{
  "query": {
    "kev": "1",
    "page": "23"
  },
  "count": 20,
  "total": 1734,
  "page": 23,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T02:47:12.621Z",
    "kev": "2026-10-07T02:46:12.406Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T02:47:12.620Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=23",
    "next": "https://spydr.io/threats.json?kev=1&page=24"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-25181",
      "url": "https://spydr.io/cve/CVE-2025-25181",
      "published": "2025-02-03T20:15:37.477Z",
      "modified": "2026-06-17T09:00:26.210Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.55549,
      "epss_percentile": 0.99015,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Advantive"
      ],
      "products": [
        "Advantive VeraCore"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter."
    },
    {
      "id": "CVE-2024-57968",
      "url": "https://spydr.io/cve/CVE-2024-57968",
      "published": "2025-02-03T20:15:36.550Z",
      "modified": "2026-06-17T08:14:20.447Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.32284,
      "epss_percentile": 0.98284,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Advantive"
      ],
      "products": [
        "Advantive VeraCore"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during web browsing by other users). upload.aspx can be used for this."
    },
    {
      "id": "CVE-2024-13161",
      "url": "https://spydr.io/cve/CVE-2024-13161",
      "published": "2025-01-14T18:15:26.640Z",
      "modified": "2026-06-17T07:01:20.837Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.90081,
      "epss_percentile": 0.99794,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information."
    },
    {
      "id": "CVE-2024-13160",
      "url": "https://spydr.io/cve/CVE-2024-13160",
      "published": "2025-01-14T18:15:26.447Z",
      "modified": "2026-06-17T07:01:20.707Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.91247,
      "epss_percentile": 0.99808,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information."
    },
    {
      "id": "CVE-2024-13159",
      "url": "https://spydr.io/cve/CVE-2024-13159",
      "published": "2025-01-14T18:15:26.243Z",
      "modified": "2026-06-17T07:01:20.577Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99992,
      "epss_percentile": 0.99987,
      "exploited": true,
      "kev": {
        "added": "2025-03-10",
        "due": "2025-03-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager"
      ],
      "cwes": [
        "CWE-36"
      ],
      "description": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information."
    },
    {
      "id": "CVE-2025-22226",
      "url": "https://spydr.io/cve/CVE-2025-22226",
      "published": "2025-03-04T12:15:33.973Z",
      "modified": "2026-06-17T08:45:44.380Z",
      "score": 6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01769,
      "epss_percentile": 0.77396,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "ESXi",
        "VMware Workstation",
        "VMware Fusion",
        "VMware Cloud Foundation",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process."
    },
    {
      "id": "CVE-2025-22225",
      "url": "https://spydr.io/cve/CVE-2025-22225",
      "published": "2025-03-04T12:15:33.840Z",
      "modified": "2026-08-04T05:16:33.493Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01016,
      "epss_percentile": 0.62124,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware ESXi",
        "VMware Cloud Foundation",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-787",
        "CWE-123"
      ],
      "description": "VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox."
    },
    {
      "id": "CVE-2025-22224",
      "url": "https://spydr.io/cve/CVE-2025-22224",
      "published": "2025-03-04T12:15:33.687Z",
      "modified": "2026-06-17T08:45:43.370Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01561,
      "epss_percentile": 0.7443,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware ESXi",
        "VMware Workstation",
        "VMware Cloud Foundation",
        "VMware Telco Cloud Platform",
        "VMware Telco Cloud Infrastructure"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host."
    },
    {
      "id": "CVE-2024-50302",
      "url": "https://spydr.io/cve/CVE-2024-50302",
      "published": "2024-11-19T02:16:32.320Z",
      "modified": "2026-06-17T08:04:10.447Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00811,
      "epss_percentile": 0.55538,
      "exploited": true,
      "kev": {
        "added": "2025-03-04",
        "due": "2025-03-25",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux",
        "Siemens"
      ],
      "products": [
        "Linux",
        "Siemens RUGGEDCOM RST2428P",
        "Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family",
        "Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 family",
        "Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem"
      ],
      "cwes": [
        "CWE-908"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report."
    },
    {
      "id": "CVE-2024-4885",
      "url": "https://spydr.io/cve/CVE-2024-4885",
      "published": "2024-06-25T20:15:12.970Z",
      "modified": "2026-06-17T08:03:06.323Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99288,
      "epss_percentile": 0.99937,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software Corporation",
        "progress"
      ],
      "products": [
        "Progress Software Corporation WhatsUp Gold",
        "progress whatsup_gold"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\\nmconsole privileges."
