{
  "query": {
    "kev": "1",
    "page": "16"
  },
  "count": 20,
  "total": 1734,
  "page": 16,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T11:44:39.558Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T11:45:39.554Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=16",
    "next": "https://spydr.io/threats.json?kev=1&page=17"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-61882",
      "url": "https://spydr.io/cve/CVE-2025-61882",
      "published": "2025-10-05T04:15:40.340Z",
      "modified": "2026-08-04T05:16:36.247Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.99732,
      "epss_percentile": 0.99952,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle Concurrent Processing"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2021-43226",
      "url": "https://spydr.io/cve/CVE-2021-43226",
      "published": "2021-12-15T15:15:09.737Z",
      "modified": "2026-08-22T04:16:54.773Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03098,
      "epss_percentile": 0.87313,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2"
      ],
      "cwes": [],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-22555",
      "url": "https://spydr.io/cve/CVE-2021-22555",
      "published": "2021-07-07T12:15:08.453Z",
      "modified": "2026-06-17T03:37:25.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.78684,
      "epss_percentile": 0.9958,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netapp",
        "linux",
        "brocade"
      ],
      "products": [
        "Linux Kernel"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space"
    },
    {
      "id": "CVE-2013-3918",
      "url": "https://spydr.io/cve/CVE-2013-3918",
      "published": "2013-11-12T14:35:11.713Z",
      "modified": "2026-06-16T23:56:01.110Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73693,
      "epss_percentile": 0.99462,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista",
        "microsoft windows xp"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka \"InformationCardSigninHelper Vulnerability.\""
    },
    {
      "id": "CVE-2011-3402",
      "url": "https://spydr.io/cve/CVE-2011-3402",
      "published": "2011-11-04T21:55:04.693Z",
      "modified": "2026-06-16T23:33:14.020Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.78138,
      "epss_percentile": 0.99568,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows vista",
        "microsoft windows xp"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka \"TrueType Font Parsing Vulnerability.\""
    },
    {
      "id": "CVE-2010-3962",
      "url": "https://spydr.io/cve/CVE-2010-3962",
      "published": "2010-11-05T17:00:02.890Z",
      "modified": "2026-06-16T23:23:53.780Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.96831,
      "epss_percentile": 0.99887,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an \"invalid flag reference\" issue or \"Uninitialized Memory Corruption Vulnerability,\" as exploited in the wild in November 2010."
    },
    {
      "id": "CVE-2010-3765",
      "url": "https://spydr.io/cve/CVE-2010-3765",
      "published": "2010-10-28T00:00:05.237Z",
      "modified": "2026-06-16T23:23:28.500Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.83156,
      "epss_percentile": 0.9967,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mozilla"
      ],
      "products": [
        "mozilla firefox",
        "mozilla thunderbird",
        "mozilla seamonkey"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware."
    },
    {
      "id": "CVE-2025-21043",
      "url": "https://spydr.io/cve/CVE-2025-21043",
      "published": "2025-09-12T08:15:44.920Z",
      "modified": "2026-06-17T08:42:30.067Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0214,
      "epss_percentile": 0.814,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code."
    },
    {
      "id": "CVE-2025-4008",
      "url": "https://spydr.io/cve/CVE-2025-4008",
      "published": "2025-05-21T16:15:33.987Z",
      "modified": "2026-06-17T09:32:18.077Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "onekey.com",
      "epss": 0.93667,
      "epss_percentile": 0.99842,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Smartbedded"
      ],
      "products": [
        "Smartbedded MeteoBridge"
      ],
      "cwes": [
        "CWE-77",
        "CWE-306"
      ],
      "description": "The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices."
    },
    {
      "id": "CVE-2017-1000353",
      "url": "https://spydr.io/cve/CVE-2017-1000353",
      "published": "2018-01-29T17:29:00.193Z",
      "modified": "2026-06-17T00:59:00.597Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99679,
      "epss_percentile": 0.9995,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "jenkins",
        "oracle"
      ],
      "products": [
        "jenkins",
        "oracle communications cloud native core automated test suite"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default."
