{
  "query": {
    "kev": "1",
    "page": "67"
  },
  "count": 20,
  "total": 1739,
  "page": 67,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T20:50:27.752Z",
    "kev": "2026-10-08T20:50:27.346Z",
    "epss": "2026-10-08T19:01:23.474Z",
    "breaches": "2026-10-08T18:49:28.295Z",
    "posts": "2026-10-08T20:50:27.752Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=67",
    "next": "https://spydr.io/threats.json?kev=1&page=68"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2015-7645",
      "url": "https://spydr.io/cve/CVE-2015-7645",
      "published": "2015-10-15T10:59:10.530Z",
      "modified": "2026-06-17T00:32:53.400Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.65339,
      "epss_percentile": 0.99243,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation"
      ],
      "cwes": [],
      "description": "Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015."
    },
    {
      "id": "CVE-2015-2545",
      "url": "https://spydr.io/cve/CVE-2015-2545",
      "published": "2015-09-09T00:59:52.190Z",
      "modified": "2026-06-17T00:24:16.650Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85937,
      "epss_percentile": 0.99725,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office"
      ],
      "cwes": [],
      "description": "Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka \"Microsoft Office Malformed EPS File Vulnerability.\""
    },
    {
      "id": "CVE-2015-1642",
      "url": "https://spydr.io/cve/CVE-2015-1642",
      "published": "2015-08-15T00:59:00.110Z",
      "modified": "2026-06-17T00:22:45.180Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.53087,
      "epss_percentile": 0.98955,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-2590",
      "url": "https://spydr.io/cve/CVE-2015-2590",
      "published": "2015-07-16T10:59:17.050Z",
      "modified": "2026-06-17T00:24:21.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.25469,
      "epss_percentile": 0.97907,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "canonical",
        "debian",
        "suse",
        "opensuse",
        "redhat"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "canonical ubuntu linux",
        "debian linux",
        "suse linux enterprise debuginfo",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise server",
        "redhat satellite",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for ibm z systems eus",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for power little endian",
        "redhat enterprise linux for power little endian eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server tus"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732."
    },
    {
      "id": "CVE-2015-2387",
      "url": "https://spydr.io/cve/CVE-2015-2387",
      "published": "2015-07-14T22:59:08.103Z",
      "modified": "2026-06-17T00:24:01.693Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34878,
      "epss_percentile": 0.98399,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka \"ATMFD.DLL Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-2424",
      "url": "https://spydr.io/cve/CVE-2015-2424",
      "published": "2015-07-14T21:59:35.987Z",
      "modified": "2026-06-17T00:24:04.850Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.40388,
      "epss_percentile": 0.98612,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft excel viewer",
        "microsoft office",
        "microsoft office compatibility pack",
        "microsoft powerpoint",
        "microsoft word",
        "microsoft word viewer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka \"Microsoft Office Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2015-5119",
      "url": "https://spydr.io/cve/CVE-2015-5119",
      "published": "2015-07-08T14:59:05.677Z",
      "modified": "2026-06-17T00:28:28.970Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99344,
      "epss_percentile": 0.99939,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015."
    },
    {
      "id": "CVE-2015-1701",
      "url": "https://spydr.io/cve/CVE-2015-1701",
      "published": "2015-04-21T10:59:00.073Z",
      "modified": "2026-08-14T05:16:52.667Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55923,
      "epss_percentile": 0.99026,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 2003 server",
        "microsoft windows 7",
        "microsoft windows server 2008",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka \"Win32k Elevation of Privilege Vulnerability.\""
    },
    {
      "id": "CVE-2015-3043",
      "url": "https://spydr.io/cve/CVE-2015-3043",
      "published": "2015-04-14T22:59:21.323Z",
      "modified": "2026-06-17T00:25:10.877Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.73862,
      "epss_percentile": 0.99471,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "novell",
        "opensuse",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "novell suse linux enterprise desktop",
        "novell suse linux enterprise workstation extension",
        "opensuse evergreen",
        "opensuse",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042."
