{
  "query": {
    "kev": "1",
    "page": "19"
  },
  "count": 20,
  "total": 1734,
  "page": 19,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T14:45:46.442Z",
    "kev": "2026-10-06T14:44:46.299Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T14:45:46.442Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=19",
    "next": "https://spydr.io/threats.json?kev=1&page=20"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-6554",
      "url": "https://spydr.io/cve/CVE-2025-6554",
      "published": "2025-06-30T22:15:29.873Z",
      "modified": "2026-06-17T10:02:08.217Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "score_source": "CISA ADP",
      "epss": 0.14142,
      "epss_percentile": 0.96477,
      "exploited": true,
      "kev": {
        "added": "2025-07-02",
        "due": "2025-07-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-48928",
      "url": "https://spydr.io/cve/CVE-2025-48928",
      "published": "2025-05-28T17:15:25.020Z",
      "modified": "2026-06-17T09:30:30.087Z",
      "score": 4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "mitre.org",
      "epss": 0.00553,
      "epss_percentile": 0.4425,
      "exploited": true,
      "kev": {
        "added": "2025-07-01",
        "due": "2025-07-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeleMessage"
      ],
      "products": [
        "TeleMessage service"
      ],
      "cwes": [
        "CWE-528",
        "CWE-552"
      ],
      "description": "The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a \"core dump\" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025."
    },
    {
      "id": "CVE-2025-48927",
      "url": "https://spydr.io/cve/CVE-2025-48927",
      "published": "2025-05-28T17:15:24.837Z",
      "modified": "2026-06-17T09:30:29.883Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "mitre.org",
      "epss": 0.11104,
      "epss_percentile": 0.95813,
      "exploited": true,
      "kev": {
        "added": "2025-07-01",
        "due": "2025-07-22",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeleMessage"
      ],
      "products": [
        "TeleMessage service"
      ],
      "cwes": [
        "CWE-1188"
      ],
      "description": "The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025."
    },
    {
      "id": "CVE-2025-6543",
      "url": "https://spydr.io/cve/CVE-2025-6543",
      "published": "2025-06-25T13:15:27.293Z",
      "modified": "2026-06-17T10:02:07.007Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "citrix.com",
      "epss": 0.10562,
      "epss_percentile": 0.95656,
      "exploited": true,
      "kev": {
        "added": "2025-06-30",
        "due": "2025-07-21",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server"
    },
    {
      "id": "CVE-2024-54085",
      "url": "https://spydr.io/cve/CVE-2024-54085",
      "published": "2025-03-11T14:15:22.893Z",
      "modified": "2026-06-17T08:09:44.677Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "ami.com",
      "epss": 0.60747,
      "epss_percentile": 0.99127,
      "exploited": true,
      "kev": {
        "added": "2025-06-25",
        "due": "2025-07-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "AMI"
      ],
      "products": [
        "AMI MegaRAC-SPx"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability."
    },
    {
      "id": "CVE-2024-0769",
      "url": "https://spydr.io/cve/CVE-2024-0769",
      "published": "2024-01-21T08:15:07.550Z",
      "modified": "2026-06-17T06:54:13.300Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82714,
      "epss_percentile": 0.99661,
      "exploited": true,
      "kev": {
        "added": "2025-06-25",
        "due": "2025-07-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "D-Link"
      ],
      "products": [
        "D-Link DIR-859",
        "dlink dir-859_firmware"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced."
    },
    {
      "id": "CVE-2019-6693",
      "url": "https://spydr.io/cve/CVE-2019-6693",
      "published": "2019-11-21T16:15:13.173Z",
      "modified": "2026-08-04T05:16:27.110Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.05828,
      "epss_percentile": 0.92943,
      "exploited": true,
      "kev": {
        "added": "2025-06-25",
        "due": "2025-07-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiGate"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set)."
    },
    {
      "id": "CVE-2023-0386",
      "url": "https://spydr.io/cve/CVE-2023-0386",
      "published": "2023-03-22T21:15:18.090Z",
      "modified": "2026-06-17T05:25:25.427Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0788,
      "epss_percentile": 0.94546,
      "exploited": true,
      "kev": {
        "added": "2025-06-17",
        "due": "2025-07-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "debian",
        "netapp",
        "canonical",
        "linux"
      ],
      "products": [
        "Kernel"
      ],
      "cwes": [
        "CWE-282"
      ],
      "description": "A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system."
