{
  "query": {
    "kev": "1",
    "page": "13"
  },
  "count": 20,
  "total": 1734,
  "page": 13,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T09:44:34.321Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T09:45:34.451Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=13",
    "next": "https://spydr.io/threats.json?kev=1&page=14"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-37079",
      "url": "https://spydr.io/cve/CVE-2024-37079",
      "published": "2024-06-18T06:15:11.350Z",
      "modified": "2026-06-17T07:37:43.330Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22377,
      "epss_percentile": 0.97633,
      "exploited": true,
      "kev": {
        "added": "2026-01-23",
        "due": "2026-02-13",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution."
    },
    {
      "id": "CVE-2025-68645",
      "url": "https://spydr.io/cve/CVE-2025-68645",
      "published": "2025-12-22T18:16:17.070Z",
      "modified": "2026-06-17T09:59:22.500Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.48873,
      "epss_percentile": 0.98846,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-98"
      ],
      "description": "A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory."
    },
    {
      "id": "CVE-2025-54313",
      "url": "https://spydr.io/cve/CVE-2025-54313",
      "published": "2025-07-19T17:15:23.733Z",
      "modified": "2026-06-17T09:39:49.897Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N",
      "score_source": "mitre.org",
      "epss": 0.04522,
      "epss_percentile": 0.91249,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "prettier"
      ],
      "products": [
        "prettier eslint-config-prettier"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows."
    },
    {
      "id": "CVE-2025-34026",
      "url": "https://spydr.io/cve/CVE-2025-34026",
      "published": "2025-05-21T22:15:50.510Z",
      "modified": "2026-06-17T09:13:19.833Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.8194,
      "epss_percentile": 0.99643,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Versa"
      ],
      "products": [
        "Versa Concerto"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable."
    },
    {
      "id": "CVE-2025-31125",
      "url": "https://spydr.io/cve/CVE-2025-31125",
      "published": "2025-03-31T17:15:43.163Z",
      "modified": "2026-06-17T09:09:54.040Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.65189,
      "epss_percentile": 0.99236,
      "exploited": true,
      "kev": {
        "added": "2026-01-22",
        "due": "2026-02-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vitejs"
      ],
      "products": [
        "vitejs vite"
      ],
      "cwes": [
        "CWE-200",
        "CWE-284"
      ],
      "description": "Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11."
    },
    {
      "id": "CVE-2026-20045",
      "url": "https://spydr.io/cve/CVE-2026-20045",
      "published": "2026-01-21T17:16:08.077Z",
      "modified": "2026-06-17T10:16:58.097Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04541,
      "epss_percentile": 0.9128,
      "exploited": true,
      "kev": {
        "added": "2026-01-21",
        "due": "2026-02-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Unified Communications Manager",
        "Cisco Unified Communications Manager IM and Presence Service",
        "Cisco Unity Connection"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.&nbsp; This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.&nbsp; Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root."
    },
    {
      "id": "CVE-2026-20805",
      "url": "https://spydr.io/cve/CVE-2026-20805",
      "published": "2026-01-13T18:16:07.023Z",
      "modified": "2026-07-30T21:16:56.810Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.07203,
      "epss_percentile": 0.94132,
      "exploited": true,
      "kev": {
        "added": "2026-01-13",
        "due": "2026-02-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally."
    },
    {
      "id": "CVE-2025-8110",
      "url": "https://spydr.io/cve/CVE-2025-8110",
      "published": "2025-12-10T14:16:19.847Z",
      "modified": "2026-06-17T10:06:19.407Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.85202,
      "epss_percentile": 0.99711,
      "exploited": true,
      "kev": {
        "added": "2026-01-12",
        "due": "2026-02-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gogs"
      ],
      "products": [
        "Gogs"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code."
    },
    {
      "id": "CVE-2025-37164",
      "url": "https://spydr.io/cve/CVE-2025-37164",
      "published": "2025-12-16T17:16:07.843Z",
      "modified": "2026-06-17T09:15:17.283Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90193,
      "epss_percentile": 0.99796,
      "exploited": true,
      "kev": {
        "added": "2026-01-07",
        "due": "2026-01-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Hewlett Packard Enterprise (HPE)"
      ],
      "products": [
        "Hewlett Packard Enterprise (HPE) HPE OneView"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A remote code execution issue exists in HPE OneView."
    },
    {
      "id": "CVE-2009-0556",
      "url": "https://spydr.io/cve/CVE-2009-0556",
      "published": "2009-04-03T18:30:00.610Z",
      "modified": "2026-06-16T23:05:17.900Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.67312,
      "epss_percentile": 0.99289,
      "exploited": true,
      "kev": {
        "added": "2026-01-07",
        "due": "2026-01-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office powerpoint",
        "microsoft powerpoint"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka \"Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2025-14847",
      "url": "https://spydr.io/cve/CVE-2025-14847",
      "published": "2025-12-19T11:15:49.277Z",
      "modified": "2026-06-17T08:36:38.717Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "mongodb.com",
      "epss": 0.83218,
      "epss_percentile": 0.99672,
      "exploited": true,
      "kev": {
        "added": "2025-12-29",
        "due": "2026-01-19",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "MongoDB Inc."
