{
  "query": {
    "kev": "1",
    "page": "35"
  },
  "count": 20,
  "total": 1734,
  "page": 35,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T12:47:36.253Z",
    "kev": "2026-10-07T13:46:38.070Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T13:47:38.262Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=35",
    "next": "https://spydr.io/threats.json?kev=1&page=36"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-7024",
      "url": "https://spydr.io/cve/CVE-2023-7024",
      "published": "2023-12-21T23:15:11.213Z",
      "modified": "2026-06-17T06:51:53.730Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06671,
      "epss_percentile": 0.93711,
      "exploited": true,
      "kev": {
        "added": "2024-01-02",
        "due": "2024-01-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-47565",
      "url": "https://spydr.io/cve/CVE-2023-47565",
      "published": "2023-12-08T16:15:16.367Z",
      "modified": "2026-06-17T06:32:55.230Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73277,
      "epss_percentile": 0.99449,
      "exploited": true,
      "kev": {
        "added": "2023-12-21",
        "due": "2024-01-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. VioStor NVR"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later"
    },
    {
      "id": "CVE-2023-49897",
      "url": "https://spydr.io/cve/CVE-2023-49897",
      "published": "2023-12-06T07:15:41.883Z",
      "modified": "2026-06-17T06:36:40.620Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.50447,
      "epss_percentile": 0.98885,
      "exploited": true,
      "kev": {
        "added": "2023-12-21",
        "due": "2024-01-11",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FXC Inc."
      ],
      "products": [
        "FXC Inc. AE1021PE",
        "FXC Inc. AE1021"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product."
    },
    {
      "id": "CVE-2023-6448",
      "url": "https://spydr.io/cve/CVE-2023-6448",
      "published": "2023-12-05T18:15:12.643Z",
      "modified": "2026-06-17T06:50:46.670Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02072,
      "epss_percentile": 0.80816,
      "exploited": true,
      "kev": {
        "added": "2023-12-11",
        "due": "2023-12-18",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Unitronics"
      ],
      "products": [
        "Unitronics VisiLogic"
      ],
      "cwes": [
        "CWE-1188",
        "CWE-798"
      ],
      "description": "Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system."
    },
    {
      "id": "CVE-2023-41266",
      "url": "https://spydr.io/cve/CVE-2023-41266",
      "published": "2023-08-29T23:15:09.380Z",
      "modified": "2026-08-05T05:16:40.290Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.84843,
      "epss_percentile": 0.99706,
      "exploited": true,
      "kev": {
        "added": "2023-12-07",
        "due": "2023-12-28",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qlik"
      ],
      "products": [
        "qlik_sense"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13."
    },
    {
      "id": "CVE-2023-41265",
      "url": "https://spydr.io/cve/CVE-2023-41265",
      "published": "2023-08-29T23:15:09.170Z",
      "modified": "2026-08-05T05:16:39.700Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88215,
      "epss_percentile": 0.99767,
      "exploited": true,
      "kev": {
        "added": "2023-12-07",
        "due": "2023-12-28",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qlik"
      ],
      "products": [
        "qlik_sense"
      ],
      "cwes": [
        "CWE-444"
      ],
      "description": "An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13."
    },
    {
      "id": "CVE-2023-33107",
      "url": "https://spydr.io/cve/CVE-2023-33107",
      "published": "2023-12-05T03:15:14.860Z",
      "modified": "2026-06-17T06:00:58.287Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00739,
      "epss_percentile": 0.53062,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm 315_5g_iot_modem_firmware",
        "qualcomm apq8017_firmware",
        "qualcomm apq8064au_firmware",
        "qualcomm aqt1000_firmware",
        "qualcomm ar8031_firmware",
        "qualcomm ar8035_firmware",
        "qualcomm c-v2x_9150_firmware",
        "qualcomm csra6620_firmware",
        "qualcomm csra6640_firmware",
        "qualcomm csrb31024_firmware",
        "qualcomm fastconnect_6200_firmware",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm flight_rb5_5g_platform_firmware",
        "qualcomm mdm9250_firmware",
        "qualcomm mdm9650_firmware",
        "qualcomm msm8108_firmware"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call."
    },
    {
      "id": "CVE-2023-33106",
      "url": "https://spydr.io/cve/CVE-2023-33106",
      "published": "2023-12-05T03:15:14.673Z",
      "modified": "2026-06-17T06:00:56.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00788,
      "epss_percentile": 0.54744,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm ar8035_firmware",
        "qualcomm csra6620_firmware",
        "qualcomm csra6640_firmware",
        "qualcomm fastconnect_6200_firmware",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm flight_rb5_5g_platform_firmware",
        "qualcomm qam8255p_firmware",
        "qualcomm qam8295p_firmware",
        "qualcomm qam8650p_firmware",
        "qualcomm qam8775p_firmware",
        "qualcomm qca6174a_firmware",
        "qualcomm qca6391_firmware",
        "qualcomm qca6426_firmware",
        "qualcomm qca6436_firmware",
        "qualcomm qca6574_firmware",
        "qualcomm qca6574a_firmware"
      ],
      "cwes": [
        "CWE-823",
        "CWE-119"
      ],
      "description": "Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND."
