{
  "query": {
    "exploited": "1",
    "page": "79"
  },
  "count": 20,
  "total": 1739,
  "page": 79,
  "limit": 20,
  "updated": {
    "cves": "2026-10-10T04:52:49.140Z",
    "kev": "2026-10-10T05:52:51.089Z",
    "epss": "2026-10-10T01:02:39.688Z",
    "breaches": "2026-10-10T00:52:39.619Z",
    "posts": "2026-10-10T05:52:51.444Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=79",
    "next": "https://spydr.io/threats.json?exploited=1&page=80"
  },
  "coverage": {
    "cves_published_since": "2026-06-12",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2015-2425",
      "url": "https://spydr.io/cve/CVE-2015-2425",
      "published": "2015-07-14T21:59:36.813Z",
      "modified": "2026-06-17T00:24:05.047Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.44727,
      "epss_percentile": 0.98742,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2015-2383 and CVE-2015-2384."
    },
    {
      "id": "CVE-2015-2424",
      "url": "https://spydr.io/cve/CVE-2015-2424",
      "published": "2015-07-14T21:59:35.987Z",
      "modified": "2026-06-17T00:24:04.850Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.40388,
      "epss_percentile": 0.98613,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft excel viewer",
        "microsoft office",
        "microsoft office compatibility pack",
        "microsoft powerpoint",
        "microsoft word",
        "microsoft word viewer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-2419",
      "url": "https://spydr.io/cve/CVE-2015-2419",
      "published": "2015-07-14T21:59:33.283Z",
      "modified": "2026-06-17T00:24:04.143Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.53127,
      "epss_percentile": 0.98958,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"JScript9 Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-5123",
      "url": "https://spydr.io/cve/CVE-2015-5123",
      "published": "2015-07-14T10:59:01.337Z",
      "modified": "2026-06-17T00:28:31.153Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1883,
      "epss_percentile": 0.97221,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "opensuse",
        "suse",
        "adobe"
      ],
      "products": [
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux server eus",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "adobe flash player",
        "adobe flash player desktop runtime"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015."
    },
    {
      "id": "CVE-2015-5122",
      "url": "https://spydr.io/cve/CVE-2015-5122",
      "published": "2015-07-14T10:59:00.213Z",
      "modified": "2026-06-17T00:28:30.877Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93978,
      "epss_percentile": 0.99846,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "adobe flash player desktop runtime",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux server eus",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015."
    },
    {
      "id": "CVE-2015-5119",
      "url": "https://spydr.io/cve/CVE-2015-5119",
      "published": "2015-07-08T14:59:05.677Z",
      "modified": "2026-06-17T00:28:28.970Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99344,
      "epss_percentile": 0.99939,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015."
    },
    {
      "id": "CVE-2015-3113",
      "url": "https://spydr.io/cve/CVE-2015-3113",
      "published": "2015-06-23T21:59:01.960Z",
      "modified": "2026-06-17T00:25:19.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99812,
      "epss_percentile": 0.99958,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "hp",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "hp insight orchestration",
        "hp system management homepage",
        "hp systems insight manager",
        "hp version control agent",
        "hp version control repository manager",
        "hp virtual connect enterprise manager",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-787",
        "CWE-122"
      ],
      "description": "Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015."
    },
    {
      "id": "CVE-2015-2360",
      "url": "https://spydr.io/cve/CVE-2015-2360",
      "published": "2015-06-10T01:59:38.890Z",
      "modified": "2026-06-17T00:23:58.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.1484,
      "epss_percentile": 0.9662,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-119",
        "CWE-416"
      ],
      "description": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2015-1770",
      "url": "https://spydr.io/cve/CVE-2015-1770",
      "published": "2015-06-10T01:59:36.483Z",
      "modified": "2026-06-17T00:22:57.577Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34995,
      "epss_percentile": 0.98403,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office"
      ],
      "cwes": [
        "CWE-824"
      ],
      "description": "Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office Uninitialized Memory Use Vulnerability.\""
    },
    {
      "id": "CVE-2015-4068",
      "url": "https://spydr.io/cve/CVE-2015-4068",
      "published": "2015-05-29T15:59:23.327Z",
      "modified": "2026-06-17T00:26:43.280Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.63643,
      "epss_percentile": 0.992,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arcserve"
      ],
      "products": [
        "arcserve udp"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet."
    },
    {
      "id": "CVE-2015-3306",
      "url": "https://spydr.io/cve/CVE-2015-3306",
      "published": "2015-05-18T15:59:10.743Z",
      "modified": "2026-10-09T16:17:18.210Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.98033,
      "epss_percentile": 0.9991,
      "exploited": true,
      "kev": {
        "added": "2026-10-08",
        "due": "2026-10-11",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "fedoraproject",
        "debian",
        "opensuse",
        "suse",
        "proftpd"
      ],
      "products": [
        "fedoraproject fedora",
        "debian linux",
        "opensuse tumbleweed",
        "suse linux enterprise server",
        "proftpd"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands."
