{
  "query": {
    "kev": "1",
    "page": "43"
  },
  "count": 20,
  "total": 1734,
  "page": 43,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T20:48:31.249Z",
    "kev": "2026-10-07T21:49:33.076Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T21:48:33.240Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=43",
    "next": "https://spydr.io/threats.json?kev=1&page=44"
  },
  "coverage": {
    "cves_published_since": "2026-06-09",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2023-26360",
      "url": "https://spydr.io/cve/CVE-2023-26360",
      "published": "2023-03-23T20:15:15.263Z",
      "modified": "2026-06-17T05:43:10.340Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
      "score_source": "adobe.com",
      "epss": 0.97339,
      "epss_percentile": 0.99898,
      "exploited": true,
      "kev": {
        "added": "2023-03-15",
        "due": "2023-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe ColdFusion"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction."
    },
    {
      "id": "CVE-2023-24880",
      "url": "https://spydr.io/cve/CVE-2023-24880",
      "published": "2023-03-14T17:15:17.683Z",
      "modified": "2026-06-17T05:40:10.753Z",
      "score": 4.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.78005,
      "epss_percentile": 0.99567,
      "exploited": true,
      "kev": {
        "added": "2023-03-14",
        "due": "2023-04-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-23397",
      "url": "https://spydr.io/cve/CVE-2023-23397",
      "published": "2023-03-14T17:15:13.263Z",
      "modified": "2026-06-17T05:37:01.380Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97159,
      "epss_percentile": 0.99894,
      "exploited": true,
      "kev": {
        "added": "2023-03-14",
        "due": "2023-04-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office LTSC 2021",
        "Microsoft Outlook 2016",
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Office 2019",
        "Microsoft Outlook 2013 Service Pack 1"
      ],
      "cwes": [
        "CWE-20",
        "CWE-294"
      ],
      "description": "Microsoft Outlook Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-41328",
      "url": "https://spydr.io/cve/CVE-2022-41328",
      "published": "2023-03-07T17:15:12.093Z",
      "modified": "2026-06-17T05:03:02.417Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.10682,
      "epss_percentile": 0.95704,
      "exploited": true,
      "kev": {
        "added": "2023-03-14",
        "due": "2023-04-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands."
    },
    {
      "id": "CVE-2021-39144",
      "url": "https://spydr.io/cve/CVE-2021-39144",
      "published": "2021-08-23T18:15:12.087Z",
      "modified": "2026-06-17T04:03:09.313Z",
      "score": 8.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98124,
      "epss_percentile": 0.99913,
      "exploited": true,
      "kev": {
        "added": "2023-03-10",
        "due": "2023-03-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "x-stream"
      ],
      "products": [
        "x-stream xstream"
      ],
      "cwes": [
        "CWE-94",
        "CWE-502",
        "CWE-306"
      ],
      "description": "XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose."
    },
    {
      "id": "CVE-2020-5741",
      "url": "https://spydr.io/cve/CVE-2020-5741",
      "published": "2020-05-08T13:15:11.137Z",
      "modified": "2026-06-17T03:22:09.140Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72936,
      "epss_percentile": 0.99441,
      "exploited": true,
      "kev": {
        "added": "2023-03-10",
        "due": "2023-03-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "plex"
      ],
      "products": [
        "Plex Media Server (Windows)"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code."
    },
    {
      "id": "CVE-2022-35914",
      "url": "https://spydr.io/cve/CVE-2022-35914",
      "published": "2022-09-19T16:15:11.253Z",
      "modified": "2026-06-17T04:52:30.600Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9988,
      "epss_percentile": 0.99965,
      "exploited": true,
      "kev": {
        "added": "2023-03-07",
        "due": "2023-03-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "glpi-project"
      ],
      "products": [
        "glpi-project glpi"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection."
    },
    {
      "id": "CVE-2022-33891",
      "url": "https://spydr.io/cve/CVE-2022-33891",
      "published": "2022-07-18T07:15:07.600Z",
      "modified": "2026-06-17T04:49:25.943Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93244,
      "epss_percentile": 0.99835,
      "exploited": true,
      "kev": {
        "added": "2023-03-07",
        "due": "2023-03-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Spark"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1."
    },
    {
      "id": "CVE-2022-28810",
      "url": "https://spydr.io/cve/CVE-2022-28810",
      "published": "2022-04-18T13:15:08.233Z",
      "modified": "2026-06-17T04:39:06.870Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70966,
      "epss_percentile": 0.99391,
      "exploited": true,
      "kev": {
        "added": "2023-03-07",
        "due": "2023-03-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine adselfservice plus"
      ],
      "cwes": [
        "CWE-78",
        "CWE-798"
      ],
      "description": "Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field."
    },
    {
      "id": "CVE-2022-36537",
      "url": "https://spydr.io/cve/CVE-2022-36537",
      "published": "2022-08-26T20:15:08.303Z",
      "modified": "2026-06-17T04:53:38.087Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.95397,
      "epss_percentile": 0.99869,
      "exploited": true,
      "kev": {
        "added": "2023-02-27",
        "due": "2023-03-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zkoss"
      ],
      "products": [
        "zkoss zk framework"
      ],
      "cwes": [],
      "description": "ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader."