    },
    {
      "id": "CVE-2015-7755",
      "url": "https://spydr.io/cve/CVE-2015-7755",
      "published": "2015-12-19T14:59:01.453Z",
      "modified": "2026-06-17T00:33:04.553Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61139,
      "epss_percentile": 0.99138,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "juniper"
      ],
      "products": [
        "juniper screenos"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session."
    },
    {
      "id": "CVE-2014-6278",
      "url": "https://spydr.io/cve/CVE-2014-6278",
      "published": "2014-09-30T10:55:04.723Z",
      "modified": "2026-06-17T00:12:50.047Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.99621,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2025-10-02",
        "due": "2025-10-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gnu"
      ],
      "products": [
        "gnu bash"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277."
    },
    {
      "id": "CVE-2025-20352",
      "url": "https://spydr.io/cve/CVE-2025-20352",
      "published": "2025-09-24T18:15:36.930Z",
      "modified": "2026-09-26T00:10:00.127Z",
      "score": 7.7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "cisco.com",
      "epss": 0.39447,
      "epss_percentile": 0.98571,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS",
        "Cisco IOS XE Software",
        "Cisco IOS XE Catalyst SD-WAN"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP."
    },
    {
      "id": "CVE-2025-59689",
      "url": "https://spydr.io/cve/CVE-2025-59689",
      "published": "2025-09-19T20:15:40.340Z",
      "modified": "2026-06-17T09:46:31.727Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "mitre.org",
      "epss": 0.01864,
      "epss_percentile": 0.78555,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Libraesva"
      ],
      "products": [
        "Libraesva Email Security Gateway"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7."
    },
    {
      "id": "CVE-2025-10035",
      "url": "https://spydr.io/cve/CVE-2025-10035",
      "published": "2025-09-18T22:15:41.857Z",
      "modified": "2026-08-04T05:16:33.317Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99799,
      "epss_percentile": 0.99957,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortra"
      ],
      "products": [
        "Fortra GoAnywhere MFT"
      ],
      "cwes": [
        "CWE-77",
        "CWE-502"
      ],
      "description": "A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection."
    },
    {
      "id": "CVE-2025-32463",
      "url": "https://spydr.io/cve/CVE-2025-32463",
      "published": "2025-06-30T21:15:30.257Z",
      "modified": "2026-06-17T09:12:02.147Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55498,
      "epss_percentile": 0.99012,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sudo project"
      ],
      "products": [
        "Sudo project Sudo"
      ],
      "cwes": [
        "CWE-829"
      ],
      "description": "Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option."
    },
    {
      "id": "CVE-2021-21311",
      "url": "https://spydr.io/cve/CVE-2021-21311",
      "published": "2021-02-11T21:15:13.820Z",
      "modified": "2026-06-17T03:35:16.213Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.98464,
      "epss_percentile": 0.99918,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vrana"
      ],
      "products": [
        "vrana adminer"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9."
    },
    {
      "id": "CVE-2025-20362",
      "url": "https://spydr.io/cve/CVE-2025-20362",
      "published": "2025-09-25T16:15:32.280Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
      "score_source": "NVD",
      "epss": 0.87085,
      "epss_percentile": 0.99746,
      "exploited": true,
      "kev": {
        "added": "2025-09-25",
        "due": "2025-09-26",
        "action": "The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
        "Cisco Secure Firewall Threat Defense (FTD) Software"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software [\"#fs\"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication."
    },
    {
      "id": "CVE-2025-20333",
      "url": "https://spydr.io/cve/CVE-2025-20333",
      "published": "2025-09-25T16:15:32.073Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.70651,
      "epss_percentile": 0.99378,
      "exploited": true,
      "kev": {
        "added": "2025-09-25",
        "due": "2025-09-26",
        "action": "The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
        "Cisco Secure Firewall Threat Defense (FTD) Software"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device."
    },
    {
      "id": "CVE-2025-10585",
      "url": "https://spydr.io/cve/CVE-2025-10585",
      "published": "2025-09-24T17:15:39.473Z",
      "modified": "2026-07-14T15:21:36.793Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05391,
      "epss_percentile": 0.9244,
      "exploited": true,
      "kev": {
        "added": "2025-09-23",
        "due": "2025-10-14",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "Siemens"
      ],
      "products": [
        "Google Chrome",
        "Siemens CADRA"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
