{
  "query": {
    "kev": "1",
    "page": "17"
  },
  "count": 20,
  "total": 1734,
  "page": 17,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T12:45:42.157Z",
    "kev": "2026-10-06T12:44:41.793Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T12:45:42.157Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=17",
    "next": "https://spydr.io/threats.json?kev=1&page=18"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-5086",
      "url": "https://spydr.io/cve/CVE-2025-5086",
      "published": "2025-06-02T18:15:25.010Z",
      "modified": "2026-06-17T09:47:10.400Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "3ds.com",
      "epss": 0.96915,
      "epss_percentile": 0.99888,
      "exploited": true,
      "kev": {
        "added": "2025-09-11",
        "due": "2025-10-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Dassault Systèmes"
      ],
      "products": [
        "Dassault Systèmes DELMIA Apriso"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution."
    },
    {
      "id": "CVE-2025-48543",
      "url": "https://spydr.io/cve/CVE-2025-48543",
      "published": "2025-09-04T19:15:40.780Z",
      "modified": "2026-06-17T09:29:49.153Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.00543,
      "epss_percentile": 0.4368,
      "exploited": true,
      "kev": {
        "added": "2025-09-04",
        "due": "2025-09-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2025-53690",
      "url": "https://spydr.io/cve/CVE-2025-53690",
      "published": "2025-09-03T20:15:33.473Z",
      "modified": "2026-06-17T09:38:43.133Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.51094,
      "epss_percentile": 0.98903,
      "exploited": true,
      "kev": {
        "added": "2025-09-04",
        "due": "2025-09-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sitecore"
      ],
      "products": [
        "Sitecore Experience Manager (XM)",
        "Sitecore Experience Platform (XP)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0."
    },
    {
      "id": "CVE-2025-38352",
      "url": "https://spydr.io/cve/CVE-2025-38352",
      "published": "2025-07-22T08:15:23.577Z",
      "modified": "2026-09-08T18:17:32.447Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.01289,
      "epss_percentile": 0.69216,
      "exploited": true,
      "kev": {
        "added": "2025-09-04",
        "due": "2025-09-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent or debugger right after unlock_task_sighand(). If a concurrent posix_cpu_timer_del() runs at that moment, it won't be able to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or lock_task_sighand() will fail. Add the tsk->exit_state check into run_posix_cpu_timers() to fix this. This fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because exit_task_work() is called before exit_notify(). But the check still makes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail anyway in this case."
    },
    {
      "id": "CVE-2025-9377",
      "url": "https://spydr.io/cve/CVE-2025-9377",
      "published": "2025-08-29T18:15:43.220Z",
      "modified": "2026-06-17T10:08:50.390Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.33524,
      "epss_percentile": 0.9834,
      "exploited": true,
      "kev": {
        "added": "2025-09-03",
        "due": "2025-09-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TP-Link Systems Inc."
      ],
      "products": [
        "TP-Link Systems Inc. Archer C7(EU) V2",
        "TP-Link Systems Inc. TL-WR841N/ND(MS) V9"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download and install the patch(es)."
    },
    {
      "id": "CVE-2023-50224",
      "url": "https://spydr.io/cve/CVE-2023-50224",
      "published": "2024-05-03T03:16:10.833Z",
      "modified": "2026-09-03T17:28:42.113Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "trendmicro.com",
      "epss": 0.15558,
      "epss_percentile": 0.96739,
      "exploited": true,
      "kev": {
        "added": "2025-09-03",
        "due": "2025-09-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TP-Link"
      ],
      "products": [
        "TP-Link TL-WR841N",
        "TP-Link TL-WR841ND",
        "TP-Link TL-MR6400",
        "TP-Link Archer C5",
        "TP-Link Archer C7",
        "TP-Link TL-WDR3600",
        "TP-Link TL-WDR4300",
        "TP-Link TL-WDR3500",
        "TP-Link TL-WR740N",
        "TP-Link TL-WR741ND",
        "TP-Link TL-WR749N",
        "TP-Link TL-MR3420",
        "TP-Link TL-WR1043ND",
        "TP-Link TL-WR1045ND",
        "TP-Link TL-WR840N",
        "TP-Link TL-WR842N",
        "TP-Link TL-WR842ND",
        "TP-Link TL-WR845N",
        "TP-Link TL-WR941ND",
        "TP-Link TL-WR945N"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899."
    },
    {
      "id": "CVE-2025-55177",
      "url": "https://spydr.io/cve/CVE-2025-55177",
      "published": "2025-08-29T16:15:36.723Z",
      "modified": "2026-06-17T09:41:24.433Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "fb.com",
      "epss": 0.04304,
      "epss_percentile": 0.90853,
      "exploited": true,
      "kev": {
        "added": "2025-09-02",
        "due": "2025-09-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Facebook"
      ],
      "products": [
        "Facebook WhatsApp Desktop for Mac",
        "Facebook WhatsApp Business for iOS",
        "Facebook WhatsApp for iOS"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this vulnerability, in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users."
    },
    {
      "id": "CVE-2020-24363",
      "url": "https://spydr.io/cve/CVE-2020-24363",
      "published": "2020-08-31T16:15:15.380Z",
      "modified": "2026-06-17T03:05:25.970Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.20689,
      "epss_percentile": 0.97467,
      "exploited": true,
      "kev": {
        "added": "2025-09-02",
        "due": "2025-09-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tp-link"
      ],
      "products": [
        "tp-link tl-wa855re firmware"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password."
    },
    {
      "id": "CVE-2025-57819",
      "url": "https://spydr.io/cve/CVE-2025-57819",
      "published": "2025-08-28T17:15:36.790Z",
      "modified": "2026-09-26T00:10:00.127Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.85463,
      "epss_percentile": 0.99717,
      "exploited": true,
      "kev": {
        "added": "2025-08-29",
        "due": "2025-09-19",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FreePBX"
      ],
      "products": [
        "FreePBX endpoint"
      ],
      "cwes": [
        "CWE-89",
        "CWE-288"
      ],
      "description": "FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3."
