{
  "query": {
    "kev": "1",
    "page": "55"
  },
  "count": 20,
  "total": 1734,
  "page": 55,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T08:49:00.339Z",
    "kev": "2026-10-08T08:50:00.134Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T06:48:55.302Z",
    "posts": "2026-10-08T08:49:00.339Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=55",
    "next": "https://spydr.io/threats.json?kev=1&page=56"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-29464",
      "url": "https://spydr.io/cve/CVE-2022-29464",
      "published": "2022-04-18T22:15:09.027Z",
      "modified": "2026-06-17T04:40:13.993Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99992,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wso2"
      ],
      "products": [
        "wso2 api manager",
        "wso2 enterprise integrator",
        "wso2 identity server",
        "wso2 identity server analytics",
        "wso2 identity server as key manager",
        "wso2 open banking am",
        "wso2 open banking iam",
        "wso2 open banking km"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0."
    },
    {
      "id": "CVE-2022-26904",
      "url": "https://spydr.io/cve/CVE-2022-26904",
      "published": "2022-04-15T19:15:15.027Z",
      "modified": "2026-06-17T04:36:05.480Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.16948,
      "epss_percentile": 0.96993,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Windows User Profile Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-0847",
      "url": "https://spydr.io/cve/CVE-2022-0847",
      "published": "2022-03-10T17:44:57.283Z",
      "modified": "2026-06-17T04:21:21.750Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92795,
      "epss_percentile": 0.99829,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "fedoraproject",
        "redhat",
        "ovirt",
        "netapp",
        "siemens",
        "sonicwall"
      ],
      "products": [
        "kernel"
      ],
      "cwes": [
        "CWE-665"
      ],
      "description": "A flaw was found in the way the \"flags\" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system."
    },
    {
      "id": "CVE-2022-21919",
      "url": "https://spydr.io/cve/CVE-2022-21919",
      "published": "2022-01-11T21:15:13.463Z",
      "modified": "2026-06-17T04:27:16.930Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02434,
      "epss_percentile": 0.83769,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows User Profile Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-41357",
      "url": "https://spydr.io/cve/CVE-2021-41357",
      "published": "2021-10-13T01:15:13.950Z",
      "modified": "2026-06-17T04:08:24.537Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01582,
      "epss_percentile": 0.74778,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2"
      ],
      "cwes": [],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-40450",
      "url": "https://spydr.io/cve/CVE-2021-40450",
      "published": "2021-10-13T01:15:09.750Z",
      "modified": "2026-06-17T04:06:56.627Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01582,
      "epss_percentile": 0.74778,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2"
      ],
      "cwes": [],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2019-1003029",
      "url": "https://spydr.io/cve/CVE-2019-1003029",
      "published": "2019-03-08T21:29:00.297Z",
      "modified": "2026-06-17T02:09:34.290Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7444,
      "epss_percentile": 0.99484,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Jenkins project"
      ],
      "products": [
        "Jenkins project Jenkins Script Security Plugin"
      ],
      "cwes": [],
      "description": "A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM."
    },
    {
      "id": "CVE-2022-22718",
      "url": "https://spydr.io/cve/CVE-2022-22718",
      "published": "2022-02-09T17:15:10.280Z",
      "modified": "2026-06-17T04:28:51.470Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.18464,
      "epss_percentile": 0.97176,
      "exploited": true,
      "kev": {
        "added": "2022-04-19",
        "due": "2022-05-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [],
      "description": "Windows Print Spooler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2019-3568",
      "url": "https://spydr.io/cve/CVE-2019-3568",
      "published": "2019-05-14T20:29:03.187Z",
      "modified": "2026-06-17T02:35:14.707Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.30076,
      "epss_percentile": 0.98175,
      "exploited": true,
      "kev": {
        "added": "2022-04-19",
        "due": "2022-05-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Facebook"
      ],
      "products": [
        "Facebook WhatsApp for Android",
        "Facebook WhatsApp Business for Android",
        "Facebook WhatsApp for iOS",
        "Facebook WhatsApp Business for iOS",
        "Facebook WhatsApp for Windows Phone",
        "Facebook WhatsApp for Tizen"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15."
