{
  "query": {
    "kev": "1",
    "page": "60"
  },
  "count": 20,
  "total": 1734,
  "page": 60,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T12:49:09.674Z",
    "kev": "2026-10-08T13:50:11.773Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T13:49:11.704Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=60",
    "next": "https://spydr.io/threats.json?kev=1&page=61"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-16920",
      "url": "https://spydr.io/cve/CVE-2019-16920",
      "published": "2019-09-27T12:15:10.017Z",
      "modified": "2026-06-17T02:22:57.810Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99996,
      "epss_percentile": 0.99989,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-655 firmware",
        "dlink dir-866l firmware",
        "dlink dir-652 firmware",
        "dlink dhp-1565 firmware",
        "dlink dir-855l firmware",
        "dlink dap-1533 firmware",
        "dlink dir-862l firmware",
        "dlink dir-615 firmware",
        "dlink dir-835 firmware",
        "dlink dir-825 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a \"PingTest\" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825."
    },
    {
      "id": "CVE-2019-15107",
      "url": "https://spydr.io/cve/CVE-2019-15107",
      "published": "2019-08-16T03:15:11.387Z",
      "modified": "2026-08-06T05:16:35.140Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9971,
      "epss_percentile": 0.99951,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "webmin"
      ],
      "products": [
        "webmin"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability."
    },
    {
      "id": "CVE-2019-12991",
      "url": "https://spydr.io/cve/CVE-2019-12991",
      "published": "2019-07-16T18:15:13.117Z",
      "modified": "2026-06-17T02:15:52.457Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74052,
      "epss_percentile": 0.99475,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix netscaler sd-wan",
        "citrix sd-wan"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6)."
    },
    {
      "id": "CVE-2019-12989",
      "url": "https://spydr.io/cve/CVE-2019-12989",
      "published": "2019-07-16T18:15:12.930Z",
      "modified": "2026-06-17T02:15:52.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94957,
      "epss_percentile": 0.99862,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix netscaler sd-wan",
        "citrix sd-wan"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection."
    },
    {
      "id": "CVE-2019-0903",
      "url": "https://spydr.io/cve/CVE-2019-0903",
      "published": "2019-05-16T19:29:02.303Z",
      "modified": "2026-06-17T02:09:09.837Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.21713,
      "epss_percentile": 0.97581,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'."
    },
    {
      "id": "CVE-2018-14839",
      "url": "https://spydr.io/cve/CVE-2018-14839",
      "published": "2019-05-14T21:29:00.247Z",
      "modified": "2026-06-17T01:41:44.377Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89354,
      "epss_percentile": 0.99782,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "lg"
      ],
      "products": [
        "lg n1a1 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters."
    },
    {
      "id": "CVE-2019-2616",
      "url": "https://spydr.io/cve/CVE-2019-2616",
      "published": "2019-04-23T19:32:51.537Z",
      "modified": "2026-06-17T02:34:13.690Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.92183,
      "epss_percentile": 0.99821,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation BI Publisher (formerly XML Publisher)"
      ],
      "cwes": [],
      "description": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)."
    },
    {
      "id": "CVE-2019-10068",
      "url": "https://spydr.io/cve/CVE-2019-10068",
      "published": "2019-03-26T18:29:00.403Z",
      "modified": "2026-06-17T02:10:09.030Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95074,
      "epss_percentile": 0.99863,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "kentico"
      ],
      "products": [
        "kentico xperience"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted."
    },
    {
      "id": "CVE-2019-1003030",
      "url": "https://spydr.io/cve/CVE-2019-1003030",
      "published": "2019-03-08T21:29:00.343Z",
      "modified": "2026-06-17T02:09:34.493Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97058,
      "epss_percentile": 0.99892,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Jenkins project"
      ],
      "products": [
        "Jenkins project Jenkins Pipeline: Groovy Plugin"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM."
    },
    {
      "id": "CVE-2019-6340",
      "url": "https://spydr.io/cve/CVE-2019-6340",
      "published": "2019-02-21T21:29:00.343Z",
      "modified": "2026-06-17T02:39:02.497Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92017,
      "epss_percentile": 0.9982,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Drupal"
      ],
      "products": [
        "Drupal Core"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)"
    },
    {
      "id": "CVE-2018-8414",
      "url": "https://spydr.io/cve/CVE-2018-8414",
      "published": "2018-08-15T17:29:10.393Z",
      "modified": "2026-06-17T02:04:48.927Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72912,
      "epss_percentile": 0.99441,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Servers",
        "Microsoft Windows 10"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka \"Windows Shell Remote Code Execution Vulnerability.\" This affects Windows 10 Servers, Windows 10."
