{
  "query": {
    "kev": "1",
    "page": "8"
  },
  "count": 20,
  "total": 1734,
  "page": 8,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T04:45:22.933Z",
    "kev": "2026-10-06T05:44:24.841Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T05:45:25.054Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=8",
    "next": "https://spydr.io/threats.json?kev=1&page=9"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2009-1537",
      "url": "https://spydr.io/cve/CVE-2009-1537",
      "published": "2009-05-29T18:30:00.187Z",
      "modified": "2026-06-16T23:07:28.827Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.51207,
      "epss_percentile": 0.98906,
      "exploited": true,
      "kev": {
        "added": "2026-05-20",
        "due": "2026-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft directx",
        "microsoft windows 2000",
        "microsoft windows 2003 server",
        "microsoft windows server 2003",
        "microsoft windows xp"
      ],
      "cwes": [
        "CWE-158"
      ],
      "description": "Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka \"DirectX NULL Byte Overwrite Vulnerability.\""
    },
    {
      "id": "CVE-2008-4250",
      "url": "https://spydr.io/cve/CVE-2008-4250",
      "published": "2008-10-23T22:00:01.357Z",
      "modified": "2026-06-16T22:57:29.393Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.98751,
      "epss_percentile": 0.99925,
      "exploited": true,
      "kev": {
        "added": "2026-05-20",
        "due": "2026-06-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft windows 2000",
        "microsoft windows server 2003",
        "microsoft windows server 2008",
        "microsoft windows vista",
        "microsoft windows xp"
      ],
      "cwes": [
        "CWE-94",
        "CWE-119"
      ],
      "description": "The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka \"Server Service Vulnerability.\""
    },
    {
      "id": "CVE-2026-42897",
      "url": "https://spydr.io/cve/CVE-2026-42897",
      "published": "2026-05-14T18:16:49.360Z",
      "modified": "2026-06-17T10:48:34.893Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.00519,
      "epss_percentile": 0.42127,
      "exploited": true,
      "kev": {
        "added": "2026-05-15",
        "due": "2026-05-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 14",
        "Microsoft Exchange Server 2019 Cumulative Update 15",
        "Microsoft Exchange Server Subscription Edition RTM"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network."
    },
    {
      "id": "CVE-2026-20182",
      "url": "https://spydr.io/cve/CVE-2026-20182",
      "published": "2026-05-14T17:16:19.387Z",
      "modified": "2026-06-17T15:06:02.767Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.91522,
      "epss_percentile": 0.99812,
      "exploited": true,
      "kev": {
        "added": "2026-05-14",
        "due": "2026-05-17",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Controller",
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp; A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric."
    },
    {
      "id": "CVE-2026-42208",
      "url": "https://spydr.io/cve/CVE-2026-42208",
      "published": "2026-05-08T04:16:19.923Z",
      "modified": "2026-07-15T02:21:28.627Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.05772,
      "epss_percentile": 0.92868,
      "exploited": true,
      "kev": {
        "added": "2026-05-08",
        "due": "2026-05-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "BerriAI",
        "Red Hat"
      ],
      "products": [
        "BerriAI litellm",
        "Red Hat Lightspeed Core",
        "Red Hat Ansible Automation Platform 2",
        "Red Hat OpenShift AI (RHOAI)"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted Authorization header to any LLM API route (for example POST /chat/completions) and reach this query through the proxy's error-handling path. An attacker could read data from the proxy's database and may be able to modify it, leading to unauthorised access to the proxy and the credentials it manages. This issue has been patched in version 1.83.7."
    },
    {
      "id": "CVE-2026-6973",
      "url": "https://spydr.io/cve/CVE-2026-6973",
      "published": "2026-05-07T16:16:23.163Z",
      "modified": "2026-06-17T11:01:34.360Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.02537,
      "epss_percentile": 0.84412,
      "exploited": true,
      "kev": {
        "added": "2026-05-07",
        "due": "2026-05-10",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution."
    },
    {
      "id": "CVE-2026-0300",
      "url": "https://spydr.io/cve/CVE-2026-0300",
      "published": "2026-05-06T19:16:35.730Z",
      "modified": "2026-06-17T10:10:43.073Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Red",
      "score_source": "paloaltonetworks.com",
      "epss": 0.31725,
      "epss_percentile": 0.98252,
      "exploited": true,
      "kev": {
        "added": "2026-05-06",
        "due": "2026-05-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks",
        "Siemens"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access",
        "Siemens RUGGEDCOM APE1808"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability."
    },
    {
      "id": "CVE-2026-31431",
      "url": "https://spydr.io/cve/CVE-2026-31431",
      "published": "2026-04-22T09:16:21.270Z",
      "modified": "2026-09-08T15:13:07.273Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.03437,
      "epss_percentile": 0.88591,
      "exploited": true,
      "kev": {
        "added": "2026-05-01",
        "due": "2026-05-15",
        "action": "\"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux",
        "Red Hat",
        "Siemens"
      ],
      "products": [
        "Linux",
        "Red Hat NVIDIA for RHEL 10",
        "Red Hat Enterprise Linux 10",
        "Red Hat Enterprise Linux 10.0 Extended Update Support",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
        "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
        "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
        "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
        "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
        "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9",
        "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
        "Red Hat Enterprise Linux 9.4 Extended Update Support",
        "Red Hat Enterprise Linux 9.6 Extended Update Support",
        "Red Hat OpenShift Container Platform 4.12",
        "Red Hat OpenShift Container Platform 4.13",
        "Red Hat OpenShift Container Platform 4.14"
      ],
      "cwes": [
        "CWE-669",
        "CWE-1288"
      ],
      "description": "In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly."
