{
  "query": {
    "kev": "1",
    "page": "36"
  },
  "count": 20,
  "total": 1734,
  "page": 36,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T14:47:40.746Z",
    "kev": "2026-10-07T14:46:40.605Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T14:47:40.746Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=36",
    "next": "https://spydr.io/threats.json?kev=1&page=37"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-36025",
      "url": "https://spydr.io/cve/CVE-2023-36025",
      "published": "2023-11-14T18:15:31.867Z",
      "modified": "2026-06-17T06:05:41.527Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88085,
      "epss_percentile": 0.99764,
      "exploited": true,
      "kev": {
        "added": "2023-11-14",
        "due": "2023-12-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012"
      ],
      "cwes": [],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-47246",
      "url": "https://spydr.io/cve/CVE-2023-47246",
      "published": "2023-11-10T06:15:30.510Z",
      "modified": "2026-07-31T04:16:43.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98851,
      "epss_percentile": 0.99927,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-12-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sysaid"
      ],
      "products": [
        "sysaid_on-premises"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023."
    },
    {
      "id": "CVE-2023-36851",
      "url": "https://spydr.io/cve/CVE-2023-36851",
      "published": "2023-09-27T15:18:54.877Z",
      "modified": "2026-06-17T06:07:13.967Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.01123,
      "epss_percentile": 0.65148,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload and download arbitrary files via J-Web, leading to a loss of integrity or confidentiality, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * 21.2 versions prior to 21.2R3-S8; * 21.4 versions prior to 21.4R3-S6; * 22.1 versions prior to 22.1R3-S5; * 22.2 versions prior to 22.2R3-S3; * 22.3 versions prior to 22.3R3-S2; * 22.4 versions prior to 22,4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S2, 23.2R2."
    },
    {
      "id": "CVE-2023-36847",
      "url": "https://spydr.io/cve/CVE-2023-36847",
      "published": "2023-08-17T20:15:10.553Z",
      "modified": "2026-06-17T06:07:13.203Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.83455,
      "epss_percentile": 0.99678,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S4; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S1; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3."
    },
    {
      "id": "CVE-2023-36846",
      "url": "https://spydr.io/cve/CVE-2023-36846",
      "published": "2023-08-17T20:15:10.457Z",
      "modified": "2026-06-17T06:07:12.957Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.93473,
      "epss_percentile": 0.99839,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on SRX Series: * All versions prior to 20.4R3-S8; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S6; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S3; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3; * 22.4 versions prior to 22.4R2-S1, 22.4R3."
    },
    {
      "id": "CVE-2023-36845",
      "url": "https://spydr.io/cve/CVE-2023-36845",
      "published": "2023-08-17T20:15:10.360Z",
      "modified": "2026-06-17T06:07:12.753Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "juniper.net",
      "epss": 0.9507,
      "epss_percentile": 0.99862,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-473"
      ],
      "description": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R2-S2, 22.3R3-S1; * 22.4 versions prior to 22.4R2-S1, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2."
    },
    {
      "id": "CVE-2023-36844",
      "url": "https://spydr.io/cve/CVE-2023-36844",
      "published": "2023-08-17T20:15:10.267Z",
      "modified": "2026-06-17T06:07:12.573Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.89958,
      "epss_percentile": 0.99792,
      "exploited": true,
      "kev": {
        "added": "2023-11-13",
        "due": "2023-11-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Juniper Networks"
      ],
      "products": [
        "Juniper Networks Junos OS"
      ],
      "cwes": [
        "CWE-473"
      ],
      "description": "A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; * 21.4 versions prior to 21.4R3-S5; * 22.1 versions prior to 22.1R3-S4; * 22.2 versions prior to 22.2R3-S2; * 22.3 versions prior to 22.3R3-S1; * 22.4 versions prior to 22.4R2-S2, 22.4R3; * 23.2 versions prior to 23.2R1-S1, 23.2R2."
    },
    {
      "id": "CVE-2023-29552",
      "url": "https://spydr.io/cve/CVE-2023-29552",
      "published": "2023-04-25T16:15:09.537Z",
      "modified": "2026-06-17T05:50:32.263Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.63975,
      "epss_percentile": 0.99205,
      "exploited": true,
      "kev": {
        "added": "2023-11-08",
        "due": "2023-11-29",
        "action": "Apply mitigations per vendor instructions or disable SLP service or port 427/UDP on all systems running on untrusted networks, including those directly connected to the Internet.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netapp",
        "suse",
        "vmware",
        "service location protocol project"
      ],
      "products": [
        "netapp smi-s provider",
        "suse manager server",
        "suse linux enterprise server",
        "vmware esxi",
        "service location protocol project service location protocol"
      ],
      "cwes": [],
      "description": "The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor."