    },
    {
      "id": "CVE-2018-8373",
      "url": "https://spydr.io/cve/CVE-2018-8373",
      "published": "2018-08-15T17:29:06.673Z",
      "modified": "2026-06-17T02:04:43.443Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61912,
      "epss_percentile": 0.99156,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 9",
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting Engine Memory Corruption Vulnerability.\" This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390."
    },
    {
      "id": "CVE-2018-6961",
      "url": "https://spydr.io/cve/CVE-2018-6961",
      "published": "2018-06-11T22:29:00.230Z",
      "modified": "2026-06-17T02:02:31.090Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86252,
      "epss_percentile": 0.9973,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "VMware"
      ],
      "products": [
        "VMware NSX SD-WAN by VeloCloud"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution."
    },
    {
      "id": "CVE-2018-11138",
      "url": "https://spydr.io/cve/CVE-2018-11138",
      "published": "2018-05-31T18:29:00.557Z",
      "modified": "2026-08-13T05:17:15.700Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91719,
      "epss_percentile": 0.99815,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "quest"
      ],
      "products": [
        "quest kace system management appliance"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system."
    },
    {
      "id": "CVE-2018-1273",
      "url": "https://spydr.io/cve/CVE-2018-1273",
      "published": "2018-04-11T13:29:00.290Z",
      "modified": "2026-08-26T05:18:03.100Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96956,
      "epss_percentile": 0.9989,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Spring by Pivotal"
      ],
      "products": [
        "Spring by Pivotal Spring Framework"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack."
    },
    {
      "id": "CVE-2018-0147",
      "url": "https://spydr.io/cve/CVE-2018-0147",
      "published": "2018-03-08T07:29:00.377Z",
      "modified": "2026-06-17T01:29:56.093Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.18212,
      "epss_percentile": 0.97143,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco Secure Access Control System"
      ],
      "cwes": [
        "CWE-20",
        "CWE-502"
      ],
      "description": "A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges. Cisco Bug IDs: CSCvh25988."
    },
    {
      "id": "CVE-2018-0125",
      "url": "https://spydr.io/cve/CVE-2018-0125",
      "published": "2018-02-08T07:29:00.570Z",
      "modified": "2026-06-17T01:29:37.637Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55186,
      "epss_percentile": 0.99008,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco RV132W and RV134W"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an incomplete input validation on user-controlled input in an HTTP request to the targeted device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user and gain full control of the affected system or cause it to reload, resulting in a DoS condition. This vulnerability is fixed in firmware version 1.0.1.11 for the following Cisco products: RV132W ADSL2+ Wireless-N VPN Router and RV134W VDSL2 Wireless-AC VPN Router. Cisco Bug IDs: CSCvg92737, CSCvh60170."
    },
    {
      "id": "CVE-2017-12617",
      "url": "https://spydr.io/cve/CVE-2017-12617",
      "published": "2017-10-04T01:29:02.120Z",
      "modified": "2026-08-25T16:28:27.310Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99968,
      "epss_percentile": 0.99977,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Tomcat"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server."
    },
    {
      "id": "CVE-2015-1187",
      "url": "https://spydr.io/cve/CVE-2015-1187",
      "published": "2017-09-21T16:29:00.147Z",
      "modified": "2026-06-17T00:21:55.167Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82863,
      "epss_percentile": 0.99665,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink",
        "trendnet"
      ],
      "products": [
        "dlink dir-626l firmware",
        "dlink dir-636l firmware",
        "dlink dir-808l firmware",
        "dlink dir-810l firmware",
        "dlink dir-820l firmware",
        "dlink dir-826l firmware",
        "dlink dir-830l firmware",
        "dlink dir-836l firmware",
        "trendnet tew-731br firmware",
        "dlink dir-651 firmware",
        "trendnet tew-651br firmware",
        "trendnet tew-652br firmware",
        "trendnet tew-711br firmware",
        "trendnet tew-810dr firmware",
        "trendnet tew-813dru firmware"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp."
    },
    {
      "id": "CVE-2017-12615",
      "url": "https://spydr.io/cve/CVE-2017-12615",
      "published": "2017-09-19T13:29:00.190Z",
      "modified": "2026-08-06T05:16:34.690Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99641,
      "epss_percentile": 0.99949,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Tomcat"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
