{
  "query": {
    "kev": "1",
    "page": "20"
  },
  "count": 20,
  "total": 1734,
  "page": 20,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T22:46:18.712Z",
    "kev": "2026-10-06T23:45:20.765Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T23:46:20.864Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=20",
    "next": "https://spydr.io/threats.json?kev=1&page=21"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-56145",
      "url": "https://spydr.io/cve/CVE-2024-56145",
      "published": "2024-12-18T21:15:08.530Z",
      "modified": "2026-06-17T08:11:45.717Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.97405,
      "epss_percentile": 0.99899,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "craftcms"
      ],
      "products": [
        "craftcms cms"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue."
    },
    {
      "id": "CVE-2023-39780",
      "url": "https://spydr.io/cve/CVE-2023-39780",
      "published": "2023-09-11T19:15:43.190Z",
      "modified": "2026-06-17T06:12:51.930Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39514,
      "epss_percentile": 0.98576,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ASUS"
      ],
      "products": [
        "ASUS RT-AX55"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar \"token-generated module\" issue, see CVE-2023-41345; for the similar \"token-refresh module\" issue, see CVE-2023-41346; for the similar \"check token module\" issue, see CVE-2023-41347; and for the similar \"code-authentication module\" issue, see CVE-2023-41348."
    },
    {
      "id": "CVE-2021-32030",
      "url": "https://spydr.io/cve/CVE-2021-32030",
      "published": "2021-05-06T15:15:07.973Z",
      "modified": "2026-06-17T03:52:42.307Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99393,
      "epss_percentile": 0.99941,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "asus"
      ],
      "products": [
        "asus lyra mini firmware",
        "asus gt-ac2900 firmware"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\\0' matches the device's default value of '\\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN."
    },
    {
      "id": "CVE-2025-4632",
      "url": "https://spydr.io/cve/CVE-2025-4632",
      "published": "2025-05-13T06:15:36.537Z",
      "modified": "2026-06-17T09:33:39.023Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24295,
      "epss_percentile": 0.97807,
      "exploited": true,
      "kev": {
        "added": "2025-05-22",
        "due": "2025-06-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Electronics"
      ],
      "products": [
        "Samsung Electronics MagicINFO 9 Server"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority."
    },
    {
      "id": "CVE-2025-4428",
      "url": "https://spydr.io/cve/CVE-2025-4428",
      "published": "2025-05-13T16:15:32.463Z",
      "modified": "2026-06-17T09:33:13.990Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86519,
      "epss_percentile": 0.99735,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests."
    },
    {
      "id": "CVE-2025-4427",
      "url": "https://spydr.io/cve/CVE-2025-4427",
      "published": "2025-05-13T16:15:32.330Z",
      "modified": "2026-06-17T09:33:13.873Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99927,
      "epss_percentile": 0.99969,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API."
    },
    {
      "id": "CVE-2025-27920",
      "url": "https://spydr.io/cve/CVE-2025-27920",
      "published": "2025-05-05T16:15:50.857Z",
      "modified": "2026-06-17T09:04:23.737Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01865,
      "epss_percentile": 0.78598,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Srimax"
      ],
      "products": [
        "Srimax Output Messenger"
      ],
      "cwes": [
        "CWE-24"
      ],
      "description": "Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access."
    },
    {
      "id": "CVE-2024-11182",
      "url": "https://spydr.io/cve/CVE-2024-11182",
      "published": "2024-11-15T11:15:10.410Z",
      "modified": "2026-06-17T06:57:13.713Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "eset.com",
      "epss": 0.17591,
      "epss_percentile": 0.9707,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "MDaemon"
      ],
      "products": [
        "MDaemon Email Server"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window."
    },
    {
      "id": "CVE-2024-27443",
      "url": "https://spydr.io/cve/CVE-2024-27443",
      "published": "2024-08-12T15:15:20.283Z",
      "modified": "2026-06-17T07:19:54.627Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.23632,
      "epss_percentile": 0.97755,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zimbra"
      ],
      "products": [
        "zimbra collaboration"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code."
    },
    {
      "id": "CVE-2023-38950",
      "url": "https://spydr.io/cve/CVE-2023-38950",
      "published": "2023-08-03T23:15:11.117Z",
      "modified": "2026-07-09T13:57:25.203Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.92468,
      "epss_percentile": 0.99824,
      "exploited": true,
      "kev": {
        "added": "2025-05-19",
        "due": "2025-06-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zkteco"
      ],
      "products": [
        "zkteco biotime"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime."