    },
    {
      "id": "CVE-2026-41940",
      "url": "https://spydr.io/cve/CVE-2026-41940",
      "published": "2026-04-29T16:16:25.037Z",
      "modified": "2026-09-30T18:18:18.563Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "vulncheck.com",
      "epss": 0.98527,
      "epss_percentile": 0.9992,
      "exploited": true,
      "kev": {
        "added": "2026-04-30",
        "due": "2026-05-03",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "WebPros"
      ],
      "products": [
        "WebPros cPanel",
        "WebPros WP Squared",
        "WebPros WHM"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel."
    },
    {
      "id": "CVE-2026-32202",
      "url": "https://spydr.io/cve/CVE-2026-32202",
      "published": "2026-04-14T18:17:27.360Z",
      "modified": "2026-08-14T17:17:51.127Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "score_source": "microsoft.com",
      "epss": 0.04902,
      "epss_percentile": 0.91837,
      "exploited": true,
      "kev": {
        "added": "2026-04-28",
        "due": "2026-05-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 23H2",
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows 11 version 26H1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-693"
      ],
      "description": "Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network."
    },
    {
      "id": "CVE-2024-1708",
      "url": "https://spydr.io/cve/CVE-2024-1708",
      "published": "2024-02-21T16:15:50.233Z",
      "modified": "2026-06-17T07:04:50.430Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95436,
      "epss_percentile": 0.99869,
      "exploited": true,
      "kev": {
        "added": "2026-04-28",
        "due": "2026-05-12",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ConnectWise"
      ],
      "products": [
        "ConnectWise ScreenConnect"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems."
    },
    {
      "id": "CVE-2025-29635",
      "url": "https://spydr.io/cve/CVE-2025-29635",
      "published": "2025-03-25T14:15:29.043Z",
      "modified": "2026-06-17T09:05:33.707Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.87944,
      "epss_percentile": 0.99762,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-823x firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution."
    },
    {
      "id": "CVE-2024-57728",
      "url": "https://spydr.io/cve/CVE-2024-57728",
      "published": "2025-01-15T23:15:09.777Z",
      "modified": "2026-06-17T08:13:58.993Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64664,
      "epss_percentile": 0.99223,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "simple-help"
      ],
      "products": [
        "simple-help simplehelp"
      ],
      "cwes": [
        "CWE-59",
        "CWE-22"
      ],
      "description": "SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user."
    },
    {
      "id": "CVE-2024-57726",
      "url": "https://spydr.io/cve/CVE-2024-57726",
      "published": "2025-01-15T23:15:09.520Z",
      "modified": "2026-06-17T08:13:58.677Z",
      "score": 9.9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.66601,
      "epss_percentile": 0.9927,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "simple-help"
      ],
      "products": [
        "simple-help simplehelp"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role."
    },
    {
      "id": "CVE-2024-7399",
      "url": "https://spydr.io/cve/CVE-2024-7399",
      "published": "2024-08-12T13:38:41.550Z",
      "modified": "2026-10-01T19:17:15.393Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91941,
      "epss_percentile": 0.99817,
      "exploited": true,
      "kev": {
        "added": "2026-04-24",
        "due": "2026-05-08",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Electronics"
      ],
      "products": [
        "Samsung Electronics MagicINFO 9 Server"
      ],
      "cwes": [
        "CWE-22",
        "CWE-434"
      ],
      "description": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority."
    },
    {
      "id": "CVE-2026-39987",
      "url": "https://spydr.io/cve/CVE-2026-39987",
      "published": "2026-04-09T18:17:02.807Z",
      "modified": "2026-06-17T10:42:51.460Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "github.com",
      "epss": 0.37865,
      "epss_percentile": 0.98509,
      "exploited": true,
      "kev": {
        "added": "2026-04-23",
        "due": "2026-05-07",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "marimo-team"
      ],
      "products": [
        "marimo-team marimo"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0."
    },
    {
      "id": "CVE-2026-33825",
      "url": "https://spydr.io/cve/CVE-2026-33825",
      "published": "2026-04-14T18:17:35.100Z",
      "modified": "2026-07-24T22:10:00.140Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.00399,
      "epss_percentile": 0.3182,
      "exploited": true,
      "kev": {
        "added": "2026-04-22",
        "due": "2026-05-06",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Defender Antimalware Platform"
      ],
      "cwes": [
        "CWE-1220"
      ],
      "description": "Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2026-20133",
      "url": "https://spydr.io/cve/CVE-2026-20133",
      "published": "2026-02-25T17:25:30.983Z",
      "modified": "2026-06-17T10:17:11.190Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.31829,
      "epss_percentile": 0.98256,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system restrictions. An authenticated attacker with netadmin privileges could exploit this vulnerability by accessing the vshell of an affected system. A successful exploit could allow the attacker to read sensitive information on the underlying operating system."
    },
    {
      "id": "CVE-2026-20128",
      "url": "https://spydr.io/cve/CVE-2026-20128",
      "published": "2026-02-25T17:25:30.150Z",
      "modified": "2026-06-17T10:17:10.543Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "cisco.com",
      "epss": 0.07064,
      "epss_percentile": 0.94024,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-257"
      ],
      "description": "A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by sending a crafted HTTP request and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability."
    },
    {
      "id": "CVE-2026-20122",
      "url": "https://spydr.io/cve/CVE-2026-20122",
      "published": "2026-02-25T17:25:28.170Z",
      "modified": "2026-06-17T10:17:09.043Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.24978,
      "epss_percentile": 0.9786,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN Manager"
      ],
      "cwes": [
        "CWE-648"
      ],
      "description": "A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system&nbsp;and gain vmanage user privileges."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
