{
  "query": {
    "kev": "1",
    "page": "34"
  },
  "count": 20,
  "total": 1734,
  "page": 34,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T12:47:36.253Z",
    "kev": "2026-10-07T12:46:35.984Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T12:47:36.253Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=34",
    "next": "https://spydr.io/threats.json?kev=1&page=35"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2024-21893",
      "url": "https://spydr.io/cve/CVE-2024-21893",
      "published": "2024-01-31T18:15:47.437Z",
      "modified": "2026-08-04T05:16:30.353Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99999,
      "exploited": true,
      "kev": {
        "added": "2024-01-31",
        "due": "2024-02-02",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti ICS",
        "Ivanti IPS",
        "ivanti connect_secure",
        "ivanti policy_secure"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication."
    },
    {
      "id": "CVE-2022-48618",
      "url": "https://spydr.io/cve/CVE-2022-48618",
      "published": "2024-01-09T18:15:45.120Z",
      "modified": "2026-06-17T05:15:43.393Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00487,
      "epss_percentile": 0.39861,
      "exploited": true,
      "kev": {
        "added": "2024-01-31",
        "due": "2024-02-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple tvOS",
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple watchOS",
        "apple iphone_os",
        "apple ipados"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1."
    },
    {
      "id": "CVE-2023-22527",
      "url": "https://spydr.io/cve/CVE-2023-22527",
      "published": "2024-01-16T05:15:08.290Z",
      "modified": "2026-06-17T05:35:38.480Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99984,
      "epss_percentile": 0.99982,
      "exploited": true,
      "kev": {
        "added": "2024-01-24",
        "due": "2024-02-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin."
    },
    {
      "id": "CVE-2024-23222",
      "url": "https://spydr.io/cve/CVE-2024-23222",
      "published": "2024-01-23T01:15:11.500Z",
      "modified": "2026-06-17T07:12:19.937Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10593,
      "epss_percentile": 0.95671,
      "exploited": true,
      "kev": {
        "added": "2024-01-23",
        "due": "2024-02-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple visionOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update to the latest iOS version."
    },
    {
      "id": "CVE-2023-34048",
      "url": "https://spydr.io/cve/CVE-2023-34048",
      "published": "2023-10-25T18:17:27.897Z",
      "modified": "2026-06-17T06:02:47.860Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99428,
      "epss_percentile": 0.99942,
      "exploited": true,
      "kev": {
        "added": "2024-01-22",
        "due": "2024-02-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation (VMware vCenter Server)",
        "vmware cloud_foundation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution."
    },
    {
      "id": "CVE-2023-35082",
      "url": "https://spydr.io/cve/CVE-2023-35082",
      "published": "2023-08-15T16:15:11.633Z",
      "modified": "2026-06-17T06:04:23.757Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99996,
      "exploited": true,
      "kev": {
        "added": "2024-01-18",
        "due": "2024-02-08",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti EPMM"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier."
    },
    {
      "id": "CVE-2023-6549",
      "url": "https://spydr.io/cve/CVE-2023-6549",
      "published": "2024-01-17T21:15:11.690Z",
      "modified": "2026-06-17T06:50:58.160Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.57633,
      "epss_percentile": 0.99062,
      "exploited": true,
      "kev": {
        "added": "2024-01-17",
        "due": "2024-02-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cloud Software Group"
      ],
      "products": [
        "Cloud Software Group NetScaler ADC"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read"
    },
    {
      "id": "CVE-2023-6548",
      "url": "https://spydr.io/cve/CVE-2023-6548",
      "published": "2024-01-17T20:15:50.627Z",
      "modified": "2026-06-17T06:50:58.003Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03191,
      "epss_percentile": 0.87693,
      "exploited": true,
      "kev": {
        "added": "2024-01-17",
        "due": "2024-01-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cloud Software Group",
        "citrix"
      ],
      "products": [
        "Cloud Software Group NetScaler ADC",
        "Cloud Software Group NetScaler Gateway",
        "citrix netscaler_application_delivery_controller",
        "citrix netscaler_gateway"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface."
    },
    {
      "id": "CVE-2024-0519",
      "url": "https://spydr.io/cve/CVE-2024-0519",
      "published": "2024-01-16T22:15:37.753Z",
      "modified": "2026-06-17T06:53:41.133Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03802,
      "epss_percentile": 0.8971,
      "exploited": true,
      "kev": {
        "added": "2024-01-17",
        "due": "2024-02-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787",
        "CWE-125"
      ],
      "description": "Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2018-15133",
      "url": "https://spydr.io/cve/CVE-2018-15133",
      "published": "2018-08-09T19:29:00.333Z",
      "modified": "2026-06-17T01:42:06.387Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.76814,
      "epss_percentile": 0.99537,
      "exploited": true,
      "kev": {
        "added": "2024-01-16",
        "due": "2024-02-06",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "laravel"
      ],
      "products": [
        "laravel"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack."
