{
  "query": {
    "kev": "1",
    "page": "27"
  },
  "count": 20,
  "total": 1734,
  "page": 27,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T06:47:22.780Z",
    "kev": "2026-10-07T06:46:22.231Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T06:47:22.780Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=27",
    "next": "https://spydr.io/threats.json?kev=1&page=28"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-9465",
      "url": "https://spydr.io/cve/CVE-2024-9465",
      "published": "2024-10-09T17:15:20.287Z",
      "modified": "2026-06-17T08:24:37.313Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber",
      "score_source": "paloaltonetworks.com",
      "epss": 0.99626,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2024-11-14",
        "due": "2024-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Expedition"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system."
    },
    {
      "id": "CVE-2024-9463",
      "url": "https://spydr.io/cve/CVE-2024-9463",
      "published": "2024-10-09T17:15:19.973Z",
      "modified": "2026-06-17T08:24:37.050Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber",
      "score_source": "paloaltonetworks.com",
      "epss": 0.98546,
      "epss_percentile": 0.99921,
      "exploited": true,
      "kev": {
        "added": "2024-11-14",
        "due": "2024-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Expedition"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls."
    },
    {
      "id": "CVE-2024-49039",
      "url": "https://spydr.io/cve/CVE-2024-49039",
      "published": "2024-11-12T18:15:44.160Z",
      "modified": "2026-08-04T05:16:30.980Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.14179,
      "epss_percentile": 0.9649,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Windows Task Scheduler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-43451",
      "url": "https://spydr.io/cve/CVE-2024-43451",
      "published": "2024-11-12T18:15:22.483Z",
      "modified": "2026-06-17T07:51:04.273Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.84108,
      "epss_percentile": 0.99689,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-73"
      ],
      "description": "NTLM Hash Disclosure Spoofing Vulnerability"
    },
    {
      "id": "CVE-2021-41277",
      "url": "https://spydr.io/cve/CVE-2021-41277",
      "published": "2021-11-17T20:15:10.587Z",
      "modified": "2026-06-17T04:08:13.543Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.97178,
      "epss_percentile": 0.99895,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "metabase"
      ],
      "products": [
        "metabase"
      ],
      "cwes": [
        "CWE-200",
        "CWE-22"
      ],
      "description": "Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application."
    },
    {
      "id": "CVE-2021-26086",
      "url": "https://spydr.io/cve/CVE-2021-26086",
      "published": "2021-08-16T01:15:06.353Z",
      "modified": "2026-06-17T03:42:50.110Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99992,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Jira Server",
        "Atlassian Jira Data Center"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1."
    },
    {
      "id": "CVE-2014-2120",
      "url": "https://spydr.io/cve/CVE-2014-2120",
      "published": "2014-03-19T01:15:04.007Z",
      "modified": "2026-06-17T00:06:05.827Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.22558,
      "epss_percentile": 0.97658,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco adaptive_security_appliance_software"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025."
    },
    {
      "id": "CVE-2024-43093",
      "url": "https://spydr.io/cve/CVE-2024-43093",
      "published": "2024-11-13T18:15:21.713Z",
      "modified": "2026-06-17T07:50:25.587Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00709,
      "epss_percentile": 0.5196,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-176"
      ],
      "description": "In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation."
    },
    {
      "id": "CVE-2024-51567",
      "url": "https://spydr.io/cve/CVE-2024-51567",
      "published": "2024-10-29T23:15:04.307Z",
      "modified": "2026-08-04T05:16:31.190Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86633,
      "epss_percentile": 0.99737,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cyberpanel"
      ],
      "products": [
        "cyberpanel"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected."
    },
    {
      "id": "CVE-2024-5910",
      "url": "https://spydr.io/cve/CVE-2024-5910",
      "published": "2024-07-10T19:15:11.390Z",
      "modified": "2026-06-17T08:16:53.600Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.91684,
      "epss_percentile": 0.99814,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Expedition"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue."
    },
    {
      "id": "CVE-2019-16278",
      "url": "https://spydr.io/cve/CVE-2019-16278",
      "published": "2019-10-14T17:15:09.427Z",
      "modified": "2026-06-17T02:22:03.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99033,
      "epss_percentile": 0.99931,
      "exploited": true,
      "kev": {
        "added": "2024-11-07",
        "due": "2024-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nazgul"
      ],
      "products": [
        "nazgul nostromo_nhttpd"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request."
    },
    {
      "id": "CVE-2024-8957",
      "url": "https://spydr.io/cve/CVE-2024-8957",
      "published": "2024-09-17T21:15:13.423Z",
      "modified": "2026-06-17T08:23:37.947Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.79703,
      "epss_percentile": 0.996,
      "exploited": true,
      "kev": {
        "added": "2024-11-04",
        "due": "2024-11-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PTZOptics"
      ],
      "products": [
        "PTZOptics PT30X-SDI",
        "PTZOptics PT30X-NDI",
        "ptzoptics pt30x-sdi_firmware",
        "ptzoptics pt30x-ndi_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may lead to arbitrary command execution when ntp_client is started. When chained with CVE-2024-8956, a remote and unauthenticated attacker can execute arbitrary OS commands on affected devices."