    },
    {
      "id": "CVE-2025-43200",
      "url": "https://spydr.io/cve/CVE-2025-43200",
      "published": "2025-06-16T22:16:41.120Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 4.2,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "score_source": "CISA ADP",
      "epss": 0.01191,
      "epss_percentile": 0.66908,
      "exploited": true,
      "kev": {
        "added": "2025-06-16",
        "due": "2025-07-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS",
        "Apple macOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [],
      "description": "This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
    },
    {
      "id": "CVE-2023-33538",
      "url": "https://spydr.io/cve/CVE-2023-33538",
      "published": "2023-06-07T04:15:10.623Z",
      "modified": "2026-06-17T06:01:53.847Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41606,
      "epss_percentile": 0.98644,
      "exploited": true,
      "kev": {
        "added": "2025-06-16",
        "due": "2025-07-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tp-link"
      ],
      "products": [
        "tp-link tl-wr940n firmware",
        "tp-link tl-wr841n firmware",
        "tp-link tl-wr740n firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm ."
    },
    {
      "id": "CVE-2025-33053",
      "url": "https://spydr.io/cve/CVE-2025-33053",
      "published": "2025-06-10T17:22:18.853Z",
      "modified": "2026-06-17T09:13:01.030Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.87015,
      "epss_percentile": 0.99745,
      "exploited": true,
      "kev": {
        "added": "2025-06-10",
        "due": "2025-07-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-73"
      ],
      "description": "External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-24016",
      "url": "https://spydr.io/cve/CVE-2025-24016",
      "published": "2025-02-10T20:15:42.540Z",
      "modified": "2026-06-17T08:57:53.677Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.9384,
      "epss_percentile": 0.99843,
      "exploited": true,
      "kev": {
        "added": "2025-06-10",
        "due": "2025-07-01",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wazuh"
      ],
      "products": [
        "wazuh"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix."
    },
    {
      "id": "CVE-2025-32433",
      "url": "https://spydr.io/cve/CVE-2025-32433",
      "published": "2025-04-16T22:15:14.373Z",
      "modified": "2026-06-17T09:11:59.137Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "github.com",
      "epss": 0.98786,
      "epss_percentile": 0.99926,
      "exploited": true,
      "kev": {
        "added": "2025-06-09",
        "due": "2025-06-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "erlang"
      ],
      "products": [
        "erlang otp"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules."
    },
    {
      "id": "CVE-2024-42009",
      "url": "https://spydr.io/cve/CVE-2024-42009",
      "published": "2024-08-05T19:15:38.220Z",
      "modified": "2026-06-17T07:48:37.930Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.82882,
      "epss_percentile": 0.99665,
      "exploited": true,
      "kev": {
        "added": "2025-06-09",
        "due": "2025-06-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube"
      ],
      "products": [
        "roundcube webmail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php."
    },
    {
      "id": "CVE-2025-5419",
      "url": "https://spydr.io/cve/CVE-2025-5419",
      "published": "2025-06-03T00:15:21.043Z",
      "modified": "2026-06-17T09:47:52.993Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.07821,
      "epss_percentile": 0.94506,
      "exploited": true,
      "kev": {
        "added": "2025-06-05",
        "due": "2025-06-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-125",
        "CWE-787"
      ],
      "description": "Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2025-21479",
      "url": "https://spydr.io/cve/CVE-2025-21479",
      "published": "2025-06-03T07:15:20.933Z",
      "modified": "2026-06-17T08:43:33.660Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.00843,
      "epss_percentile": 0.56507,
      "exploited": true,
      "kev": {
        "added": "2025-06-03",
        "due": "2025-06-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands."
    },
    {
      "id": "CVE-2025-27038",
      "url": "https://spydr.io/cve/CVE-2025-27038",
      "published": "2025-06-03T06:15:27.133Z",
      "modified": "2026-06-17T09:02:48.833Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.01016,
      "epss_percentile": 0.62062,
      "exploited": true,
      "kev": {
        "added": "2025-06-03",
        "due": "2025-06-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Memory corruption while rendering graphics using Adreno GPU drivers in Chrome."
    },
    {
      "id": "CVE-2025-21480",
      "url": "https://spydr.io/cve/CVE-2025-21480",
      "published": "2025-06-03T06:15:26.190Z",
      "modified": "2026-06-17T08:43:33.857Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.0046,
      "epss_percentile": 0.37657,
      "exploited": true,
      "kev": {
        "added": "2025-06-03",
        "due": "2025-06-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands."
    },
    {
      "id": "CVE-2025-35939",
      "url": "https://spydr.io/cve/CVE-2025-35939",
      "published": "2025-05-07T23:15:54.103Z",
      "modified": "2026-06-17T09:14:18.460Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.01349,
      "epss_percentile": 0.70535,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Craft"
      ],
      "products": [
        "Craft CMS"
      ],
      "cwes": [
        "CWE-472"
      ],
      "description": "Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue."
    },
    {
      "id": "CVE-2025-3935",
      "url": "https://spydr.io/cve/CVE-2025-3935",
      "published": "2025-04-25T19:15:49.143Z",
      "modified": "2026-06-17T09:20:57.337Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03507,
      "epss_percentile": 0.88825,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ConnectWise"
      ],
      "products": [
        "ConnectWise ScreenConnect"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior. This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