    },
    {
      "id": "CVE-2014-4114",
      "url": "https://spydr.io/cve/CVE-2014-4114",
      "published": "2014-10-15T10:55:07.817Z",
      "modified": "2026-06-17T00:09:27.550Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.81628,
      "epss_percentile": 0.99637,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows rt",
        "microsoft windows rt 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a \"Sandworm\" attack in June through October 2014, aka \"Windows OLE Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2014-0496",
      "url": "https://spydr.io/cve/CVE-2014-0496",
      "published": "2014-01-15T16:13:04.100Z",
      "modified": "2026-06-17T00:03:09.010Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.3998,
      "epss_percentile": 0.98597,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe acrobat"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors."
    },
    {
      "id": "CVE-2013-5065",
      "url": "https://spydr.io/cve/CVE-2013-5065",
      "published": "2013-11-28T00:55:04.677Z",
      "modified": "2026-06-16T23:58:19.633Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34651,
      "epss_percentile": 0.98389,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 2003 server",
        "microsoft windows xp"
      ],
      "cwes": [],
      "description": "NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013."
    },
    {
      "id": "CVE-2013-3897",
      "url": "https://spydr.io/cve/CVE-2013-3897",
      "published": "2013-10-09T14:54:25.747Z",
      "modified": "2026-06-16T23:55:58.860Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7731,
      "epss_percentile": 0.99547,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka \"Internet Explorer Memory Corruption Vulnerability.\""
    },
    {
      "id": "CVE-2013-3346",
      "url": "https://spydr.io/cve/CVE-2013-3346",
      "published": "2013-08-30T20:55:06.230Z",
      "modified": "2026-06-16T23:54:55.737Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.78913,
      "epss_percentile": 0.99587,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe acrobat",
        "adobe acrobat reader"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341."
    },
    {
      "id": "CVE-2013-1675",
      "url": "https://spydr.io/cve/CVE-2013-1675",
      "published": "2013-05-16T11:45:30.877Z",
      "modified": "2026-06-16T23:51:53.300Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.06696,
      "epss_percentile": 0.93745,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mozilla",
        "canonical",
        "debian",
        "redhat",
        "opensuse"
      ],
      "products": [
        "mozilla firefox",
        "mozilla thunderbird",
        "mozilla thunderbird esr",
        "canonical ubuntu linux",
        "debian linux",
        "redhat gluster storage server for on-premise",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for ibm z systems eus",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for scientific computing",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server eus from rhui",
        "redhat enterprise linux workstation",
        "opensuse"
      ],
      "cwes": [
        "CWE-665"
      ],
      "description": "Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site."
    },
    {
      "id": "CVE-2013-1347",
      "url": "https://spydr.io/cve/CVE-2013-1347",
      "published": "2013-05-05T11:07:00.527Z",
      "modified": "2026-06-16T23:51:15.717Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7774,
      "epss_percentile": 0.9956,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013."
    },
    {
      "id": "CVE-2013-0641",
      "url": "https://spydr.io/cve/CVE-2013-0641",
      "published": "2013-02-14T01:55:02.070Z",
      "modified": "2026-06-16T23:49:49.270Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.32346,
      "epss_percentile": 0.98291,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe acrobat",
        "adobe acrobat reader",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux workstation",
        "opensuse",
        "suse linux enterprise desktop"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013."
    },
    {
      "id": "CVE-2013-0640",
      "url": "https://spydr.io/cve/CVE-2013-0640",
      "published": "2013-02-14T01:55:02.023Z",
      "modified": "2026-06-16T23:49:49.060Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86927,
      "epss_percentile": 0.99745,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "redhat"
      ],
      "products": [
        "adobe acrobat",
        "adobe acrobat reader",
        "opensuse",
        "suse linux enterprise desktop",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013."
    },
    {
      "id": "CVE-2013-0632",
      "url": "https://spydr.io/cve/CVE-2013-0632",
      "published": "2013-01-17T00:55:01.200Z",
      "modified": "2026-06-16T23:49:48.073Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93603,
      "epss_percentile": 0.99842,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe coldfusion"
      ],
      "cwes": [
        "CWE-276"
      ],
      "description": "administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013."
    },
    {
      "id": "CVE-2012-4681",
      "url": "https://spydr.io/cve/CVE-2012-4681",
      "published": "2012-08-28T00:55:01.860Z",
      "modified": "2026-08-06T05:16:34.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98536,
      "epss_percentile": 0.99921,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "oracle",
        "redhat"
      ],
      "products": [
        "oracle jdk",
        "oracle jre",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using \"reflection with a trusted immediate caller\" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
