{
  "query": {
    "kev": "1",
    "page": "24"
  },
  "count": 20,
  "total": 1734,
  "page": 24,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T02:47:12.621Z",
    "kev": "2026-10-07T03:46:14.963Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T03:47:15.195Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=24",
    "next": "https://spydr.io/threats.json?kev=1&page=25"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-23209",
      "url": "https://spydr.io/cve/CVE-2025-23209",
      "published": "2025-01-18T01:15:07.633Z",
      "modified": "2026-06-17T08:52:39.483Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21776,
      "epss_percentile": 0.97581,
      "exploited": true,
      "kev": {
        "added": "2025-02-20",
        "due": "2025-03-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "craftcms"
      ],
      "products": [
        "craftcms cms"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue."
    },
    {
      "id": "CVE-2025-0108",
      "url": "https://spydr.io/cve/CVE-2025-0108",
      "published": "2025-02-12T21:15:16.290Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.98455,
      "epss_percentile": 0.99918,
      "exploited": true,
      "kev": {
        "added": "2025-02-18",
        "due": "2025-03-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software."
    },
    {
      "id": "CVE-2024-53704",
      "url": "https://spydr.io/cve/CVE-2024-53704",
      "published": "2025-01-09T07:15:27.203Z",
      "modified": "2026-08-04T05:16:31.367Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95132,
      "epss_percentile": 0.99864,
      "exploited": true,
      "kev": {
        "added": "2025-02-18",
        "due": "2025-03-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SonicOS"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication."
    },
    {
      "id": "CVE-2024-57727",
      "url": "https://spydr.io/cve/CVE-2024-57727",
      "published": "2025-01-15T23:15:09.650Z",
      "modified": "2026-08-04T05:16:31.913Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.96576,
      "epss_percentile": 0.99882,
      "exploited": true,
      "kev": {
        "added": "2025-02-13",
        "due": "2025-03-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "simple-help"
      ],
      "products": [
        "simple-help simplehelp"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords."
    },
    {
      "id": "CVE-2025-24200",
      "url": "https://spydr.io/cve/CVE-2025-24200",
      "published": "2025-02-10T19:15:40.107Z",
      "modified": "2026-06-17T08:58:17.800Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.0442,
      "epss_percentile": 0.91078,
      "exploited": true,
      "kev": {
        "added": "2025-02-12",
        "due": "2025-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
    },
    {
      "id": "CVE-2024-41710",
      "url": "https://spydr.io/cve/CVE-2024-41710",
      "published": "2024-08-12T19:15:16.850Z",
      "modified": "2026-06-17T07:48:05.950Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41646,
      "epss_percentile": 0.98648,
      "exploited": true,
      "kev": {
        "added": "2025-02-12",
        "due": "2025-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel 6940_sip_firmware",
        "mitel 6905_sip_firmware",
        "mitel 6910_sip_firmware",
        "mitel 6915_sip_firmware",
        "mitel 6920_sip_firmware",
        "mitel 6920w_sip_firmware",
        "mitel 6930w_sip_firmware",
        "mitel 6940w_sip_firmware",
        "mitel 6970_conference_firmware"
      ],
      "cwes": [
        "CWE-88"
      ],
      "description": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system."
    },
    {
      "id": "CVE-2025-21418",
      "url": "https://spydr.io/cve/CVE-2025-21418",
      "published": "2025-02-11T18:15:40.023Z",
      "modified": "2026-06-17T08:43:19.180Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01568,
      "epss_percentile": 0.74529,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-21391",
      "url": "https://spydr.io/cve/CVE-2025-21391",
      "published": "2025-02-11T18:15:37.723Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02303,
      "epss_percentile": 0.82768,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows Storage Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-40891",
      "url": "https://spydr.io/cve/CVE-2024-40891",
      "published": "2025-02-04T10:15:08.920Z",
      "modified": "2026-06-17T07:46:48.213Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.21536,
      "epss_percentile": 0.97562,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel VMG4325-B10A firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet."
    },
    {
      "id": "CVE-2024-40890",
      "url": "https://spydr.io/cve/CVE-2024-40890",
      "published": "2025-02-04T10:15:08.717Z",
      "modified": "2026-06-17T07:46:48.077Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.20703,
      "epss_percentile": 0.97473,
      "exploited": true,
      "kev": {
        "added": "2025-02-11",
        "due": "2025-03-04",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel VMG4325-B10A firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request."