    },
    {
      "id": "CVE-2022-47986",
      "url": "https://spydr.io/cve/CVE-2022-47986",
      "published": "2023-02-17T16:15:10.873Z",
      "modified": "2026-06-17T05:14:33.047Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99965,
      "epss_percentile": 0.99977,
      "exploited": true,
      "kev": {
        "added": "2023-02-21",
        "due": "2023-03-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "IBM"
      ],
      "products": [
        "IBM Aspera Faspex"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512."
    },
    {
      "id": "CVE-2022-41223",
      "url": "https://spydr.io/cve/CVE-2022-41223",
      "published": "2022-11-22T01:15:32.897Z",
      "modified": "2026-06-17T05:02:49.103Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10657,
      "epss_percentile": 0.95695,
      "exploited": true,
      "kev": {
        "added": "2023-02-21",
        "due": "2023-03-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel mivoice connect"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type."
    },
    {
      "id": "CVE-2022-40765",
      "url": "https://spydr.io/cve/CVE-2022-40765",
      "published": "2022-11-22T01:15:31.847Z",
      "modified": "2026-06-17T05:02:00.547Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10566,
      "epss_percentile": 0.95673,
      "exploited": true,
      "kev": {
        "added": "2023-02-21",
        "due": "2023-03-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel mivoice connect"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters."
    },
    {
      "id": "CVE-2022-46169",
      "url": "https://spydr.io/cve/CVE-2022-46169",
      "published": "2022-12-05T21:15:10.527Z",
      "modified": "2026-06-17T05:11:21.140Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99826,
      "epss_percentile": 0.9996,
      "exploited": true,
      "kev": {
        "added": "2023-02-16",
        "due": "2023-03-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cacti"
      ],
      "products": [
        "cacti"
      ],
      "cwes": [
        "CWE-74",
        "CWE-78",
        "CWE-863"
      ],
      "description": "Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti. The following call to `gethostbyaddr` will resolve this IP address to the hostname of the server, which will pass the `poller` hostname check because of the default entry. After the authorization of the `remote_agent.php` file is bypassed, an attacker can trigger different actions. One of these actions is called `polldata`. The called function `poll_for_data` retrieves a few request parameters and loads the corresponding `poller_item` entries from the database. If the `action` of a `poller_item` equals `POLLER_ACTION_SCRIPT_PHP`, the function `proc_open` is used to execute a PHP script. The attacker-controlled parameter `$poller_id` is retrieved via the function `get_nfilter_request_var`, which allows arbitrary strings. This variable is later inserted into the string passed to `proc_open`, which leads to a command injection vulnerability. By e.g. providing the `poller_id=;id` the `id` command is executed. In order to reach the vulnerable call, the attacker must provide a `host_id` and `local_data_id`, where the `action` of the corresponding `poller_item` is set to `POLLER_ACTION_SCRIPT_PHP`. Both of these ids (`host_id` and `local_data_id`) can easily be bruteforced. The only requirement is that a `poller_item` with an `POLLER_ACTION_SCRIPT_PHP` action exists. This is very likely on a productive instance because this action is added by some predefined templates like `Device - Uptime` or `Device - Polling Time`. This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a `poller_item` with the `action` type `POLLER_ACTION_SCRIPT_PHP` (`2`) is configured. The authorization bypass should be prevented by not allowing an attacker to make `get_client_addr` (file `lib/functions.php`) return an arbitrary IP address. This could be done by not honoring the `HTTP_...` `$_SERVER` variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with `1.2.23` being the first release containing the patch."
    },
    {
      "id": "CVE-2023-23529",
      "url": "https://spydr.io/cve/CVE-2023-23529",
      "published": "2023-02-27T20:15:14.710Z",
      "modified": "2026-06-17T05:37:21.160Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09502,
      "epss_percentile": 0.95327,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple Safari",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2023-21823",
      "url": "https://spydr.io/cve/CVE-2023-21823",
      "published": "2023-02-14T21:15:12.297Z",
      "modified": "2026-08-19T17:18:20.093Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.05563,
      "epss_percentile": 0.92649,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office for Android",
        "Microsoft Office for iOS",
        "Microsoft Office for Universal",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Windows Graphics Component Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-23376",
      "url": "https://spydr.io/cve/CVE-2023-23376",
      "published": "2023-02-14T20:15:16.907Z",
      "modified": "2026-08-19T17:18:20.433Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.10853,
      "epss_percentile": 0.95754,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-21715",
      "url": "https://spydr.io/cve/CVE-2023-21715",
      "published": "2023-02-14T20:15:14.280Z",
      "modified": "2026-08-19T17:18:12.137Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12011,
      "epss_percentile": 0.96034,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Microsoft Publisher Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2022-24990",
      "url": "https://spydr.io/cve/CVE-2022-24990",
      "published": "2023-02-07T18:15:09.100Z",
      "modified": "2026-06-17T04:32:54.773Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.83166,
      "epss_percentile": 0.99672,
      "exploited": true,
      "kev": {
        "added": "2023-02-10",
        "due": "2023-03-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "terra-master"
      ],
      "products": [
        "terra-master terramaster operating system"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending \"User-Agent: TNAS\" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response."
    },
    {
      "id": "CVE-2023-0669",
      "url": "https://spydr.io/cve/CVE-2023-0669",
      "published": "2023-02-06T20:15:14.300Z",
      "modified": "2026-08-06T05:16:38.057Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99996,
      "exploited": true,
      "kev": {
        "added": "2023-02-10",
        "due": "2023-03-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortra"
      ],
      "products": [
        "Fortra Goanywhere MFT"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
