{
  "query": {
    "kev": "1",
    "page": "72"
  },
  "count": 20,
  "total": 1739,
  "page": 72,
  "limit": 20,
  "updated": {
    "cves": "2026-10-09T00:50:36.126Z",
    "kev": "2026-10-09T00:50:35.768Z",
    "epss": "2026-10-09T01:01:36.165Z",
    "breaches": "2026-10-09T00:49:35.859Z",
    "posts": "2026-10-09T00:50:36.126Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=72",
    "next": "https://spydr.io/threats.json?kev=1&page=73"
  },
  "coverage": {
    "cves_published_since": "2026-06-11",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2018-13382",
      "url": "https://spydr.io/cve/CVE-2018-13382",
      "published": "2019-06-04T21:29:00.373Z",
      "modified": "2026-06-17T01:39:18.570Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.81691,
      "epss_percentile": 0.99638,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, FortiProxy"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests"
    },
    {
      "id": "CVE-2019-9670",
      "url": "https://spydr.io/cve/CVE-2019-9670",
      "published": "2019-05-29T22:29:01.507Z",
      "modified": "2026-06-17T02:44:09.363Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99986,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml."
    },
    {
      "id": "CVE-2018-13383",
      "url": "https://spydr.io/cve/CVE-2018-13383",
      "published": "2019-05-29T18:29:00.693Z",
      "modified": "2026-06-17T01:39:18.710Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.33647,
      "epss_percentile": 0.98351,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS and FortiProxy"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages."
    },
    {
      "id": "CVE-2019-2725",
      "url": "https://spydr.io/cve/CVE-2019-2725",
      "published": "2019-04-26T19:29:00.463Z",
      "modified": "2026-10-01T21:17:15.087Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99964,
      "epss_percentile": 0.99976,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Tape Library ACSLS"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2019-7609",
      "url": "https://spydr.io/cve/CVE-2019-7609",
      "published": "2019-03-25T19:29:02.147Z",
      "modified": "2026-06-17T02:40:45.257Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95338,
      "epss_percentile": 0.99867,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Elastic"
      ],
      "products": [
        "Elastic Kibana"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system."
    },
    {
      "id": "CVE-2017-1000486",
      "url": "https://spydr.io/cve/CVE-2017-1000486",
      "published": "2018-01-03T20:29:00.643Z",
      "modified": "2026-06-17T00:59:15.417Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94104,
      "epss_percentile": 0.99847,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "primetek"
      ],
      "products": [
        "primetek primefaces"
      ],
      "cwes": [
        "CWE-326"
      ],
      "description": "Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution"
    },
    {
      "id": "CVE-2015-7450",
      "url": "https://spydr.io/cve/CVE-2015-7450",
      "published": "2016-01-02T21:59:15.800Z",
      "modified": "2026-06-17T00:32:33.670Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97764,
      "epss_percentile": 0.99905,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ibm"
      ],
      "products": [
        "ibm sterling b2b integrator",
        "ibm sterling integrator",
        "ibm tivoli common reporting",
        "ibm watson content analytics",
        "ibm watson explorer analytical components",
        "ibm watson explorer annotation administration console",
        "ibm websphere application server"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library."
    },
    {
      "id": "CVE-2013-3900",
      "url": "https://spydr.io/cve/CVE-2013-3900",
      "published": "2013-12-11T00:55:03.693Z",
      "modified": "2026-10-07T17:58:36.270Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "microsoft.com",
      "epss": 0.44647,
      "epss_percentile": 0.98739,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows Server 2025 (Server Core installation)",
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows Server 2025",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-347"
      ],
      "description": "Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. This includes all currently supported versions of Windows 10 and Windows 11. The supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. See the Security Updates table for the list of affected software. Vulnerability Description A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a way as to add malicious code to the file without invalidating the signature. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of this vulnerability requires that a user or application run or install a specially crafted, signed PE file. An attacker could modify an... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900"
    },
    {
      "id": "CVE-2021-4102",
      "url": "https://spydr.io/cve/CVE-2021-4102",
      "published": "2022-02-11T23:15:08.273Z",
      "modified": "2026-06-17T04:19:02.250Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07836,
      "epss_percentile": 0.94539,
      "exploited": true,
      "kev": {
        "added": "2021-12-15",
        "due": "2021-12-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2021-43890",
      "url": "https://spydr.io/cve/CVE-2021-43890",
      "published": "2021-12-15T15:15:11.207Z",
      "modified": "2026-08-06T05:16:36.653Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11294,
      "epss_percentile": 0.95876,
      "exploited": true,
      "kev": {
        "added": "2021-12-15",
        "due": "2021-12-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft App Installer"
      ],
      "cwes": [],
      "description": "We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations."
