{
  "query": {
    "kev": "1",
    "page": "84"
  },
  "count": 20,
  "total": 1739,
  "page": 84,
  "limit": 20,
  "updated": {
    "cves": "2026-10-10T12:53:07.900Z",
    "kev": "2026-10-10T12:53:07.335Z",
    "epss": "2026-10-10T13:03:07.413Z",
    "breaches": "2026-10-10T12:53:07.511Z",
    "posts": "2026-10-10T12:53:07.899Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=84",
    "next": "https://spydr.io/threats.json?kev=1&page=85"
  },
  "coverage": {
    "cves_published_since": "2026-06-12",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2019-7481",
      "url": "https://spydr.io/cve/CVE-2019-7481",
      "published": "2019-12-17T23:15:14.923Z",
      "modified": "2026-08-12T05:17:26.930Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99906,
      "epss_percentile": 0.99966,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA100"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier."
    },
    {
      "id": "CVE-2019-18935",
      "url": "https://spydr.io/cve/CVE-2019-18935",
      "published": "2019-12-11T13:15:11.767Z",
      "modified": "2026-06-17T02:25:36.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99737,
      "epss_percentile": 0.99953,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "telerik"
      ],
      "products": [
        "telerik ui for asp.net ajax"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)"
    },
    {
      "id": "CVE-2019-5544",
      "url": "https://spydr.io/cve/CVE-2019-5544",
      "published": "2019-12-06T16:15:11.467Z",
      "modified": "2026-06-17T02:37:52.780Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97258,
      "epss_percentile": 0.99896,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware",
        "redhat",
        "openslp",
        "fedoraproject"
      ],
      "products": [
        "ESXi and Horizon DaaS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8."
    },
    {
      "id": "CVE-2019-1429",
      "url": "https://spydr.io/cve/CVE-2019-1429",
      "published": "2019-11-12T19:15:14.770Z",
      "modified": "2026-06-17T02:28:35.873Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7729,
      "epss_percentile": 0.99548,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 9",
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 11 on Windows Server 2012",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [
        "CWE-416",
        "CWE-787"
      ],
      "description": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428."
    },
    {
      "id": "CVE-2019-18187",
      "url": "https://spydr.io/cve/CVE-2019-18187",
      "published": "2019-10-28T20:15:11.003Z",
      "modified": "2026-06-17T02:24:26.050Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.25125,
      "epss_percentile": 0.97887,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro"
      ],
      "products": [
        "Trend Micro OfficeScan"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication."
    },
    {
      "id": "CVE-2019-2215",
      "url": "https://spydr.io/cve/CVE-2019-2215",
      "published": "2019-10-11T19:15:10.947Z",
      "modified": "2026-06-17T02:33:27.307Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72105,
      "epss_percentile": 0.99421,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google",
        "debian",
        "canonical",
        "netapp",
        "huawei"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095"
    },
    {
      "id": "CVE-2019-16759",
      "url": "https://spydr.io/cve/CVE-2019-16759",
      "published": "2019-09-24T22:15:13.183Z",
      "modified": "2026-06-17T02:22:44.363Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99728,
      "epss_percentile": 0.99952,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vbulletin"
      ],
      "products": [
        "vbulletin"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request."
    },
    {
      "id": "CVE-2019-1367",
      "url": "https://spydr.io/cve/CVE-2019-1367",
      "published": "2019-09-23T20:15:13.447Z",
      "modified": "2026-06-17T02:28:28.333Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.52449,
      "epss_percentile": 0.9894,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Internet Explorer 9",
        "Microsoft Internet Explorer 11",
        "Microsoft Internet Explorer 11 on Windows Server 2012",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Internet Explorer 10"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221."
    },
    {
      "id": "CVE-2019-16256",
      "url": "https://spydr.io/cve/CVE-2019-16256",
      "published": "2019-09-12T13:15:10.327Z",
      "modified": "2026-06-17T02:22:00.793Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04949,
      "epss_percentile": 0.91951,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "trustedconnectivityalliance"
      ],
      "products": [
        "trustedconnectivityalliance s@t browser"
      ],
      "cwes": [],
      "description": "Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker."
    },
    {
      "id": "CVE-2019-1215",
      "url": "https://spydr.io/cve/CVE-2019-1215",
      "published": "2019-09-11T22:15:14.587Z",
      "modified": "2026-06-17T02:28:05.677Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19254,
      "epss_percentile": 0.97277,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303."
