{
  "query": {
    "kev": "1",
    "page": "26"
  },
  "count": 20,
  "total": 1734,
  "page": 26,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T04:47:17.455Z",
    "kev": "2026-10-07T05:46:19.852Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T05:47:20.222Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=26",
    "next": "https://spydr.io/threats.json?kev=1&page=27"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-11001",
      "url": "https://spydr.io/cve/CVE-2019-11001",
      "published": "2019-04-08T17:29:00.590Z",
      "modified": "2026-06-17T02:12:05.760Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.37542,
      "epss_percentile": 0.98498,
      "exploited": true,
      "kev": {
        "added": "2024-12-18",
        "due": "2025-01-08",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "reolink"
      ],
      "products": [
        "reolink rlc-410w firmware",
        "reolink c1 pro firmware",
        "reolink c2 pro firmware",
        "reolink rlc-422w firmware",
        "reolink rlc-511w firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the \"TestEmail\" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 field."
    },
    {
      "id": "CVE-2018-14933",
      "url": "https://spydr.io/cve/CVE-2018-14933",
      "published": "2018-08-04T19:29:00.263Z",
      "modified": "2026-06-17T01:41:54.600Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94884,
      "epss_percentile": 0.99859,
      "exploited": true,
      "kev": {
        "added": "2024-12-18",
        "due": "2025-01-08",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nuuo"
      ],
      "products": [
        "nuuo nvrmini firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command."
    },
    {
      "id": "CVE-2024-55956",
      "url": "https://spydr.io/cve/CVE-2024-55956",
      "published": "2024-12-13T21:15:13.767Z",
      "modified": "2026-08-05T05:16:42.863Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93968,
      "epss_percentile": 0.99845,
      "exploited": true,
      "kev": {
        "added": "2024-12-17",
        "due": "2025-01-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cleo"
      ],
      "products": [
        "cleo harmony",
        "cleo lexicom",
        "cleo vltrader"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory."
    },
    {
      "id": "CVE-2024-35250",
      "url": "https://spydr.io/cve/CVE-2024-35250",
      "published": "2024-06-11T17:16:02.650Z",
      "modified": "2026-07-20T16:16:51.603Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.25222,
      "epss_percentile": 0.97886,
      "exploited": true,
      "kev": {
        "added": "2024-12-16",
        "due": "2025-01-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-20767",
      "url": "https://spydr.io/cve/CVE-2024-20767",
      "published": "2024-03-18T12:15:06.870Z",
      "modified": "2026-06-17T07:07:49.320Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "adobe.com",
      "epss": 0.98514,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2024-12-16",
        "due": "2025-01-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet."
    },
    {
      "id": "CVE-2024-50623",
      "url": "https://spydr.io/cve/CVE-2024-50623",
      "published": "2024-10-28T00:15:03.657Z",
      "modified": "2026-07-31T04:16:44.760Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98607,
      "epss_percentile": 0.99922,
      "exploited": true,
      "kev": {
        "added": "2024-12-13",
        "due": "2025-01-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cleo"
      ],
      "products": [
        "cleo harmomy",
        "cleo vltrader",
        "cleo lexicom"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution."
    },
    {
      "id": "CVE-2024-49138",
      "url": "https://spydr.io/cve/CVE-2024-49138",
      "published": "2024-12-12T02:04:40.307Z",
      "modified": "2026-06-17T07:59:29.057Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.26215,
      "epss_percentile": 0.97949,
      "exploited": true,
      "kev": {
        "added": "2024-12-10",
        "due": "2024-12-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-122"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-51378",
      "url": "https://spydr.io/cve/CVE-2024-51378",
      "published": "2024-10-29T23:15:04.083Z",
      "modified": "2026-08-05T05:16:41.870Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94748,
      "epss_percentile": 0.99858,
      "exploited": true,
      "kev": {
        "added": "2024-12-04",
        "due": "2024-12-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cyberpanel"
      ],
      "products": [
        "cyberpanel"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected."
    },
    {
      "id": "CVE-2024-11667",
      "url": "https://spydr.io/cve/CVE-2024-11667",
      "published": "2024-11-27T10:15:04.210Z",
      "modified": "2026-08-05T05:16:40.797Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02929,
      "epss_percentile": 0.86641,
      "exploited": true,
      "kev": {
        "added": "2024-12-03",
        "due": "2024-12-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ATP series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel USG FLEX 50(W) series firmware",
        "Zyxel USG20(W)-VPN series firmware",
        "zyxel usg_flex_firmware",
        "zyxel atp_firmware",
        "zyxel usg20-vpn_firmware",
        "zyxel usg_flex_50w_firmware"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL."
    },
    {
      "id": "CVE-2024-11680",
      "url": "https://spydr.io/cve/CVE-2024-11680",
      "published": "2024-11-26T10:15:04.540Z",
      "modified": "2026-07-14T23:17:13.570Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91697,
      "epss_percentile": 0.99814,
      "exploited": true,
      "kev": {
        "added": "2024-12-03",
        "due": "2024-12-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ProjectSend"
      ],
      "products": [
        "ProjectSend"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript."
