{
  "query": {
    "kev": "1",
    "page": "70"
  },
  "count": 20,
  "total": 1739,
  "page": 70,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T22:50:31.810Z",
    "kev": "2026-10-08T22:50:31.419Z",
    "epss": "2026-10-08T19:01:23.474Z",
    "breaches": "2026-10-08T18:49:28.295Z",
    "posts": "2026-10-08T22:50:31.809Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=70",
    "next": "https://spydr.io/threats.json?kev=1&page=71"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-0145",
      "url": "https://spydr.io/cve/CVE-2017-0145",
      "published": "2017-03-17T00:59:04.040Z",
      "modified": "2026-08-14T05:16:54.037Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8985,
      "epss_percentile": 0.99791,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Windows SMB"
      ],
      "cwes": [],
      "description": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\" This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148."
    },
    {
      "id": "CVE-2017-0144",
      "url": "https://spydr.io/cve/CVE-2017-0144",
      "published": "2017-03-17T00:59:04.010Z",
      "modified": "2026-08-14T05:16:53.770Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9923,
      "epss_percentile": 0.99936,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Windows SMB"
      ],
      "cwes": [],
      "description": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\" This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148."
    },
    {
      "id": "CVE-2016-3088",
      "url": "https://spydr.io/cve/CVE-2016-3088",
      "published": "2016-06-01T20:59:04.123Z",
      "modified": "2026-06-17T00:44:56.753Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98518,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "apache activemq"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request."
    },
    {
      "id": "CVE-2015-1635",
      "url": "https://spydr.io/cve/CVE-2015-1635",
      "published": "2015-04-14T20:59:01.263Z",
      "modified": "2026-06-17T00:22:44.360Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.99999,
      "epss_percentile": 0.99998,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 7",
        "microsoft windows 8",
        "microsoft windows 8.1",
        "microsoft windows server 2008",
        "microsoft windows server 2012"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka \"HTTP.sys Remote Code Execution Vulnerability.\""
    },
    {
      "id": "CVE-2015-1130",
      "url": "https://spydr.io/cve/CVE-2015-1130",
      "published": "2015-04-10T14:59:43.073Z",
      "modified": "2026-06-17T00:21:50.007Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09887,
      "epss_percentile": 0.95464,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple mac os x"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors."
    },
    {
      "id": "CVE-2015-2051",
      "url": "https://spydr.io/cve/CVE-2015-2051",
      "published": "2015-02-23T17:59:08.320Z",
      "modified": "2026-06-17T00:23:30.663Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97101,
      "epss_percentile": 0.99893,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-645",
        "dlink dir-645_firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface."
    },
    {
      "id": "CVE-2014-4404",
      "url": "https://spydr.io/cve/CVE-2014-4404",
      "published": "2014-09-18T10:55:09.827Z",
      "modified": "2026-06-17T00:09:56.033Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48923,
      "epss_percentile": 0.98853,
      "exploited": true,
      "kev": {
        "added": "2022-02-10",
        "due": "2022-08-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os",
        "apple mac os x",
        "apple tvos"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties."
    },
    {
      "id": "CVE-2022-21882",
      "url": "https://spydr.io/cve/CVE-2022-21882",
      "published": "2022-01-11T21:15:11.507Z",
      "modified": "2026-08-15T04:18:00.220Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.59205,
      "epss_percentile": 0.99097,
      "exploited": true,
      "kev": {
        "added": "2022-02-04",
        "due": "2022-02-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-22587",
      "url": "https://spydr.io/cve/CVE-2022-22587",
      "published": "2022-03-18T18:15:12.480Z",
      "modified": "2026-06-17T04:28:38.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11638,
      "epss_percentile": 0.95955,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-02-11",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2021-20038",
      "url": "https://spydr.io/cve/CVE-2021-20038",
      "published": "2021-12-08T10:15:07.750Z",
      "modified": "2026-06-17T03:33:11.327Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99912,
      "epss_percentile": 0.99967,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-02-11",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA100"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions."
    },
    {
      "id": "CVE-2020-5722",
      "url": "https://spydr.io/cve/CVE-2020-5722",
      "published": "2020-03-23T20:15:12.043Z",
      "modified": "2026-06-17T03:22:06.003Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84406,
      "epss_percentile": 0.99696,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "grandstream"
      ],
      "products": [
        "Grandstream UCM6200 Series"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17."