      ],
      "products": [
        "MongoDB Inc. MongoDB Server"
      ],
      "cwes": [
        "CWE-130"
      ],
      "description": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0."
    },
    {
      "id": "CVE-2023-52163",
      "url": "https://spydr.io/cve/CVE-2023-52163",
      "published": "2025-02-03T21:15:12.060Z",
      "modified": "2026-06-17T06:42:12.770Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.96921,
      "epss_percentile": 0.99888,
      "exploited": true,
      "kev": {
        "added": "2025-12-22",
        "due": "2026-01-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "digiever"
      ],
      "products": [
        "digiever ds-2105 pro firmware"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."
    },
    {
      "id": "CVE-2025-14733",
      "url": "https://spydr.io/cve/CVE-2025-14733",
      "published": "2025-12-19T01:16:05.530Z",
      "modified": "2026-09-09T04:17:52.700Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
      "score_source": "CNA",
      "epss": 0.2651,
      "epss_percentile": 0.97959,
      "exploited": true,
      "kev": {
        "added": "2025-12-19",
        "due": "2025-12-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WatchGuard"
      ],
      "products": [
        "WatchGuard Fireware OS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured."
    },
    {
      "id": "CVE-2025-40602",
      "url": "https://spydr.io/cve/CVE-2025-40602",
      "published": "2025-12-18T11:15:46.760Z",
      "modified": "2026-06-17T09:21:49.277Z",
      "score": 6.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.02756,
      "epss_percentile": 0.85767,
      "exploited": true,
      "kev": {
        "added": "2025-12-17",
        "due": "2025-12-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA1000"
      ],
      "cwes": [
        "CWE-250",
        "CWE-862"
      ],
      "description": "A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC)."
    },
    {
      "id": "CVE-2025-20393",
      "url": "https://spydr.io/cve/CVE-2025-20393",
      "published": "2025-12-17T17:15:48.523Z",
      "modified": "2026-06-17T08:41:39.983Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.32392,
      "epss_percentile": 0.98289,
      "exploited": true,
      "kev": {
        "added": "2025-12-17",
        "due": "2025-12-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Email",
        "Cisco Secure Email and Web Manager"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with&nbsp;root privileges."
    },
    {
      "id": "CVE-2025-59374",
      "url": "https://spydr.io/cve/CVE-2025-59374",
      "published": "2025-12-17T05:16:13.080Z",
      "modified": "2026-09-25T23:10:00.463Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01197,
      "epss_percentile": 0.67061,
      "exploited": true,
      "kev": {
        "added": "2025-12-17",
        "due": "2026-01-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ASUS"
      ],
      "products": [
        "ASUS live update"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "\"UNSUPPORTED WHEN ASSIGNED\" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue."
    },
    {
      "id": "CVE-2025-59718",
      "url": "https://spydr.io/cve/CVE-2025-59718",
      "published": "2025-12-09T18:15:54.983Z",
      "modified": "2026-06-17T09:46:35.807Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.68293,
      "epss_percentile": 0.99315,
      "exploited": true,
      "kev": {
        "added": "2025-12-16",
        "due": "2025-12-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet",
        "Siemens"
      ],
      "products": [
        "Fortinet FortiSwitchManager",
        "Fortinet FortiOS",
        "Fortinet FortiProxy",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-347"
      ],
      "description": "A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message."
    },
    {
      "id": "CVE-2025-43529",
      "url": "https://spydr.io/cve/CVE-2025-43529",
      "published": "2025-12-17T21:16:11.570Z",
      "modified": "2026-09-30T20:10:00.247Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.08763,
      "epss_percentile": 0.95026,
      "exploited": true,
      "kev": {
        "added": "2025-12-15",
        "due": "2026-01-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report."
    },
    {
      "id": "CVE-2025-14611",
      "url": "https://spydr.io/cve/CVE-2025-14611",
      "published": "2025-12-12T21:15:53.107Z",
      "modified": "2026-06-17T08:36:15.740Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.53302,
      "epss_percentile": 0.98956,
      "exploited": true,
      "kev": {
        "added": "2025-12-15",
        "due": "2026-01-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gladinet"
      ],
      "products": [
        "Gladinet CentreStack and TrioFox"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door for future exploitation and can be leveraged with previous vulnerabilities to gain a full system compromise."
    },
    {
      "id": "CVE-2025-14174",
      "url": "https://spydr.io/cve/CVE-2025-14174",
      "published": "2025-12-12T20:15:39.663Z",
      "modified": "2026-09-30T16:10:00.223Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.22327,
      "epss_percentile": 0.97626,
      "exploited": true,
      "kev": {
        "added": "2025-12-12",
        "due": "2026-01-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787",
        "CWE-119"
      ],
      "description": "Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
