{
  "query": {
    "kev": "1",
    "page": "18"
  },
  "count": 20,
  "total": 1734,
  "page": 18,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T12:45:42.157Z",
    "kev": "2026-10-06T13:44:43.860Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T13:45:44.551Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=18",
    "next": "https://spydr.io/threats.json?kev=1&page=19"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-40799",
      "url": "https://spydr.io/cve/CVE-2022-40799",
      "published": "2022-11-29T05:15:11.310Z",
      "modified": "2026-06-17T05:02:02.970Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3365,
      "epss_percentile": 0.98345,
      "exploited": true,
      "kev": {
        "added": "2025-08-05",
        "due": "2025-08-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dnr-322l firmware"
      ],
      "cwes": [
        "CWE-494"
      ],
      "description": "Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device."
    },
    {
      "id": "CVE-2020-25079",
      "url": "https://spydr.io/cve/CVE-2020-25079",
      "published": "2020-09-02T16:15:12.690Z",
      "modified": "2026-06-17T03:06:20.840Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54007,
      "epss_percentile": 0.98976,
      "exploited": true,
      "kev": {
        "added": "2025-08-05",
        "due": "2025-08-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dcs-4703e firmware",
        "dlink dcs-4705e firmware",
        "dlink dcs-4802e firmware",
        "dlink dcs-p703 firmware",
        "dlink dcs-4603 firmware",
        "dlink dcs-4622 firmware",
        "dlink dcs-4701e firmware",
        "dlink dcs-2530l firmware",
        "dlink dcs-2670l firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection."
    },
    {
      "id": "CVE-2020-25078",
      "url": "https://spydr.io/cve/CVE-2020-25078",
      "published": "2020-09-02T16:15:12.627Z",
      "modified": "2026-06-17T03:06:20.660Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.97511,
      "epss_percentile": 0.999,
      "exploited": true,
      "kev": {
        "added": "2025-08-05",
        "due": "2025-08-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dcs-4603 firmware",
        "dlink dcs-4622 firmware",
        "dlink dcs-4701e firmware",
        "dlink dcs-4703e firmware",
        "dlink dcs-4705e firmware",
        "dlink dcs-4802e firmware",
        "dlink dcs-p703 firmware",
        "dlink dcs-2530l firmware",
        "dlink dcs-2670l firmware"
      ],
      "cwes": [],
      "description": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure."
    },
    {
      "id": "CVE-2025-20337",
      "url": "https://spydr.io/cve/CVE-2025-20337",
      "published": "2025-07-16T17:15:30.573Z",
      "modified": "2026-06-17T08:41:29.520Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.67825,
      "epss_percentile": 0.99302,
      "exploited": true,
      "kev": {
        "added": "2025-07-28",
        "due": "2025-08-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Identity Services Engine Software",
        "Cisco ISE Passive Identity Connector"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device."
    },
    {
      "id": "CVE-2025-20281",
      "url": "https://spydr.io/cve/CVE-2025-20281",
      "published": "2025-06-25T16:15:26.017Z",
      "modified": "2026-06-17T08:41:19.980Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.97601,
      "epss_percentile": 0.99902,
      "exploited": true,
      "kev": {
        "added": "2025-07-28",
        "due": "2025-08-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Identity Services Engine Software"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device."
    },
    {
      "id": "CVE-2023-2533",
      "url": "https://spydr.io/cve/CVE-2023-2533",
      "published": "2023-06-20T15:15:11.560Z",
      "modified": "2026-06-17T05:52:47.993Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28621,
      "epss_percentile": 0.98088,
      "exploited": true,
      "kev": {
        "added": "2025-07-28",
        "due": "2025-08-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut NG/MF"
      ],
      "cwes": [
        "CWE-352"
      ],
      "description": "A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. This could be exploited if the target is an admin with a current login session. Exploiting this would typically involve the possibility of deceiving an admin into clicking a specially crafted malicious link, potentially leading to unauthorized changes."
    },
    {
      "id": "CVE-2025-54309",
      "url": "https://spydr.io/cve/CVE-2025-54309",
      "published": "2025-07-18T19:15:25.353Z",
      "modified": "2026-06-17T09:39:49.643Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94905,
      "epss_percentile": 0.99859,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "CrushFTP"
      ],
      "products": [
        "CrushFTP"
      ],
      "cwes": [
        "CWE-420"
      ],
      "description": "CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025."
    },
    {
      "id": "CVE-2025-6558",
      "url": "https://spydr.io/cve/CVE-2025-6558",
      "published": "2025-07-15T18:15:24.533Z",
      "modified": "2026-10-01T12:00:53.397Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.09464,
      "epss_percentile": 0.95295,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-49706",
      "url": "https://spydr.io/cve/CVE-2025-49706",
      "published": "2025-07-08T17:15:58.250Z",
      "modified": "2026-08-04T05:16:34.723Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "microsoft.com",
      "epss": 0.99076,
      "epss_percentile": 0.99932,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-07-23",
        "action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network."
