{
  "query": {
    "kev": "1",
    "page": "39"
  },
  "count": 20,
  "total": 1734,
  "page": 39,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T16:47:45.059Z",
    "kev": "2026-10-07T17:46:46.967Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T17:47:47.210Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=39",
    "next": "https://spydr.io/threats.json?kev=1&page=40"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-29298",
      "url": "https://spydr.io/cve/CVE-2023-29298",
      "published": "2023-07-12T16:15:11.623Z",
      "modified": "2026-06-17T05:49:44.727Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.9979,
      "epss_percentile": 0.99955,
      "exploited": true,
      "kev": {
        "added": "2023-07-20",
        "due": "2023-08-10",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-3519",
      "url": "https://spydr.io/cve/CVE-2023-3519",
      "published": "2023-07-19T18:15:11.513Z",
      "modified": "2026-08-05T05:16:39.130Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99749,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2023-07-19",
        "due": "2023-08-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix NetScaler ADC",
        "Citrix NetScaler Gateway"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Unauthenticated remote code execution"
    },
    {
      "id": "CVE-2023-36884",
      "url": "https://spydr.io/cve/CVE-2023-36884",
      "published": "2023-07-11T19:15:09.623Z",
      "modified": "2026-08-10T16:18:30.637Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.98932,
      "epss_percentile": 0.99928,
      "exploited": true,
      "kev": {
        "added": "2023-07-17",
        "due": "2023-08-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Windows Search Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-37450",
      "url": "https://spydr.io/cve/CVE-2023-37450",
      "published": "2023-07-27T00:15:15.497Z",
      "modified": "2026-06-17T06:08:14.593Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1895,
      "epss_percentile": 0.9723,
      "exploited": true,
      "kev": {
        "added": "2023-07-13",
        "due": "2023-08-03",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple tvOS",
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple watchOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2022-29303",
      "url": "https://spydr.io/cve/CVE-2022-29303",
      "published": "2022-05-12T16:15:07.600Z",
      "modified": "2026-06-17T04:39:59.293Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97997,
      "epss_percentile": 0.99909,
      "exploited": true,
      "kev": {
        "added": "2023-07-13",
        "due": "2023-08-03",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "contec"
      ],
      "products": [
        "contec sv-cpt-mc310 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php."
    },
    {
      "id": "CVE-2023-36874",
      "url": "https://spydr.io/cve/CVE-2023-36874",
      "published": "2023-07-11T18:15:20.733Z",
      "modified": "2026-06-17T06:07:16.410Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.42564,
      "epss_percentile": 0.98674,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows Error Reporting Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-35311",
      "url": "https://spydr.io/cve/CVE-2023-35311",
      "published": "2023-07-11T18:15:17.177Z",
      "modified": "2026-06-17T06:04:38.140Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.15522,
      "epss_percentile": 0.96723,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office LTSC 2021",
        "Microsoft Office 2019",
        "Microsoft Outlook 2016",
        "Microsoft Outlook 2013",
        "Microsoft Outlook 2013 Service Pack 1"
      ],
      "cwes": [
        "CWE-367"
      ],
      "description": "Microsoft Outlook Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-32049",
      "url": "https://spydr.io/cve/CVE-2023-32049",
      "published": "2023-07-11T18:15:13.430Z",
      "modified": "2026-06-17T05:57:57.393Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04156,
      "epss_percentile": 0.90585,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-32046",
      "url": "https://spydr.io/cve/CVE-2023-32046",
      "published": "2023-07-11T18:15:13.313Z",
      "modified": "2026-06-17T05:57:57.037Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.10049,
      "epss_percentile": 0.95504,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows MSHTML Platform Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-31199",
      "url": "https://spydr.io/cve/CVE-2022-31199",
      "published": "2022-11-08T01:15:09.767Z",
      "modified": "2026-06-17T04:45:01.133Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.36009,
      "epss_percentile": 0.98436,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netwrix"
      ],
      "products": [
        "netwrix auditor"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors."
