{
  "query": {
    "exploited": "1",
    "page": "80"
  },
  "count": 20,
  "total": 1739,
  "page": 80,
  "limit": 20,
  "updated": {
    "cves": "2026-10-10T06:52:53.843Z",
    "kev": "2026-10-10T06:52:53.234Z",
    "epss": "2026-10-10T07:02:53.632Z",
    "breaches": "2026-10-10T06:52:53.471Z",
    "posts": "2026-10-10T06:52:53.843Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=80",
    "next": "https://spydr.io/threats.json?exploited=1&page=81"
  },
  "coverage": {
    "cves_published_since": "2026-06-12",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2015-2051",
      "url": "https://spydr.io/cve/CVE-2015-2051",
      "published": "2015-02-23T17:59:08.320Z",
      "modified": "2026-06-17T00:23:30.663Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97101,
      "epss_percentile": 0.99893,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-645",
        "dlink dir-645_firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface."
    },
    {
      "id": "CVE-2015-1427",
      "url": "https://spydr.io/cve/CVE-2015-1427",
      "published": "2015-02-17T15:59:04.560Z",
      "modified": "2026-06-17T00:22:24.453Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99906,
      "epss_percentile": 0.99966,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "elastic",
        "redhat"
      ],
      "products": [
        "elasticsearch",
        "redhat fuse"
      ],
      "cwes": [],
      "description": "The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script."
    },
    {
      "id": "CVE-2015-0071",
      "url": "https://spydr.io/cve/CVE-2015-0071",
      "published": "2015-02-11T03:01:12.497Z",
      "modified": "2026-06-17T00:19:30.960Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.33581,
      "epss_percentile": 0.98349,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka \"Internet Explorer ASLR Bypass Vulnerability.\""
    },
    {
      "id": "CVE-2015-0313",
      "url": "https://spydr.io/cve/CVE-2015-0313",
      "published": "2015-02-02T19:59:00.053Z",
      "modified": "2026-06-17T00:19:58.420Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95266,
      "epss_percentile": 0.99866,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "microsoft"
      ],
      "products": [
        "adobe flash player",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "microsoft internet explorer",
        "microsoft edge"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322."
    },
    {
      "id": "CVE-2015-0311",
      "url": "https://spydr.io/cve/CVE-2015-0311",
      "published": "2015-01-23T21:59:04.897Z",
      "modified": "2026-06-17T00:19:58.077Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85589,
      "epss_percentile": 0.9972,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "suse",
        "microsoft"
      ],
      "products": [
        "adobe flash player",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "microsoft internet explorer",
        "microsoft edge"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015."
    },
    {
      "id": "CVE-2015-0310",
      "url": "https://spydr.io/cve/CVE-2015-0310",
      "published": "2015-01-23T21:59:00.050Z",
      "modified": "2026-06-17T00:19:57.890Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.15097,
      "epss_percentile": 0.96659,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015."
    },
    {
      "id": "CVE-2015-0016",
      "url": "https://spydr.io/cve/CVE-2015-0016",
      "published": "2015-01-13T22:59:07.190Z",
      "modified": "2026-06-17T00:19:25.567Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.75777,
      "epss_percentile": 0.99515,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka \"Directory Traversal Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2014-100005",
      "url": "https://spydr.io/cve/CVE-2014-100005",
      "published": "2015-01-13T11:59:04.477Z",
      "modified": "2026-06-17T00:04:00.147Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.43456,
      "epss_percentile": 0.98709,
      "exploited": true,
      "kev": {
        "added": "2024-05-16",
        "due": "2024-06-06",
        "action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-600_firmware",
        "dlink dir-600"
      ],
      "cwes": [
        "CWE-352"
      ],
      "description": "Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php."
    },
    {
      "id": "CVE-2014-9163",
      "url": "https://spydr.io/cve/CVE-2014-9163",
      "published": "2014-12-10T21:59:35.163Z",
      "modified": "2026-06-17T00:17:51.397Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.20724,
      "epss_percentile": 0.97483,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014."
