{
  "query": {
    "kev": "1",
    "page": "32"
  },
  "count": 20,
  "total": 1734,
  "page": 32,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T10:47:31.354Z",
    "kev": "2026-10-07T10:46:31.132Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T10:47:31.354Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=32",
    "next": "https://spydr.io/threats.json?kev=1&page=33"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-5274",
      "url": "https://spydr.io/cve/CVE-2024-5274",
      "published": "2024-05-28T15:15:10.443Z",
      "modified": "2026-06-17T08:15:35.493Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07472,
      "epss_percentile": 0.94306,
      "exploited": true,
      "kev": {
        "added": "2024-05-28",
        "due": "2024-06-18",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2020-17519",
      "url": "https://spydr.io/cve/CVE-2020-17519",
      "published": "2021-01-05T12:15:12.680Z",
      "modified": "2026-06-17T02:59:04.010Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.97809,
      "epss_percentile": 0.99906,
      "exploited": true,
      "kev": {
        "added": "2024-05-23",
        "due": "2024-06-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "apache"
      ],
      "products": [
        "Apache Software Foundation Apache Flink",
        "apache flink"
      ],
      "cwes": [
        "CWE-552"
      ],
      "description": "A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master."
    },
    {
      "id": "CVE-2024-4947",
      "url": "https://spydr.io/cve/CVE-2024-4947",
      "published": "2024-05-15T21:15:09.273Z",
      "modified": "2026-06-17T08:03:15.550Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.15236,
      "epss_percentile": 0.96675,
      "exploited": true,
      "kev": {
        "added": "2024-05-20",
        "due": "2024-06-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-43208",
      "url": "https://spydr.io/cve/CVE-2023-43208",
      "published": "2023-10-26T17:15:09.033Z",
      "modified": "2026-06-17T06:25:15.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82708,
      "epss_percentile": 0.99661,
      "exploited": true,
      "kev": {
        "added": "2024-05-20",
        "due": "2024-06-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nextgen"
      ],
      "products": [
        "nextgen mirth connect"
      ],
      "cwes": [
        "CWE-78",
        "CWE-502"
      ],
      "description": "NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679."
    },
    {
      "id": "CVE-2024-4761",
      "url": "https://spydr.io/cve/CVE-2024-4761",
      "published": "2024-05-14T16:17:35.810Z",
      "modified": "2026-06-17T08:02:50.823Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11007,
      "epss_percentile": 0.95792,
      "exploited": true,
      "kev": {
        "added": "2024-05-16",
        "due": "2024-06-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2021-40655",
      "url": "https://spydr.io/cve/CVE-2021-40655",
      "published": "2021-09-24T21:15:07.310Z",
      "modified": "2026-06-17T04:07:13.547Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.86659,
      "epss_percentile": 0.99737,
      "exploited": true,
      "kev": {
        "added": "2024-05-16",
        "due": "2024-06-06",
        "action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-605l_firmware",
        "dlink dir-605l"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page"
    },
    {
      "id": "CVE-2014-100005",
      "url": "https://spydr.io/cve/CVE-2014-100005",
      "published": "2015-01-13T11:59:04.477Z",
      "modified": "2026-06-17T00:04:00.147Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.43456,
      "epss_percentile": 0.98704,
      "exploited": true,
      "kev": {
        "added": "2024-05-16",
        "due": "2024-06-06",
        "action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-600_firmware",
        "dlink dir-600"
      ],
      "cwes": [
        "CWE-352"
      ],
      "description": "Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php."
    },
    {
      "id": "CVE-2024-30051",
      "url": "https://spydr.io/cve/CVE-2024-30051",
      "published": "2024-05-14T17:17:21.763Z",
      "modified": "2026-06-17T07:26:08.450Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.05687,
      "epss_percentile": 0.92781,
      "exploited": true,
      "kev": {
        "added": "2024-05-14",
        "due": "2024-06-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows DWM Core Library Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-30040",
      "url": "https://spydr.io/cve/CVE-2024-30040",
      "published": "2024-05-14T17:17:12.410Z",
      "modified": "2026-06-17T07:26:06.870Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.03939,
      "epss_percentile": 0.90093,
      "exploited": true,
      "kev": {
        "added": "2024-05-14",
        "due": "2024-06-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Windows MSHTML Platform Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-4671",
      "url": "https://spydr.io/cve/CVE-2024-4671",
      "published": "2024-05-14T15:44:15.573Z",
      "modified": "2026-06-17T08:02:22.630Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08348,
      "epss_percentile": 0.94813,
      "exploited": true,
      "kev": {
        "added": "2024-05-13",
        "due": "2024-06-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "fedoraproject"
      ],
      "products": [
        "Google Chrome",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-7028",
      "url": "https://spydr.io/cve/CVE-2023-7028",
      "published": "2024-01-12T14:15:49.420Z",
      "modified": "2026-06-17T06:51:54.410Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94647,
      "epss_percentile": 0.99856,
      "exploited": true,
      "kev": {
        "added": "2024-05-01",
        "due": "2024-05-22",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GitLab"
      ],
      "products": [
        "GitLab"
      ],
      "cwes": [
        "CWE-640"
      ],
      "description": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address."
