift"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request."
    },
    {
      "id": "CVE-2015-4852",
      "url": "https://spydr.io/cve/CVE-2015-4852",
      "published": "2015-11-18T15:59:00.133Z",
      "modified": "2026-06-17T00:28:02.700Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96032,
      "epss_percentile": 0.99877,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle"
      ],
      "products": [
        "oracle virtual desktop infrastructure",
        "oracle storagetek tape analytics sw tool",
        "oracle weblogic server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product."
    },
    {
      "id": "CVE-2015-4902",
      "url": "https://spydr.io/cve/CVE-2015-4902",
      "published": "2015-10-22T00:00:03.093Z",
      "modified": "2026-06-17T00:28:08.793Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "CISA ADP",
      "epss": 0.13603,
      "epss_percentile": 0.96382,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "redhat",
        "suse",
        "opensuse"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "redhat satellite",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux eus compute node",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for ibm z systems eus",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for power little endian",
        "redhat enterprise linux for power little endian eus",
        "redhat enterprise linux for scientific computing",
        "redhat enterprise linux server",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation",
        "suse linux enterprise module for legacy",
        "opensuse leap",
        "opensuse",
        "suse linux enterprise server"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment."
    },
    {
      "id": "CVE-2015-7645",
      "url": "https://spydr.io/cve/CVE-2015-7645",
      "published": "2015-10-15T10:59:10.530Z",
      "modified": "2026-06-17T00:32:53.400Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.65339,
      "epss_percentile": 0.99244,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation"
      ],
      "cwes": [],
      "description": "Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015."
    },
    {
      "id": "CVE-2015-2546",
      "url": "https://spydr.io/cve/CVE-2015-2546",
      "published": "2015-09-09T00:59:53.207Z",
      "modified": "2026-08-14T05:16:52.893Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.10107,
      "epss_percentile": 0.95541,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka \"Win32k Memory Corruption Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518."
    },
    {
      "id": "CVE-2015-2545",
      "url": "https://spydr.io/cve/CVE-2015-2545",
      "published": "2015-09-09T00:59:52.190Z",
      "modified": "2026-06-17T00:24:16.650Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85937,
      "epss_percentile": 0.99726,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office"
      ],
      "cwes": [],
      "description": "Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka \"Microsoft Office Malformed EPS File Vulnerability.\""
    },
    {
      "id": "CVE-2015-2502",
      "url": "https://spydr.io/cve/CVE-2015-2502",
      "published": "2015-08-19T10:59:00.090Z",
      "modified": "2026-06-17T00:24:12.337Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.51001,
      "epss_percentile": 0.98906,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Memory Corruption Vulnerability,\" as exploited in the wild in August 2015."
    },
    {
      "id": "CVE-2015-1769",
      "url": "https://spydr.io/cve/CVE-2015-1769",
      "published": "2015-08-15T00:59:01.467Z",
      "modified": "2026-06-17T00:22:57.410Z",
      "score": 6.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.04078,
      "epss_percentile": 0.90446,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10",
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-264"
      ],
      "description": "Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka \"Mount Manager Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2015-1642",
      "url": "https://spydr.io/cve/CVE-2015-1642",
      "published": "2015-08-15T00:59:00.110Z",
      "modified": "2026-06-17T00:22:45.180Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.53087,
      "epss_percentile": 0.98956,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-3246",
      "url": "https://spydr.io/cve/CVE-2015-3246",
      "published": "2015-08-11T14:59:07.040Z",
      "modified": "2026-10-02T11:33:29.473Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.08434,
      "epss_percentile": 0.94876,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "opensuse",
        "libuser project"
      ],
      "products": [
        "redhat enterprise linux",
        "opensuse",
        "libuser project libuser"
      ],
      "cwes": [
        "CWE-264",
        "CWE-367"
      ],
      "description": "libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges."
    },
    {
      "id": "CVE-2015-4495",
      "url": "https://spydr.io/cve/CVE-2015-4495",
      "published": "2015-08-08T00:59:04.597Z",
      "modified": "2026-06-17T00:27:24.177Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.68558,
      "epss_percentile": 0.99325,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mozilla",
        "oracle",
        "canonical",
        "redhat",
        "suse",
        "opensuse"
      ],
      "products": [
        "mozilla firefox",
        "mozilla firefox os",
        "oracle solaris",
        "canonical ubuntu linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "suse linux enterprise debuginfo",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise server",
        "suse linux enterprise software development kit"
      ],
      "cwes": [
        "CWE-346"
      ],
      "description": "The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015."
    },
    {
      "id": "CVE-2015-5477",
      "url": "https://spydr.io/cve/CVE-2015-5477",
      "published": "2015-07-29T14:59:05.397Z",
      "modified": "2026-10-09T19:12:37.977Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "CISA ADP",
      "epss": 0.91807,
      "epss_percentile": 0.99816,
      "exploited": true,
      "kev": {
        "added": "2026-10-08",
        "due": "2026-10-11",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "juniper",
        "fedoraproject",
        "redhat",
        "debian",
        "oracle",
        "hp",
        "canonical",
        "netapp",
        "apple",
        "hpe"
      ],
      "products": [
        "juniper junos",
        "fedoraproject fedora",
        "redhat enterprise linux",
        "redhat enterprise linux aus",
        "debian linux",
        "oracle vm server",
        "oracle solaris",
        "hp-ux",
        "canonical ubuntu linux",
        "netapp clustered data ontap",
        "apple os x server",
        "hpe dns",
        "hp openvms",
        "hpe vcx",
        "suse linux enterprise debuginfo",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise server",
        "suse linux enterprise software development kit"
      ],
      "cwes": [
        "CWE-19",
        "CWE-617"
      ],
      "description": "named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries."
    },
    {
      "id": "CVE-2015-2426",
      "url": "https://spydr.io/cve/CVE-2015-2426",
      "published": "2015-07-20T18:59:01.210Z",
      "modified": "2026-06-17T00:24:05.220Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.86576,
      "epss_percentile": 0.99736,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10",
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-119",
        "CWE-124"
      ],
      "description": "Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka \"OpenType Font Driver Vulnerability.\""
    },
    {
      "id": "CVE-2015-2590",
      "url": "https://spydr.io/cve/CVE-2015-2590",
      "published": "2015-07-16T10:59:17.050Z",
      "modified": "2026-06-17T00:24:21.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.25469,
      "epss_percentile": 0.97909,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "canonical",
        "debian",
        "suse",
        "opensuse",
        "redhat"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "canonical ubuntu linux",
        "debian linux",
        "suse linux enterprise debuginfo",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise server",
        "redhat satellite",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for ibm z systems eus",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for power little endian",
        "redhat enterprise linux for power little endian eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server tus"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732."
    },
    {
      "id": "CVE-2015-2387",
      "url": "https://spydr.io/cve/CVE-2015-2387",
      "published": "2015-07-14T22:59:08.103Z",
      "modified": "2026-06-17T00:24:01.693Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34878,
      "epss_percentile": 0.984,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka \"ATMFD.DLL Memory Corruption Vulnerability.\""
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
