{
  "query": {
    "kev": "1",
    "page": "33"
  },
  "count": 20,
  "total": 1734,
  "page": 33,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T10:47:31.354Z",
    "kev": "2026-10-07T11:46:33.386Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T11:47:33.740Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=33",
    "next": "https://spydr.io/threats.json?kev=1&page=34"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-29745",
      "url": "https://spydr.io/cve/CVE-2024-29745",
      "published": "2024-04-05T20:15:08.253Z",
      "modified": "2026-06-17T07:23:00.270Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00482,
      "epss_percentile": 0.395,
      "exploited": true,
      "kev": {
        "added": "2024-04-04",
        "due": "2024-04-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Android"
      ],
      "cwes": [
        "CWE-908"
      ],
      "description": "there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation."
    },
    {
      "id": "CVE-2023-24955",
      "url": "https://spydr.io/cve/CVE-2023-24955",
      "published": "2023-05-09T18:15:13.317Z",
      "modified": "2026-06-17T05:40:22.183Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.84974,
      "epss_percentile": 0.99708,
      "exploited": true,
      "kev": {
        "added": "2024-03-26",
        "due": "2024-04-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Microsoft SharePoint Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-48788",
      "url": "https://spydr.io/cve/CVE-2023-48788",
      "published": "2024-03-12T15:15:46.973Z",
      "modified": "2026-06-17T06:34:58.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98446,
      "epss_percentile": 0.99918,
      "exploited": true,
      "kev": {
        "added": "2024-03-25",
        "due": "2024-04-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiClientEMS",
        "fortinet forticlient_enterprise_management_server"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets."
    },
    {
      "id": "CVE-2021-44529",
      "url": "https://spydr.io/cve/CVE-2021-44529",
      "published": "2021-12-08T22:15:10.163Z",
      "modified": "2026-08-04T05:16:27.567Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99105,
      "epss_percentile": 0.99933,
      "exploited": true,
      "kev": {
        "added": "2024-03-25",
        "due": "2024-04-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti"
      ],
      "products": [
        "Ivanti EPM",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody)."
    },
    {
      "id": "CVE-2019-7256",
      "url": "https://spydr.io/cve/CVE-2019-7256",
      "published": "2019-07-02T19:15:11.147Z",
      "modified": "2026-06-17T02:40:19.833Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97081,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2024-03-25",
        "due": "2024-04-15",
        "action": "Contact the vendor for guidance on remediating firmware, per their advisory.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nortekcontrol"
      ],
      "products": [
        "nortekcontrol linear_emerge_essential_firmware",
        "nortekcontrol linear_emerge_elite_firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Linear eMerge E3-Series devices allow Command Injections."
    },
    {
      "id": "CVE-2024-27198",
      "url": "https://spydr.io/cve/CVE-2024-27198",
      "published": "2024-03-04T18:15:09.040Z",
      "modified": "2026-06-17T07:19:24.987Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99938,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2024-03-07",
        "due": "2024-03-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "JetBrains"
      ],
      "products": [
        "JetBrains TeamCity"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible"
    },
    {
      "id": "CVE-2024-23296",
      "url": "https://spydr.io/cve/CVE-2024-23296",
      "published": "2024-03-05T20:16:01.553Z",
      "modified": "2026-06-17T07:12:32.137Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01411,
      "epss_percentile": 0.71803,
      "exploited": true,
      "kev": {
        "added": "2024-03-06",
        "due": "2024-03-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS",
        "apple ipad_os",
        "apple iphone_os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited."
    },
    {
      "id": "CVE-2024-23225",
      "url": "https://spydr.io/cve/CVE-2024-23225",
      "published": "2024-03-05T20:16:01.370Z",
      "modified": "2026-06-17T07:12:20.443Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01481,
      "epss_percentile": 0.73097,
      "exploited": true,
      "kev": {
        "added": "2024-03-06",
        "due": "2024-03-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS",
        "Apple watchOS",
        "apple ipad_os",
        "apple iphone_os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited."
    },
    {
      "id": "CVE-2023-21237",
      "url": "https://spydr.io/cve/CVE-2023-21237",
      "published": "2023-06-28T18:15:16.560Z",
      "modified": "2026-06-17T05:32:08.713Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.00266,
      "epss_percentile": 0.16885,
      "exploited": true,
      "kev": {
        "added": "2024-03-05",
        "due": "2024-03-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android",
        "google android"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-251586912"
    },
    {
      "id": "CVE-2021-36380",
      "url": "https://spydr.io/cve/CVE-2021-36380",
      "published": "2021-08-13T16:15:07.607Z",
      "modified": "2026-06-17T03:58:46.613Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97647,
      "epss_percentile": 0.99903,
      "exploited": true,
      "kev": {
        "added": "2024-03-05",
        "due": "2024-03-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sunhillo"
      ],
      "products": [
        "sunhillo sureline"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi."
