{
  "query": {
    "kev": "1",
    "page": "61"
  },
  "count": 20,
  "total": 1734,
  "page": 61,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T14:49:13.947Z",
    "kev": "2026-10-08T14:50:13.692Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T14:49:13.947Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=61",
    "next": "https://spydr.io/threats.json?kev=1&page=62"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-6316",
      "url": "https://spydr.io/cve/CVE-2017-6316",
      "published": "2017-07-20T04:29:00.423Z",
      "modified": "2026-06-17T01:22:08.357Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7303,
      "epss_percentile": 0.99445,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix netscaler sd-wan"
      ],
      "cwes": [],
      "description": "Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID."
    },
    {
      "id": "CVE-2016-1555",
      "url": "https://spydr.io/cve/CVE-2016-1555",
      "published": "2017-04-21T15:59:00.333Z",
      "modified": "2026-06-17T00:42:09.427Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98288,
      "epss_percentile": 0.99916,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear wnap320 firmware",
        "netgear wndap350 firmware",
        "netgear wndap360 firmware",
        "netgear wndap210v2 firmware",
        "netgear wn604 firmware",
        "netgear wndap660 firmware",
        "netgear wn802tv2 firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary commands."
    },
    {
      "id": "CVE-2017-3881",
      "url": "https://spydr.io/cve/CVE-2017-3881",
      "published": "2017-03-17T22:59:00.640Z",
      "modified": "2026-06-17T01:19:06.913Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9895,
      "epss_percentile": 0.99929,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "Cisco IOS and IOS XE Software"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893."
    },
    {
      "id": "CVE-2017-0146",
      "url": "https://spydr.io/cve/CVE-2017-0146",
      "published": "2017-03-17T00:59:04.070Z",
      "modified": "2026-06-17T00:57:09.713Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89862,
      "epss_percentile": 0.99791,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Windows SMB"
      ],
      "cwes": [],
      "description": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\" This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148."
    },
    {
      "id": "CVE-2017-6334",
      "url": "https://spydr.io/cve/CVE-2017-6334",
      "published": "2017-03-06T02:59:00.433Z",
      "modified": "2026-06-17T01:22:10.303Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7264,
      "epss_percentile": 0.99433,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear dgn2200 series firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077."
    },
    {
      "id": "CVE-2016-10174",
      "url": "https://spydr.io/cve/CVE-2016-10174",
      "published": "2017-01-30T04:59:00.157Z",
      "modified": "2026-06-17T00:39:12.707Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83328,
      "epss_percentile": 0.99675,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear d6100 firmware",
        "netgear d7000 firmware",
        "netgear d7800 firmware",
        "netgear jnr1010v2 firmware",
        "netgear jnr3300 firmware",
        "netgear jwnr2010v5 firmware",
        "netgear r2000 firmware",
        "netgear r6100 firmware",
        "netgear r6220 firmware",
        "netgear r7500 firmware",
        "netgear r7500v2 firmware",
        "netgear wndr3700v4 firmware",
        "netgear wndr3800 firmware",
        "netgear wndr4300 firmware",
        "netgear wndr4300v2 firmware",
        "netgear wndr4500v3 firmware",
        "netgear wndr4700 firmware",
        "netgear wnr1000v2 firmware",
        "netgear wnr1000v4 firmware",
        "netgear wnr2000v3 firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution."
    },
    {
      "id": "CVE-2016-7892",
      "url": "https://spydr.io/cve/CVE-2016-7892",
      "published": "2016-12-15T06:59:56.313Z",
      "modified": "2026-06-17T00:53:43.090Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.18786,
      "epss_percentile": 0.97214,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution."
    },
    {
      "id": "CVE-2016-4171",
      "url": "https://spydr.io/cve/CVE-2016-4171",
      "published": "2016-06-16T14:59:51.017Z",
      "modified": "2026-06-17T00:47:02.337Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.20055,
      "epss_percentile": 0.97388,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016."
    },
    {
      "id": "CVE-2016-0752",
      "url": "https://spydr.io/cve/CVE-2016-0752",
      "published": "2016-02-16T02:59:06.783Z",
      "modified": "2026-06-17T00:38:09.067Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.95537,
      "epss_percentile": 0.9987,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rubyonrails",
        "opensuse",
        "suse",
        "debian",
        "redhat"
      ],
      "products": [
        "rubyonrails rails",
        "opensuse leap",
        "opensuse",
        "suse linux enterprise module for containers",
        "debian linux",
        "redhat software collections"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname."
