{
  "query": {
    "kev": "1",
    "page": "31"
  },
  "count": 20,
  "total": 1734,
  "page": 31,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T08:47:26.795Z",
    "kev": "2026-10-07T09:46:28.973Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T09:47:28.904Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=31",
    "next": "https://spydr.io/threats.json?kev=1&page=32"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-34102",
      "url": "https://spydr.io/cve/CVE-2024-34102",
      "published": "2024-06-13T09:15:10.380Z",
      "modified": "2026-06-17T07:32:54.930Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.99994,
      "epss_percentile": 0.99988,
      "exploited": true,
      "kev": {
        "added": "2024-07-17",
        "due": "2024-08-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Commerce"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2024-28995",
      "url": "https://spydr.io/cve/CVE-2024-28995",
      "published": "2024-06-06T09:15:14.167Z",
      "modified": "2026-06-17T07:22:13.360Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99614,
      "epss_percentile": 0.99948,
      "exploited": true,
      "kev": {
        "added": "2024-07-17",
        "due": "2024-08-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Serv-U"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine."
    },
    {
      "id": "CVE-2022-22948",
      "url": "https://spydr.io/cve/CVE-2022-22948",
      "published": "2022-03-29T18:15:08.040Z",
      "modified": "2026-06-17T04:29:13.573Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.13282,
      "epss_percentile": 0.96292,
      "exploited": true,
      "kev": {
        "added": "2024-07-17",
        "due": "2024-08-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server and VMware Cloud Foundation",
        "vmware cloud_foundation",
        "vmware vcenter_server"
      ],
      "cwes": [
        "CWE-276"
      ],
      "description": "The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information."
    },
    {
      "id": "CVE-2024-36401",
      "url": "https://spydr.io/cve/CVE-2024-36401",
      "published": "2024-07-01T16:15:04.120Z",
      "modified": "2026-06-17T07:36:38.833Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99813,
      "epss_percentile": 0.99958,
      "exploited": true,
      "kev": {
        "added": "2024-07-15",
        "due": "2024-08-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "geoserver"
      ],
      "products": [
        "geoserver"
      ],
      "cwes": [
        "CWE-95",
        "CWE-94"
      ],
      "description": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a default GeoServer installation due to unsafely evaluating property names as XPath expressions. The GeoTools library API that GeoServer calls evaluates property/attribute names for feature types in a way that unsafely passes them to the commons-jxpath library which can execute arbitrary code when evaluating XPath expressions. This XPath evaluation is intended to be used only by complex feature types (i.e., Application Schema data stores) but is incorrectly being applied to simple feature types as well which makes this vulnerability apply to **ALL** GeoServer instances. No public PoC is provided but this vulnerability has been confirmed to be exploitable through WFS GetFeature, WFS GetPropertyValue, WMS GetMap, WMS GetFeatureInfo, WMS GetLegendGraphic and WPS Execute requests. This vulnerability can lead to executing arbitrary code. Versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2 contain a patch for the issue. A workaround exists by removing the `gt-complex-x.y.jar` file from the GeoServer where `x.y` is the GeoTools version (e.g., `gt-complex-31.1.jar` if running GeoServer 2.25.1). This will remove the vulnerable code from GeoServer but may break some GeoServer functionality or prevent GeoServer from deploying if the gt-complex module is needed."
