{
  "query": {
    "kev": "1",
    "page": "28"
  },
  "count": 20,
  "total": 1734,
  "page": 28,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T06:47:22.780Z",
    "kev": "2026-10-07T06:46:22.231Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T06:47:22.780Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=28",
    "next": "https://spydr.io/threats.json?kev=1&page=29"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-28987",
      "url": "https://spydr.io/cve/CVE-2024-28987",
      "published": "2024-08-21T22:15:04.350Z",
      "modified": "2026-06-17T07:22:12.560Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.93299,
      "epss_percentile": 0.99836,
      "exploited": true,
      "kev": {
        "added": "2024-10-15",
        "due": "2024-11-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data."
    },
    {
      "id": "CVE-2024-30088",
      "url": "https://spydr.io/cve/CVE-2024-30088",
      "published": "2024-06-11T17:15:56.810Z",
      "modified": "2026-08-04T05:16:30.547Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.68202,
      "epss_percentile": 0.99314,
      "exploited": true,
      "kev": {
        "added": "2024-10-15",
        "due": "2024-11-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "Windows Kernel Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-9380",
      "url": "https://spydr.io/cve/CVE-2024-9380",
      "published": "2024-10-08T17:15:56.970Z",
      "modified": "2026-06-17T08:24:27.317Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.59651,
      "epss_percentile": 0.99107,
      "exploited": true,
      "kev": {
        "added": "2024-10-09",
        "due": "2024-10-30",
        "action": "As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution."
    },
    {
      "id": "CVE-2024-9379",
      "url": "https://spydr.io/cve/CVE-2024-9379",
      "published": "2024-10-08T17:15:56.727Z",
      "modified": "2026-10-01T19:17:15.580Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.43782,
      "epss_percentile": 0.98712,
      "exploited": true,
      "kev": {
        "added": "2024-10-09",
        "due": "2024-10-30",
        "action": "As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements."
    },
    {
      "id": "CVE-2024-23113",
      "url": "https://spydr.io/cve/CVE-2024-23113",
      "published": "2024-02-15T14:15:46.503Z",
      "modified": "2026-06-17T07:12:03.503Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61725,
      "epss_percentile": 0.99152,
      "exploited": true,
      "kev": {
        "added": "2024-10-09",
        "due": "2024-10-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiSwitchManager",
        "Fortinet FortiOS",
        "Fortinet FortiPAM",
        "Fortinet FortiProxy"
      ],
      "cwes": [
        "CWE-134"
      ],
      "description": "A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets."
    },
    {
      "id": "CVE-2024-43573",
      "url": "https://spydr.io/cve/CVE-2024-43573",
      "published": "2024-10-08T18:15:24.817Z",
      "modified": "2026-06-17T07:51:19.627Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.46109,
      "epss_percentile": 0.98779,
      "exploited": true,
      "kev": {
        "added": "2024-10-08",
        "due": "2024-10-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Windows MSHTML Platform Spoofing Vulnerability"
    },
    {
      "id": "CVE-2024-43572",
      "url": "https://spydr.io/cve/CVE-2024-43572",
      "published": "2024-10-08T18:15:24.593Z",
      "modified": "2026-06-17T07:51:19.433Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.66695,
      "epss_percentile": 0.99273,
      "exploited": true,
      "kev": {
        "added": "2024-10-08",
        "due": "2024-10-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-707"
      ],
      "description": "Microsoft Management Console Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-43047",
      "url": "https://spydr.io/cve/CVE-2024-43047",
      "published": "2024-10-07T13:15:15.257Z",
      "modified": "2026-06-17T07:50:18.910Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "qualcomm.com",
      "epss": 0.00674,
      "epss_percentile": 0.50533,
      "exploited": true,
      "kev": {
        "added": "2024-10-08",
        "due": "2024-10-29",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm qam8295p_firmware",
        "qualcomm qca6174a_firmware",
        "qualcomm qca6391_firmware",
        "qualcomm qca6426_firmware",
        "qualcomm qca6436_firmware",
        "qualcomm qca6574au_firmware",
        "qualcomm qca6584au_firmware",
        "qualcomm qca6595_firmware",
        "qualcomm qca6595au_firmware",
        "qualcomm qca6688aq_firmware",
        "qualcomm qca6696_firmware",
        "qualcomm qca6698aq_firmware",
        "qualcomm qcs410_firmware",
        "qualcomm qcs610_firmware",
        "qualcomm qcs6490_firmware"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Memory corruption while maintaining memory maps of HLOS memory."
    },
    {
      "id": "CVE-2024-45519",
      "url": "https://spydr.io/cve/CVE-2024-45519",
      "published": "2024-10-02T22:15:02.770Z",
      "modified": "2026-06-17T07:54:22.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99907,
      "epss_percentile": 0.99966,
      "exploited": true,
      "kev": {
        "added": "2024-10-03",
        "due": "2024-10-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands."