    },
    {
      "id": "CVE-2023-33063",
      "url": "https://spydr.io/cve/CVE-2023-33063",
      "published": "2023-12-05T03:15:12.067Z",
      "modified": "2026-06-17T06:00:38.380Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00672,
      "epss_percentile": 0.50455,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc.",
        "qualcomm"
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon",
        "qualcomm 315_5g_iot_modem_firmware",
        "qualcomm apq8017_firmware",
        "qualcomm aqt1000_firmware",
        "qualcomm ar8031_firmware",
        "qualcomm ar8035_firmware",
        "qualcomm ar9380_firmware",
        "qualcomm c-v2x_9150_firmware",
        "qualcomm csr8811_firmware",
        "qualcomm csra6620_firmware",
        "qualcomm csra6640_firmware",
        "qualcomm csrb31024_firmware",
        "qualcomm fastconnect_6200_firmware",
        "qualcomm fastconnect_6700_firmware",
        "qualcomm fastconnect_6800_firmware",
        "qualcomm fastconnect_6900_firmware",
        "qualcomm fastconnect_7800_firmware",
        "qualcomm flight_rb5_5g_platform_firmware",
        "qualcomm immersive_home_214_platform_firmware",
        "qualcomm immersive_home_216_platform_firmware"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Memory corruption in DSP Services during a remote call from HLOS to DSP."
    },
    {
      "id": "CVE-2022-22071",
      "url": "https://spydr.io/cve/CVE-2022-22071",
      "published": "2022-06-14T10:15:19.003Z",
      "modified": "2026-06-17T04:27:37.993Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00411,
      "epss_percentile": 0.33155,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music"
    },
    {
      "id": "CVE-2023-42917",
      "url": "https://spydr.io/cve/CVE-2023-42917",
      "published": "2023-11-30T23:15:07.280Z",
      "modified": "2026-06-17T06:24:49.733Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09295,
      "epss_percentile": 0.95243,
      "exploited": true,
      "kev": {
        "added": "2023-12-04",
        "due": "2023-12-25",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple macOS",
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1."
    },
    {
      "id": "CVE-2023-42916",
      "url": "https://spydr.io/cve/CVE-2023-42916",
      "published": "2023-11-30T23:15:07.223Z",
      "modified": "2026-06-17T06:24:49.510Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.17823,
      "epss_percentile": 0.97095,
      "exploited": true,
      "kev": {
        "added": "2023-12-04",
        "due": "2023-12-25",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple macOS",
        "Apple iOS and iPadOS",
        "apple iphone_os",
        "apple ipados"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1."
    },
    {
      "id": "CVE-2023-6345",
      "url": "https://spydr.io/cve/CVE-2023-6345",
      "published": "2023-11-29T12:15:07.077Z",
      "modified": "2026-06-17T06:50:34.617Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.16468,
      "epss_percentile": 0.96908,
      "exploited": true,
      "kev": {
        "added": "2023-11-30",
        "due": "2023-12-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-49103",
      "url": "https://spydr.io/cve/CVE-2023-49103",
      "published": "2023-11-21T22:15:08.277Z",
      "modified": "2026-06-17T06:35:22.550Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.78428,
      "epss_percentile": 0.99574,
      "exploited": true,
      "kev": {
        "added": "2023-11-30",
        "due": "2023-12-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "owncloud"
      ],
      "products": [
        "owncloud graph api"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure."
    },
    {
      "id": "CVE-2023-4911",
      "url": "https://spydr.io/cve/CVE-2023-4911",
      "published": "2023-10-03T18:15:10.463Z",
      "modified": "2026-06-17T06:38:52.787Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.63769,
      "epss_percentile": 0.99202,
      "exploited": true,
      "kev": {
        "added": "2023-11-21",
        "due": "2023-12-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Red Hat",
        "Siemens"
      ],
      "products": [
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 8.6 Extended Update Support",
        "Red Hat Enterprise Linux 9",
        "Red Hat Enterprise Linux 9.0 Extended Update Support",
        "Red Hat Virtualization 4 for Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 6",
        "Red Hat Enterprise Linux 7",
        "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
        "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
        "Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges."
    },
    {
      "id": "CVE-2023-36584",
      "url": "https://spydr.io/cve/CVE-2023-36584",
      "published": "2023-10-10T18:15:14.280Z",
      "modified": "2026-06-17T06:06:36.723Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.03055,
      "epss_percentile": 0.87168,
      "exploited": true,
      "kev": {
        "added": "2023-11-16",
        "due": "2023-12-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-1671",
      "url": "https://spydr.io/cve/CVE-2023-1671",
      "published": "2023-04-04T10:15:07.197Z",
      "modified": "2026-06-17T05:28:29.373Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99992,
      "exploited": true,
      "kev": {
        "added": "2023-11-16",
        "due": "2023-12-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sophos"
      ],
      "products": [
        "Sophos Web Appliance"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code."
    },
    {
      "id": "CVE-2020-2551",
      "url": "https://spydr.io/cve/CVE-2020-2551",
      "published": "2020-01-15T17:15:17.190Z",
      "modified": "2026-06-17T03:12:20.303Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93217,
      "epss_percentile": 0.99834,
      "exploited": true,
      "kev": {
        "added": "2023-11-16",
        "due": "2023-12-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation WebLogic Server"
      ],
      "cwes": [],
      "description": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2023-36036",
      "url": "https://spydr.io/cve/CVE-2023-36036",
      "published": "2023-11-14T18:15:33.033Z",
      "modified": "2026-06-17T06:05:43.003Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1667,
      "epss_percentile": 0.96948,
      "exploited": true,
      "kev": {
        "added": "2023-11-14",
        "due": "2023-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-36033",
      "url": "https://spydr.io/cve/CVE-2023-36033",
      "published": "2023-11-14T18:15:32.677Z",
      "modified": "2026-06-17T06:05:42.567Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10945,
      "epss_percentile": 0.95777,
      "exploited": true,
      "kev": {
        "added": "2023-11-14",
        "due": "2023-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)"
      ],
      "cwes": [
        "CWE-822",
        "CWE-119"
      ],
      "description": "Windows DWM Core Library Elevation of Privilege Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
