{
  "query": {
    "kev": "1",
    "page": "42"
  },
  "count": 20,
  "total": 1734,
  "page": 42,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T20:48:31.249Z",
    "kev": "2026-10-07T20:49:30.912Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T20:48:31.249Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=42",
    "next": "https://spydr.io/threats.json?kev=1&page=43"
  },
  "coverage": {
    "cves_published_since": "2026-06-09",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-29492",
      "url": "https://spydr.io/cve/CVE-2023-29492",
      "published": "2023-04-11T05:15:07.393Z",
      "modified": "2026-06-17T05:50:13.017Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0269,
      "epss_percentile": 0.85426,
      "exploited": true,
      "kev": {
        "added": "2023-04-13",
        "due": "2023-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "novisurvey"
      ],
      "products": [
        "novisurvey novi_survey"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data."
    },
    {
      "id": "CVE-2023-20963",
      "url": "https://spydr.io/cve/CVE-2023-20963",
      "published": "2023-03-24T20:15:10.010Z",
      "modified": "2026-06-17T05:31:19.720Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01465,
      "epss_percentile": 0.72871,
      "exploited": true,
      "kev": {
        "added": "2023-04-13",
        "due": "2023-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-295"
      ],
      "description": "In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519"
    },
    {
      "id": "CVE-2023-28252",
      "url": "https://spydr.io/cve/CVE-2023-28252",
      "published": "2023-04-11T21:15:25.137Z",
      "modified": "2026-06-17T05:47:14.567Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.48973,
      "epss_percentile": 0.98853,
      "exploited": true,
      "kev": {
        "added": "2023-04-11",
        "due": "2023-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-28206",
      "url": "https://spydr.io/cve/CVE-2023-28206",
      "published": "2023-04-10T19:15:07.273Z",
      "modified": "2026-06-17T05:47:06.300Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23215,
      "epss_percentile": 0.97722,
      "exploited": true,
      "kev": {
        "added": "2023-04-10",
        "due": "2023-05-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-28205",
      "url": "https://spydr.io/cve/CVE-2023-28205",
      "published": "2023-04-10T19:15:07.237Z",
      "modified": "2026-06-17T05:47:06.097Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.27076,
      "epss_percentile": 0.98003,
      "exploited": true,
      "kev": {
        "added": "2023-04-10",
        "due": "2023-05-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple Safari",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-26083",
      "url": "https://spydr.io/cve/CVE-2023-26083",
      "published": "2023-04-06T16:15:07.843Z",
      "modified": "2026-06-17T05:42:38.457Z",
      "score": 3.3,
      "severity": "low",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01218,
      "epss_percentile": 0.67701,
      "exploited": true,
      "kev": {
        "added": "2023-04-07",
        "due": "2023-04-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm 5th gen gpu architecture kernel driver",
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-401"
      ],
      "description": "Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from r41p0 - r42p0 allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata."
    },
    {
      "id": "CVE-2021-27878",
      "url": "https://spydr.io/cve/CVE-2021-27878",
      "published": "2021-03-01T22:15:14.537Z",
      "modified": "2026-06-17T03:45:33.063Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23952,
      "epss_percentile": 0.97783,
      "exploited": true,
      "kev": {
        "added": "2023-04-07",
        "due": "2023-04-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veritas"
      ],
      "products": [
        "veritas backup exec"
      ],
      "cwes": [],
      "description": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges."
    },
    {
      "id": "CVE-2021-27877",
      "url": "https://spydr.io/cve/CVE-2021-27877",
      "published": "2021-03-01T22:15:14.460Z",
      "modified": "2026-06-17T03:45:32.920Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.6491,
      "epss_percentile": 0.99233,
      "exploited": true,
      "kev": {
        "added": "2023-04-07",
        "due": "2023-04-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veritas"
      ],
      "products": [
        "veritas backup exec"
      ],
      "cwes": [],
      "description": "An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands."