    },
    {
      "id": "CVE-2021-44168",
      "url": "https://spydr.io/cve/CVE-2021-44168",
      "published": "2022-01-04T13:15:07.957Z",
      "modified": "2026-06-17T04:11:59.317Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00865,
      "epss_percentile": 0.57391,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-494"
      ],
      "description": "A download of code without integrity check vulnerability in the \"execute restore src-vis\" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages."
    },
    {
      "id": "CVE-2021-44515",
      "url": "https://spydr.io/cve/CVE-2021-44515",
      "published": "2021-12-12T05:15:07.997Z",
      "modified": "2026-06-17T04:12:29.943Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99871,
      "epss_percentile": 0.99963,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine desktop central"
      ],
      "cwes": [],
      "description": "Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3."
    },
    {
      "id": "CVE-2021-44228",
      "url": "https://spydr.io/cve/CVE-2021-44228",
      "published": "2021-12-10T10:15:09.143Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 1,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Log4j2"
      ],
      "cwes": [
        "CWE-20",
        "CWE-400",
        "CWE-502",
        "CWE-917"
      ],
      "description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects."
    },
    {
      "id": "CVE-2021-35394",
      "url": "https://spydr.io/cve/CVE-2021-35394",
      "published": "2021-08-16T12:15:07.267Z",
      "modified": "2026-06-17T03:57:29.187Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99877,
      "epss_percentile": 0.99964,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "realtek"
      ],
      "products": [
        "realtek rtl819x jungle software development kit"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers."
    },
    {
      "id": "CVE-2020-17463",
      "url": "https://spydr.io/cve/CVE-2020-17463",
      "published": "2020-08-13T13:15:17.357Z",
      "modified": "2026-06-17T02:58:58.307Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89689,
      "epss_percentile": 0.99788,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "thedaylightstudio"
      ],
      "products": [
        "thedaylightstudio fuel cms"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items."
    },
    {
      "id": "CVE-2020-8816",
      "url": "https://spydr.io/cve/CVE-2020-8816",
      "published": "2020-05-29T19:15:10.983Z",
      "modified": "2026-06-17T03:26:59.643Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7819,
      "epss_percentile": 0.9957,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "pi-hole"
      ],
      "products": [
        "pi-hole"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease."
    },
    {
      "id": "CVE-2019-10758",
      "url": "https://spydr.io/cve/CVE-2019-10758",
      "published": "2019-12-24T22:15:11.183Z",
      "modified": "2026-06-17T02:11:36.920Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84726,
      "epss_percentile": 0.99703,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mongo-express project"
      ],
      "products": [
        "mongo-express"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment."
    },
    {
      "id": "CVE-2019-0193",
      "url": "https://spydr.io/cve/CVE-2019-0193",
      "published": "2019-08-01T14:15:13.113Z",
      "modified": "2026-06-17T02:07:55.447Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83547,
      "epss_percentile": 0.99681,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache"
      ],
      "products": [
        "Apache Solr"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's \"dataConfig\" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property \"enable.dih.dataConfigParam\" to true."
    },
    {
      "id": "CVE-2019-13272",
      "url": "https://spydr.io/cve/CVE-2019-13272",
      "published": "2019-07-17T13:15:10.687Z",
      "modified": "2026-06-17T02:16:26.033Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.52199,
      "epss_percentile": 0.98933,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "debian",
        "fedoraproject",
        "canonical",
        "redhat",
        "netapp"
      ],
      "products": [
        "linux kernel",
        "debian linux",
        "fedoraproject fedora",
        "canonical ubuntu linux",
        "redhat enterprise linux",
        "redhat enterprise linux for arm 64",
        "redhat enterprise linux for ibm z systems",
        "redhat enterprise linux for real time",
        "redhat enterprise linux for real time for nfv",
        "redhat enterprise linux for real time for nfv tus",
        "redhat enterprise linux for real time tus",
        "netapp aff a700s firmware",
        "netapp h410c firmware",
        "netapp h610s firmware",
        "netapp active iq unified manager",
        "netapp e-series performance analyzer",
        "netapp e-series santricity os controller",
        "netapp hci management node",
        "netapp service processor",
        "netapp solidfire"
      ],
      "cwes": [],
      "description": "In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments."
    },
    {
      "id": "CVE-2019-7238",
      "url": "https://spydr.io/cve/CVE-2019-7238",
      "published": "2019-03-21T17:29:01.180Z",
      "modified": "2026-06-17T02:40:18.367Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77146,
      "epss_percentile": 0.99543,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sonatype"
      ],
      "products": [
        "sonatype nexus repository manager"
      ],
      "cwes": [],
      "description": "Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
