{
  "query": {
    "kev": "1",
    "page": "54"
  },
  "count": 20,
  "total": 1734,
  "page": 54,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T06:48:55.607Z",
    "kev": "2026-10-08T07:49:57.657Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T06:48:55.302Z",
    "posts": "2026-10-08T07:48:57.797Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=54",
    "next": "https://spydr.io/threats.json?kev=1&page=55"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-7286",
      "url": "https://spydr.io/cve/CVE-2019-7286",
      "published": "2019-12-18T18:15:22.067Z",
      "modified": "2026-06-17T02:40:23.413Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.15939,
      "epss_percentile": 0.96818,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges."
    },
    {
      "id": "CVE-2019-13720",
      "url": "https://spydr.io/cve/CVE-2019-13720",
      "published": "2019-11-25T15:15:33.887Z",
      "modified": "2026-06-17T02:17:17.277Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.4914,
      "epss_percentile": 0.98857,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2019-1385",
      "url": "https://spydr.io/cve/CVE-2019-1385",
      "published": "2019-11-12T19:15:12.503Z",
      "modified": "2026-08-12T05:17:23.810Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03604,
      "epss_percentile": 0.89155,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-11708",
      "url": "https://spydr.io/cve/CVE-2019-11708",
      "published": "2019-07-23T14:15:15.327Z",
      "modified": "2026-06-17T02:13:28.273Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55874,
      "epss_percentile": 0.99023,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox ESR",
        "Mozilla Firefox",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2."
    },
    {
      "id": "CVE-2019-11707",
      "url": "https://spydr.io/cve/CVE-2019-11707",
      "published": "2019-07-23T14:15:15.233Z",
      "modified": "2026-06-17T02:13:28.073Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.37696,
      "epss_percentile": 0.98507,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox ESR",
        "Mozilla Firefox",
        "Mozilla Thunderbird"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2."
    },
    {
      "id": "CVE-2019-1130",
      "url": "https://spydr.io/cve/CVE-2019-1130",
      "published": "2019-07-15T19:15:21.047Z",
      "modified": "2026-08-12T05:17:23.177Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01719,
      "epss_percentile": 0.76753,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server",
        "Microsoft Windows",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129."
    },
    {
      "id": "CVE-2019-0880",
      "url": "https://spydr.io/cve/CVE-2019-0880",
      "published": "2019-07-15T19:15:15.687Z",
      "modified": "2026-06-17T02:09:06.100Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02289,
      "epss_percentile": 0.82679,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server",
        "Microsoft Windows",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-5786",
      "url": "https://spydr.io/cve/CVE-2019-5786",
      "published": "2019-06-27T17:15:13.770Z",
      "modified": "2026-06-17T02:38:12.210Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.61085,
      "epss_percentile": 0.99139,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page."
    },
    {
      "id": "CVE-2019-0703",
      "url": "https://spydr.io/cve/CVE-2019-0703",
      "published": "2019-04-09T00:29:00.887Z",
      "modified": "2026-06-17T02:08:43.507Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.0964,
      "epss_percentile": 0.95374,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server"
      ],
      "cwes": [],
      "description": "An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821."
    },
    {
      "id": "CVE-2019-0676",
      "url": "https://spydr.io/cve/CVE-2019-0676",
      "published": "2019-03-05T23:29:02.613Z",
      "modified": "2026-06-17T02:08:40.863Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.0811,
      "epss_percentile": 0.94691,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [],
      "description": "An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'."
    },
    {
      "id": "CVE-2018-8589",
      "url": "https://spydr.io/cve/CVE-2018-8589",
      "published": "2018-11-14T01:29:02.067Z",
      "modified": "2026-06-17T02:05:09.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03023,
      "epss_percentile": 0.87055,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008",
        "Microsoft Windows 7",
        "Microsoft Windows Server 2008 R2"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka \"Windows Win32k Elevation of Privilege Vulnerability.\" This affects Windows Server 2008, Windows 7, Windows Server 2008 R2."
    },
    {
      "id": "CVE-2018-5002",
      "url": "https://spydr.io/cve/CVE-2018-5002",
      "published": "2018-07-09T19:29:03.750Z",
      "modified": "2026-06-17T01:59:26.417Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.25059,
      "epss_percentile": 0.97875,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat"
      ],
      "products": [
        "Adobe Flash Player 29.0.0.171 and earlier versions"
      ],
      "cwes": [
        "CWE-787",
        "CWE-121"
      ],
      "description": "Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user."