    },
    {
      "id": "CVE-2021-29256",
      "url": "https://spydr.io/cve/CVE-2021-29256",
      "published": "2021-05-24T18:15:08.033Z",
      "modified": "2026-06-17T03:47:27.647Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02988,
      "epss_percentile": 0.86887,
      "exploited": true,
      "kev": {
        "added": "2023-07-07",
        "due": "2023-07-28",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": ". The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0."
    },
    {
      "id": "CVE-2021-25489",
      "url": "https://spydr.io/cve/CVE-2021-25489",
      "published": "2021-10-06T18:15:09.667Z",
      "modified": "2026-06-17T03:42:10.737Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.00531,
      "epss_percentile": 0.42964,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-20",
        "CWE-134"
      ],
      "description": "Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic."
    },
    {
      "id": "CVE-2021-25487",
      "url": "https://spydr.io/cve/CVE-2021-25487",
      "published": "2021-10-06T18:15:09.567Z",
      "modified": "2026-06-17T03:42:10.500Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00635,
      "epss_percentile": 0.48724,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer."
    },
    {
      "id": "CVE-2021-25395",
      "url": "https://spydr.io/cve/CVE-2021-25395",
      "published": "2021-06-11T15:15:09.030Z",
      "modified": "2026-06-17T03:42:00.387Z",
      "score": 6.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00366,
      "epss_percentile": 0.28309,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised."
    },
    {
      "id": "CVE-2021-25394",
      "url": "https://spydr.io/cve/CVE-2021-25394",
      "published": "2021-06-11T15:15:08.957Z",
      "modified": "2026-06-17T03:42:00.260Z",
      "score": 6.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00401,
      "epss_percentile": 0.32171,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-416",
        "CWE-362"
      ],
      "description": "A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised."
    },
    {
      "id": "CVE-2021-25372",
      "url": "https://spydr.io/cve/CVE-2021-25372",
      "published": "2021-03-26T19:15:12.303Z",
      "modified": "2026-06-17T03:41:57.807Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00804,
      "epss_percentile": 0.55313,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-787",
        "CWE-703"
      ],
      "description": "An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access."
    },
    {
      "id": "CVE-2021-25371",
      "url": "https://spydr.io/cve/CVE-2021-25371",
      "published": "2021-03-26T19:15:12.227Z",
      "modified": "2026-06-17T03:41:57.673Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00802,
      "epss_percentile": 0.55207,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-912"
      ],
      "description": "A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP."
    },
    {
      "id": "CVE-2019-20500",
      "url": "https://spydr.io/cve/CVE-2019-20500",
      "published": "2020-03-05T15:15:11.253Z",
      "modified": "2026-06-17T02:30:35.163Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97109,
      "epss_percentile": 0.99893,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dwl-2600ap firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter."
    },
    {
      "id": "CVE-2019-17621",
      "url": "https://spydr.io/cve/CVE-2019-17621",
      "published": "2019-12-30T17:15:19.857Z",
      "modified": "2026-06-17T02:24:17.420Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89624,
      "epss_percentile": 0.99786,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-859 firmware",
        "dlink dir-822 firmware",
        "dlink dir-823 firmware",
        "dlink dir-865l firmware",
        "dlink dir-868l firmware",
        "dlink dir-869 firmware",
        "dlink dir-880l firmware",
        "dlink dir-890l firmware",
        "dlink dir-890r firmware",
        "dlink dir-885l firmware",
        "dlink dir-885r firmware",
        "dlink dir-895l firmware",
        "dlink dir-895r firmware",
        "dlink dir-818lx firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network."
    },
    {
      "id": "CVE-2023-32439",
      "url": "https://spydr.io/cve/CVE-2023-32439",
      "published": "2023-06-23T18:15:13.813Z",
      "modified": "2026-06-17T05:58:50.663Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23968,
      "epss_percentile": 0.97782,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple Safari",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