    },
    {
      "id": "CVE-2024-21887",
      "url": "https://spydr.io/cve/CVE-2024-21887",
      "published": "2024-01-12T17:15:10.017Z",
      "modified": "2026-08-04T05:16:30.193Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99999,
      "exploited": true,
      "kev": {
        "added": "2024-01-10",
        "due": "2024-01-22",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti ICS",
        "Ivanti IPS"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance."
    },
    {
      "id": "CVE-2023-46805",
      "url": "https://spydr.io/cve/CVE-2023-46805",
      "published": "2024-01-12T17:15:09.530Z",
      "modified": "2026-10-01T21:17:17.487Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.99986,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2024-01-10",
        "due": "2024-01-22",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti ICS",
        "Ivanti IPS"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks."
    },
    {
      "id": "CVE-2023-29357",
      "url": "https://spydr.io/cve/CVE-2023-29357",
      "published": "2023-06-14T00:15:09.903Z",
      "modified": "2026-06-17T05:49:52.747Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99984,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2024-01-10",
        "due": "2024-01-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Server 2019"
      ],
      "cwes": [
        "CWE-303"
      ],
      "description": "Microsoft SharePoint Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-41990",
      "url": "https://spydr.io/cve/CVE-2023-41990",
      "published": "2023-09-12T00:15:09.463Z",
      "modified": "2026-06-17T06:23:12.903Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01388,
      "epss_percentile": 0.71371,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple tvOS",
        "Apple macOS",
        "Apple watchOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1."
    },
    {
      "id": "CVE-2023-38203",
      "url": "https://spydr.io/cve/CVE-2023-38203",
      "published": "2023-07-20T16:15:12.180Z",
      "modified": "2026-06-17T06:09:39.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.97074,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-29300",
      "url": "https://spydr.io/cve/CVE-2023-29300",
      "published": "2023-07-12T16:15:11.733Z",
      "modified": "2026-06-17T05:49:44.993Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.99991,
      "epss_percentile": 0.99986,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-27524",
      "url": "https://spydr.io/cve/CVE-2023-27524",
      "published": "2023-04-24T16:15:07.843Z",
      "modified": "2026-06-17T05:45:23.917Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97405,
      "epss_percentile": 0.99899,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Superset"
      ],
      "cwes": [
        "CWE-1188"
      ],
      "description": "Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access unauthorized resources. This does not affect Superset administrators who have changed the default value for SECRET_KEY config. All superset installations should always set a unique secure random SECRET_KEY. Your SECRET_KEY is used to securely sign all session cookies and encrypting sensitive information on the database. Add a strong SECRET_KEY to your `superset_config.py` file like: SECRET_KEY = <YOUR_OWN_RANDOM_GENERATED_SECRET_KEY> Alternatively you can set it with `SUPERSET_SECRET_KEY` environment variable."
    },
    {
      "id": "CVE-2023-23752",
      "url": "https://spydr.io/cve/CVE-2023-23752",
      "published": "2023-02-16T17:15:10.603Z",
      "modified": "2026-06-17T05:37:50.963Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99827,
      "epss_percentile": 0.9996,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Joomla! Project",
        "joomla"
      ],
      "products": [
        "Joomla! Project Joomla! CMS",
        "joomla\\!"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints."
    },
    {
      "id": "CVE-2016-20017",
      "url": "https://spydr.io/cve/CVE-2016-20017",
      "published": "2022-10-19T05:15:08.817Z",
      "modified": "2026-06-17T00:43:05.853Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64238,
      "epss_percentile": 0.99212,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dsl-2750b firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022."
    },
    {
      "id": "CVE-2023-7101",
      "url": "https://spydr.io/cve/CVE-2023-7101",
      "published": "2023-12-24T22:15:07.983Z",
      "modified": "2026-06-17T06:52:04.040Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19106,
      "epss_percentile": 0.97252,
      "exploited": true,
      "kev": {
        "added": "2024-01-02",
        "due": "2024-01-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Douglas Wilson",
        "jmcnamara",
        "debian",
        "fedoraproject"
      ],
      "products": [
        "Douglas Wilson Spreadsheet::ParseExcel",
        "jmcnamara spreadsheet\\",
        "debian_linux",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-95",
        "CWE-94"
      ],
      "description": "Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems from the evaluation of Number format strings (not to be confused with printf-style format strings) within the Excel parsing logic."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