    },
    {
      "id": "CVE-2015-1671",
      "url": "https://spydr.io/cve/CVE-2015-1671",
      "published": "2015-05-13T10:59:03.910Z",
      "modified": "2026-06-17T00:22:47.647Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.48986,
      "epss_percentile": 0.98856,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft .net framework",
        "microsoft live meeting",
        "microsoft lync",
        "microsoft silverlight"
      ],
      "cwes": [],
      "description": "The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka \"TrueType Font Parsing Vulnerability.\""
    },
    {
      "id": "CVE-2014-8361",
      "url": "https://spydr.io/cve/CVE-2014-8361",
      "published": "2015-05-01T15:59:01.287Z",
      "modified": "2026-06-17T00:16:37.030Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99975,
      "epss_percentile": 0.99979,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink",
        "realtek",
        "aterm"
      ],
      "products": [
        "dlink dir-905l firmware",
        "dlink dir-605l firmware",
        "dlink dir-600l firmware",
        "dlink dir-619l firmware",
        "dlink dir-809 firmware",
        "dlink dir-900l firmware",
        "realtek sdk",
        "dlink dir-501 firmware",
        "dlink dir-515 firmware",
        "dlink dir-615 firmware",
        "aterm wg1900hp2 firmware",
        "aterm wg1900hp firmware",
        "aterm wg1800hp4 firmware",
        "aterm wg1800hp3 firmware",
        "aterm wg1200hs2 firmware",
        "aterm wg1200hp3 firmware",
        "aterm wg1200hp2 firmware",
        "aterm w1200ex firmware",
        "aterm w1200ex-ms firmware",
        "aterm wg1200hs firmware"
      ],
      "cwes": [],
      "description": "The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023."
    },
    {
      "id": "CVE-2015-3035",
      "url": "https://spydr.io/cve/CVE-2015-3035",
      "published": "2015-04-22T01:59:02.553Z",
      "modified": "2026-06-17T00:25:09.817Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.83948,
      "epss_percentile": 0.99689,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tp-link"
      ],
      "products": [
        "tp-link tl-wr741nd firmware",
        "tp-link tl-wr841n firmware",
        "tp-link tl-wr740n firmware",
        "tp-link archer c5 firmware",
        "tp-link tl-wdr3600 firmware",
        "tp-link archer c7 firmware",
        "tp-link tl-wr841nd firmware",
        "tp-link archer c9 firmware",
        "tp-link archer c8 firmware",
        "tp-link tl-wdr4300 firmware",
        "tp-link tl-wdr3500 firmware"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/."
    },
    {
      "id": "CVE-2015-1701",
      "url": "https://spydr.io/cve/CVE-2015-1701",
      "published": "2015-04-21T10:59:00.073Z",
      "modified": "2026-08-14T05:16:52.667Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55923,
      "epss_percentile": 0.99027,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 2003 server",
        "microsoft windows 7",
        "microsoft windows server 2008",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka \"Win32k Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2015-3043",
      "url": "https://spydr.io/cve/CVE-2015-3043",
      "published": "2015-04-14T22:59:21.323Z",
      "modified": "2026-06-17T00:25:10.877Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73862,
      "epss_percentile": 0.99471,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "novell",
        "opensuse",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "novell suse linux enterprise desktop",
        "novell suse linux enterprise workstation extension",
        "opensuse evergreen",
        "opensuse",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042."
    },
    {
      "id": "CVE-2015-1641",
      "url": "https://spydr.io/cve/CVE-2015-1641",
      "published": "2015-04-14T20:59:05.250Z",
      "modified": "2026-06-17T00:22:45.033Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96698,
      "epss_percentile": 0.99885,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office",
        "microsoft office compatibility pack",
        "microsoft office web apps",
        "microsoft outlook",
        "microsoft sharepoint server",
        "microsoft word"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to execute arbitrary code via a crafted RTF document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-1635",
      "url": "https://spydr.io/cve/CVE-2015-1635",
      "published": "2015-04-14T20:59:01.263Z",
      "modified": "2026-06-17T00:22:44.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.99999,
      "epss_percentile": 0.99998,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka \"HTTP.sys Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2015-1130",
      "url": "https://spydr.io/cve/CVE-2015-1130",
      "published": "2015-04-10T14:59:43.073Z",
      "modified": "2026-06-17T00:21:50.007Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09887,
      "epss_percentile": 0.95469,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple mac os x"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors."
    },
    {
      "id": "CVE-2015-0666",
      "url": "https://spydr.io/cve/CVE-2015-0666",
      "published": "2015-04-03T10:59:04.290Z",
      "modified": "2026-06-17T00:20:42.127Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.40379,
      "epss_percentile": 0.98613,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco prime data center network manager"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