    },
    {
      "id": "CVE-2025-49704",
      "url": "https://spydr.io/cve/CVE-2025-49704",
      "published": "2025-07-08T17:15:57.867Z",
      "modified": "2026-06-17T09:31:46.077Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99995,
      "epss_percentile": 0.99988,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-07-23",
        "action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-2776",
      "url": "https://spydr.io/cve/CVE-2025-2776",
      "published": "2025-05-07T15:15:57.573Z",
      "modified": "2026-06-17T09:07:36.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64726,
      "epss_percentile": 0.99225,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SysAid"
      ],
      "products": [
        "SysAid On-Prem"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives."
    },
    {
      "id": "CVE-2025-2775",
      "url": "https://spydr.io/cve/CVE-2025-2775",
      "published": "2025-05-07T15:15:57.447Z",
      "modified": "2026-06-17T09:07:36.247Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.42612,
      "epss_percentile": 0.98675,
      "exploited": true,
      "kev": {
        "added": "2025-07-22",
        "due": "2025-08-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SysAid"
      ],
      "products": [
        "SysAid On-Prem"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives."
    },
    {
      "id": "CVE-2025-53770",
      "url": "https://spydr.io/cve/CVE-2025-53770",
      "published": "2025-07-20T01:15:30.777Z",
      "modified": "2026-08-04T05:16:34.887Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99998,
      "epss_percentile": 0.99991,
      "exploited": true,
      "kev": {
        "added": "2025-07-20",
        "due": "2025-07-21",
        "action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation."
    },
    {
      "id": "CVE-2025-25257",
      "url": "https://spydr.io/cve/CVE-2025-25257",
      "published": "2025-07-17T16:15:34.723Z",
      "modified": "2026-06-17T09:00:34.647Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99775,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2025-07-18",
        "due": "2025-08-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiWeb"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 allows an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests."
    },
    {
      "id": "CVE-2025-47812",
      "url": "https://spydr.io/cve/CVE-2025-47812",
      "published": "2025-07-10T17:15:47.210Z",
      "modified": "2026-06-17T09:28:43.200Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "mitre.org",
      "epss": 0.93235,
      "epss_percentile": 0.99834,
      "exploited": true,
      "kev": {
        "added": "2025-07-14",
        "due": "2025-08-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wftpserver"
      ],
      "products": [
        "wftpserver Wing FTP Server"
      ],
      "cwes": [
        "CWE-158"
      ],
      "description": "In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts."
    },
    {
      "id": "CVE-2025-5777",
      "url": "https://spydr.io/cve/CVE-2025-5777",
      "published": "2025-06-17T13:15:21.523Z",
      "modified": "2026-08-04T05:16:35.613Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.99972,
      "epss_percentile": 0.99978,
      "exploited": true,
      "kev": {
        "added": "2025-07-10",
        "due": "2025-07-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-125",
        "CWE-908",
        "CWE-457"
      ],
      "description": "Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server"
    },
    {
      "id": "CVE-2019-9621",
      "url": "https://spydr.io/cve/CVE-2019-9621",
      "published": "2019-04-30T18:29:08.633Z",
      "modified": "2026-06-17T02:44:03.280Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.81037,
      "epss_percentile": 0.99625,
      "exploited": true,
      "kev": {
        "added": "2025-07-07",
        "due": "2025-07-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component."
    },
    {
      "id": "CVE-2019-5418",
      "url": "https://spydr.io/cve/CVE-2019-5418",
      "published": "2019-03-27T14:29:01.533Z",
      "modified": "2026-06-17T02:37:39.103Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.98507,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2025-07-07",
        "due": "2025-07-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Rails"
      ],
      "products": [
        "Rails https://github.com/rails/rails"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed."
    },
    {
      "id": "CVE-2014-3931",
      "url": "https://spydr.io/cve/CVE-2014-3931",
      "published": "2017-03-31T16:59:00.237Z",
      "modified": "2026-06-17T00:09:09.423Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28978,
      "epss_percentile": 0.98112,
      "exploited": true,
      "kev": {
        "added": "2025-07-07",
        "due": "2025-07-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "multi-router looking glass project"
      ],
      "products": [
        "multi-router looking glass project multi-router looking glass"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption."
    },
    {
      "id": "CVE-2016-10033",
      "url": "https://spydr.io/cve/CVE-2016-10033",
      "published": "2016-12-30T19:59:00.137Z",
      "modified": "2026-06-17T00:38:55.477Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99714,
      "epss_percentile": 0.99951,
      "exploited": true,
      "kev": {
        "added": "2025-07-07",
        "due": "2025-07-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "phpmailer project",
        "wordpress",
        "joomla"
      ],
      "products": [
        "phpmailer project phpmailer",
        "wordpress",
        "joomla!"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \\\" (backslash double quote) in a crafted Sender property."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