    },
    {
      "id": "CVE-2024-38112",
      "url": "https://spydr.io/cve/CVE-2024-38112",
      "published": "2024-07-09T17:15:47.860Z",
      "modified": "2026-06-17T07:39:26.777Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.84225,
      "epss_percentile": 0.99693,
      "exploited": true,
      "kev": {
        "added": "2024-07-09",
        "due": "2024-07-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows Server 2019"
      ],
      "cwes": [
        "CWE-451"
      ],
      "description": "Windows MSHTML Platform Spoofing Vulnerability"
    },
    {
      "id": "CVE-2024-38080",
      "url": "https://spydr.io/cve/CVE-2024-38080",
      "published": "2024-07-09T17:15:43.410Z",
      "modified": "2026-06-17T07:39:22.737Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.07115,
      "epss_percentile": 0.94077,
      "exploited": true,
      "kev": {
        "added": "2024-07-09",
        "due": "2024-07-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Windows Hyper-V Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-23692",
      "url": "https://spydr.io/cve/CVE-2024-23692",
      "published": "2024-05-31T10:15:09.330Z",
      "modified": "2026-08-11T04:17:15.300Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99485,
      "epss_percentile": 0.99944,
      "exploited": true,
      "kev": {
        "added": "2024-07-09",
        "due": "2024-07-30",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Rejetto"
      ],
      "products": [
        "Rejetto HTTP File Server"
      ],
      "cwes": [
        "CWE-1336",
        "CWE-94"
      ],
      "description": "Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported."
    },
    {
      "id": "CVE-2024-20399",
      "url": "https://spydr.io/cve/CVE-2024-20399",
      "published": "2024-07-01T17:15:04.383Z",
      "modified": "2026-06-17T07:06:56.067Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04306,
      "epss_percentile": 0.90872,
      "exploited": true,
      "kev": {
        "added": "2024-07-02",
        "due": "2024-07-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco NX-OS Software",
        "cisco nx-os"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root. Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials. The following Cisco devices already allow administrative users to access the underlying operating system through the bash-shell feature, so, for these devices, this vulnerability does not grant any additional privileges: Nexus 3000 Series Switches Nexus 7000 Series Switches that are running Cisco NX-OS Software releases 8.1(1) and later Nexus 9000 Series Switches in standalone NX-OS mode"
    },
    {
      "id": "CVE-2022-2586",
      "url": "https://spydr.io/cve/CVE-2022-2586",
      "published": "2024-01-08T18:15:44.620Z",
      "modified": "2026-08-20T14:17:08.057Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10202,
      "epss_percentile": 0.95552,
      "exploited": true,
      "kev": {
        "added": "2024-06-26",
        "due": "2024-07-17",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "The Linux Kernel Organization",
        "linux"
      ],
      "products": [
        "The Linux Kernel Organization linux",
        "linux_kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted."
    },
    {
      "id": "CVE-2022-24816",
      "url": "https://spydr.io/cve/CVE-2022-24816",
      "published": "2022-04-13T21:15:07.683Z",
      "modified": "2026-06-17T04:32:35.060Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99911,
      "epss_percentile": 0.99967,
      "exploited": true,
      "kev": {
        "added": "2024-06-26",
        "due": "2024-07-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "geosolutions-it",
        "geosolutionsgroup"
      ],
      "products": [
        "geosolutions-it jai-ext",
        "geosolutionsgroup jai-ext"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath."
    },
    {
      "id": "CVE-2020-13965",
      "url": "https://spydr.io/cve/CVE-2020-13965",
      "published": "2020-06-09T03:15:11.250Z",
      "modified": "2026-06-17T02:54:01.497Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.76596,
      "epss_percentile": 0.99531,
      "exploited": true,
      "kev": {
        "added": "2024-06-26",
        "due": "2024-07-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube"
      ],
      "products": [
        "roundcube webmail"
      ],
      "cwes": [
        "CWE-79",
        "CWE-80"
      ],
      "description": "An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview."
    },
    {
      "id": "CVE-2024-32896",
      "url": "https://spydr.io/cve/CVE-2024-32896",
      "published": "2024-06-13T21:15:54.080Z",
      "modified": "2026-06-17T07:30:38.333Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02985,
      "epss_percentile": 0.86876,
      "exploited": true,
      "kev": {
        "added": "2024-06-13",
        "due": "2024-07-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-670",
        "CWE-783"
      ],
      "description": "there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation."
    },
    {
      "id": "CVE-2024-4358",
      "url": "https://spydr.io/cve/CVE-2024-4358",
      "published": "2024-05-29T15:16:06.477Z",
      "modified": "2026-06-17T08:01:44.540Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97482,
      "epss_percentile": 0.999,
      "exploited": true,
      "kev": {
        "added": "2024-06-13",
        "due": "2024-07-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software Corporation",
        "progress_software"
      ],
      "products": [
        "Progress Software Corporation Telerik Report Server",
        "progress_software telerik_report_server"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability."
