{
  "query": {
    "kev": "1",
    "page": "49"
  },
  "count": 20,
  "total": 1734,
  "page": 49,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T02:48:45.529Z",
    "kev": "2026-10-08T02:49:45.513Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T02:48:45.528Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=49",
    "next": "https://spydr.io/threats.json?kev=1&page=50"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2016-2386",
      "url": "https://spydr.io/cve/CVE-2016-2386",
      "published": "2016-02-16T15:59:00.133Z",
      "modified": "2026-06-17T00:43:56.867Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.71522,
      "epss_percentile": 0.99405,
      "exploited": true,
      "kev": {
        "added": "2022-06-09",
        "due": "2022-06-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079."
    },
    {
      "id": "CVE-2019-7195",
      "url": "https://spydr.io/cve/CVE-2019-7195",
      "published": "2019-12-05T17:15:13.183Z",
      "modified": "2026-06-17T02:40:14.637Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89544,
      "epss_percentile": 0.99785,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qnap"
      ],
      "products": [
        "QNAP NAS devices running Photo Station"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions."
    },
    {
      "id": "CVE-2019-7194",
      "url": "https://spydr.io/cve/CVE-2019-7194",
      "published": "2019-12-05T17:15:13.107Z",
      "modified": "2026-06-17T02:40:14.473Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83124,
      "epss_percentile": 0.9967,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qnap"
      ],
      "products": [
        "QNAP NAS devices running Photo Station"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions."
    },
    {
      "id": "CVE-2019-7193",
      "url": "https://spydr.io/cve/CVE-2019-7193",
      "published": "2019-12-05T17:15:13.027Z",
      "modified": "2026-06-17T02:40:14.317Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14367,
      "epss_percentile": 0.96534,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qnap"
      ],
      "products": [
        "QNAP NAS devices"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions."
    },
    {
      "id": "CVE-2019-7192",
      "url": "https://spydr.io/cve/CVE-2019-7192",
      "published": "2019-12-05T17:15:12.950Z",
      "modified": "2026-06-17T02:40:14.153Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.88102,
      "epss_percentile": 0.99765,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "qnap"
      ],
      "products": [
        "QNAP NAS devices running Photo Station"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions."
    },
    {
      "id": "CVE-2019-15271",
      "url": "https://spydr.io/cve/CVE-2019-15271",
      "published": "2019-11-26T03:15:11.050Z",
      "modified": "2026-06-17T02:19:59.500Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05488,
      "epss_percentile": 0.92563,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges."
    },
    {
      "id": "CVE-2019-5825",
      "url": "https://spydr.io/cve/CVE-2019-5825",
      "published": "2019-11-25T20:15:11.483Z",
      "modified": "2026-06-17T02:38:16.623Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.55925,
      "epss_percentile": 0.99025,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2018-17480",
      "url": "https://spydr.io/cve/CVE-2018-17480",
      "published": "2018-12-11T16:29:00.623Z",
      "modified": "2026-06-17T01:45:56.153Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3564,
      "epss_percentile": 0.98424,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
    },
    {
      "id": "CVE-2018-6065",
      "url": "https://spydr.io/cve/CVE-2018-6065",
      "published": "2018-11-14T15:29:01.250Z",
      "modified": "2026-06-17T02:01:16.080Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.60304,
      "epss_percentile": 0.99121,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2018-17463",
      "url": "https://spydr.io/cve/CVE-2018-17463",
      "published": "2018-11-14T15:29:00.297Z",
      "modified": "2026-06-17T01:45:53.927Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84564,
      "epss_percentile": 0.99699,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [],
      "description": "Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
    },
    {
      "id": "CVE-2018-4990",
      "url": "https://spydr.io/cve/CVE-2018-4990",
      "published": "2018-07-09T19:29:03.327Z",
      "modified": "2026-06-17T01:59:25.090Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.36228,
      "epss_percentile": 0.98446,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions"
      ],
      "cwes": [
        "CWE-415"
      ],
      "description": "Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user."
    },
    {
      "id": "CVE-2017-5070",
      "url": "https://spydr.io/cve/CVE-2017-5070",
      "published": "2017-10-27T05:29:00.847Z",
      "modified": "2026-06-17T01:19:51.973Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.32071,
      "epss_percentile": 0.98275,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "redhat"
      ],
      "products": [
        "Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
    },
    {
      "id": "CVE-2017-6862",
      "url": "https://spydr.io/cve/CVE-2017-6862",
      "published": "2017-05-26T20:29:00.177Z",
      "modified": "2026-06-17T01:23:13.937Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.45748,
      "epss_percentile": 0.9877,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "NETGEAR All versions prior to WNR2000v3 1.1.2.14, WNR2000v4 1.0.0.66, WNR2000v5 1.0.0.42"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR ID is PSV-2016-0261."
    },
    {
      "id": "CVE-2017-5030",
      "url": "https://spydr.io/cve/CVE-2017-5030",
      "published": "2017-04-24T23:59:00.190Z",
      "modified": "2026-06-17T01:19:46.750Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.40635,
      "epss_percentile": 0.98618,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "debian",
        "redhat"
      ],
      "products": [
        "Google Chrome prior to 57.0.2987.98 for Linux, Windows and Mac, and 57.0.2987.108 for Android"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page."
    },
    {
      "id": "CVE-2016-5198",
      "url": "https://spydr.io/cve/CVE-2016-5198",
      "published": "2017-01-19T05:59:00.213Z",
      "modified": "2026-06-17T00:48:57.617Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34164,
      "epss_percentile": 0.98368,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "redhat"
      ],
      "products": [
        "Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page."
    },
    {
      "id": "CVE-2016-1646",
      "url": "https://spydr.io/cve/CVE-2016-1646",
      "published": "2016-03-29T10:59:00.160Z",
      "modified": "2026-06-17T00:42:19.940Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.4811,
      "epss_percentile": 0.98829,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "debian",
        "canonical",
        "google",
        "suse",
        "opensuse",
        "redhat"
      ],
      "products": [
        "debian linux",
        "canonical ubuntu linux",
        "google chrome",
        "suse package hub",
        "opensuse leap",
        "opensuse",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code."
    },
    {
      "id": "CVE-2013-1331",
      "url": "https://spydr.io/cve/CVE-2013-1331",
      "published": "2013-06-12T03:29:57.117Z",
      "modified": "2026-06-16T23:51:13.833Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.79822,
      "epss_percentile": 0.99604,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka \"Office Buffer Overflow Vulnerability.\""
    },
    {
      "id": "CVE-2012-5054",
      "url": "https://spydr.io/cve/CVE-2012-5054",
      "published": "2012-09-24T17:55:07.217Z",
      "modified": "2026-06-16T23:46:05.460Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21194,
      "epss_percentile": 0.97534,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments."
    },
    {
      "id": "CVE-2012-4969",
      "url": "https://spydr.io/cve/CVE-2012-4969",
      "published": "2012-09-18T10:39:14.147Z",
      "modified": "2026-06-16T23:45:58.897Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8025,
      "epss_percentile": 0.99613,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012."
    },
    {
      "id": "CVE-2012-1889",
      "url": "https://spydr.io/cve/CVE-2012-1889",
      "published": "2012-06-13T04:46:46.190Z",
      "modified": "2026-06-16T23:40:29.923Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83516,
      "epss_percentile": 0.9968,
      "exploited": true,
      "kev": {
        "added": "2022-06-08",
        "due": "2022-06-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft xml core services"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