    },
    {
      "id": "CVE-2015-4068",
      "url": "https://spydr.io/cve/CVE-2015-4068",
      "published": "2015-05-29T15:59:23.327Z",
      "modified": "2026-06-17T00:26:43.280Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.63643,
      "epss_percentile": 0.99199,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arcserve"
      ],
      "products": [
        "arcserve udp"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet."
    },
    {
      "id": "CVE-2015-3035",
      "url": "https://spydr.io/cve/CVE-2015-3035",
      "published": "2015-04-22T01:59:02.553Z",
      "modified": "2026-06-17T00:25:09.817Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.83948,
      "epss_percentile": 0.99688,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tp-link"
      ],
      "products": [
        "tp-link tl-wr741nd firmware",
        "tp-link tl-wr841n firmware",
        "tp-link tl-wr740n firmware",
        "tp-link archer c5 firmware",
        "tp-link tl-wdr3600 firmware",
        "tp-link archer c7 firmware",
        "tp-link tl-wr841nd firmware",
        "tp-link archer c9 firmware",
        "tp-link archer c8 firmware",
        "tp-link tl-wdr4300 firmware",
        "tp-link tl-wdr3500 firmware"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/."
    },
    {
      "id": "CVE-2015-0666",
      "url": "https://spydr.io/cve/CVE-2015-0666",
      "published": "2015-04-03T10:59:04.290Z",
      "modified": "2026-06-17T00:20:42.127Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.40379,
      "epss_percentile": 0.98611,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco prime data center network manager"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241."
    },
    {
      "id": "CVE-2015-1427",
      "url": "https://spydr.io/cve/CVE-2015-1427",
      "published": "2015-02-17T15:59:04.560Z",
      "modified": "2026-06-17T00:22:24.453Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99906,
      "epss_percentile": 0.99966,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "elastic",
        "redhat"
      ],
      "products": [
        "elasticsearch",
        "redhat fuse"
      ],
      "cwes": [],
      "description": "The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script."
    },
    {
      "id": "CVE-2014-6324",
      "url": "https://spydr.io/cve/CVE-2014-6324",
      "published": "2014-11-18T23:59:02.503Z",
      "modified": "2026-06-17T00:12:54.610Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.87335,
      "epss_percentile": 0.99753,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012"
      ],
      "cwes": [],
      "description": "The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka \"Kerberos Checksum Vulnerability.\""
    },
    {
      "id": "CVE-2014-6332",
      "url": "https://spydr.io/cve/CVE-2014-6332",
      "published": "2014-11-11T22:55:05.200Z",
      "modified": "2026-06-17T00:12:55.477Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.94918,
      "epss_percentile": 0.99861,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka \"Windows OLE Automation Array Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2014-6287",
      "url": "https://spydr.io/cve/CVE-2014-6287",
      "published": "2014-10-07T10:55:04.493Z",
      "modified": "2026-06-17T00:12:50.983Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99323,
      "epss_percentile": 0.99939,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rejetto"
      ],
      "products": [
        "rejetto http file server"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action."
    },
    {
      "id": "CVE-2014-3120",
      "url": "https://spydr.io/cve/CVE-2014-3120",
      "published": "2014-07-28T19:55:04.490Z",
      "modified": "2026-06-17T00:07:37.603Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.88559,
      "epss_percentile": 0.99772,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "elastic"
      ],
      "products": [
        "elasticsearch"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine."
    },
    {
      "id": "CVE-2014-0130",
      "url": "https://spydr.io/cve/CVE-2014-0130",
      "published": "2014-05-07T10:55:04.133Z",
      "modified": "2026-06-17T00:02:21.133Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.53703,
      "epss_percentile": 0.98973,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "rubyonrails"
      ],
      "products": [
        "redhat subscription asset manager",
        "redhat enterprise linux server",
        "rubyonrails rails"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request."
    },
    {
      "id": "CVE-2013-5223",
      "url": "https://spydr.io/cve/CVE-2013-5223",
      "published": "2013-11-19T04:50:12.063Z",
      "modified": "2026-06-16T23:58:32.217Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.50833,
      "epss_percentile": 0.989,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dsl-2760u firmware"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl."
    },
    {
      "id": "CVE-2013-4810",
      "url": "https://spydr.io/cve/CVE-2013-4810",
      "published": "2013-09-16T13:01:46.207Z",
      "modified": "2026-06-16T23:57:56.050Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.79468,
      "epss_percentile": 0.99597,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "hp"
      ],
      "products": [
        "hp application lifecycle management",
        "hp procurve manager"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
