{
  "query": {
    "kev": "1",
    "page": "30"
  },
  "count": 20,
  "total": 1734,
  "page": 30,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T08:47:26.795Z",
    "kev": "2026-10-07T09:46:28.973Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T09:47:28.904Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=30",
    "next": "https://spydr.io/threats.json?kev=1&page=31"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-33045",
      "url": "https://spydr.io/cve/CVE-2021-33045",
      "published": "2021-09-15T22:15:10.687Z",
      "modified": "2026-06-17T03:54:04.020Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99593,
      "epss_percentile": 0.99947,
      "exploited": true,
      "kev": {
        "added": "2024-08-21",
        "due": "2024-09-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dahuasecurity"
      ],
      "products": [
        "Some Dahua IP Camera, Video Intercom, NVR, XVR devices"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets."
    },
    {
      "id": "CVE-2021-33044",
      "url": "https://spydr.io/cve/CVE-2021-33044",
      "published": "2021-09-15T22:15:10.497Z",
      "modified": "2026-06-17T03:54:03.827Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99987,
      "epss_percentile": 0.99984,
      "exploited": true,
      "kev": {
        "added": "2024-08-21",
        "due": "2024-09-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dahuasecurity"
      ],
      "products": [
        "Some Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devices"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets."
    },
    {
      "id": "CVE-2021-31196",
      "url": "https://spydr.io/cve/CVE-2021-31196",
      "published": "2021-07-14T18:15:09.463Z",
      "modified": "2026-08-10T19:58:38.973Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.54056,
      "epss_percentile": 0.9898,
      "exploited": true,
      "kev": {
        "added": "2024-08-21",
        "due": "2024-09-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 20",
        "Microsoft Exchange Server 2016 Cumulative Update 21",
        "Microsoft Exchange Server 2019 Cumulative Update 10",
        "Microsoft Exchange Server 2019 Cumulative Update 9"
      ],
      "cwes": [],
      "description": "Microsoft Exchange Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-23897",
      "url": "https://spydr.io/cve/CVE-2024-23897",
      "published": "2024-01-24T18:15:09.370Z",
      "modified": "2026-06-17T07:13:49.330Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99995,
      "exploited": true,
      "kev": {
        "added": "2024-08-19",
        "due": "2024-09-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Jenkins Project",
        "jenkins"
      ],
      "products": [
        "Jenkins Project Jenkins",
        "jenkins"
      ],
      "cwes": [
        "CWE-22",
        "CWE-27"
      ],
      "description": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system."
    },
    {
      "id": "CVE-2024-28986",
      "url": "https://spydr.io/cve/CVE-2024-28986",
      "published": "2024-08-13T23:15:16.627Z",
      "modified": "2026-06-17T07:22:12.443Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "solarwinds.com",
      "epss": 0.84628,
      "epss_percentile": 0.997,
      "exploited": true,
      "kev": {
        "added": "2024-08-15",
        "due": "2024-09-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Web Help Desk"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing. However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available."
    },
    {
      "id": "CVE-2024-38213",
      "url": "https://spydr.io/cve/CVE-2024-38213",
      "published": "2024-08-13T18:15:30.750Z",
      "modified": "2026-06-17T07:39:41.937Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "microsoft.com",
      "epss": 0.13626,
      "epss_percentile": 0.96379,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-38193",
      "url": "https://spydr.io/cve/CVE-2024-38193",
      "published": "2024-08-13T18:15:28.230Z",
      "modified": "2026-06-17T07:39:39.247Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.28739,
      "epss_percentile": 0.98097,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-38189",
      "url": "https://spydr.io/cve/CVE-2024-38189",
      "published": "2024-08-13T18:15:27.733Z",
      "modified": "2026-06-17T07:39:38.820Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.08194,
      "epss_percentile": 0.94727,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office 2019",
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Project 2016",
        "Microsoft Office LTSC 2021"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Microsoft Project Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2024-38178",
      "url": "https://spydr.io/cve/CVE-2024-38178",
      "published": "2024-08-13T18:15:26.220Z",
      "modified": "2026-06-17T07:39:37.397Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.4138,
      "epss_percentile": 0.98639,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Scripting Engine Memory Corruption Vulnerability"
    },
    {
      "id": "CVE-2024-38107",
      "url": "https://spydr.io/cve/CVE-2024-38107",
      "published": "2024-08-13T18:15:10.963Z",
      "modified": "2026-06-17T07:39:26.377Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01635,
      "epss_percentile": 0.75515,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows 11 Version 24H2"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Power Dependency Coordinator Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-38106",
      "url": "https://spydr.io/cve/CVE-2024-38106",
      "published": "2024-08-13T18:15:10.713Z",
      "modified": "2026-06-17T07:39:26.217Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.06337,
      "epss_percentile": 0.93444,
      "exploited": true,
      "kev": {
        "added": "2024-08-13",
        "due": "2024-09-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 11 Version 24H2"
      ],
      "cwes": [
        "CWE-591"
      ],
      "description": "Windows Kernel Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-36971",
      "url": "https://spydr.io/cve/CVE-2024-36971",
      "published": "2024-06-10T09:15:09.127Z",
      "modified": "2026-06-17T07:37:30.630Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02701,
      "epss_percentile": 0.85463,
      "exploited": true,
      "kev": {
        "added": "2024-08-07",
        "due": "2024-08-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux",
        "linux_kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear sk->sk_dst_cache, then call dst_release(old_dst). Note that sk_dst_reset(sk) is implementing this protocol correctly, while __dst_negative_advice() uses the wrong order. Given that ip6_negative_advice() has special logic against RTF_CACHE, this means each of the three ->negative_advice() existing methods must perform the sk_dst_reset() themselves. Note the check against NULL dst is centralized in __dst_negative_advice(), there is no need to duplicate it in various callbacks. Many thanks to Clement Lecigne for tracking this issue. This old bug became visible after the blamed commit, using UDP sockets."
