{
  "query": {
    "exploited": "1",
    "page": "84"
  },
  "count": 20,
  "total": 1739,
  "page": 84,
  "limit": 20,
  "updated": {
    "cves": "2026-10-10T08:52:58.095Z",
    "kev": "2026-10-10T09:52:59.900Z",
    "epss": "2026-10-10T07:02:53.632Z",
    "breaches": "2026-10-10T06:52:53.471Z",
    "posts": "2026-10-10T09:53:00.177Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=84",
    "next": "https://spydr.io/threats.json?exploited=1&page=85"
  },
  "coverage": {
    "cves_published_since": "2026-06-12",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2012-0518",
      "url": "https://spydr.io/cve/CVE-2012-0518",
      "published": "2012-10-16T23:55:03.087Z",
      "modified": "2026-06-16T23:37:27.830Z",
      "score": 4.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.04685,
      "epss_percentile": 0.91555,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle"
      ],
      "products": [
        "oracle fusion middleware"
      ],
      "cwes": [
        "CWE-601"
      ],
      "description": "Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175."
    },
    {
      "id": "CVE-2012-5076",
      "url": "https://spydr.io/cve/CVE-2012-5076",
      "published": "2012-10-16T21:55:02.073Z",
      "modified": "2026-06-16T23:46:10.790Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.9125,
      "epss_percentile": 0.99809,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "suse"
      ],
      "products": [
        "oracle jre",
        "suse linux enterprise desktop"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS."
    },
    {
      "id": "CVE-2012-5054",
      "url": "https://spydr.io/cve/CVE-2012-5054",
      "published": "2012-09-24T17:55:07.217Z",
      "modified": "2026-06-16T23:46:05.460Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21194,
      "epss_percentile": 0.97537,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments."
    },
    {
      "id": "CVE-2012-4969",
      "url": "https://spydr.io/cve/CVE-2012-4969",
      "published": "2012-09-18T10:39:14.147Z",
      "modified": "2026-06-16T23:45:58.897Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8025,
      "epss_percentile": 0.99614,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012."
    },
    {
      "id": "CVE-2012-4681",
      "url": "https://spydr.io/cve/CVE-2012-4681",
      "published": "2012-08-28T00:55:01.860Z",
      "modified": "2026-08-06T05:16:34.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98536,
      "epss_percentile": 0.99921,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "redhat"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using \"reflection with a trusted immediate caller\" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class."
    },
    {
      "id": "CVE-2012-1535",
      "url": "https://spydr.io/cve/CVE-2012-1535",
      "published": "2012-08-15T10:31:40.677Z",
      "modified": "2026-06-16T23:39:42.360Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70384,
      "epss_percentile": 0.99374,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation",
        "opensuse",
        "suse linux enterprise desktop"
      ],
      "cwes": [
        "CWE-20",
        "CWE-94"
      ],
      "description": "Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document."
    },
    {
      "id": "CVE-2012-1856",
      "url": "https://spydr.io/cve/CVE-2012-1856",
      "published": "2012-08-15T01:55:01.490Z",
      "modified": "2026-06-16T23:40:26.290Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72032,
      "epss_percentile": 0.99419,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft commerce server",
        "microsoft host integration server",
        "microsoft office",
        "microsoft office web components",
        "microsoft sql server",
        "microsoft visual basic",
        "microsoft visual foxpro"
      ],
      "cwes": [],
      "description": "The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka \"MSCOMCTL.OCX RCE Vulnerability.\""
    },
    {
      "id": "CVE-2012-1854",
      "url": "https://spydr.io/cve/CVE-2012-1854",
      "published": "2012-07-10T21:55:05.587Z",
      "modified": "2026-06-16T23:40:25.993Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.21028,
      "epss_percentile": 0.9752,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office",
        "microsoft visual basic for applications",
        "microsoft visual basic for applications sdk"
      ],
      "cwes": [
        "CWE-426"
      ],
      "description": "Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka \"Visual Basic for Applications Insecure Library Loading Vulnerability,\" as exploited in the wild in July 2012."
    },
    {
      "id": "CVE-2012-1723",
      "url": "https://spydr.io/cve/CVE-2012-1723",
      "published": "2012-06-16T21:55:03.500Z",
      "modified": "2026-08-06T05:16:33.940Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.93688,
      "epss_percentile": 0.99843,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "redhat"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "redhat icedtea6",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot."
    },
    {
      "id": "CVE-2012-1889",
      "url": "https://spydr.io/cve/CVE-2012-1889",
      "published": "2012-06-13T04:46:46.190Z",
      "modified": "2026-06-16T23:40:29.923Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83516,
      "epss_percentile": 0.9968,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft xml core services"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site."
