{
  "query": {
    "kev": "1",
    "page": "40"
  },
  "count": 20,
  "total": 1734,
  "page": 40,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T18:47:59.881Z",
    "kev": "2026-10-07T18:48:32.700Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T18:47:59.881Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=40",
    "next": "https://spydr.io/threats.json?kev=1&page=41"
  },
  "coverage": {
    "cves_published_since": "2026-06-09",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-32435",
      "url": "https://spydr.io/cve/CVE-2023-32435",
      "published": "2023-06-23T18:15:13.767Z",
      "modified": "2026-06-17T05:58:50.090Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22951,
      "epss_percentile": 0.97698,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple Safari"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7."
    },
    {
      "id": "CVE-2023-32434",
      "url": "https://spydr.io/cve/CVE-2023-32434",
      "published": "2023-06-23T18:15:13.720Z",
      "modified": "2026-06-17T05:58:49.887Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.51517,
      "epss_percentile": 0.98917,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple iOS and iPadOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7."
    },
    {
      "id": "CVE-2023-27992",
      "url": "https://spydr.io/cve/CVE-2023-27992",
      "published": "2023-06-19T12:15:09.433Z",
      "modified": "2026-06-17T05:46:20.047Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.82828,
      "epss_percentile": 0.99665,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel NAS326 firmware",
        "Zyxel NAS540 firmware",
        "Zyxel NAS542 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request."
    },
    {
      "id": "CVE-2023-20867",
      "url": "https://spydr.io/cve/CVE-2023-20867",
      "published": "2023-06-13T17:15:14.070Z",
      "modified": "2026-06-17T05:31:03.380Z",
      "score": 3.9,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.1353,
      "epss_percentile": 0.96361,
      "exploited": true,
      "kev": {
        "added": "2023-06-23",
        "due": "2023-07-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware Tools"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine."
    },
    {
      "id": "CVE-2023-20887",
      "url": "https://spydr.io/cve/CVE-2023-20887",
      "published": "2023-06-07T15:15:09.190Z",
      "modified": "2026-06-17T05:31:07.117Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98281,
      "epss_percentile": 0.99915,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "Aria Operations for Networks (Formerly vRealize Network Insight)"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution."
    },
    {
      "id": "CVE-2021-44026",
      "url": "https://spydr.io/cve/CVE-2021-44026",
      "published": "2021-11-19T04:15:07.197Z",
      "modified": "2026-06-17T04:11:48.777Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.69882,
      "epss_percentile": 0.99359,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "fedoraproject",
        "debian"
      ],
      "products": [
        "roundcube webmail",
        "fedoraproject fedora",
        "debian linux"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params."
    },
    {
      "id": "CVE-2020-35730",
      "url": "https://spydr.io/cve/CVE-2020-35730",
      "published": "2020-12-28T20:15:13.150Z",
      "modified": "2026-06-17T03:14:12.273Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.3292,
      "epss_percentile": 0.9832,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "fedoraproject",
        "debian"
      ],
      "products": [
        "roundcube webmail",
        "fedoraproject fedora",
        "debian linux"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php."
    },
    {
      "id": "CVE-2020-12641",
      "url": "https://spydr.io/cve/CVE-2020-12641",
      "published": "2020-05-04T15:15:14.417Z",
      "modified": "2026-06-17T02:52:03.327Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84336,
      "epss_percentile": 0.99695,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "opensuse"
      ],
      "products": [
        "roundcube webmail",
        "opensuse backports sle",
        "opensuse leap"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path."
    },
    {
      "id": "CVE-2016-9079",
      "url": "https://spydr.io/cve/CVE-2016-9079",
      "published": "2018-06-11T21:29:01.797Z",
      "modified": "2026-06-17T00:55:29.057Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.87536,
      "epss_percentile": 0.99757,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1."
    },
    {
      "id": "CVE-2016-0165",
      "url": "https://spydr.io/cve/CVE-2016-0165",
      "published": "2016-04-12T23:59:28.303Z",
      "modified": "2026-06-17T00:37:02.613Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13732,
      "epss_percentile": 0.96415,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0167."
    },
    {
      "id": "CVE-2023-27997",
      "url": "https://spydr.io/cve/CVE-2023-27997",
      "published": "2023-06-13T09:15:16.613Z",
      "modified": "2026-07-31T04:16:43.707Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85689,
      "epss_percentile": 0.99721,
      "exploited": true,
      "kev": {
        "added": "2023-06-13",
        "due": "2023-07-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS-6K7K",
        "Fortinet FortiProxy",
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests."