    },
    {
      "id": "CVE-2023-45727",
      "url": "https://spydr.io/cve/CVE-2023-45727",
      "published": "2023-10-18T10:15:08.643Z",
      "modified": "2026-06-17T06:29:25.203Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.03542,
      "epss_percentile": 0.88943,
      "exploited": true,
      "kev": {
        "added": "2024-12-03",
        "due": "2024-12-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "North Grid Corporation",
        "northgrid"
      ],
      "products": [
        "North Grid Corporation Proself Enterprise/Standard Edition",
        "North Grid Corporation Proself Gateway Edition",
        "North Grid Corporation Proself Mail Sanitize Edition",
        "northgrid proself"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker."
    },
    {
      "id": "CVE-2023-28461",
      "url": "https://spydr.io/cve/CVE-2023-28461",
      "published": "2023-03-15T23:15:10.070Z",
      "modified": "2026-08-05T05:16:37.477Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.68079,
      "epss_percentile": 0.9931,
      "exploited": true,
      "kev": {
        "added": "2024-11-25",
        "due": "2024-12-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arraynetworks"
      ],
      "products": [
        "arraynetworks arrayos_ag"
      ],
      "cwes": [
        "CWE-287",
        "CWE-306"
      ],
      "description": "Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated \"a new Array AG release with the fix will be available soon.\""
    },
    {
      "id": "CVE-2024-44309",
      "url": "https://spydr.io/cve/CVE-2024-44309",
      "published": "2024-11-20T00:15:17.137Z",
      "modified": "2026-06-17T07:52:45.903Z",
      "score": 6.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
      "score_source": "NVD",
      "epss": 0.2259,
      "epss_percentile": 0.97662,
      "exploited": true,
      "kev": {
        "added": "2024-11-21",
        "due": "2024-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple visionOS",
        "apple iphone_os",
        "apple ipad_os"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems."
    },
    {
      "id": "CVE-2024-44308",
      "url": "https://spydr.io/cve/CVE-2024-44308",
      "published": "2024-11-20T00:15:17.080Z",
      "modified": "2026-06-17T07:52:45.440Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10075,
      "epss_percentile": 0.95514,
      "exploited": true,
      "kev": {
        "added": "2024-11-21",
        "due": "2024-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple visionOS",
        "apple iphone_os",
        "apple ipad_os"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems."
    },
    {
      "id": "CVE-2024-21287",
      "url": "https://spydr.io/cve/CVE-2024-21287",
      "published": "2024-11-18T22:15:05.897Z",
      "modified": "2026-06-17T07:08:56.087Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "oracle.com",
      "epss": 0.01723,
      "epss_percentile": 0.76751,
      "exploited": true,
      "kev": {
        "added": "2024-11-21",
        "due": "2024-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Oracle Agile PLM Framework"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."
    },
    {
      "id": "CVE-2024-38813",
      "url": "https://spydr.io/cve/CVE-2024-38813",
      "published": "2024-09-17T18:15:04.127Z",
      "modified": "2026-06-17T07:41:05.720Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.17355,
      "epss_percentile": 0.97041,
      "exploited": true,
      "kev": {
        "added": "2024-11-20",
        "due": "2024-12-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "broadcom"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation",
        "broadcom vmware_center_server",
        "broadcom vmware_cloud_foundation"
      ],
      "cwes": [
        "CWE-250",
        "CWE-273"
      ],
      "description": "The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet."
    },
    {
      "id": "CVE-2024-38812",
      "url": "https://spydr.io/cve/CVE-2024-38812",
      "published": "2024-09-17T18:15:03.920Z",
      "modified": "2026-06-17T07:41:05.577Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.54571,
      "epss_percentile": 0.98993,
      "exploited": true,
      "kev": {
        "added": "2024-11-20",
        "due": "2024-12-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "broadcom"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation",
        "broadcom vmware_vcenter_server",
        "broadcom vmware_cloud_foundation"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution."
    },
    {
      "id": "CVE-2024-9474",
      "url": "https://spydr.io/cve/CVE-2024-9474",
      "published": "2024-11-18T16:15:29.780Z",
      "modified": "2026-08-04T05:16:32.247Z",
      "score": 6.9,
      "severity": "medium",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.94824,
      "epss_percentile": 0.99859,
      "exploited": true,
      "kev": {
        "added": "2024-11-18",
        "due": "2024-12-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, the management interfaces for affected devices should not be exposed to untrusted networks, including the internet.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2024-0012",
      "url": "https://spydr.io/cve/CVE-2024-0012",
      "published": "2024-11-18T16:15:11.683Z",
      "modified": "2026-08-04T05:16:29.473Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.99855,
      "epss_percentile": 0.99961,
      "exploited": true,
      "kev": {
        "added": "2024-11-18",
        "due": "2024-12-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Additionally, management interface for affected devices should not be exposed to untrusted networks, including the internet.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474 https://security.paloaltonetworks.com/CVE-2024-9474 . The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2024-1212",
      "url": "https://spydr.io/cve/CVE-2024-1212",
      "published": "2024-02-21T18:15:50.417Z",
      "modified": "2026-07-13T19:49:31.120Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95388,
      "epss_percentile": 0.99868,
      "exploited": true,
      "kev": {
        "added": "2024-11-18",
        "due": "2024-12-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software",
        "kemptechnologies"
      ],
      "products": [
        "Progress Software LoadMaster",
        "kemptechnologies loadmaster"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