    },
    {
      "id": "CVE-2018-6882",
      "url": "https://spydr.io/cve/CVE-2018-6882",
      "published": "2018-03-27T16:29:00.530Z",
      "modified": "2026-10-01T20:17:17.443Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.29761,
      "epss_percentile": 0.98159,
      "exploited": true,
      "kev": {
        "added": "2022-04-19",
        "due": "2022-05-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment."
    },
    {
      "id": "CVE-2022-1364",
      "url": "https://spydr.io/cve/CVE-2022-1364",
      "published": "2022-07-26T22:15:09.147Z",
      "modified": "2026-06-17T04:22:17.713Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1372,
      "epss_percentile": 0.96413,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-22960",
      "url": "https://spydr.io/cve/CVE-2022-22960",
      "published": "2022-04-13T18:15:13.510Z",
      "modified": "2026-06-17T04:29:14.960Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.35519,
      "epss_percentile": 0.98419,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware Workspace ONE Access, Identity Manager and vRealize Automation"
      ],
      "cwes": [
        "CWE-732"
      ],
      "description": "VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'."
    },
    {
      "id": "CVE-2019-16057",
      "url": "https://spydr.io/cve/CVE-2019-16057",
      "published": "2019-09-16T12:15:10.910Z",
      "modified": "2026-06-17T02:21:36.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86491,
      "epss_percentile": 0.99734,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dns-320 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection."
    },
    {
      "id": "CVE-2010-5330",
      "url": "https://spydr.io/cve/CVE-2010-5330",
      "published": "2019-06-11T21:29:00.350Z",
      "modified": "2026-06-16T23:26:34.420Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39362,
      "epss_percentile": 0.98573,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ui"
      ],
      "products": [
        "ui airos"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected."
    },
    {
      "id": "CVE-2018-7841",
      "url": "https://spydr.io/cve/CVE-2018-7841",
      "published": "2019-05-22T20:29:01.480Z",
      "modified": "2026-06-17T02:03:50.500Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72675,
      "epss_percentile": 0.99434,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "U.motion"
      ],
      "products": [
        "U.motion Builder software version 1.3.4"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered."
    },
    {
      "id": "CVE-2019-3929",
      "url": "https://spydr.io/cve/CVE-2019-3929",
      "published": "2019-04-30T21:29:00.713Z",
      "modified": "2026-06-17T02:35:52.860Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98952,
      "epss_percentile": 0.99929,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Crestron"
      ],
      "products": [
        "Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4."
      ],
      "cwes": [
        "CWE-79",
        "CWE-78"
      ],
      "description": "The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware 1.4.2.3, Optoma WPS-Pro firmware 1.0.0.5, Blackbox HD WPS firmware 1.0.0.5, InFocus LiteShow3 firmware 1.0.16, and InFocus LiteShow4 2.0.0.7 are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root."
    },
    {
      "id": "CVE-2016-4523",
      "url": "https://spydr.io/cve/CVE-2016-4523",
      "published": "2016-06-09T10:59:04.073Z",
      "modified": "2026-06-17T00:47:42.740Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.31167,
      "epss_percentile": 0.98232,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "trihedral"
      ],
      "products": [
        "trihedral vtscada"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors."
    },
    {
      "id": "CVE-2014-0780",
      "url": "https://spydr.io/cve/CVE-2014-0780",
      "published": "2014-04-25T05:12:07.787Z",
      "modified": "2026-06-17T00:03:37.613Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74679,
      "epss_percentile": 0.99492,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "InduSoft"
      ],
      "products": [
        "InduSoft Web Studio"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests."
    },
    {
      "id": "CVE-2007-3010",
      "url": "https://spydr.io/cve/CVE-2007-3010",
      "published": "2007-09-18T21:17:00.000Z",
      "modified": "2026-06-16T22:40:52.660Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97385,
      "epss_percentile": 0.99898,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "al-enterprise"
      ],
      "products": [
        "al-enterprise omnipcx enterprise communication server"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action."
    },
    {
      "id": "CVE-2022-22954",
      "url": "https://spydr.io/cve/CVE-2022-22954",
      "published": "2022-04-11T20:15:19.890Z",
      "modified": "2026-06-17T04:29:14.263Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99998,
      "epss_percentile": 0.9999,
      "exploited": true,
      "kev": {
        "added": "2022-04-14",
        "due": "2022-05-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware Workspace ONE Access and Identity Manager"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