    },
    {
      "id": "CVE-2020-0787",
      "url": "https://spydr.io/cve/CVE-2020-0787",
      "published": "2020-03-12T16:15:15.203Z",
      "modified": "2026-08-12T05:17:28.020Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.42524,
      "epss_percentile": 0.98676,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1909 for 32-bit Systems",
        "Microsoft Windows 10 Version 1909 for x64-based Systems",
        "Microsoft Windows 10 Version 1909 for ARM64-based Systems",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2017-5689",
      "url": "https://spydr.io/cve/CVE-2017-5689",
      "published": "2017-05-02T14:59:00.520Z",
      "modified": "2026-06-17T01:21:02.563Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92189,
      "epss_percentile": 0.99821,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Intel Corporation"
      ],
      "products": [
        "Intel Corporation Intel Active Mangement Technology, Intel Small Business Technology, Intel Standard Manageability"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT)."
    },
    {
      "id": "CVE-2014-7169",
      "url": "https://spydr.io/cve/CVE-2014-7169",
      "published": "2014-09-25T01:55:04.367Z",
      "modified": "2026-06-17T00:14:28.143Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9994,
      "epss_percentile": 0.99972,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gnu",
        "arista",
        "oracle",
        "qnap",
        "mageia",
        "redhat",
        "suse",
        "opensuse",
        "debian",
        "ibm"
      ],
      "products": [
        "gnu bash",
        "arista eos",
        "oracle linux",
        "qnap qts",
        "mageia",
        "redhat gluster storage server for on-premise",
        "redhat virtualization",
        "redhat enterprise linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for scientific computing",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "suse studio onsite"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271."
    },
    {
      "id": "CVE-2014-6271",
      "url": "https://spydr.io/cve/CVE-2014-6271",
      "published": "2014-09-24T18:48:04.477Z",
      "modified": "2026-06-17T00:12:48.020Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99993,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "gnu",
        "arista",
        "oracle",
        "qnap",
        "mageia",
        "redhat",
        "suse",
        "opensuse",
        "debian",
        "ibm"
      ],
      "products": [
        "gnu bash",
        "arista eos",
        "oracle linux",
        "qnap qts",
        "mageia",
        "redhat gluster storage server for on-premise",
        "redhat virtualization",
        "redhat enterprise linux",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for power big endian",
        "redhat enterprise linux for power big endian eus",
        "redhat enterprise linux for scientific computing",
        "redhat enterprise linux server",
        "redhat enterprise linux server aus",
        "redhat enterprise linux server from rhui",
        "redhat enterprise linux server tus",
        "redhat enterprise linux workstation",
        "suse studio onsite"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka \"ShellShock.\" NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix."
    },
    {
      "id": "CVE-2014-1776",
      "url": "https://spydr.io/cve/CVE-2014-1776",
      "published": "2014-04-27T10:55:03.340Z",
      "modified": "2026-06-17T00:05:32.593Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.82682,
      "epss_percentile": 0.99661,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-07-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that \"VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks.\""
    },
    {
      "id": "CVE-2021-35247",
      "url": "https://spydr.io/cve/CVE-2021-35247",
      "published": "2022-01-10T14:10:17.667Z",
      "modified": "2026-06-17T03:57:22.850Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.03453,
      "epss_percentile": 0.8869,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-02-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Serv-U"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U."
    },
    {
      "id": "CVE-2018-8453",
      "url": "https://spydr.io/cve/CVE-2018-8453",
      "published": "2018-10-10T13:29:02.557Z",
      "modified": "2026-08-13T05:17:19.440Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70042,
      "epss_percentile": 0.99364,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-07-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 7",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows RT 8.1",
        "Microsoft Windows Server 2008",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2012",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2008 R2",
        "Microsoft Windows 10",
        "Microsoft Windows 10 Servers"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers."
    },
    {
      "id": "CVE-2012-0391",
      "url": "https://spydr.io/cve/CVE-2012-0391",
      "published": "2012-01-08T15:55:01.217Z",
      "modified": "2026-06-16T23:37:12.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.75599,
      "epss_percentile": 0.99509,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-07-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "apache struts"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter."
    },
    {
      "id": "CVE-2006-1547",
      "url": "https://spydr.io/cve/CVE-2006-1547",
      "published": "2006-03-30T22:02:00.000Z",
      "modified": "2026-06-16T22:23:10.577Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.54635,
      "epss_percentile": 0.98997,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-07-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apache"
      ],
      "products": [
        "apache struts"
      ],
      "cwes": [
        "CWE-749"
      ],
      "description": "ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
