{
  "query": {
    "kev": "1",
    "page": "37"
  },
  "count": 20,
  "total": 1734,
  "page": 37,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T14:47:40.746Z",
    "kev": "2026-10-07T15:46:42.531Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T15:47:42.703Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=37",
    "next": "https://spydr.io/threats.json?kev=1&page=38"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-21608",
      "url": "https://spydr.io/cve/CVE-2023-21608",
      "published": "2023-01-18T19:15:11.877Z",
      "modified": "2026-06-17T05:33:17.210Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.61475,
      "epss_percentile": 0.99146,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Acrobat Reader"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
    },
    {
      "id": "CVE-2023-42824",
      "url": "https://spydr.io/cve/CVE-2023-42824",
      "published": "2023-10-04T19:15:10.490Z",
      "modified": "2026-06-17T06:24:36.060Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01095,
      "epss_percentile": 0.6445,
      "exploited": true,
      "kev": {
        "added": "2023-10-05",
        "due": "2023-10-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6."
    },
    {
      "id": "CVE-2023-22515",
      "url": "https://spydr.io/cve/CVE-2023-22515",
      "published": "2023-10-04T14:15:10.440Z",
      "modified": "2026-06-17T05:35:37.127Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99223,
      "epss_percentile": 0.99936,
      "exploited": true,
      "kev": {
        "added": "2023-10-05",
        "due": "2023-10-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue."
    },
    {
      "id": "CVE-2023-40044",
      "url": "https://spydr.io/cve/CVE-2023-40044",
      "published": "2023-09-27T15:18:57.307Z",
      "modified": "2026-06-17T06:15:55.110Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90355,
      "epss_percentile": 0.99798,
      "exploited": true,
      "kev": {
        "added": "2023-10-05",
        "due": "2023-10-26",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Progress Software Corporation"
      ],
      "products": [
        "Progress Software Corporation WS_FTP Server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system."
    },
    {
      "id": "CVE-2023-42793",
      "url": "https://spydr.io/cve/CVE-2023-42793",
      "published": "2023-09-19T17:15:08.330Z",
      "modified": "2026-06-17T06:24:31.210Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99987,
      "epss_percentile": 0.99984,
      "exploited": true,
      "kev": {
        "added": "2023-10-04",
        "due": "2023-10-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "JetBrains"
      ],
      "products": [
        "JetBrains TeamCity"
      ],
      "cwes": [
        "CWE-288",
        "CWE-306"
      ],
      "description": "In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible"
    },
    {
      "id": "CVE-2023-28229",
      "url": "https://spydr.io/cve/CVE-2023-28229",
      "published": "2023-04-11T21:15:23.387Z",
      "modified": "2026-06-17T05:47:11.090Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01671,
      "epss_percentile": 0.7604,
      "exploited": true,
      "kev": {
        "added": "2023-10-04",
        "due": "2023-10-25",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2"
      ],
      "cwes": [
        "CWE-591"
      ],
      "description": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-4211",
      "url": "https://spydr.io/cve/CVE-2023-4211",
      "published": "2023-10-01T18:15:09.927Z",
      "modified": "2026-06-17T06:37:19.410Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01098,
      "epss_percentile": 0.64539,
      "exploited": true,
      "kev": {
        "added": "2023-10-03",
        "due": "2023-10-24",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Arm Ltd"
      ],
      "products": [
        "Arm Ltd Midgard GPU Kernel Driver",
        "Arm Ltd Bifrost GPU Kernel Driver",
        "Arm Ltd Valhall GPU Kernel Driver",
        "Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory."
    },
    {
      "id": "CVE-2023-5217",
      "url": "https://spydr.io/cve/CVE-2023-5217",
      "published": "2023-09-28T16:15:10.980Z",
      "modified": "2026-06-17T06:48:06.467Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.49013,
      "epss_percentile": 0.98852,
      "exploited": true,
      "kev": {
        "added": "2023-10-02",
        "due": "2023-10-23",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome",
        "Google libvpx"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2018-14667",
      "url": "https://spydr.io/cve/CVE-2018-14667",
      "published": "2018-11-06T22:29:00.193Z",
      "modified": "2026-06-17T01:41:24.937Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74202,
      "epss_percentile": 0.99478,
      "exploited": true,
      "kev": {
        "added": "2023-09-28",
        "due": "2023-10-19",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "[UNKNOWN]"
      ],
      "products": [
        "[UNKNOWN] RichFaces"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData."
    },
    {
      "id": "CVE-2023-41993",
      "url": "https://spydr.io/cve/CVE-2023-41993",
      "published": "2023-09-21T19:15:11.660Z",
      "modified": "2026-06-17T06:23:13.433Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24349,
      "epss_percentile": 0.97811,
      "exploited": true,
      "kev": {
        "added": "2023-09-25",
        "due": "2023-10-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple",
        "fedoraproject",
        "debian",
        "oracle",
        "netapp"
      ],
      "products": [
        "Apple macOS",
        "apple iphone_os",
        "apple ipad_os",
        "fedoraproject fedora",
        "debian_linux",
        "oracle graalvm",
        "oracle jdk",
        "oracle jre",
        "netapp cloud_insights_acquisition_unit",
        "netapp cloud_insights_storage_workload_security_agent",
        "netapp oncommand_insight",
        "netapp oncommand_workflow_automation"
      ],
      "cwes": [
        "CWE-754"
      ],
      "description": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7."
