{
  "query": {
    "kev": "1",
    "page": "46"
  },
  "count": 20,
  "total": 1734,
  "page": 46,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T22:48:36.014Z",
    "kev": "2026-10-07T23:49:38.149Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T23:48:38.351Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=46",
    "next": "https://spydr.io/threats.json?kev=1&page=47"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-41040",
      "url": "https://spydr.io/cve/CVE-2022-41040",
      "published": "2022-10-03T01:15:08.753Z",
      "modified": "2026-06-17T05:02:28.500Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99956,
      "epss_percentile": 0.99974,
      "exploited": true,
      "kev": {
        "added": "2022-09-30",
        "due": "2022-10-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12",
        "Microsoft Exchange Server 2016 Cumulative Update 23"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Microsoft Exchange Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-36804",
      "url": "https://spydr.io/cve/CVE-2022-36804",
      "published": "2022-08-25T06:15:09.077Z",
      "modified": "2026-06-17T04:54:00.640Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99174,
      "epss_percentile": 0.99934,
      "exploited": true,
      "kev": {
        "added": "2022-09-30",
        "due": "2022-10-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Bitbucket Server",
        "Atlassian Bitbucket Data Center"
      ],
      "cwes": [
        "CWE-78",
        "CWE-88"
      ],
      "description": "Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew."
    },
    {
      "id": "CVE-2022-3236",
      "url": "https://spydr.io/cve/CVE-2022-3236",
      "published": "2022-09-23T13:15:10.327Z",
      "modified": "2026-06-17T04:59:07.653Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98905,
      "epss_percentile": 0.99927,
      "exploited": true,
      "kev": {
        "added": "2022-09-23",
        "due": "2022-10-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sophos"
      ],
      "products": [
        "Sophos Firewall"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older."
    },
    {
      "id": "CVE-2022-35405",
      "url": "https://spydr.io/cve/CVE-2022-35405",
      "published": "2022-07-19T15:15:08.680Z",
      "modified": "2026-06-17T04:51:46.637Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99924,
      "epss_percentile": 0.99969,
      "exploited": true,
      "kev": {
        "added": "2022-09-22",
        "due": "2022-10-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine access manager plus",
        "zohocorp manageengine pam360",
        "zohocorp manageengine password manager pro"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)"
    },
    {
      "id": "CVE-2022-40139",
      "url": "https://spydr.io/cve/CVE-2022-40139",
      "published": "2022-09-19T18:15:09.960Z",
      "modified": "2026-06-17T05:01:01.087Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03291,
      "epss_percentile": 0.88138,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro"
      ],
      "products": [
        "Trend Micro Apex One"
      ],
      "cwes": [],
      "description": "Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability."
    },
    {
      "id": "CVE-2013-2597",
      "url": "https://spydr.io/cve/CVE-2013-2597",
      "published": "2014-08-31T10:55:03.753Z",
      "modified": "2026-06-16T23:53:41.697Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.01503,
      "epss_percentile": 0.73531,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "codeaurora"
      ],
      "products": [
        "codeaurora android-msm"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument."
    },
    {
      "id": "CVE-2013-6282",
      "url": "https://spydr.io/cve/CVE-2013-6282",
      "published": "2013-11-20T13:19:43.023Z",
      "modified": "2026-06-17T00:00:14.617Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39711,
      "epss_percentile": 0.98587,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux"
      ],
      "products": [
        "linux kernel"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013."
    },
    {
      "id": "CVE-2013-2094",
      "url": "https://spydr.io/cve/CVE-2013-2094",
      "published": "2013-05-14T20:55:01.527Z",
      "modified": "2026-06-16T23:52:44.150Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.47709,
      "epss_percentile": 0.98821,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux"
      ],
      "products": [
        "linux kernel"
      ],
      "cwes": [
        "CWE-189"
      ],
      "description": "The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call."
    },
    {
      "id": "CVE-2013-2596",
      "url": "https://spydr.io/cve/CVE-2013-2596",
      "published": "2013-04-13T02:59:46.627Z",
      "modified": "2026-06-16T23:53:41.450Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03212,
      "epss_percentile": 0.878,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "motorola"
      ],
      "products": [
        "linux kernel",
        "motorola android"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program."
