{
  "query": {
    "kev": "1",
    "page": "14"
  },
  "count": 20,
  "total": 1734,
  "page": 14,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T10:44:36.922Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T10:45:36.976Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=14",
    "next": "https://spydr.io/threats.json?kev=1&page=15"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2018-4063",
      "url": "https://spydr.io/cve/CVE-2018-4063",
      "published": "2019-05-06T19:29:00.637Z",
      "modified": "2026-06-17T01:58:18.623Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.27059,
      "epss_percentile": 0.97994,
      "exploited": true,
      "kev": {
        "added": "2025-12-12",
        "due": "2026-01-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sierrawireless"
      ],
      "products": [
        "Sierra Wireless"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability."
    },
    {
      "id": "CVE-2025-58360",
      "url": "https://spydr.io/cve/CVE-2025-58360",
      "published": "2025-11-25T21:15:56.363Z",
      "modified": "2026-06-17T09:44:21.613Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.60522,
      "epss_percentile": 0.99122,
      "exploited": true,
      "kev": {
        "added": "2025-12-11",
        "due": "2026-01-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "geoserver"
      ],
      "products": [
        "geoserver"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0."
    },
    {
      "id": "CVE-2025-62221",
      "url": "https://spydr.io/cve/CVE-2025-62221",
      "published": "2025-12-09T18:15:56.517Z",
      "modified": "2026-09-25T23:10:00.463Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02505,
      "epss_percentile": 0.84192,
      "exploited": true,
      "kev": {
        "added": "2025-12-09",
        "due": "2025-12-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-6218",
      "url": "https://spydr.io/cve/CVE-2025-6218",
      "published": "2025-06-21T01:15:29.123Z",
      "modified": "2026-06-17T10:01:24.380Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.0",
      "vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "trendmicro.com",
      "epss": 0.90479,
      "epss_percentile": 0.99799,
      "exploited": true,
      "kev": {
        "added": "2025-12-09",
        "due": "2025-12-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "RARLAB"
      ],
      "products": [
        "RARLAB WinRAR"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198."
    },
    {
      "id": "CVE-2025-66644",
      "url": "https://spydr.io/cve/CVE-2025-66644",
      "published": "2025-12-05T19:15:53.293Z",
      "modified": "2026-06-17T09:57:08.520Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03415,
      "epss_percentile": 0.88517,
      "exploited": true,
      "kev": {
        "added": "2025-12-08",
        "due": "2025-12-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Array Networks"
      ],
      "products": [
        "Array Networks ArrayOS AG"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025."
    },
    {
      "id": "CVE-2022-37055",
      "url": "https://spydr.io/cve/CVE-2022-37055",
      "published": "2022-08-28T17:15:08.363Z",
      "modified": "2026-06-17T04:54:32.267Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55531,
      "epss_percentile": 0.99013,
      "exploited": true,
      "kev": {
        "added": "2025-12-08",
        "due": "2025-12-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink go-rt-ac750 firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,"
    },
    {
      "id": "CVE-2025-55182",
      "url": "https://spydr.io/cve/CVE-2025-55182",
      "published": "2025-12-03T16:15:56.463Z",
      "modified": "2026-08-04T05:16:35.063Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "fb.com",
      "epss": 0.99802,
      "epss_percentile": 0.99957,
      "exploited": true,
      "kev": {
        "added": "2025-12-05",
        "due": "2025-12-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Meta"
      ],
      "products": [
        "Meta react-server-dom-webpack",
        "Meta react-server-dom-turbopack",
        "Meta react-server-dom-parcel"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints."
    },
    {
      "id": "CVE-2021-26828",
      "url": "https://spydr.io/cve/CVE-2021-26828",
      "published": "2021-06-11T12:15:12.017Z",
      "modified": "2026-06-17T03:43:49.877Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39356,
      "epss_percentile": 0.98567,
      "exploited": true,
      "kev": {
        "added": "2025-12-03",
        "due": "2025-12-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "scadabr"
      ],
      "products": [
        "scadabr"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm."
    },
    {
      "id": "CVE-2025-48633",
      "url": "https://spydr.io/cve/CVE-2025-48633",
      "published": "2025-12-08T17:16:19.610Z",
      "modified": "2026-09-30T16:10:00.223Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00262,
      "epss_percentile": 0.16382,
      "exploited": true,
      "kev": {
        "added": "2025-12-02",
        "due": "2025-12-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [],
      "description": "In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2025-48572",
      "url": "https://spydr.io/cve/CVE-2025-48572",
      "published": "2025-12-08T17:16:15.003Z",
      "modified": "2026-09-30T16:10:00.223Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.00259,
      "epss_percentile": 0.1599,
      "exploited": true,
      "kev": {
        "added": "2025-12-02",
        "due": "2025-12-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2021-26829",
      "url": "https://spydr.io/cve/CVE-2021-26829",
      "published": "2021-06-11T12:15:12.053Z",
      "modified": "2026-06-17T03:43:50.063Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.4805,
      "epss_percentile": 0.98824,
      "exploited": true,
      "kev": {
        "added": "2025-11-28",
        "due": "2025-12-19",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "scadabr"
      ],
      "products": [
        "scadabr"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm."