    },
    {
      "id": "CVE-2021-27876",
      "url": "https://spydr.io/cve/CVE-2021-27876",
      "published": "2021-03-01T22:15:14.350Z",
      "modified": "2026-06-17T03:45:32.780Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.13518,
      "epss_percentile": 0.96357,
      "exploited": true,
      "kev": {
        "added": "2023-04-07",
        "due": "2023-04-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veritas"
      ],
      "products": [
        "veritas backup exec"
      ],
      "cwes": [],
      "description": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges."
    },
    {
      "id": "CVE-2019-1388",
      "url": "https://spydr.io/cve/CVE-2019-1388",
      "published": "2019-11-12T19:15:12.583Z",
      "modified": "2026-06-17T02:28:30.783Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08589,
      "epss_percentile": 0.94951,
      "exploited": true,
      "kev": {
        "added": "2023-04-07",
        "due": "2023-04-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2022-27926",
      "url": "https://spydr.io/cve/CVE-2022-27926",
      "published": "2022-04-21T00:15:08.450Z",
      "modified": "2026-06-17T04:37:45.020Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.17634,
      "epss_percentile": 0.97081,
      "exploited": true,
      "kev": {
        "added": "2023-04-03",
        "due": "2023-04-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters."
    },
    {
      "id": "CVE-2022-42948",
      "url": "https://spydr.io/cve/CVE-2022-42948",
      "published": "2023-03-24T14:15:09.927Z",
      "modified": "2026-06-17T05:05:39.117Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02706,
      "epss_percentile": 0.85518,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "helpsystems"
      ],
      "products": [
        "helpsystems cobalt strike"
      ],
      "cwes": [
        "CWE-116"
      ],
      "description": "Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI."
    },
    {
      "id": "CVE-2023-0266",
      "url": "https://spydr.io/cve/CVE-2023-0266",
      "published": "2023-01-30T14:15:10.500Z",
      "modified": "2026-06-17T05:25:09.763Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03702,
      "epss_percentile": 0.89439,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux Kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e"
    },
    {
      "id": "CVE-2022-38181",
      "url": "https://spydr.io/cve/CVE-2022-38181",
      "published": "2022-10-25T19:15:11.487Z",
      "modified": "2026-06-17T04:56:14.803Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14093,
      "epss_percentile": 0.96478,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0."
    },
    {
      "id": "CVE-2022-3038",
      "url": "https://spydr.io/cve/CVE-2022-3038",
      "published": "2022-09-26T16:15:11.793Z",
      "modified": "2026-06-17T04:58:41.230Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24925,
      "epss_percentile": 0.97864,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "fedoraproject"
      ],
      "products": [
        "Google Chrome",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-39197",
      "url": "https://spydr.io/cve/CVE-2022-39197",
      "published": "2022-09-22T01:15:11.963Z",
      "modified": "2026-06-17T04:57:53.710Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.46446,
      "epss_percentile": 0.9879,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "helpsystems"
      ],
      "products": [
        "helpsystems cobalt strike"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed)."
    },
    {
      "id": "CVE-2022-22706",
      "url": "https://spydr.io/cve/CVE-2022-22706",
      "published": "2022-03-03T15:15:08.610Z",
      "modified": "2026-06-17T04:28:50.043Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01062,
      "epss_percentile": 0.63542,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0."
    },
    {
      "id": "CVE-2021-30900",
      "url": "https://spydr.io/cve/CVE-2021-30900",
      "published": "2021-08-24T19:15:18.083Z",
      "modified": "2026-06-17T03:51:06.180Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05204,
      "epss_percentile": 0.92266,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2017-7494",
      "url": "https://spydr.io/cve/CVE-2017-7494",
      "published": "2017-05-30T18:29:00.190Z",
      "modified": "2026-06-17T01:24:27.813Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99448,
      "epss_percentile": 0.99943,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samba"
      ],
      "products": [
        "samba"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it."
    },
    {
      "id": "CVE-2013-3163",
      "url": "https://spydr.io/cve/CVE-2013-3163",
      "published": "2013-07-10T03:46:10.527Z",
      "modified": "2026-06-16T23:54:37.740Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70676,
      "epss_percentile": 0.99382,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Internet Explorer Memory Corruption Vulnerability,\" a different vulnerability than CVE-2013-3144 and CVE-2013-3151."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
