{
  "query": {
    "kev": "1",
    "page": "63"
  },
  "count": 20,
  "total": 1734,
  "page": 63,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T16:49:18.208Z",
    "kev": "2026-10-08T16:50:18.245Z",
    "epss": "2026-10-08T13:01:09.708Z",
    "breaches": "2026-10-08T12:49:09.286Z",
    "posts": "2026-10-08T16:49:18.208Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=63",
    "next": "https://spydr.io/threats.json?kev=1&page=64"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-0543",
      "url": "https://spydr.io/cve/CVE-2019-0543",
      "published": "2019-01-08T21:29:00.517Z",
      "modified": "2026-06-17T02:08:20.077Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04718,
      "epss_percentile": 0.91587,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1607",
        "microsoft windows 10 1703",
        "microsoft windows 10 1709",
        "microsoft windows 10 1803",
        "microsoft windows 10 1809",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 1709",
        "microsoft windows server 1803",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows server 2016",
        "microsoft windows server 2019"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka \"Microsoft Windows Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2018-8120",
      "url": "https://spydr.io/cve/CVE-2018-8120",
      "published": "2018-05-09T19:29:01.277Z",
      "modified": "2026-08-13T05:17:18.967Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73434,
      "epss_percentile": 0.99456,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008",
        "Microsoft Windows 7",
        "Microsoft Windows Server 2008 R2"
      ],
      "cwes": [
        "CWE-404"
      ],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166."
    },
    {
      "id": "CVE-2017-0101",
      "url": "https://spydr.io/cve/CVE-2017-0101",
      "published": "2017-03-17T00:59:02.743Z",
      "modified": "2026-06-17T00:57:04.553Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.57482,
      "epss_percentile": 0.99061,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Windows"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka \"Windows Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2016-3309",
      "url": "https://spydr.io/cve/CVE-2016-3309",
      "published": "2016-08-09T21:59:16.113Z",
      "modified": "2026-06-17T00:45:28.227Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.20467,
      "epss_percentile": 0.97451,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 10 1511",
        "microsoft windows 10 1607",
        "microsoft windows 7",
        "microsoft windows 8.1",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311."
    },
    {
      "id": "CVE-2015-2546",
      "url": "https://spydr.io/cve/CVE-2015-2546",
      "published": "2015-09-09T00:59:53.207Z",
      "modified": "2026-08-14T05:16:52.893Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.10107,
      "epss_percentile": 0.95533,
      "exploited": true,
      "kev": {
        "added": "2022-03-15",
        "due": "2022-04-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 10 1507",
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka \"Win32k Memory Corruption Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518."
    },
    {
      "id": "CVE-2022-26486",
      "url": "https://spydr.io/cve/CVE-2022-26486",
      "published": "2022-12-22T20:15:22.797Z",
      "modified": "2026-08-19T15:29:21.807Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02351,
      "epss_percentile": 0.83178,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-03-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Firefox for Android",
        "Mozilla Thunderbird",
        "Mozilla Focus"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0."
    },
    {
      "id": "CVE-2022-26485",
      "url": "https://spydr.io/cve/CVE-2022-26485",
      "published": "2022-12-22T20:15:22.563Z",
      "modified": "2026-08-19T15:29:21.807Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14261,
      "epss_percentile": 0.96513,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-03-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Firefox for Android",
        "Mozilla Thunderbird",
        "Mozilla Focus"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0."
    },
    {
      "id": "CVE-2021-21973",
      "url": "https://spydr.io/cve/CVE-2021-21973",
      "published": "2021-02-24T17:15:15.923Z",
      "modified": "2026-06-17T03:36:28.910Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.88012,
      "epss_percentile": 0.99763,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-03-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server",
        "VMware Cloud Foundation"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2)."
    },
    {
      "id": "CVE-2020-8218",
      "url": "https://spydr.io/cve/CVE-2020-8218",
      "published": "2020-07-30T13:15:11.847Z",
      "modified": "2026-06-17T03:26:04.493Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3225,
      "epss_percentile": 0.98286,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti",
        "pulsesecure"
      ],
      "products": [
        "Pulse Connect Secure"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface."