    },
    {
      "id": "CVE-2014-8439",
      "url": "https://spydr.io/cve/CVE-2014-8439",
      "published": "2014-11-25T23:59:00.053Z",
      "modified": "2026-06-17T00:16:43.437Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.20369,
      "epss_percentile": 0.97434,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player",
        "adobe air",
        "adobe air sdk",
        "adobe air sdk & compiler"
      ],
      "cwes": [
        "CWE-119",
        "CWE-416"
      ],
      "description": "Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors."
    },
    {
      "id": "CVE-2014-6324",
      "url": "https://spydr.io/cve/CVE-2014-6324",
      "published": "2014-11-18T23:59:02.503Z",
      "modified": "2026-06-17T00:12:54.610Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.87335,
      "epss_percentile": 0.99753,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012"
      ],
      "cwes": [],
      "description": "The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka \"Kerberos Checksum Vulnerability.\""
    },
    {
      "id": "CVE-2014-6332",
      "url": "https://spydr.io/cve/CVE-2014-6332",
      "published": "2014-11-11T22:55:05.200Z",
      "modified": "2026-06-17T00:12:55.477Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.94918,
      "epss_percentile": 0.99861,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka \"Windows OLE Automation Array Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2014-4077",
      "url": "https://spydr.io/cve/CVE-2014-4077",
      "published": "2014-11-11T22:55:04.637Z",
      "modified": "2026-06-17T00:09:23.740Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54577,
      "epss_percentile": 0.98997,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office 2007 ime",
        "microsoft windows 7",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka \"Microsoft IME (Japanese) Elevation of Privilege Vulnerability,\" as exploited in the wild in 2014."
    },
    {
      "id": "CVE-2014-6352",
      "url": "https://spydr.io/cve/CVE-2014-6352",
      "published": "2014-10-22T14:55:06.247Z",
      "modified": "2026-06-17T00:12:57.463Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77485,
      "epss_percentile": 0.99553,
      "exploited": true,
      "kev": {
        "added": "2022-02-25",
        "due": "2022-08-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document."
    },
    {
      "id": "CVE-2014-4148",
      "url": "https://spydr.io/cve/CVE-2014-4148",
      "published": "2014-10-15T10:55:08.693Z",
      "modified": "2026-06-17T00:09:30.150Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.5985,
      "epss_percentile": 0.99113,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka \"TrueType Font Parsing Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2014-4123",
      "url": "https://spydr.io/cve/CVE-2014-4123",
      "published": "2014-10-15T10:55:08.037Z",
      "modified": "2026-06-17T00:09:28.370Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.47133,
      "epss_percentile": 0.98808,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of Privilege Vulnerability,\" as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124."
    },
    {
      "id": "CVE-2014-4114",
      "url": "https://spydr.io/cve/CVE-2014-4114",
      "published": "2014-10-15T10:55:07.817Z",
      "modified": "2026-06-17T00:09:27.550Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.81628,
      "epss_percentile": 0.99637,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a \"Sandworm\" attack in June through October 2014, aka \"Windows OLE Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2014-4113",
      "url": "https://spydr.io/cve/CVE-2014-4113",
      "published": "2014-10-15T10:55:07.473Z",
      "modified": "2026-06-17T00:09:27.350Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.86928,
      "epss_percentile": 0.99745,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka \"Win32k.sys Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2014-6287",
      "url": "https://spydr.io/cve/CVE-2014-6287",
      "published": "2014-10-07T10:55:04.493Z",
      "modified": "2026-06-17T00:12:50.983Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99323,
      "epss_percentile": 0.99939,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rejetto"
      ],
      "products": [
        "rejetto http file server"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action."
    },
    {
      "id": "CVE-2014-6278",
      "url": "https://spydr.io/cve/CVE-2014-6278",
      "published": "2014-09-30T10:55:04.723Z",
      "modified": "2026-06-17T00:12:50.047Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.99621,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gnu"
      ],
      "products": [
        "gnu bash"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