    },
    {
      "id": "CVE-2010-2568",
      "url": "https://spydr.io/cve/CVE-2010-2568",
      "published": "2010-07-22T05:43:49.703Z",
      "modified": "2026-06-16T23:20:59.973Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.91324,
      "epss_percentile": 0.99811,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows vista",
        "microsoft windows xp"
      ],
      "cwes": [],
      "description": "Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems."
    },
    {
      "id": "CVE-2022-32917",
      "url": "https://spydr.io/cve/CVE-2022-32917",
      "published": "2022-09-20T21:15:11.200Z",
      "modified": "2026-06-17T04:48:12.837Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05603,
      "epss_percentile": 0.92704,
      "exploited": true,
      "kev": {
        "added": "2022-09-14",
        "due": "2022-10-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2022-37969",
      "url": "https://spydr.io/cve/CVE-2022-37969",
      "published": "2022-09-13T19:15:12.323Z",
      "modified": "2026-09-10T04:17:35.097Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.28275,
      "epss_percentile": 0.98076,
      "exploited": true,
      "kev": {
        "added": "2022-09-14",
        "due": "2022-10-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-3075",
      "url": "https://spydr.io/cve/CVE-2022-3075",
      "published": "2022-09-26T16:15:13.463Z",
      "modified": "2026-06-17T04:58:46.630Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05806,
      "epss_percentile": 0.92938,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page."
    },
    {
      "id": "CVE-2022-27593",
      "url": "https://spydr.io/cve/CVE-2022-27593",
      "published": "2022-09-08T11:15:19.503Z",
      "modified": "2026-06-17T04:37:19.550Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87908,
      "epss_percentile": 0.99762,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. Photo Station"
      ],
      "cwes": [
        "CWE-610"
      ],
      "description": "An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later"
    },
    {
      "id": "CVE-2022-26258",
      "url": "https://spydr.io/cve/CVE-2022-26258",
      "published": "2022-03-28T00:15:07.813Z",
      "modified": "2026-07-09T13:57:20.300Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91981,
      "epss_percentile": 0.99819,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-820l firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp."
    },
    {
      "id": "CVE-2020-9934",
      "url": "https://spydr.io/cve/CVE-2020-9934",
      "published": "2020-10-16T17:15:17.637Z",
      "modified": "2026-06-17T03:28:50.000Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.03208,
      "epss_percentile": 0.87781,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS"
      ],
      "cwes": [],
      "description": "An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information."
    },
    {
      "id": "CVE-2018-13374",
      "url": "https://spydr.io/cve/CVE-2018-13374",
      "published": "2019-01-22T14:29:00.220Z",
      "modified": "2026-10-01T19:17:13.713Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.38088,
      "epss_percentile": 0.98524,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, fortiADC"
      ],
      "cwes": [
        "CWE-732"
      ],
      "description": "A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one."
    },
    {
      "id": "CVE-2018-2628",
      "url": "https://spydr.io/cve/CVE-2018-2628",
      "published": "2018-04-19T02:29:00.457Z",
      "modified": "2026-06-17T01:55:57.647Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99958,
      "epss_percentile": 0.99975,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation WebLogic Server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2018-7445",
      "url": "https://spydr.io/cve/CVE-2018-7445",
      "published": "2018-03-19T21:29:01.083Z",
      "modified": "2026-06-17T02:03:08.460Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.60809,
      "epss_percentile": 0.99131,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mikrotik"
      ],
      "products": [
        "mikrotik routeros"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable."
    },
    {
      "id": "CVE-2018-6530",
      "url": "https://spydr.io/cve/CVE-2018-6530",
      "published": "2018-03-06T20:29:00.987Z",
      "modified": "2026-06-17T02:01:58.547Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96682,
      "epss_percentile": 0.99885,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-860l firmware",
        "dlink dir-865l firmware",
        "dlink dir-868l firmware",
        "dlink dir-880l firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