    },
    {
      "id": "CVE-2023-20118",
      "url": "https://spydr.io/cve/CVE-2023-20118",
      "published": "2023-04-13T07:15:21.080Z",
      "modified": "2026-06-17T05:29:31.353Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54107,
      "epss_percentile": 0.98981,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacker would need to have valid administrative credentials on the affected device. Cisco has not and will not release software updates that address this vulnerability. However, administrators may disable the affected feature as described in the Workarounds [\"#workarounds\"] section. {{value}} [\"%7b%7bvalue%7d%7d\"])}]]"
    },
    {
      "id": "CVE-2022-43939",
      "url": "https://spydr.io/cve/CVE-2022-43939",
      "published": "2023-04-03T19:15:07.047Z",
      "modified": "2026-06-17T05:07:31.013Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92266,
      "epss_percentile": 0.99821,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Hitachi Vantara"
      ],
      "products": [
        "Hitachi Vantara Pentaho Business Analytics Server"
      ],
      "cwes": [
        "CWE-647"
      ],
      "description": "Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented."
    },
    {
      "id": "CVE-2022-43769",
      "url": "https://spydr.io/cve/CVE-2022-43769",
      "published": "2023-04-03T18:15:07.703Z",
      "modified": "2026-06-17T05:07:17.553Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9767,
      "epss_percentile": 0.99903,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Hitachi Vantara"
      ],
      "products": [
        "Hitachi Vantara Pentaho Business Analytics Server"
      ],
      "cwes": [
        "CWE-74",
        "CWE-94"
      ],
      "description": "Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream."
    },
    {
      "id": "CVE-2018-8639",
      "url": "https://spydr.io/cve/CVE-2018-8639",
      "published": "2018-12-12T00:29:01.840Z",
      "modified": "2026-06-17T02:05:14.420Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22179,
      "epss_percentile": 0.97617,
      "exploited": true,
      "kev": {
        "added": "2025-03-03",
        "due": "2025-03-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 7",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows RT 8.1",
        "Microsoft Windows Server 2008",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2012",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2008 R2",
        "Microsoft Windows 10",
        "Microsoft Windows 10 Servers"
      ],
      "cwes": [
        "CWE-404"
      ],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641."
    },
    {
      "id": "CVE-2024-49035",
      "url": "https://spydr.io/cve/CVE-2024-49035",
      "published": "2024-11-26T20:15:31.763Z",
      "modified": "2026-06-17T07:59:16.540Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.013,
      "epss_percentile": 0.69517,
      "exploited": true,
      "kev": {
        "added": "2025-02-25",
        "due": "2025-03-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Partner Center"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network."
    },
    {
      "id": "CVE-2023-34192",
      "url": "https://spydr.io/cve/CVE-2023-34192",
      "published": "2023-07-06T16:15:10.047Z",
      "modified": "2026-06-17T06:03:05.923Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77266,
      "epss_percentile": 0.99545,
      "exploited": true,
      "kev": {
        "added": "2025-02-25",
        "due": "2025-03-18",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function."
    },
    {
      "id": "CVE-2024-20953",
      "url": "https://spydr.io/cve/CVE-2024-20953",
      "published": "2024-02-17T02:15:49.520Z",
      "modified": "2026-06-17T07:08:14.457Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.03934,
      "epss_percentile": 0.90083,
      "exploited": true,
      "kev": {
        "added": "2025-02-24",
        "due": "2025-03-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation Agile PLM Framework",
        "oracle agile_plm_framework"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2017-3066",
      "url": "https://spydr.io/cve/CVE-2017-3066",
      "published": "2017-04-27T14:59:00.233Z",
      "modified": "2026-06-17T01:17:26.550Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90597,
      "epss_percentile": 0.99801,
      "exploited": true,
      "kev": {
        "added": "2025-02-24",
        "due": "2025-03-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution."
    },
    {
      "id": "CVE-2025-24989",
      "url": "https://spydr.io/cve/CVE-2025-24989",
      "published": "2025-02-19T23:15:15.167Z",
      "modified": "2026-06-17T08:59:56.470Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01622,
      "epss_percentile": 0.75313,
      "exploited": true,
      "kev": {
        "added": "2025-02-21",
        "due": "2025-03-14",
        "action": "Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Power Pages"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you."
    },
    {
      "id": "CVE-2025-0111",
      "url": "https://spydr.io/cve/CVE-2025-0111",
      "published": "2025-02-12T21:15:16.793Z",
      "modified": "2026-06-17T08:25:51.493Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.01999,
      "epss_percentile": 0.80062,
      "exploited": true,
      "kev": {
        "added": "2025-02-20",
        "due": "2025-03-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-73",
        "CWE-610"
      ],
      "description": "An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