    },
    {
      "id": "CVE-2024-26169",
      "url": "https://spydr.io/cve/CVE-2024-26169",
      "published": "2024-03-12T17:15:56.173Z",
      "modified": "2026-06-17T07:17:15.207Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04014,
      "epss_percentile": 0.9028,
      "exploited": true,
      "kev": {
        "added": "2024-06-13",
        "due": "2024-07-04",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Windows Error Reporting Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-4577",
      "url": "https://spydr.io/cve/CVE-2024-4577",
      "published": "2024-06-09T20:15:09.550Z",
      "modified": "2026-06-17T08:02:11.493Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99987,
      "epss_percentile": 0.99984,
      "exploited": true,
      "kev": {
        "added": "2024-06-12",
        "due": "2024-07-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PHP Group"
      ],
      "products": [
        "PHP Group PHP"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use \"Best-Fit\" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc."
    },
    {
      "id": "CVE-2024-4610",
      "url": "https://spydr.io/cve/CVE-2024-4610",
      "published": "2024-06-07T12:15:09.077Z",
      "modified": "2026-06-17T08:02:15.760Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00764,
      "epss_percentile": 0.53943,
      "exploited": true,
      "kev": {
        "added": "2024-06-12",
        "due": "2024-07-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Arm Ltd",
        "arm"
      ],
      "products": [
        "Arm Ltd Bifrost GPU Kernel Driver",
        "Arm Ltd Valhall GPU Kernel Driver",
        "arm bifrost_gpu_kernel_driver",
        "arm valhall_gpu_kernel_driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0."
    },
    {
      "id": "CVE-2017-3506",
      "url": "https://spydr.io/cve/CVE-2017-3506",
      "published": "2017-04-24T19:59:03.037Z",
      "modified": "2026-06-17T01:18:26.670Z",
      "score": 7.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.96281,
      "epss_percentile": 0.99879,
      "exploited": true,
      "kev": {
        "added": "2024-06-03",
        "due": "2024-06-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation WebLogic Server",
        "oracle weblogic_server"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)."
    },
    {
      "id": "CVE-2024-24919",
      "url": "https://spydr.io/cve/CVE-2024-24919",
      "published": "2024-05-28T19:15:10.060Z",
      "modified": "2026-08-05T05:16:41.323Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99978,
      "epss_percentile": 0.9998,
      "exploited": true,
      "kev": {
        "added": "2024-05-30",
        "due": "2024-06-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "checkpoint"
      ],
      "products": [
        "checkpoint Check Point Quantum Gateway, Spark Gateway and CloudGuard Network",
        "checkpoint quantum_security_gateway_firmware",
        "checkpoint cloudguard_network",
        "checkpoint quantum_spark_appliances"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available."
    },
    {
      "id": "CVE-2024-1086",
      "url": "https://spydr.io/cve/CVE-2024-1086",
      "published": "2024-01-31T13:15:10.827Z",
      "modified": "2026-08-07T19:59:58.823Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28058,
      "epss_percentile": 0.98062,
      "exploited": true,
      "kev": {
        "added": "2024-05-30",
        "due": "2024-06-20",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux Kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660."
    },
    {
      "id": "CVE-2024-4978",
      "url": "https://spydr.io/cve/CVE-2024-4978",
      "published": "2024-05-23T02:15:09.257Z",
      "modified": "2026-06-17T08:03:19.347Z",
      "score": 8.7,
      "severity": "high",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.26937,
      "epss_percentile": 0.97991,
      "exploited": true,
      "kev": {
        "added": "2024-05-29",
        "due": "2024-06-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Justice AV Solutions",
        "javs"
      ],
      "products": [
        "Justice AV Solutions Viewer",
        "javs viewer"
      ],
      "cwes": [
        "CWE-506"
      ],
      "description": "Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