    },
    {
      "id": "CVE-2023-3079",
      "url": "https://spydr.io/cve/CVE-2023-3079",
      "published": "2023-06-05T22:15:12.383Z",
      "modified": "2026-06-17T06:13:18.817Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3211,
      "epss_percentile": 0.98278,
      "exploited": true,
      "kev": {
        "added": "2023-06-07",
        "due": "2023-06-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2023-33010",
      "url": "https://spydr.io/cve/CVE-2023-33010",
      "published": "2023-05-24T13:15:09.640Z",
      "modified": "2026-06-17T06:00:17.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29024,
      "epss_percentile": 0.98121,
      "exploited": true,
      "kev": {
        "added": "2023-06-05",
        "due": "2023-06-26",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ATP series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel USG FLEX 50(W) firmware",
        "Zyxel USG20(W)-VPN firmware",
        "Zyxel VPN series firmware",
        "Zyxel ZyWALL/USG series firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device."
    },
    {
      "id": "CVE-2023-33009",
      "url": "https://spydr.io/cve/CVE-2023-33009",
      "published": "2023-05-24T13:15:09.560Z",
      "modified": "2026-06-17T06:00:16.810Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.28144,
      "epss_percentile": 0.98068,
      "exploited": true,
      "kev": {
        "added": "2023-06-05",
        "due": "2023-06-26",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ATP series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel USG FLEX 50(W) firmware",
        "Zyxel USG20(W)-VPN firmware",
        "Zyxel VPN series firmware",
        "Zyxel ZyWALL/USG series firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device."
    },
    {
      "id": "CVE-2023-34362",
      "url": "https://spydr.io/cve/CVE-2023-34362",
      "published": "2023-06-02T14:15:09.487Z",
      "modified": "2026-06-17T06:03:28.760Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99934,
      "epss_percentile": 0.99971,
      "exploited": true,
      "kev": {
        "added": "2023-06-02",
        "due": "2023-06-23",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "progress"
      ],
      "products": [
        "progress moveit_transfer",
        "progress moveit_cloud"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions."
    },
    {
      "id": "CVE-2023-28771",
      "url": "https://spydr.io/cve/CVE-2023-28771",
      "published": "2023-04-25T02:15:08.743Z",
      "modified": "2026-06-17T05:48:44.217Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "zyxel.com.tw",
      "epss": 0.99284,
      "epss_percentile": 0.99937,
      "exploited": true,
      "kev": {
        "added": "2023-05-31",
        "due": "2023-06-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel ZyWALL/USG series firmware",
        "Zyxel VPN series firmware",
        "Zyxel USG FLEX series firmware",
        "Zyxel ATP series firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device."
    },
    {
      "id": "CVE-2023-2868",
      "url": "https://spydr.io/cve/CVE-2023-2868",
      "published": "2023-05-24T19:15:09.363Z",
      "modified": "2026-06-17T05:53:39.770Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87691,
      "epss_percentile": 0.99758,
      "exploited": true,
      "kev": {
        "added": "2023-05-26",
        "due": "2023-06-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Barracuda"
      ],
      "products": [
        "Barracuda Email Security Gateway"
      ],
      "cwes": [
        "CWE-20",
        "CWE-77"
      ],
      "description": "A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances."
    },
    {
      "id": "CVE-2023-32409",
      "url": "https://spydr.io/cve/CVE-2023-32409",
      "published": "2023-06-23T18:15:13.183Z",
      "modified": "2026-06-17T05:58:47.027Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.1653,
      "epss_percentile": 0.96929,
      "exploited": true,
      "kev": {
        "added": "2023-05-22",
        "due": "2023-06-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple tvOS"
      ],
      "cwes": [],
      "description": "The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-32373",
      "url": "https://spydr.io/cve/CVE-2023-32373",
      "published": "2023-06-23T18:15:12.007Z",
      "modified": "2026-06-17T05:58:42.273Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12172,
      "epss_percentile": 0.96061,
      "exploited": true,
      "kev": {
        "added": "2023-05-22",
        "due": "2023-06-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-28204",
      "url": "https://spydr.io/cve/CVE-2023-28204",
      "published": "2023-06-23T18:15:11.333Z",
      "modified": "2026-06-17T05:47:05.880Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.14292,
      "epss_percentile": 0.96518,
      "exploited": true,
      "kev": {
        "added": "2023-05-22",
        "due": "2023-06-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple Safari",
        "Apple watchOS",
        "Apple iOS and iPadOS",
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
