{
  "query": {
    "kev": "1",
    "page": "25"
  },
  "count": 20,
  "total": 1734,
  "page": 25,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T04:47:17.455Z",
    "kev": "2026-10-07T04:46:17.408Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T04:47:17.455Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=25",
    "next": "https://spydr.io/threats.json?kev=1&page=26"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2018-9276",
      "url": "https://spydr.io/cve/CVE-2018-9276",
      "published": "2018-07-02T16:29:00.600Z",
      "modified": "2026-06-17T02:06:20.513Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86996,
      "epss_percentile": 0.99745,
      "exploited": true,
      "kev": {
        "added": "2025-02-04",
        "due": "2025-02-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "paessler"
      ],
      "products": [
        "paessler prtg network monitor"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios."
    },
    {
      "id": "CVE-2025-24085",
      "url": "https://spydr.io/cve/CVE-2025-24085",
      "published": "2025-01-27T22:15:14.990Z",
      "modified": "2026-06-17T08:58:02.497Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1751,
      "epss_percentile": 0.97061,
      "exploited": true,
      "kev": {
        "added": "2025-01-29",
        "due": "2025-02-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2."
    },
    {
      "id": "CVE-2025-23006",
      "url": "https://spydr.io/cve/CVE-2025-23006",
      "published": "2025-01-23T12:15:28.523Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23432,
      "epss_percentile": 0.97736,
      "exploited": true,
      "kev": {
        "added": "2025-01-24",
        "due": "2025-02-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA1000"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands."
    },
    {
      "id": "CVE-2020-11023",
      "url": "https://spydr.io/cve/CVE-2020-11023",
      "published": "2020-04-29T21:15:11.743Z",
      "modified": "2026-06-17T02:48:52.930Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.84887,
      "epss_percentile": 0.99707,
      "exploited": true,
      "kev": {
        "added": "2025-01-23",
        "due": "2025-02-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "jquery"
      ],
      "products": [
        "jQuery"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0."
    },
    {
      "id": "CVE-2024-50603",
      "url": "https://spydr.io/cve/CVE-2024-50603",
      "published": "2025-01-08T01:15:07.127Z",
      "modified": "2026-06-17T08:04:47.600Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98545,
      "epss_percentile": 0.99921,
      "exploited": true,
      "kev": {
        "added": "2025-01-16",
        "due": "2025-02-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Aviatrix"
      ],
      "products": [
        "Aviatrix Controller"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test."
    },
    {
      "id": "CVE-2025-21335",
      "url": "https://spydr.io/cve/CVE-2025-21335",
      "published": "2025-01-14T18:15:58.960Z",
      "modified": "2026-09-24T13:10:00.320Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.0139,
      "epss_percentile": 0.71429,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-02-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-21334",
      "url": "https://spydr.io/cve/CVE-2025-21334",
      "published": "2025-01-14T18:15:58.770Z",
      "modified": "2026-06-17T08:43:07.783Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01561,
      "epss_percentile": 0.74432,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-02-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2025-21333",
      "url": "https://spydr.io/cve/CVE-2025-21333",
      "published": "2025-01-14T18:15:58.530Z",
      "modified": "2026-06-17T08:43:07.637Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.09988,
      "epss_percentile": 0.95486,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-02-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-55591",
      "url": "https://spydr.io/cve/CVE-2024-55591",
      "published": "2025-01-14T14:15:34.450Z",
      "modified": "2026-08-05T05:16:42.380Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94149,
      "epss_percentile": 0.99848,
      "exploited": true,
      "kev": {
        "added": "2025-01-14",
        "due": "2025-01-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS",
        "Fortinet FortiProxy"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module."
    },
    {
      "id": "CVE-2024-12686",
      "url": "https://spydr.io/cve/CVE-2024-12686",
      "published": "2024-12-18T21:15:08.020Z",
      "modified": "2026-06-17T07:00:16.763Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.137,
      "epss_percentile": 0.96397,
      "exploited": true,
      "kev": {
        "added": "2025-01-13",
        "due": "2025-02-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BeyondTrust"
      ],
      "products": [
        "BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA)"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user."
    },
    {
      "id": "CVE-2023-48365",
      "url": "https://spydr.io/cve/CVE-2023-48365",
      "published": "2023-11-15T22:15:28.027Z",
      "modified": "2026-06-17T06:34:06.873Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.47453,
      "epss_percentile": 0.98812,
      "exploited": true,
      "kev": {
        "added": "2025-01-13",
        "due": "2025-02-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qlik"
      ],
      "products": [
        "qlik sense"
      ],
      "cwes": [
        "CWE-444"
      ],
      "description": "Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265."