    },
    {
      "id": "CVE-2025-7775",
      "url": "https://spydr.io/cve/CVE-2025-7775",
      "published": "2025-08-26T13:15:32.870Z",
      "modified": "2026-06-17T10:05:38.060Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.20284,
      "epss_percentile": 0.97408,
      "exploited": true,
      "kev": {
        "added": "2025-08-26",
        "due": "2025-08-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers (OR) CR virtual server with type HDX"
    },
    {
      "id": "CVE-2025-48384",
      "url": "https://spydr.io/cve/CVE-2025-48384",
      "published": "2025-07-08T19:15:42.800Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.042,
      "epss_percentile": 0.90659,
      "exploited": true,
      "kev": {
        "added": "2025-08-25",
        "due": "2025-09-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "git"
      ],
      "products": [
        "git"
      ],
      "cwes": [
        "CWE-59",
        "CWE-436"
      ],
      "description": "Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1."
    },
    {
      "id": "CVE-2024-8069",
      "url": "https://spydr.io/cve/CVE-2024-8069",
      "published": "2024-11-12T18:15:47.603Z",
      "modified": "2026-06-17T08:21:48.323Z",
      "score": 5.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.14643,
      "epss_percentile": 0.96565,
      "exploited": true,
      "kev": {
        "added": "2025-08-25",
        "due": "2025-09-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix Session Recording"
      ],
      "products": [
        "Citrix Session Recording"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server"
    },
    {
      "id": "CVE-2024-8068",
      "url": "https://spydr.io/cve/CVE-2024-8068",
      "published": "2024-11-12T18:15:47.450Z",
      "modified": "2026-06-17T08:21:48.207Z",
      "score": 5.1,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.03481,
      "epss_percentile": 0.88741,
      "exploited": true,
      "kev": {
        "added": "2025-08-25",
        "due": "2025-09-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix Session Recording"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain"
    },
    {
      "id": "CVE-2025-43300",
      "url": "https://spydr.io/cve/CVE-2025-43300",
      "published": "2025-08-21T01:15:36.243Z",
      "modified": "2026-06-17T09:23:42.063Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.32498,
      "epss_percentile": 0.98295,
      "exploited": true,
      "kev": {
        "added": "2025-08-21",
        "due": "2025-09-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
    },
    {
      "id": "CVE-2025-54948",
      "url": "https://spydr.io/cve/CVE-2025-54948",
      "published": "2025-08-05T13:15:28.487Z",
      "modified": "2026-06-17T09:40:58.740Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23919,
      "epss_percentile": 0.97773,
      "exploited": true,
      "kev": {
        "added": "2025-08-18",
        "due": "2025-09-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro, Inc."
      ],
      "products": [
        "Trend Micro, Inc. Trend Micro Apex One"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations."
    },
    {
      "id": "CVE-2025-8876",
      "url": "https://spydr.io/cve/CVE-2025-8876",
      "published": "2025-08-14T15:15:43.170Z",
      "modified": "2026-06-17T10:07:50.067Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.03448,
      "epss_percentile": 0.88633,
      "exploited": true,
      "kev": {
        "added": "2025-08-13",
        "due": "2025-08-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "N-able"
      ],
      "products": [
        "N-able N-central"
      ],
      "cwes": [
        "CWE-20",
        "CWE-78"
      ],
      "description": "Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1."
    },
    {
      "id": "CVE-2025-8875",
      "url": "https://spydr.io/cve/CVE-2025-8875",
      "published": "2025-08-14T15:15:43.020Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 9.4,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01899,
      "epss_percentile": 0.78959,
      "exploited": true,
      "kev": {
        "added": "2025-08-13",
        "due": "2025-08-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "N-able"
      ],
      "products": [
        "N-able N-central"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1."
    },
    {
      "id": "CVE-2025-8088",
      "url": "https://spydr.io/cve/CVE-2025-8088",
      "published": "2025-08-08T12:15:29.343Z",
      "modified": "2026-08-11T04:17:18.587Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "eset.com",
      "epss": 0.94051,
      "epss_percentile": 0.99846,
      "exploited": true,
      "kev": {
        "added": "2025-08-12",
        "due": "2025-09-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "win.rar GmbH"
      ],
      "products": [
        "win.rar GmbH WinRAR"
      ],
      "cwes": [
        "CWE-35"
      ],
      "description": "A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET."
    },
    {
      "id": "CVE-2013-3893",
      "url": "https://spydr.io/cve/CVE-2013-3893",
      "published": "2013-09-18T10:08:24.867Z",
      "modified": "2026-06-16T23:55:58.240Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.87526,
      "epss_percentile": 0.99755,
      "exploited": true,
      "kev": {
        "added": "2025-08-12",
        "due": "2025-09-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll."
    },
    {
      "id": "CVE-2007-0671",
      "url": "https://spydr.io/cve/CVE-2007-0671",
      "published": "2007-02-03T01:28:00.000Z",
      "modified": "2026-06-16T22:36:02.527Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.43241,
      "epss_percentile": 0.98691,
      "exploited": true,
      "kev": {
        "added": "2025-08-12",
        "due": "2025-09-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft access",
        "microsoft excel",
        "microsoft excel viewer",
        "microsoft frontpage",
        "microsoft infopath",
        "microsoft office",
        "microsoft onenote",
        "microsoft outlook",
        "microsoft powerpoint",
        "microsoft project",
        "microsoft publisher",
        "microsoft visio",
        "microsoft word",
        "microsoft word viewer"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