    },
    {
      "id": "CVE-2024-21338",
      "url": "https://spydr.io/cve/CVE-2024-21338",
      "published": "2024-02-13T18:15:49.083Z",
      "modified": "2026-08-10T16:18:40.377Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.5981,
      "epss_percentile": 0.9911,
      "exploited": true,
      "kev": {
        "added": "2024-03-04",
        "due": "2024-03-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Windows Kernel Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-29360",
      "url": "https://spydr.io/cve/CVE-2023-29360",
      "published": "2023-06-14T00:15:10.067Z",
      "modified": "2026-06-17T05:49:53.300Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.2162,
      "epss_percentile": 0.97569,
      "exploited": true,
      "kev": {
        "added": "2024-02-29",
        "due": "2024-03-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-822"
      ],
      "description": "Microsoft Streaming Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2024-1709",
      "url": "https://spydr.io/cve/CVE-2024-1709",
      "published": "2024-02-21T16:15:50.420Z",
      "modified": "2026-06-17T07:04:50.557Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9998,
      "epss_percentile": 0.99981,
      "exploited": true,
      "kev": {
        "added": "2024-02-22",
        "due": "2024-02-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ConnectWise"
      ],
      "products": [
        "ConnectWise ScreenConnect"
      ],
      "cwes": [
        "CWE-288"
      ],
      "description": "ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems."
    },
    {
      "id": "CVE-2024-21410",
      "url": "https://spydr.io/cve/CVE-2024-21410",
      "published": "2024-02-13T18:15:59.680Z",
      "modified": "2026-06-17T07:09:14.233Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.12561,
      "epss_percentile": 0.96134,
      "exploited": true,
      "kev": {
        "added": "2024-02-15",
        "due": "2024-03-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 13",
        "Microsoft Exchange Server 2019 Cumulative Update 14"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Microsoft Exchange Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2020-3259",
      "url": "https://spydr.io/cve/CVE-2020-3259",
      "published": "2020-05-06T17:15:12.777Z",
      "modified": "2026-08-12T05:17:30.263Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.71789,
      "epss_percentile": 0.99412,
      "exploited": true,
      "kev": {
        "added": "2024-02-15",
        "due": "2024-03-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Adaptive Security Appliance (ASA) Software",
        "cisco firepower_threat_defense",
        "cisco adaptive_security_appliance_software"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section."
    },
    {
      "id": "CVE-2024-21412",
      "url": "https://spydr.io/cve/CVE-2024-21412",
      "published": "2024-02-13T18:15:59.903Z",
      "modified": "2026-08-10T16:18:51.517Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
      "score_source": "microsoft.com",
      "epss": 0.9941,
      "epss_percentile": 0.99942,
      "exploited": true,
      "kev": {
        "added": "2024-02-13",
        "due": "2024-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Internet Shortcut Files Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2024-21351",
      "url": "https://spydr.io/cve/CVE-2024-21351",
      "published": "2024-02-13T18:15:51.333Z",
      "modified": "2026-08-10T16:18:42.753Z",
      "score": 7.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L",
      "score_source": "microsoft.com",
      "epss": 0.27798,
      "epss_percentile": 0.98046,
      "exploited": true,
      "kev": {
        "added": "2024-02-13",
        "due": "2024-03-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-43770",
      "url": "https://spydr.io/cve/CVE-2023-43770",
      "published": "2023-09-22T06:15:10.090Z",
      "modified": "2026-06-17T06:26:24.770Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.6366,
      "epss_percentile": 0.99198,
      "exploited": true,
      "kev": {
        "added": "2024-02-12",
        "due": "2024-03-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "debian"
      ],
      "products": [
        "roundcube webmail",
        "debian_linux"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior."
    },
    {
      "id": "CVE-2024-21762",
      "url": "https://spydr.io/cve/CVE-2024-21762",
      "published": "2024-02-09T09:15:08.087Z",
      "modified": "2026-08-04T05:16:30.003Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83428,
      "epss_percentile": 0.99677,
      "exploited": true,
      "kev": {
        "added": "2024-02-09",
        "due": "2024-02-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiProxy",
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests"
    },
    {
      "id": "CVE-2023-4762",
      "url": "https://spydr.io/cve/CVE-2023-4762",
      "published": "2023-09-05T22:15:09.677Z",
      "modified": "2026-06-17T06:38:32.743Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41375,
      "epss_percentile": 0.98638,
      "exploited": true,
      "kev": {
        "added": "2024-02-06",
        "due": "2024-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "debian",
        "fedoraproject"
      ],
      "products": [
        "Google Chrome",
        "debian_linux",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