    },
    {
      "id": "CVE-2025-0282",
      "url": "https://spydr.io/cve/CVE-2025-0282",
      "published": "2025-01-08T23:15:09.763Z",
      "modified": "2026-10-01T19:17:15.743Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99979,
      "epss_percentile": 0.9998,
      "exploited": true,
      "kev": {
        "added": "2025-01-08",
        "due": "2025-01-15",
        "action": "Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Connect Secure",
        "Ivanti Policy Secure",
        "Ivanti Neurons for ZTA gateways"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution."
    },
    {
      "id": "CVE-2024-55550",
      "url": "https://spydr.io/cve/CVE-2024-55550",
      "published": "2024-12-10T19:15:31.110Z",
      "modified": "2026-08-04T05:16:31.577Z",
      "score": 2.7,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.38155,
      "epss_percentile": 0.98523,
      "exploited": true,
      "kev": {
        "added": "2025-01-07",
        "due": "2025-01-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel micollab"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation."
    },
    {
      "id": "CVE-2024-41713",
      "url": "https://spydr.io/cve/CVE-2024-41713",
      "published": "2024-10-21T21:15:06.470Z",
      "modified": "2026-08-04T05:16:30.767Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.9811,
      "epss_percentile": 0.99912,
      "exploited": true,
      "kev": {
        "added": "2025-01-07",
        "due": "2025-01-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel micollab"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations."
    },
    {
      "id": "CVE-2020-2883",
      "url": "https://spydr.io/cve/CVE-2020-2883",
      "published": "2020-04-15T14:15:33.513Z",
      "modified": "2026-06-17T03:13:10.183Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94928,
      "epss_percentile": 0.99861,
      "exploited": true,
      "kev": {
        "added": "2025-01-07",
        "due": "2025-01-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation WebLogic Server"
      ],
      "cwes": [],
      "description": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2024-3393",
      "url": "https://spydr.io/cve/CVE-2024-3393",
      "published": "2024-12-27T10:15:17.270Z",
      "modified": "2026-06-17T07:44:11.227Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber",
      "score_source": "paloaltonetworks.com",
      "epss": 0.2912,
      "epss_percentile": 0.98124,
      "exploited": true,
      "kev": {
        "added": "2024-12-30",
        "due": "2025-01-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS"
      ],
      "cwes": [
        "CWE-754"
      ],
      "description": "A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode."
    },
    {
      "id": "CVE-2021-44207",
      "url": "https://spydr.io/cve/CVE-2021-44207",
      "published": "2021-12-21T18:15:08.143Z",
      "modified": "2026-06-17T04:12:03.230Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.17578,
      "epss_percentile": 0.97068,
      "exploited": true,
      "kev": {
        "added": "2024-12-23",
        "due": "2025-01-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "acclaimsystems"
      ],
      "products": [
        "acclaimsystems usaherds"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials."
    },
    {
      "id": "CVE-2024-12356",
      "url": "https://spydr.io/cve/CVE-2024-12356",
      "published": "2024-12-17T05:15:06.413Z",
      "modified": "2026-06-17T06:59:33.887Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87258,
      "epss_percentile": 0.99749,
      "exploited": true,
      "kev": {
        "added": "2024-12-19",
        "due": "2024-12-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BeyondTrust"
      ],
      "products": [
        "BeyondTrust Remote Support",
        "BeyondTrust Privileged Remote Access"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user."
    },
    {
      "id": "CVE-2021-40407",
      "url": "https://spydr.io/cve/CVE-2021-40407",
      "published": "2022-01-28T20:15:11.607Z",
      "modified": "2026-06-17T04:06:52.767Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.47635,
      "epss_percentile": 0.98817,
      "exploited": true,
      "kev": {
        "added": "2024-12-18",
        "due": "2025-01-08",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "reolink"
      ],
      "products": [
        "reolink rlc-410w firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability."
    },
    {
      "id": "CVE-2022-23227",
      "url": "https://spydr.io/cve/CVE-2022-23227",
      "published": "2022-01-14T18:15:10.303Z",
      "modified": "2026-06-17T04:29:42.067Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48497,
      "epss_percentile": 0.98836,
      "exploited": true,
      "kev": {
        "added": "2024-12-18",
        "due": "2025-01-08",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nuuo"
      ],
      "products": [
        "nuuo nvrmini2 firmware"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
