{
  "query": {
    "exploited": "1",
    "page": "81"
  },
  "count": 20,
  "total": 1739,
  "page": 81,
  "limit": 20,
  "updated": {
    "cves": "2026-10-10T06:52:53.843Z",
    "kev": "2026-10-10T07:52:55.656Z",
    "epss": "2026-10-10T07:02:53.632Z",
    "breaches": "2026-10-10T06:52:53.471Z",
    "posts": "2026-10-10T07:52:56.116Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=81",
    "next": "https://spydr.io/threats.json?exploited=1&page=82"
  },
  "coverage": {
    "cves_published_since": "2026-06-12",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2014-7169",
      "url": "https://spydr.io/cve/CVE-2014-7169",
      "published": "2014-09-25T01:55:04.367Z",
      "modified": "2026-06-17T00:14:28.143Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9994,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gnu",
        "arista",
        "oracle",
        "qnap",
        "mageia",
        "redhat",
        "suse",
        "opensuse",
        "debian",
        "ibm"
      ],
      "products": [
        "gnu bash",
        "arista eos",
        "oracle linux",
        "qnap qts",
        "mageia",
        "redhat gluster storage server for on-premise",
        "redhat virtualization",
        "redhat enterprise linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for scientific computing",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "suse studio onsite"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271."
    },
    {
      "id": "CVE-2014-6271",
      "url": "https://spydr.io/cve/CVE-2014-6271",
      "published": "2014-09-24T18:48:04.477Z",
      "modified": "2026-06-17T00:12:48.020Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99993,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gnu",
        "arista",
        "oracle",
        "qnap",
        "mageia",
        "redhat",
        "suse",
        "opensuse",
        "debian",
        "ibm"
      ],
      "products": [
        "gnu bash",
        "arista eos",
        "oracle linux",
        "qnap qts",
        "mageia",
        "redhat gluster storage server for on-premise",
        "redhat virtualization",
        "redhat enterprise linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for scientific computing",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "suse studio onsite"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka \"ShellShock.\" NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix."
    },
    {
      "id": "CVE-2014-4404",
      "url": "https://spydr.io/cve/CVE-2014-4404",
      "published": "2014-09-18T10:55:09.827Z",
      "modified": "2026-06-17T00:09:56.033Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48923,
      "epss_percentile": 0.98854,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os",
        "apple mac os x",
        "apple tvos"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties."
    },
    {
      "id": "CVE-2013-2597",
      "url": "https://spydr.io/cve/CVE-2013-2597",
      "published": "2014-08-31T10:55:03.753Z",
      "modified": "2026-06-16T23:53:41.697Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.01503,
      "epss_percentile": 0.7357,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "codeaurora"
      ],
      "products": [
        "codeaurora android-msm"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument."
    },
    {
      "id": "CVE-2014-2817",
      "url": "https://spydr.io/cve/CVE-2014-2817",
      "published": "2014-08-12T21:55:07.007Z",
      "modified": "2026-06-17T00:07:12.597Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.26349,
      "epss_percentile": 0.97963,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2014-0546",
      "url": "https://spydr.io/cve/CVE-2014-0546",
      "published": "2014-08-12T21:55:06.460Z",
      "modified": "2026-06-17T00:03:15.103Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.2233,
      "epss_percentile": 0.97638,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe acrobat",
        "adobe acrobat reader"
      ],
      "cwes": [],
      "description": "Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors."
    },
    {
      "id": "CVE-2014-3120",
      "url": "https://spydr.io/cve/CVE-2014-3120",
      "published": "2014-07-28T19:55:04.490Z",
      "modified": "2026-06-17T00:07:37.603Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.88559,
      "epss_percentile": 0.99773,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "elastic"
      ],
      "products": [
        "elasticsearch"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine."
    },
    {
      "id": "CVE-2013-3993",
      "url": "https://spydr.io/cve/CVE-2013-3993",
      "published": "2014-07-07T11:01:28.383Z",
      "modified": "2026-06-16T23:56:08.523Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.04766,
      "epss_percentile": 0.91681,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ibm"
      ],
      "products": [
        "ibm infosphere biginsights"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls."
    },
    {
      "id": "CVE-2014-3153",
      "url": "https://spydr.io/cve/CVE-2014-3153",
      "published": "2014-06-07T14:55:27.240Z",
      "modified": "2026-06-17T00:07:40.877Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.37233,
      "epss_percentile": 0.98492,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "redhat",
        "opensuse",
        "suse",
        "canonical",
        "oracle"
      ],
      "products": [
        "linux kernel",
        "redhat enterprise linux server aus",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise high availability extension",
        "suse linux enterprise real time extension",
        "suse linux enterprise server",
        "canonical ubuntu linux",
        "oracle linux"
      ],
      "cwes": [],
      "description": "The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification."