    },
    {
      "id": "CVE-2025-42999",
      "url": "https://spydr.io/cve/CVE-2025-42999",
      "published": "2025-05-13T01:15:48.440Z",
      "modified": "2026-08-11T04:17:17.240Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "sap.com",
      "epss": 0.13868,
      "epss_percentile": 0.96433,
      "exploited": true,
      "kev": {
        "added": "2025-05-15",
        "due": "2025-06-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP_SE"
      ],
      "products": [
        "SAP_SE SAP NetWeaver (Visual Composer development server)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system."
    },
    {
      "id": "CVE-2024-12987",
      "url": "https://spydr.io/cve/CVE-2024-12987",
      "published": "2024-12-27T16:15:24.143Z",
      "modified": "2026-06-17T07:00:55.297Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vuldb.com",
      "epss": 0.98163,
      "epss_percentile": 0.99913,
      "exploited": true,
      "kev": {
        "added": "2025-05-15",
        "due": "2025-06-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "DrayTek"
      ],
      "products": [
        "DrayTek Vigor2960",
        "DrayTek Vigor300B"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component."
    },
    {
      "id": "CVE-2025-32756",
      "url": "https://spydr.io/cve/CVE-2025-32756",
      "published": "2025-05-13T15:15:57.113Z",
      "modified": "2026-06-17T09:12:32.723Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29812,
      "epss_percentile": 0.98158,
      "exploited": true,
      "kev": {
        "added": "2025-05-14",
        "due": "2025-06-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiNDR",
        "Fortinet FortiCamera",
        "Fortinet FortiRecorder",
        "Fortinet FortiVoice",
        "Fortinet FortiMail"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie."
    },
    {
      "id": "CVE-2025-32709",
      "url": "https://spydr.io/cve/CVE-2025-32709",
      "published": "2025-05-13T17:16:04.020Z",
      "modified": "2026-06-17T09:12:27.700Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02158,
      "epss_percentile": 0.81594,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-32706",
      "url": "https://spydr.io/cve/CVE-2025-32706",
      "published": "2025-05-13T17:16:03.607Z",
      "modified": "2026-06-17T09:12:27.347Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02313,
      "epss_percentile": 0.82846,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-32701",
      "url": "https://spydr.io/cve/CVE-2025-32701",
      "published": "2025-05-13T17:16:02.710Z",
      "modified": "2026-06-17T09:12:26.723Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01403,
      "epss_percentile": 0.71673,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-30400",
      "url": "https://spydr.io/cve/CVE-2025-30400",
      "published": "2025-05-13T17:16:02.537Z",
      "modified": "2026-06-17T09:08:39.300Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.019,
      "epss_percentile": 0.79005,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Windows DWM allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2025-30397",
      "url": "https://spydr.io/cve/CVE-2025-30397",
      "published": "2025-05-13T17:16:02.370Z",
      "modified": "2026-06-17T09:08:38.813Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.26835,
      "epss_percentile": 0.97985,
      "exploited": true,
      "kev": {
        "added": "2025-05-13",
        "due": "2025-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network."
    },
    {
      "id": "CVE-2025-47729",
      "url": "https://spydr.io/cve/CVE-2025-47729",
      "published": "2025-05-08T14:15:26.883Z",
      "modified": "2026-06-17T09:28:37.040Z",
      "score": 4.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00447,
      "epss_percentile": 0.36725,
      "exploited": true,
      "kev": {
        "added": "2025-05-12",
        "due": "2025-06-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TeleMessage"
      ],
      "products": [
        "TeleMessage archiving backend"
      ],
      "cwes": [
        "CWE-912"
      ],
      "description": "The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage \"End-to-End encryption from the mobile phone through to the corporate archive\" documentation, as exploited in the wild in May 2025."
    },
    {
      "id": "CVE-2024-11120",
      "url": "https://spydr.io/cve/CVE-2024-11120",
      "published": "2024-11-15T02:15:17.757Z",
      "modified": "2026-06-17T06:57:06.503Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28386,
      "epss_percentile": 0.98079,
      "exploited": true,
      "kev": {
        "added": "2025-05-07",
        "due": "2025-05-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GeoVision"
      ],
      "products": [
        "GeoVision GV-VS12",
        "GeoVision GV-VS11",
        "GeoVision GV-DSP_LPR_V3",
        "GeoVision GVLX 4 V2",
        "GeoVision GVLX 4 V3",
        "geovision gv-vs12_firmware",
        "geovision gv-vs11_firmware",
        "geovision gv-dsp_lpr_v3_firmware",
        "geovision gvlx_4_v2_firmware",
        "geovision gvlx_4_v3_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