    },
    {
      "id": "CVE-2024-8956",
      "url": "https://spydr.io/cve/CVE-2024-8956",
      "published": "2024-09-17T20:15:07.287Z",
      "modified": "2026-06-17T08:23:37.827Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.58787,
      "epss_percentile": 0.99085,
      "exploited": true,
      "kev": {
        "added": "2024-11-04",
        "due": "2024-11-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PTZOptics"
      ],
      "products": [
        "PTZOptics PT30X-SDI",
        "PTZOptics PT30X-NDI",
        "ptzoptics pt30x-sdi_firmware",
        "ptzoptics pt30x-ndi-xx-g2_firmware"
      ],
      "cwes": [
        "CWE-306",
        "CWE-287"
      ],
      "description": "PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header. The result is a remote and unauthenticated attacker can leak sensitive data such as usernames, password hashes, and configurations details. Additionally, the attacker can update individual configuration values or overwrite the whole file."
    },
    {
      "id": "CVE-2024-20481",
      "url": "https://spydr.io/cve/CVE-2024-20481",
      "published": "2024-10-23T18:15:11.737Z",
      "modified": "2026-08-11T19:40:47.230Z",
      "score": 5.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
      "score_source": "NVD",
      "epss": 0.15874,
      "epss_percentile": 0.96801,
      "exploited": true,
      "kev": {
        "added": "2024-10-24",
        "due": "2024-11-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Adaptive Security Appliance (ASA) Software",
        "Cisco Firepower Threat Defense Software",
        "cisco adaptive_security_appliance_software"
      ],
      "cwes": [
        "CWE-772"
      ],
      "description": "A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This vulnerability is due to resource exhaustion. An attacker could exploit this vulnerability by sending a large number of VPN authentication requests to an affected device. A successful exploit could allow the attacker to exhaust resources, resulting in a DoS of the RAVPN service on the affected device. Depending on the impact of the attack, a reload of the device may be required to restore the RAVPN service. Services that are not related to VPN are not affected. Cisco Talos discussed these attacks in the blog post Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials."
    },
    {
      "id": "CVE-2024-37383",
      "url": "https://spydr.io/cve/CVE-2024-37383",
      "published": "2024-06-07T04:15:30.463Z",
      "modified": "2026-06-17T07:38:15.543Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.73296,
      "epss_percentile": 0.9945,
      "exploited": true,
      "kev": {
        "added": "2024-10-24",
        "due": "2024-11-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube"
      ],
      "products": [
        "roundcube webmail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes."
    },
    {
      "id": "CVE-2024-47575",
      "url": "https://spydr.io/cve/CVE-2024-47575",
      "published": "2024-10-23T15:15:30.707Z",
      "modified": "2026-06-17T07:57:20.260Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94766,
      "epss_percentile": 0.99858,
      "exploited": true,
      "kev": {
        "added": "2024-10-23",
        "due": "2024-11-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiManager"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests."
    },
    {
      "id": "CVE-2024-38094",
      "url": "https://spydr.io/cve/CVE-2024-38094",
      "published": "2024-07-09T17:15:46.090Z",
      "modified": "2026-06-17T07:39:24.640Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.50892,
      "epss_percentile": 0.98901,
      "exploited": true,
      "kev": {
        "added": "2024-10-22",
        "due": "2024-11-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Microsoft SharePoint Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-9537",
      "url": "https://spydr.io/cve/CVE-2024-9537",
      "published": "2024-10-18T15:15:04.170Z",
      "modified": "2026-06-17T08:24:46.673Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
      "score_source": "CNA",
      "epss": 0.03826,
      "epss_percentile": 0.89783,
      "exploited": true,
      "kev": {
        "added": "2024-10-21",
        "due": "2024-11-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ScienceLogic"
      ],
      "products": [
        "ScienceLogic SL1"
      ],
      "cwes": [],
      "description": "ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x."
    },
    {
      "id": "CVE-2024-40711",
      "url": "https://spydr.io/cve/CVE-2024-40711",
      "published": "2024-09-07T17:15:13.260Z",
      "modified": "2026-06-17T07:46:23.383Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90369,
      "epss_percentile": 0.99798,
      "exploited": true,
      "kev": {
        "added": "2024-10-17",
        "due": "2024-11-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Veeam"
      ],
      "products": [
        "Veeam Backup and Recovery",
        "veeam backup_\\&_replication"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE)."
    },
    {
      "id": "CVE-2024-9680",
      "url": "https://spydr.io/cve/CVE-2024-9680",
      "published": "2024-10-09T13:15:12.090Z",
      "modified": "2026-08-04T05:16:32.530Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23184,
      "epss_percentile": 0.97715,
      "exploited": true,
      "kev": {
        "added": "2024-10-15",
        "due": "2024-11-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