    },
    {
      "id": "CVE-2025-61757",
      "url": "https://spydr.io/cve/CVE-2025-61757",
      "published": "2025-10-21T20:20:52.117Z",
      "modified": "2026-06-17T09:50:50.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.88647,
      "epss_percentile": 0.99772,
      "exploited": true,
      "kev": {
        "added": "2025-11-21",
        "due": "2025-12-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Identity Manager"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2025-13223",
      "url": "https://spydr.io/cve/CVE-2025-13223",
      "published": "2025-11-17T23:15:45.140Z",
      "modified": "2026-07-14T15:21:34.180Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.05026,
      "epss_percentile": 0.92012,
      "exploited": true,
      "kev": {
        "added": "2025-11-19",
        "due": "2025-12-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "Siemens"
      ],
      "products": [
        "Google Chrome",
        "Siemens CADRA"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-58034",
      "url": "https://spydr.io/cve/CVE-2025-58034",
      "published": "2025-11-18T17:16:05.057Z",
      "modified": "2026-06-17T09:43:49.303Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.5558,
      "epss_percentile": 0.99014,
      "exploited": true,
      "kev": {
        "added": "2025-11-18",
        "due": "2025-11-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiWeb"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands."
    },
    {
      "id": "CVE-2025-64446",
      "url": "https://spydr.io/cve/CVE-2025-64446",
      "published": "2025-11-14T16:15:58.567Z",
      "modified": "2026-06-17T09:54:23.733Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.91838,
      "epss_percentile": 0.99815,
      "exploited": true,
      "kev": {
        "added": "2025-11-14",
        "due": "2025-11-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiWeb"
      ],
      "cwes": [
        "CWE-23"
      ],
      "description": "A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests."
    },
    {
      "id": "CVE-2025-62215",
      "url": "https://spydr.io/cve/CVE-2025-62215",
      "published": "2025-11-11T18:15:48.920Z",
      "modified": "2026-06-17T09:51:34.350Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.05985,
      "epss_percentile": 0.93097,
      "exploited": true,
      "kev": {
        "added": "2025-11-12",
        "due": "2025-12-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-362",
        "CWE-415"
      ],
      "description": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-12480",
      "url": "https://spydr.io/cve/CVE-2025-12480",
      "published": "2025-11-10T15:15:36.527Z",
      "modified": "2026-06-17T08:32:27.450Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "google.com",
      "epss": 0.95428,
      "epss_percentile": 0.99869,
      "exploited": true,
      "kev": {
        "added": "2025-11-12",
        "due": "2025-12-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TrioFox"
      ],
      "products": [
        "TrioFox"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete."
    },
    {
      "id": "CVE-2025-9242",
      "url": "https://spydr.io/cve/CVE-2025-9242",
      "published": "2025-09-17T08:15:33.960Z",
      "modified": "2026-08-10T19:59:12.133Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.913,
      "epss_percentile": 0.9981,
      "exploited": true,
      "kev": {
        "added": "2025-11-12",
        "due": "2025-12-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WatchGuard"
      ],
      "products": [
        "WatchGuard Fireware OS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured."
    },
    {
      "id": "CVE-2025-21042",
      "url": "https://spydr.io/cve/CVE-2025-21042",
      "published": "2025-09-12T08:15:44.743Z",
      "modified": "2026-09-30T23:10:00.237Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3317,
      "epss_percentile": 0.98324,
      "exploited": true,
      "kev": {
        "added": "2025-11-10",
        "due": "2025-12-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code."
    },
    {
      "id": "CVE-2025-11371",
      "url": "https://spydr.io/cve/CVE-2025-11371",
      "published": "2025-10-09T17:15:58.507Z",
      "modified": "2026-06-17T08:30:19.667Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.92137,
      "epss_percentile": 0.9982,
      "exploited": true,
      "kev": {
        "added": "2025-11-04",
        "due": "2025-11-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Gladinet"
      ],
      "products": [
        "Gladinet CentreStack and TrioFox"
      ],
      "cwes": [
        "CWE-552"
      ],
      "description": "In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions prior to and including 16.7.10368.56560"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