    },
    {
      "id": "CVE-2025-0994",
      "url": "https://spydr.io/cve/CVE-2025-0994",
      "published": "2025-02-06T16:15:41.493Z",
      "modified": "2026-06-17T08:27:29.190Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "hq.dhs.gov",
      "epss": 0.31085,
      "epss_percentile": 0.98225,
      "exploited": true,
      "kev": {
        "added": "2025-02-07",
        "due": "2025-02-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trimble"
      ],
      "products": [
        "Trimble Cityworks",
        "Trimble Cityworks (with office companion)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server."
    },
    {
      "id": "CVE-2025-0411",
      "url": "https://spydr.io/cve/CVE-2025-0411",
      "published": "2025-01-25T05:15:09.533Z",
      "modified": "2026-06-17T08:26:25.627Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.67071,
      "epss_percentile": 0.99283,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "7-Zip"
      ],
      "products": [
        "7-Zip"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456."
    },
    {
      "id": "CVE-2024-21413",
      "url": "https://spydr.io/cve/CVE-2024-21413",
      "published": "2024-02-13T18:16:00.137Z",
      "modified": "2026-08-10T16:18:51.720Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.9466,
      "epss_percentile": 0.99856,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office 2016",
        "Microsoft Office 2019",
        "Microsoft Office LTSC 2021"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Microsoft Outlook Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2022-23748",
      "url": "https://spydr.io/cve/CVE-2022-23748",
      "published": "2022-11-17T23:15:14.383Z",
      "modified": "2026-06-17T04:30:45.160Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09092,
      "epss_percentile": 0.95172,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "audinate"
      ],
      "products": [
        "Audinate Dante Application Library for Windows"
      ],
      "cwes": [
        "CWE-114",
        "CWE-426"
      ],
      "description": "mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files."
    },
    {
      "id": "CVE-2020-29574",
      "url": "https://spydr.io/cve/CVE-2020-29574",
      "published": "2020-12-11T17:15:13.480Z",
      "modified": "2026-08-15T04:17:56.567Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04658,
      "epss_percentile": 0.91487,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sophos"
      ],
      "products": [
        "sophos cyberoamos"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely."
    },
    {
      "id": "CVE-2020-15069",
      "url": "https://spydr.io/cve/CVE-2020-15069",
      "published": "2020-06-29T18:15:12.313Z",
      "modified": "2026-06-17T02:55:59.830Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10674,
      "epss_percentile": 0.95693,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sophos"
      ],
      "products": [
        "sophos xg firewall firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x."
    },
    {
      "id": "CVE-2024-53104",
      "url": "https://spydr.io/cve/CVE-2024-53104",
      "published": "2024-12-02T08:15:08.687Z",
      "modified": "2026-06-17T08:08:17.170Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03395,
      "epss_percentile": 0.88467,
      "exploited": true,
      "kev": {
        "added": "2025-02-05",
        "due": "2025-02-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming."
    },
    {
      "id": "CVE-2024-45195",
      "url": "https://spydr.io/cve/CVE-2024-45195",
      "published": "2024-09-04T09:15:04.397Z",
      "modified": "2026-06-17T07:53:46.637Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99983,
      "epss_percentile": 0.99982,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache OFBiz",
        "apache ofbiz"
      ],
      "cwes": [
        "CWE-425"
      ],
      "description": "Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue."
    },
    {
      "id": "CVE-2024-29059",
      "url": "https://spydr.io/cve/CVE-2024-29059",
      "published": "2024-03-23T00:15:09.150Z",
      "modified": "2026-06-17T07:22:20.537Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.98624,
      "epss_percentile": 0.99923,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft .NET Framework 4.8",
        "Microsoft .NET Framework 3.5 AND 4.8",
        "Microsoft .NET Framework 3.5 AND 4.7.2",
        "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2",
        "Microsoft .NET Framework 3.5 AND 4.8.1",
        "Microsoft .NET Framework 4.6.2",
        "Microsoft .NET Framework 3.5 AND 4.6/4.6.2",
        "Microsoft .NET Framework 2.0 Service Pack 2",
        "Microsoft .NET Framework 3.0 Service Pack 2",
        "Microsoft .NET Framework 3.5",
        "Microsoft .NET Framework 3.5.1"
      ],
      "cwes": [
        "CWE-209"
      ],
      "description": ".NET Framework Information Disclosure Vulnerability"
    },
    {
      "id": "CVE-2018-19410",
      "url": "https://spydr.io/cve/CVE-2018-19410",
      "published": "2018-11-21T16:29:00.347Z",
      "modified": "2026-06-17T01:49:15.640Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97939,
      "epss_percentile": 0.99909,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "paessler"
      ],
      "products": [
        "paessler prtg network monitor"
      ],
      "cwes": [],
      "description": "PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator)."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