    },
    {
      "id": "CVE-2024-32113",
      "url": "https://spydr.io/cve/CVE-2024-32113",
      "published": "2024-05-08T15:15:10.227Z",
      "modified": "2026-06-17T07:29:18.240Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99919,
      "epss_percentile": 0.99968,
      "exploited": true,
      "kev": {
        "added": "2024-08-07",
        "due": "2024-08-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache OFBiz",
        "apache ofbiz"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue."
    },
    {
      "id": "CVE-2018-0824",
      "url": "https://spydr.io/cve/CVE-2018-0824",
      "published": "2018-05-09T19:29:00.370Z",
      "modified": "2026-06-17T01:31:44.387Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73185,
      "epss_percentile": 0.99447,
      "exploited": true,
      "kev": {
        "added": "2024-08-05",
        "due": "2024-08-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows_10",
        "microsoft windows_7",
        "microsoft windows_8.1",
        "microsoft windows_rt_8.1",
        "microsoft windows_server_2008",
        "microsoft windows_server_2012",
        "microsoft windows_server_2016"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A remote code execution vulnerability exists in \"Microsoft COM for Windows\" when it fails to properly handle serialized objects, aka \"Microsoft COM for Windows Remote Code Execution Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2024-37085",
      "url": "https://spydr.io/cve/CVE-2024-37085",
      "published": "2024-06-25T15:15:12.377Z",
      "modified": "2026-06-17T07:37:43.940Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.2677,
      "epss_percentile": 0.97981,
      "exploited": true,
      "kev": {
        "added": "2024-07-30",
        "due": "2024-08-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware ESXi",
        "VMware Cloud Foundation"
      ],
      "cwes": [
        "CWE-287",
        "CWE-305"
      ],
      "description": "VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD."
    },
    {
      "id": "CVE-2023-45249",
      "url": "https://spydr.io/cve/CVE-2023-45249",
      "published": "2024-07-24T14:15:04.867Z",
      "modified": "2026-06-17T06:28:32.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.53255,
      "epss_percentile": 0.98957,
      "exploited": true,
      "kev": {
        "added": "2024-07-29",
        "due": "2024-08-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Acronis"
      ],
      "products": [
        "Acronis Cyber Infrastructure"
      ],
      "cwes": [
        "CWE-1393"
      ],
      "description": "Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132."
    },
    {
      "id": "CVE-2024-5217",
      "url": "https://spydr.io/cve/CVE-2024-5217",
      "published": "2024-07-10T17:15:12.373Z",
      "modified": "2026-06-17T08:15:25.880Z",
      "score": 9.2,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "servicenow.com",
      "epss": 0.99628,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2024-07-29",
        "due": "2024-08-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ServiceNow"
      ],
      "products": [
        "ServiceNow Now Platform",
        "servicenow"
      ],
      "cwes": [
        "CWE-184",
        "CWE-697"
      ],
      "description": "ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible."
    },
    {
      "id": "CVE-2024-4879",
      "url": "https://spydr.io/cve/CVE-2024-4879",
      "published": "2024-07-10T17:15:12.117Z",
      "modified": "2026-06-17T08:03:05.523Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "servicenow.com",
      "epss": 0.99976,
      "epss_percentile": 0.99979,
      "exploited": true,
      "kev": {
        "added": "2024-07-29",
        "due": "2024-08-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ServiceNow"
      ],
      "products": [
        "ServiceNow Now Platform",
        "servicenow"
      ],
      "cwes": [
        "CWE-1287"
      ],
      "description": "ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible."
    },
    {
      "id": "CVE-2024-39891",
      "url": "https://spydr.io/cve/CVE-2024-39891",
      "published": "2024-07-02T18:15:03.447Z",
      "modified": "2026-06-17T07:42:58.630Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01669,
      "epss_percentile": 0.76009,
      "exploited": true,
      "kev": {
        "added": "2024-07-23",
        "due": "2024-08-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "twilio"
      ],
      "products": [
        "twilio authy_2-factor_authentication"
      ],
      "cwes": [
        "CWE-203"
      ],
      "description": "In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)"
    },
    {
      "id": "CVE-2012-4792",
      "url": "https://spydr.io/cve/CVE-2012-4792",
      "published": "2012-12-30T18:55:01.477Z",
      "modified": "2026-06-16T23:45:43.277Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.78823,
      "epss_percentile": 0.99585,
      "exploited": true,
      "kev": {
        "added": "2024-07-23",
        "due": "2024-08-13",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft ie"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