    },
    {
      "id": "CVE-2012-2034",
      "url": "https://spydr.io/cve/CVE-2012-2034",
      "published": "2012-06-09T00:55:00.987Z",
      "modified": "2026-06-16T23:40:50.083Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.078,
      "epss_percentile": 0.94528,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "adobe air",
        "opensuse",
        "suse linux enterprise desktop",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037."
    },
    {
      "id": "CVE-2012-0507",
      "url": "https://spydr.io/cve/CVE-2012-0507",
      "published": "2012-06-07T22:55:17.883Z",
      "modified": "2026-08-14T05:16:51.643Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.98113,
      "epss_percentile": 0.99912,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sun",
        "oracle",
        "debian",
        "suse"
      ],
      "products": [
        "sun jre",
        "oracle jre",
        "debian linux",
        "suse linux enterprise desktop",
        "suse linux enterprise java",
        "suse linux enterprise server",
        "suse linux enterprise software development kit"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue."
    },
    {
      "id": "CVE-2012-1823",
      "url": "https://spydr.io/cve/CVE-2012-1823",
      "published": "2012-05-11T10:15:48.043Z",
      "modified": "2026-06-16T23:40:22.147Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.99998,
      "epss_percentile": 0.9999,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "php",
        "fedoraproject",
        "debian",
        "hp",
        "opensuse",
        "suse",
        "apple",
        "redhat"
      ],
      "products": [
        "php",
        "fedoraproject fedora",
        "debian linux",
        "hp-ux",
        "opensuse",
        "suse linux enterprise server",
        "suse linux enterprise software development kit",
        "apple mac os x",
        "redhat application stack",
        "redhat gluster storage server for on-premise",
        "redhat storage",
        "redhat storage for public cloud",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case."
    },
    {
      "id": "CVE-2012-1710",
      "url": "https://spydr.io/cve/CVE-2012-1710",
      "published": "2012-05-03T22:55:02.967Z",
      "modified": "2026-10-01T20:17:14.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07826,
      "epss_percentile": 0.9454,
      "exploited": true,
      "kev": {
        "added": "2022-05-25",
        "due": "2022-06-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle"
      ],
      "products": [
        "oracle fusion middleware"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709."
    },
    {
      "id": "CVE-2012-0158",
      "url": "https://spydr.io/cve/CVE-2012-0158",
      "published": "2012-04-10T21:55:01.687Z",
      "modified": "2026-06-16T23:36:48.343Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99976,
      "epss_percentile": 0.99979,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office",
        "microsoft office web components",
        "microsoft sql server 2000",
        "microsoft sql server 2005",
        "microsoft sql server 2008",
        "microsoft biztalk server",
        "microsoft commerce server",
        "microsoft commerce server 2009",
        "microsoft visual basic",
        "microsoft visual foxpro"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce Server 2002 SP4, 2007 SP2, and 2009 Gold and R2; Visual FoxPro 8.0 SP1 and 9.0 SP2; and Visual Basic 6.0 Runtime allow remote attackers to execute arbitrary code via a crafted (a) web site, (b) Office document, or (c) .rtf file that triggers \"system state\" corruption, as exploited in the wild in April 2012, aka \"MSCOMCTL.OCX RCE Vulnerability.\""
    },
    {
      "id": "CVE-2012-0151",
      "url": "https://spydr.io/cve/CVE-2012-0151",
      "published": "2012-04-10T21:55:01.597Z",
      "modified": "2026-06-16T23:36:47.550Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87719,
      "epss_percentile": 0.99759,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows vista",
        "microsoft windows xp"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka \"WinVerifyTrust Signature Validation Vulnerability.\""
    },
    {
      "id": "CVE-2012-0767",
      "url": "https://spydr.io/cve/CVE-2012-0767",
      "published": "2012-02-16T19:55:01.303Z",
      "modified": "2026-06-16T23:38:13.193Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.06187,
      "epss_percentile": 0.93329,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka \"Universal XSS (UXSS),\" as exploited in the wild in February 2012."
    },
    {
      "id": "CVE-2012-0754",
      "url": "https://spydr.io/cve/CVE-2012-0754",
      "published": "2012-02-16T19:55:01.130Z",
      "modified": "2026-06-16T23:38:11.620Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91085,
      "epss_percentile": 0.99807,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors."
    },
    {
      "id": "CVE-2012-0391",
      "url": "https://spydr.io/cve/CVE-2012-0391",
      "published": "2012-01-08T15:55:01.217Z",
      "modified": "2026-06-16T23:37:12.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.75599,
      "epss_percentile": 0.9951,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-07-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "apache struts"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter."
    },
    {
      "id": "CVE-2011-4723",
      "url": "https://spydr.io/cve/CVE-2011-4723",
      "published": "2011-12-20T11:55:08.413Z",
      "modified": "2026-06-16T23:35:18.387Z",
      "score": 5.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.03064,
      "epss_percentile": 0.87245,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-300 firmware"
      ],
      "cwes": [
        "CWE-312"
      ],
      "description": "The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