    },
    {
      "id": "CVE-2019-11581",
      "url": "https://spydr.io/cve/CVE-2019-11581",
      "published": "2019-08-09T20:15:11.270Z",
      "modified": "2026-06-17T02:13:12.170Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84621,
      "epss_percentile": 0.99701,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Jira Server and Data Center"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability."
    },
    {
      "id": "CVE-2017-6077",
      "url": "https://spydr.io/cve/CVE-2017-6077",
      "published": "2017-02-22T23:59:00.190Z",
      "modified": "2026-06-17T01:21:45.350Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.68712,
      "epss_percentile": 0.99328,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear dgn2200 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request."
    },
    {
      "id": "CVE-2016-6277",
      "url": "https://spydr.io/cve/CVE-2016-6277",
      "published": "2016-12-14T16:59:00.350Z",
      "modified": "2026-06-17T00:50:44.547Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99803,
      "epss_percentile": 0.99957,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear d6220 firmware",
        "netgear d6400 firmware",
        "netgear r6250 firmware",
        "netgear r6400 firmware",
        "netgear r6700 firmware",
        "netgear r6900 firmware",
        "netgear r7000 firmware",
        "netgear r7100lg firmware",
        "netgear r7300dst firmware",
        "netgear r7900 firmware",
        "netgear r8000 firmware"
      ],
      "cwes": [
        "CWE-352"
      ],
      "description": "NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/."
    },
    {
      "id": "CVE-2013-0631",
      "url": "https://spydr.io/cve/CVE-2013-0631",
      "published": "2013-01-09T01:55:03.617Z",
      "modified": "2026-06-16T23:49:47.907Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.66413,
      "epss_percentile": 0.99267,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe coldfusion"
      ],
      "cwes": [],
      "description": "Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013."
    },
    {
      "id": "CVE-2013-0629",
      "url": "https://spydr.io/cve/CVE-2013-0629",
      "published": "2013-01-09T01:55:03.553Z",
      "modified": "2026-06-16T23:49:47.607Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.65795,
      "epss_percentile": 0.99252,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe coldfusion"
      ],
      "cwes": [],
      "description": "Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013."
    },
    {
      "id": "CVE-2013-0625",
      "url": "https://spydr.io/cve/CVE-2013-0625",
      "published": "2013-01-09T01:55:00.803Z",
      "modified": "2026-06-16T23:49:47.163Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93758,
      "epss_percentile": 0.99843,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe coldfusion"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013."
    },
    {
      "id": "CVE-2009-3960",
      "url": "https://spydr.io/cve/CVE-2009-3960",
      "published": "2010-02-15T18:30:00.407Z",
      "modified": "2026-08-06T05:16:33.473Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.90118,
      "epss_percentile": 0.99795,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-09-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe blazeds",
        "adobe coldfusion",
        "adobe flex data services",
        "adobe livecycle",
        "adobe livecycle data services"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents."
    },
    {
      "id": "CVE-2022-20708",
      "url": "https://spydr.io/cve/CVE-2022-20708",
      "published": "2022-02-10T18:15:09.467Z",
      "modified": "2026-06-17T04:24:54.707Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14863,
      "epss_percentile": 0.96618,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-78"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20703",
      "url": "https://spydr.io/cve/CVE-2022-20703",
      "published": "2022-02-10T18:15:09.197Z",
      "modified": "2026-06-17T04:24:53.813Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09203,
      "epss_percentile": 0.95216,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-295"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20701",
      "url": "https://spydr.io/cve/CVE-2022-20701",
      "published": "2022-02-10T18:15:09.087Z",
      "modified": "2026-06-17T04:24:53.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09747,
      "epss_percentile": 0.95412,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20700",
      "url": "https://spydr.io/cve/CVE-2022-20700",
      "published": "2022-02-10T18:15:09.033Z",
      "modified": "2026-06-17T04:24:53.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05655,
      "epss_percentile": 0.92767,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