    },
    {
      "id": "CVE-2023-41992",
      "url": "https://spydr.io/cve/CVE-2023-41992",
      "published": "2023-09-21T19:15:11.520Z",
      "modified": "2026-06-17T06:23:13.257Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09515,
      "epss_percentile": 0.95323,
      "exploited": true,
      "kev": {
        "added": "2023-09-25",
        "due": "2023-10-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-754"
      ],
      "description": "The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7."
    },
    {
      "id": "CVE-2023-41991",
      "url": "https://spydr.io/cve/CVE-2023-41991",
      "published": "2023-09-21T19:15:11.283Z",
      "modified": "2026-06-17T06:23:13.087Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.1338,
      "epss_percentile": 0.96322,
      "exploited": true,
      "kev": {
        "added": "2023-09-25",
        "due": "2023-10-16",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-295"
      ],
      "description": "A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7."
    },
    {
      "id": "CVE-2023-41179",
      "url": "https://spydr.io/cve/CVE-2023-41179",
      "published": "2023-09-19T14:15:21.343Z",
      "modified": "2026-06-17T06:20:55.260Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04251,
      "epss_percentile": 0.90774,
      "exploited": true,
      "kev": {
        "added": "2023-09-21",
        "due": "2023-10-12",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro, Inc.",
        "trendmicro"
      ],
      "products": [
        "Trend Micro, Inc. Trend Micro Apex One",
        "Trend Micro, Inc. Trend Micro Worry-Free Business Security",
        "Trend Micro, Inc. Trend Micro Worry-Free Business Security Services",
        "trendmicro apex_one",
        "trendmicro worry-free_business_security",
        "trendmicro worry-free_business_security_services"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability."
    },
    {
      "id": "CVE-2023-28434",
      "url": "https://spydr.io/cve/CVE-2023-28434",
      "published": "2023-03-22T21:15:18.427Z",
      "modified": "2026-06-17T05:47:43.610Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07917,
      "epss_percentile": 0.94572,
      "exploited": true,
      "kev": {
        "added": "2023-09-19",
        "due": "2023-10-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "minio"
      ],
      "products": [
        "minio"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`."
    },
    {
      "id": "CVE-2022-22265",
      "url": "https://spydr.io/cve/CVE-2022-22265",
      "published": "2022-01-10T14:12:35.837Z",
      "modified": "2026-06-17T04:28:08.200Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00392,
      "epss_percentile": 0.31077,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-703"
      ],
      "description": "An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution."
    },
    {
      "id": "CVE-2021-3129",
      "url": "https://spydr.io/cve/CVE-2021-3129",
      "published": "2021-01-12T15:15:16.453Z",
      "modified": "2026-06-17T04:04:43.133Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99943,
      "epss_percentile": 0.99973,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "facade"
      ],
      "products": [
        "facade ignition"
      ],
      "cwes": [],
      "description": "Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2."
    },
    {
      "id": "CVE-2017-6884",
      "url": "https://spydr.io/cve/CVE-2017-6884",
      "published": "2017-04-06T17:59:00.163Z",
      "modified": "2026-10-01T19:17:13.473Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34607,
      "epss_percentile": 0.98383,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zyxel"
      ],
      "products": [
        "zyxel emg2926 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI."
    },
    {
      "id": "CVE-2014-8361",
      "url": "https://spydr.io/cve/CVE-2014-8361",
      "published": "2015-05-01T15:59:01.287Z",
      "modified": "2026-06-17T00:16:37.030Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99975,
      "epss_percentile": 0.99979,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink",
        "realtek",
        "aterm"
      ],
      "products": [
        "dlink dir-905l firmware",
        "dlink dir-605l firmware",
        "dlink dir-600l firmware",
        "dlink dir-619l firmware",
        "dlink dir-809 firmware",
        "dlink dir-900l firmware",
        "realtek sdk",
        "dlink dir-501 firmware",
        "dlink dir-515 firmware",
        "dlink dir-615 firmware",
        "aterm wg1900hp2 firmware",
        "aterm wg1900hp firmware",
        "aterm wg1800hp4 firmware",
        "aterm wg1800hp3 firmware",
        "aterm wg1200hs2 firmware",
        "aterm wg1200hp3 firmware",
        "aterm wg1200hp2 firmware",
        "aterm w1200ex firmware",
        "aterm w1200ex-ms firmware",
        "aterm wg1200hs firmware"
      ],
      "cwes": [],
      "description": "The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023."
    },
    {
      "id": "CVE-2023-26369",
      "url": "https://spydr.io/cve/CVE-2023-26369",
      "published": "2023-09-13T09:15:13.007Z",
      "modified": "2026-06-17T05:43:11.170Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.06746,
      "epss_percentile": 0.93785,
      "exploited": true,
      "kev": {
        "added": "2023-09-14",
        "due": "2023-10-05",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Acrobat Reader"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
    },
    {
      "id": "CVE-2023-4863",
      "url": "https://spydr.io/cve/CVE-2023-4863",
      "published": "2023-09-12T15:15:24.327Z",
      "modified": "2026-06-17T06:38:46.547Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99979,
      "epss_percentile": 0.9998,
      "exploited": true,
      "kev": {
        "added": "2023-09-13",
        "due": "2023-10-04",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome",
        "Google libwebp"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