    },
    {
      "id": "CVE-2014-1812",
      "url": "https://spydr.io/cve/CVE-2014-1812",
      "published": "2014-05-14T11:13:06.630Z",
      "modified": "2026-06-17T00:05:35.860Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.64876,
      "epss_percentile": 0.99233,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-255",
        "CWE-522"
      ],
      "description": "The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka \"Group Policy Preferences Password Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2014-0196",
      "url": "https://spydr.io/cve/CVE-2014-0196",
      "published": "2014-05-07T10:55:04.337Z",
      "modified": "2026-06-17T00:02:29.250Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "CISA ADP",
      "epss": 0.22475,
      "epss_percentile": 0.97657,
      "exploited": true,
      "kev": {
        "added": "2023-05-12",
        "due": "2023-06-02",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "debian",
        "redhat",
        "suse",
        "oracle",
        "canonical",
        "f5"
      ],
      "products": [
        "linux kernel",
        "debian linux",
        "redhat enterprise linux",
        "redhat enterprise linux eus",
        "redhat enterprise linux server eus",
        "suse linux enterprise desktop",
        "suse linux enterprise high availability extension",
        "suse linux enterprise server",
        "oracle linux",
        "canonical ubuntu linux",
        "f5 big-ip access policy manager",
        "f5 big-ip advanced firewall manager",
        "f5 big-ip analytics",
        "f5 big-ip application acceleration manager",
        "f5 big-ip application security manager",
        "f5 big-ip edge gateway",
        "f5 big-ip global traffic manager",
        "f5 big-ip link controller",
        "f5 big-ip local traffic manager",
        "f5 big-ip policy enforcement manager"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the \"LECHO & !OPOST\" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings."
    },
    {
      "id": "CVE-2014-0130",
      "url": "https://spydr.io/cve/CVE-2014-0130",
      "published": "2014-05-07T10:55:04.133Z",
      "modified": "2026-06-17T00:02:21.133Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.53703,
      "epss_percentile": 0.98975,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "rubyonrails"
      ],
      "products": [
        "redhat subscription asset manager",
        "redhat enterprise linux server",
        "rubyonrails rails"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request."
    },
    {
      "id": "CVE-2014-1776",
      "url": "https://spydr.io/cve/CVE-2014-1776",
      "published": "2014-04-27T10:55:03.340Z",
      "modified": "2026-06-17T00:05:32.593Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.82682,
      "epss_percentile": 0.99661,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that \"VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks.\""
    },
    {
      "id": "CVE-2014-0780",
      "url": "https://spydr.io/cve/CVE-2014-0780",
      "published": "2014-04-25T05:12:07.787Z",
      "modified": "2026-06-17T00:03:37.613Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74679,
      "epss_percentile": 0.99493,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "InduSoft"
      ],
      "products": [
        "InduSoft Web Studio"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests."
    },
    {
      "id": "CVE-2014-0160",
      "url": "https://spydr.io/cve/CVE-2014-0160",
      "published": "2014-04-07T22:55:03.893Z",
      "modified": "2026-06-17T00:02:24.467Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99997,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "openssl",
        "filezilla-project",
        "siemens",
        "intellian",
        "mitel",
        "opensuse",
        "canonical",
        "fedoraproject",
        "redhat",
        "debian"
      ],
      "products": [
        "openssl",
        "filezilla-project filezilla server",
        "siemens application processing engine firmware",
        "siemens cp 1543-1 firmware",
        "siemens simatic s7-1500 firmware",
        "siemens simatic s7-1500t firmware",
        "siemens elan-8.2",
        "siemens wincc open architecture",
        "intellian v100 firmware",
        "intellian v60 firmware",
        "mitel micollab",
        "mitel mivoice",
        "opensuse",
        "canonical ubuntu linux",
        "fedoraproject fedora",
        "redhat gluster storage",
        "redhat storage",
        "redhat virtualization",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug."
    },
    {
      "id": "CVE-2014-1761",
      "url": "https://spydr.io/cve/CVE-2014-1761",
      "published": "2014-03-25T13:24:01.067Z",
      "modified": "2026-06-17T00:05:31.070Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.7746,
      "epss_percentile": 0.99551,
      "exploited": true,
      "kev": {
        "added": "2022-02-15",
        "due": "2022-08-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office",
        "microsoft office compatibility pack",
        "microsoft office web apps",
        "microsoft office web apps server",
        "microsoft sharepoint server",
        "microsoft word",
        "microsoft word viewer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014."
    },
    {
      "id": "CVE-2014-2120",
      "url": "https://spydr.io/cve/CVE-2014-2120",
      "published": "2014-03-19T01:15:04.007Z",
      "modified": "2026-06-17T00:06:05.827Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.22558,
      "epss_percentile": 0.97665,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco adaptive_security_appliance_software"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025."
    },
    {
      "id": "CVE-2013-7331",
      "url": "https://spydr.io/cve/CVE-2013-7331",
      "published": "2014-02-26T14:55:08.520Z",
      "modified": "2026-06-17T00:01:46.240Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "score_source": "CISA ADP",
      "epss": 0.5021,
      "epss_percentile": 0.98883,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-209"
      ],
      "description": "The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014."
    },
    {
      "id": "CVE-2014-0502",
      "url": "https://spydr.io/cve/CVE-2014-0502",
      "published": "2014-02-21T05:07:00.017Z",
      "modified": "2026-06-17T00:03:09.860Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24817,
      "epss_percentile": 0.97859,
      "exploited": true,
      "kev": {
        "added": "2024-09-17",
        "due": "2024-10-08",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash_player",
        "adobe air",
        "adobe air_sdk"
      ],
      "cwes": [
        "CWE-415"
      ],
      "description": "Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014."
    },
    {
      "id": "CVE-2014-0322",
      "url": "https://spydr.io/cve/CVE-2014-0322",
      "published": "2014-02-14T16:55:07.500Z",
      "modified": "2026-06-17T00:02:47.407Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85122,
      "epss_percentile": 0.99711,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