    },
    {
      "id": "CVE-2019-1214",
      "url": "https://spydr.io/cve/CVE-2019-1214",
      "published": "2019-09-11T22:15:14.523Z",
      "modified": "2026-06-17T02:28:05.463Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01419,
      "epss_percentile": 0.72037,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-15949",
      "url": "https://spydr.io/cve/CVE-2019-15949",
      "published": "2019-09-05T17:15:12.327Z",
      "modified": "2026-06-17T02:21:24.097Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77039,
      "epss_percentile": 0.99542,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root."
    },
    {
      "id": "CVE-2019-13608",
      "url": "https://spydr.io/cve/CVE-2019-13608",
      "published": "2019-08-29T19:15:13.227Z",
      "modified": "2026-06-17T02:17:04.013Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.30041,
      "epss_percentile": 0.98175,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix storefront server"
      ],
      "cwes": [
        "CWE-611"
      ],
      "description": "Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks."
    },
    {
      "id": "CVE-2019-15752",
      "url": "https://spydr.io/cve/CVE-2019-15752",
      "published": "2019-08-28T21:15:10.880Z",
      "modified": "2026-06-17T02:21:00.877Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48628,
      "epss_percentile": 0.98845,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "docker",
        "apache"
      ],
      "products": [
        "docker",
        "apache geode"
      ],
      "cwes": [
        "CWE-732"
      ],
      "description": "Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\\DockerDesktop\\version-bin\\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command."
    },
    {
      "id": "CVE-2018-18325",
      "url": "https://spydr.io/cve/CVE-2018-18325",
      "published": "2019-07-03T17:15:10.250Z",
      "modified": "2026-06-17T01:47:00.017Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.7387,
      "epss_percentile": 0.99471,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dnnsoftware"
      ],
      "products": [
        "dnnsoftware dotnetnuke"
      ],
      "cwes": [
        "CWE-326"
      ],
      "description": "DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811."
    },
    {
      "id": "CVE-2018-15811",
      "url": "https://spydr.io/cve/CVE-2018-15811",
      "published": "2019-07-03T17:15:10.110Z",
      "modified": "2026-06-17T01:43:08.583Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.76143,
      "epss_percentile": 0.99525,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dnnsoftware"
      ],
      "products": [
        "dnnsoftware dotnetnuke"
      ],
      "cwes": [
        "CWE-326"
      ],
      "description": "DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters."
    },
    {
      "id": "CVE-2018-13379",
      "url": "https://spydr.io/cve/CVE-2018-13379",
      "published": "2019-06-04T21:29:00.233Z",
      "modified": "2026-06-17T01:39:18.123Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99995,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, FortiProxy"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests."
    },
    {
      "id": "CVE-2019-11580",
      "url": "https://spydr.io/cve/CVE-2019-11580",
      "published": "2019-06-03T14:29:00.217Z",
      "modified": "2026-06-17T02:13:11.973Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95355,
      "epss_percentile": 0.99867,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Crowd"
      ],
      "cwes": [],
      "description": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution on systems running a vulnerable version of Crowd or Crowd Data Center. All versions of Crowd from version 2.1.0 before 3.0.5 (the fixed version for 3.0.x), from version 3.1.0 before 3.1.6 (the fixed version for 3.1.x), from version 3.2.0 before 3.2.8 (the fixed version for 3.2.x), from version 3.3.0 before 3.3.5 (the fixed version for 3.3.x), and from version 3.4.0 before 3.4.4 (the fixed version for 3.4.x) are affected by this vulnerability."
    },
    {
      "id": "CVE-2019-11634",
      "url": "https://spydr.io/cve/CVE-2019-11634",
      "published": "2019-05-22T17:29:00.227Z",
      "modified": "2026-08-12T05:17:21.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08091,
      "epss_percentile": 0.9469,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "citrix"
      ],
      "products": [
        "citrix receiver",
        "citrix workspace"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "Citrix Workspace App before 1904 for Windows has Incorrect Access Control."
    },
    {
      "id": "CVE-2019-0863",
      "url": "https://spydr.io/cve/CVE-2019-0863",
      "published": "2019-05-16T19:29:00.927Z",
      "modified": "2026-06-17T02:09:03.930Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05207,
      "epss_percentile": 0.9229,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [],
      "description": "An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