    },
    {
      "id": "CVE-2023-22518",
      "url": "https://spydr.io/cve/CVE-2023-22518",
      "published": "2023-10-31T15:15:08.573Z",
      "modified": "2026-06-17T05:35:37.490Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99996,
      "exploited": true,
      "kev": {
        "added": "2023-11-07",
        "due": "2023-11-28",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
    },
    {
      "id": "CVE-2023-46604",
      "url": "https://spydr.io/cve/CVE-2023-46604",
      "published": "2023-10-27T15:15:14.017Z",
      "modified": "2026-06-17T06:31:11.370Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99891,
      "epss_percentile": 0.99965,
      "exploited": true,
      "kev": {
        "added": "2023-11-02",
        "due": "2023-11-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache ActiveMQ",
        "Apache Software Foundation Apache ActiveMQ Legacy OpenWire Module"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue."
    },
    {
      "id": "CVE-2023-46748",
      "url": "https://spydr.io/cve/CVE-2023-46748",
      "published": "2023-10-26T21:15:08.177Z",
      "modified": "2026-06-17T06:31:32.820Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04468,
      "epss_percentile": 0.91173,
      "exploited": true,
      "kev": {
        "added": "2023-10-31",
        "due": "2023-11-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated"
    },
    {
      "id": "CVE-2023-46747",
      "url": "https://spydr.io/cve/CVE-2023-46747",
      "published": "2023-10-26T21:15:08.097Z",
      "modified": "2026-06-17T06:31:32.640Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96515,
      "epss_percentile": 0.99881,
      "exploited": true,
      "kev": {
        "added": "2023-10-31",
        "due": "2023-11-21",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-288",
        "CWE-306"
      ],
      "description": "Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated"
    },
    {
      "id": "CVE-2023-5631",
      "url": "https://spydr.io/cve/CVE-2023-5631",
      "published": "2023-10-18T15:15:08.727Z",
      "modified": "2026-06-17T06:48:58.673Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.75873,
      "epss_percentile": 0.99516,
      "exploited": true,
      "kev": {
        "added": "2023-10-26",
        "due": "2023-11-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Roundcube"
      ],
      "products": [
        "Roundcubemail"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attacker to load arbitrary JavaScript code."
    },
    {
      "id": "CVE-2023-20273",
      "url": "https://spydr.io/cve/CVE-2023-20273",
      "published": "2023-10-25T18:17:23.017Z",
      "modified": "2026-06-17T05:30:12.820Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89634,
      "epss_percentile": 0.99786,
      "exploited": true,
      "kev": {
        "added": "2023-10-23",
        "due": "2023-10-27",
        "action": "Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS XE Software"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges."
    },
    {
      "id": "CVE-2023-4966",
      "url": "https://spydr.io/cve/CVE-2023-4966",
      "published": "2023-10-10T14:15:10.977Z",
      "modified": "2026-07-31T04:16:44.230Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99997,
      "exploited": true,
      "kev": {
        "added": "2023-10-18",
        "due": "2023-11-08",
        "action": "Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix NetScaler ADC",
        "Citrix NetScaler Gateway"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server."
    },
    {
      "id": "CVE-2023-20198",
      "url": "https://spydr.io/cve/CVE-2023-20198",
      "published": "2023-10-16T16:15:10.023Z",
      "modified": "2026-06-17T05:29:47.117Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99571,
      "epss_percentile": 0.99946,
      "exploited": true,
      "kev": {
        "added": "2023-10-16",
        "due": "2023-10-20",
        "action": "Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS XE Software"
      ],
      "cwes": [
        "CWE-420"
      ],
      "description": "Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343."
    },
    {
      "id": "CVE-2023-41763",
      "url": "https://spydr.io/cve/CVE-2023-41763",
      "published": "2023-10-10T18:15:18.150Z",
      "modified": "2026-06-17T06:22:45.340Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.90353,
      "epss_percentile": 0.99798,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Skype for Business Server 2015 CU13",
        "Microsoft Skype for Business Server 2019 CU7"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Skype for Business Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-36563",
      "url": "https://spydr.io/cve/CVE-2023-36563",
      "published": "2023-10-10T18:15:13.003Z",
      "modified": "2026-06-17T06:06:32.857Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.20719,
      "epss_percentile": 0.97475,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Microsoft WordPad Information Disclosure Vulnerability"
    },
    {
      "id": "CVE-2023-44487",
      "url": "https://spydr.io/cve/CVE-2023-44487",
      "published": "2023-10-10T14:15:10.883Z",
      "modified": "2026-08-11T19:37:30.880Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99998,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ietf",
        "Siemens"
      ],
      "products": [
        "ietf http",
        "Siemens RUGGEDCOM APE1808",
        "Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
        "Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
        "Siemens SINEC NMS",
        "Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP"
      ],
      "cwes": [
        "CWE-400"
      ],
      "description": "The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023."
    },
    {
      "id": "CVE-2023-20109",
      "url": "https://spydr.io/cve/CVE-2023-20109",
      "published": "2023-09-27T18:15:10.860Z",
      "modified": "2026-06-17T05:29:29.667Z",
      "score": 6.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02484,
      "epss_percentile": 0.84079,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS",
        "Cisco IOS XE Software"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could exploit this vulnerability by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a denial of service (DoS) condition. For more information, see the Details [\"#details\"] section of this advisory."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