    },
    {
      "id": "CVE-2024-29824",
      "url": "https://spydr.io/cve/CVE-2024-29824",
      "published": "2024-05-31T18:15:11.177Z",
      "modified": "2026-06-17T07:23:11.330Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99938,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2024-10-02",
        "due": "2024-10-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti EPM",
        "ivanti endpoint_manager"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code."
    },
    {
      "id": "CVE-2023-25280",
      "url": "https://spydr.io/cve/CVE-2023-25280",
      "published": "2023-03-16T01:15:46.780Z",
      "modified": "2026-06-17T05:41:01.463Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97864,
      "epss_percentile": 0.99908,
      "exploited": true,
      "kev": {
        "added": "2024-09-30",
        "due": "2024-10-21",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir820la1_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp."
    },
    {
      "id": "CVE-2020-15415",
      "url": "https://spydr.io/cve/CVE-2020-15415",
      "published": "2020-06-30T14:15:11.953Z",
      "modified": "2026-06-17T02:56:38.220Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8448,
      "epss_percentile": 0.99697,
      "exploited": true,
      "kev": {
        "added": "2024-09-30",
        "due": "2024-10-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "draytek"
      ],
      "products": [
        "draytek vigor3900_firmware",
        "draytek vigor2960_firmware",
        "draytek vigor300b_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472."
    },
    {
      "id": "CVE-2019-0344",
      "url": "https://spydr.io/cve/CVE-2019-0344",
      "published": "2019-08-14T14:15:16.463Z",
      "modified": "2026-06-17T02:08:12.500Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07079,
      "epss_percentile": 0.94049,
      "exploited": true,
      "kev": {
        "added": "2024-09-30",
        "due": "2024-10-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP SE",
        "sap"
      ],
      "products": [
        "SAP SE SAP Commerce Cloud (virtualjdbc extension)",
        "sap commerce_cloud"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection."
    },
    {
      "id": "CVE-2024-7593",
      "url": "https://spydr.io/cve/CVE-2024-7593",
      "published": "2024-08-13T19:15:16.940Z",
      "modified": "2026-06-17T08:20:30.860Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99991,
      "exploited": true,
      "kev": {
        "added": "2024-09-24",
        "due": "2024-10-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti vTM",
        "ivanti virtual_traffic_manager"
      ],
      "cwes": [
        "CWE-287",
        "CWE-303"
      ],
      "description": "Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel."
    },
    {
      "id": "CVE-2024-8963",
      "url": "https://spydr.io/cve/CVE-2024-8963",
      "published": "2024-09-19T18:15:10.600Z",
      "modified": "2026-06-17T08:23:38.600Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.98607,
      "epss_percentile": 0.99922,
      "exploited": true,
      "kev": {
        "added": "2024-09-19",
        "due": "2024-10-10",
        "action": "As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti CSA (Cloud Services Appliance)",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality."
    },
    {
      "id": "CVE-2024-27348",
      "url": "https://spydr.io/cve/CVE-2024-27348",
      "published": "2024-04-22T14:15:07.420Z",
      "modified": "2026-06-17T07:19:42.140Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9921,
      "epss_percentile": 0.99935,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache HugeGraph-Server",
        "apache hugegraph-server"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue."
    },
    {
      "id": "CVE-2022-21445",
      "url": "https://spydr.io/cve/CVE-2022-21445",
      "published": "2022-04-19T21:15:15.907Z",
      "modified": "2026-06-17T04:26:16.837Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.62478,
      "epss_percentile": 0.99169,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation Application Development Framework (ADF)",
        "oracle jdeveloper"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2020-14644",
      "url": "https://spydr.io/cve/CVE-2020-14644",
      "published": "2020-07-15T18:15:29.457Z",
      "modified": "2026-06-17T02:55:13.130Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94548,
      "epss_percentile": 0.99853,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation WebLogic Server",
        "oracle weblogic_server"
      ],
      "cwes": [],
      "description": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2020-0618",
      "url": "https://spydr.io/cve/CVE-2020-0618",
      "published": "2020-02-11T22:15:13.400Z",
      "modified": "2026-08-15T04:17:46.010Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99022,
      "epss_percentile": 0.99931,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SQL Server",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)",
        "Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)",
        "Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2014-0502",
      "url": "https://spydr.io/cve/CVE-2014-0502",
      "published": "2014-02-21T05:07:00.017Z",
      "modified": "2026-06-17T00:03:09.860Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24817,
      "epss_percentile": 0.97851,
      "exploited": true,
      "kev": {
        "added": "2024-09-17",
        "due": "2024-10-08",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash_player",
        "adobe air",
        "adobe air_sdk"
      ],
      "cwes": [
        "CWE-415"
      ],
      "description": "Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