    },
    {
      "id": "CVE-2022-30525",
      "url": "https://spydr.io/cve/CVE-2022-30525",
      "published": "2022-05-12T14:15:07.053Z",
      "modified": "2026-06-17T04:43:46.390Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99944,
      "epss_percentile": 0.99973,
      "exploited": true,
      "kev": {
        "added": "2022-05-16",
        "due": "2022-06-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel USG FLEX 100(W) firmware",
        "Zyxel USG FLEX 200 firmware",
        "Zyxel USG FLEX 500 firmware",
        "Zyxel USG FLEX 700 firmware",
        "Zyxel ATP series firmware",
        "Zyxel VPN series firmware",
        "Zyxel USG FLEX 50(W) firmware",
        "Zyxel USG 20(W)-VPN firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device."
    },
    {
      "id": "CVE-2022-22947",
      "url": "https://spydr.io/cve/CVE-2022-22947",
      "published": "2022-03-03T22:15:08.673Z",
      "modified": "2026-06-17T04:29:13.420Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98253,
      "epss_percentile": 0.99915,
      "exploited": true,
      "kev": {
        "added": "2022-05-16",
        "due": "2022-06-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware",
        "oracle"
      ],
      "products": [
        "Spring Cloud Gateway"
      ],
      "cwes": [
        "CWE-94",
        "CWE-917"
      ],
      "description": "In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host."
    },
    {
      "id": "CVE-2022-1388",
      "url": "https://spydr.io/cve/CVE-2022-1388",
      "published": "2022-05-05T17:15:10.570Z",
      "modified": "2026-06-17T04:22:20.683Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "f5.com",
      "epss": 0.99954,
      "epss_percentile": 0.99974,
      "exploited": true,
      "kev": {
        "added": "2022-05-10",
        "due": "2022-05-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated"
    },
    {
      "id": "CVE-2021-1789",
      "url": "https://spydr.io/cve/CVE-2021-1789",
      "published": "2021-04-02T18:15:21.747Z",
      "modified": "2026-06-17T03:32:33.900Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13975,
      "epss_percentile": 0.96461,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution."
    },
    {
      "id": "CVE-2019-8506",
      "url": "https://spydr.io/cve/CVE-2019-8506",
      "published": "2019-12-18T18:15:22.880Z",
      "modified": "2026-06-17T02:42:03.093Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.16159,
      "epss_percentile": 0.96856,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple tvOS",
        "Apple watchOS",
        "Apple Safari",
        "Apple iTunes for Windows",
        "Apple iCloud for Windows"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution."
    },
    {
      "id": "CVE-2014-4113",
      "url": "https://spydr.io/cve/CVE-2014-4113",
      "published": "2014-10-15T10:55:07.473Z",
      "modified": "2026-06-17T00:09:27.350Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.86928,
      "epss_percentile": 0.99745,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka \"Win32k.sys Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2014-0160",
      "url": "https://spydr.io/cve/CVE-2014-0160",
      "published": "2014-04-07T22:55:03.893Z",
      "modified": "2026-06-17T00:02:24.467Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99997,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "openssl",
        "filezilla-project",
        "siemens",
        "intellian",
        "mitel",
        "opensuse",
        "canonical",
        "fedoraproject",
        "redhat",
        "debian"
      ],
      "products": [
        "openssl",
        "filezilla-project filezilla server",
        "siemens application processing engine firmware",
        "siemens cp 1543-1 firmware",
        "siemens simatic s7-1500 firmware",
        "siemens simatic s7-1500t firmware",
        "siemens elan-8.2",
        "siemens wincc open architecture",
        "intellian v100 firmware",
        "intellian v60 firmware",
        "mitel micollab",
        "mitel mivoice",
        "opensuse",
        "canonical ubuntu linux",
        "fedoraproject fedora",
        "redhat gluster storage",
        "redhat storage",
        "redhat virtualization",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug."
    },
    {
      "id": "CVE-2014-0322",
      "url": "https://spydr.io/cve/CVE-2014-0322",
      "published": "2014-02-14T16:55:07.500Z",
      "modified": "2026-06-17T00:02:47.407Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85122,
      "epss_percentile": 0.99711,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