    },
    {
      "id": "CVE-2024-29988",
      "url": "https://spydr.io/cve/CVE-2024-29988",
      "published": "2024-04-09T17:16:01.830Z",
      "modified": "2026-06-17T07:23:30.187Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.44875,
      "epss_percentile": 0.98743,
      "exploited": true,
      "kev": {
        "added": "2024-04-30",
        "due": "2024-05-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "SmartScreen Prompt Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-20359",
      "url": "https://spydr.io/cve/CVE-2024-20359",
      "published": "2024-04-24T19:15:46.943Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.19434,
      "epss_percentile": 0.97299,
      "exploited": true,
      "kev": {
        "added": "2024-04-24",
        "due": "2024-05-01",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Adaptive Security Appliance (ASA) Software",
        "Cisco Firepower Threat Defense Software",
        "cisco asa"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash memory. An attacker could exploit this vulnerability by copying a crafted file to the disk0: file system of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device after the next reload of the device, which could alter system behavior. Because the injected code could persist across device reboots, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High."
    },
    {
      "id": "CVE-2024-20353",
      "url": "https://spydr.io/cve/CVE-2024-20353",
      "published": "2024-04-24T19:15:46.723Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.70686,
      "epss_percentile": 0.99381,
      "exploited": true,
      "kev": {
        "added": "2024-04-24",
        "due": "2024-05-01",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Adaptive Security Appliance (ASA) Software",
        "Cisco Firepower Threat Defense Software",
        "cisco asa"
      ],
      "cwes": [
        "CWE-835"
      ],
      "description": "A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads."
    },
    {
      "id": "CVE-2024-4040",
      "url": "https://spydr.io/cve/CVE-2024-4040",
      "published": "2024-04-22T20:15:07.803Z",
      "modified": "2026-06-17T08:00:59.913Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99539,
      "epss_percentile": 0.99945,
      "exploited": true,
      "kev": {
        "added": "2024-04-24",
        "due": "2024-05-01",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "CrushFTP"
      ],
      "products": [
        "CrushFTP"
      ],
      "cwes": [
        "CWE-1336",
        "CWE-94"
      ],
      "description": "A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server."
    },
    {
      "id": "CVE-2022-38028",
      "url": "https://spydr.io/cve/CVE-2022-38028",
      "published": "2022-10-11T19:15:15.067Z",
      "modified": "2026-06-17T04:55:56.497Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.14949,
      "epss_percentile": 0.96625,
      "exploited": true,
      "kev": {
        "added": "2024-04-23",
        "due": "2024-05-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows Print Spooler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-3400",
      "url": "https://spydr.io/cve/CVE-2024-3400",
      "published": "2024-04-12T08:15:06.230Z",
      "modified": "2026-06-17T07:44:11.533Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 1,
      "exploited": true,
      "kev": {
        "added": "2024-04-12",
        "due": "2024-04-19",
        "action": "Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-20",
        "CWE-77"
      ],
      "description": "A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2024-3273",
      "url": "https://spydr.io/cve/CVE-2024-3273",
      "published": "2024-04-04T01:15:50.387Z",
      "modified": "2026-06-17T07:43:41.730Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99997,
      "epss_percentile": 0.99989,
      "exploited": true,
      "kev": {
        "added": "2024-04-11",
        "due": "2024-05-02",
        "action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "D-Link"
      ],
      "products": [
        "D-Link DNS-320L",
        "D-Link DNS-325",
        "D-Link DNS-327L",
        "D-Link DNS-340L",
        "dlink dns-320l_firmware",
        "dlink dns-325_firmware",
        "dlink dns-327l_firmware",
        "dlink dns-340l_firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced."
    },
    {
      "id": "CVE-2024-3272",
      "url": "https://spydr.io/cve/CVE-2024-3272",
      "published": "2024-04-04T01:15:50.123Z",
      "modified": "2026-06-17T07:43:41.427Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98038,
      "epss_percentile": 0.9991,
      "exploited": true,
      "kev": {
        "added": "2024-04-11",
        "due": "2024-05-02",
        "action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "D-Link"
      ],
      "products": [
        "D-Link DNS-320L",
        "D-Link DNS-325",
        "D-Link DNS-327L",
        "D-Link DNS-340L",
        "dlink dns-320l_firmware",
        "dlink dns-325_firmware",
        "dlink dns-327l_firmware",
        "dlink dns-340l_firmware"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced."
    },
    {
      "id": "CVE-2024-29748",
      "url": "https://spydr.io/cve/CVE-2024-29748",
      "published": "2024-04-05T20:15:08.407Z",
      "modified": "2026-06-17T07:23:00.713Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0067,
      "epss_percentile": 0.50352,
      "exploited": true,
      "kev": {
        "added": "2024-04-04",
        "due": "2024-04-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android",
        "google pixel"
      ],
      "cwes": [
        "CWE-755",
        "CWE-280"
      ],
      "description": "there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
