{
  "query": {
    "kev": "1",
    "page": "9"
  },
  "count": 20,
  "total": 1734,
  "page": 9,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T06:44:27.275Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T06:45:27.610Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=9",
    "next": "https://spydr.io/threats.json?kev=1&page=10"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2025-32975",
      "url": "https://spydr.io/cve/CVE-2025-32975",
      "published": "2025-06-24T15:15:23.710Z",
      "modified": "2026-06-17T09:12:53.713Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.02487,
      "epss_percentile": 0.84081,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "quest"
      ],
      "products": [
        "quest kace systems management appliance"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover."
    },
    {
      "id": "CVE-2025-48700",
      "url": "https://spydr.io/cve/CVE-2025-48700",
      "published": "2025-06-23T15:15:27.930Z",
      "modified": "2026-06-17T09:30:11.837Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "CISA ADP",
      "epss": 0.01713,
      "epss_percentile": 0.76591,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-04-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction."
    },
    {
      "id": "CVE-2025-2749",
      "url": "https://spydr.io/cve/CVE-2025-2749",
      "published": "2025-03-24T19:15:52.400Z",
      "modified": "2026-06-17T09:07:33.430Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "vulncheck.com",
      "epss": 0.04054,
      "epss_percentile": 0.90349,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Kentico"
      ],
      "products": [
        "Kentico Xperience"
      ],
      "cwes": [
        "CWE-22",
        "CWE-434"
      ],
      "description": "An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178."
    },
    {
      "id": "CVE-2024-27199",
      "url": "https://spydr.io/cve/CVE-2024-27199",
      "published": "2024-03-04T18:15:09.377Z",
      "modified": "2026-06-17T07:19:25.110Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "NVD",
      "epss": 0.99991,
      "epss_percentile": 0.99986,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "JetBrains"
      ],
      "products": [
        "JetBrains TeamCity"
      ],
      "cwes": [
        "CWE-23",
        "CWE-22"
      ],
      "description": "In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible"
    },
    {
      "id": "CVE-2023-27351",
      "url": "https://spydr.io/cve/CVE-2023-27351",
      "published": "2023-04-20T16:15:07.723Z",
      "modified": "2026-10-01T19:17:14.823Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.78052,
      "epss_percentile": 0.99566,
      "exploited": true,
      "kev": {
        "added": "2026-04-20",
        "due": "2026-05-04",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "PaperCut"
      ],
      "products": [
        "PaperCut NG"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226."
    },
    {
      "id": "CVE-2026-34197",
      "url": "https://spydr.io/cve/CVE-2026-34197",
      "published": "2026-04-07T09:16:20.967Z",
      "modified": "2026-08-04T13:18:20.950Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.15492,
      "epss_percentile": 0.96713,
      "exploited": true,
      "kev": {
        "added": "2026-04-16",
        "due": "2026-04-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation",
        "Red Hat"
      ],
      "products": [
        "Apache Software Foundation Apache ActiveMQ Broker",
        "Apache Software Foundation Apache ActiveMQ All",
        "Apache Software Foundation Apache ActiveMQ",
        "Red Hat AMQ Broker 7",
        "Red Hat Data Grid 8",
        "Red Hat Enterprise Linux 8",
        "Red Hat Enterprise Linux 9",
        "Red Hat Fuse 7",
        "Red Hat JBoss Enterprise Application Platform 7",
        "Red Hat JBoss Enterprise Application Platform 8",
        "Red Hat JBoss Enterprise Application Platform Expansion Pack"
      ],
      "cwes": [
        "CWE-20",
        "CWE-94",
        "CWE-78"
      ],
      "description": "Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue"
    },
    {
      "id": "CVE-2026-32201",
      "url": "https://spydr.io/cve/CVE-2026-32201",
      "published": "2026-04-14T18:17:27.160Z",
      "modified": "2026-06-17T10:35:20.103Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.43378,
      "epss_percentile": 0.98696,
      "exploited": true,
      "kev": {
        "added": "2026-04-14",
        "due": "2026-04-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft SharePoint Enterprise Server 2016",
        "Microsoft SharePoint Server 2019",
        "Microsoft SharePoint Server Subscription Edition"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network."
    },
    {
      "id": "CVE-2009-0238",
      "url": "https://spydr.io/cve/CVE-2009-0238",
      "published": "2009-02-25T16:30:00.343Z",
      "modified": "2026-06-16T23:04:33.880Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.43212,
      "epss_percentile": 0.9869,
      "exploited": true,
      "kev": {
        "added": "2026-04-14",
        "due": "2026-04-28",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft excel",
        "microsoft excel viewer",
        "microsoft office",
        "microsoft office compatibility pack",
        "microsoft office excel viewer"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC."
    },
    {
      "id": "CVE-2026-34621",
      "url": "https://spydr.io/cve/CVE-2026-34621",
      "published": "2026-04-11T07:16:03.633Z",
      "modified": "2026-08-28T00:17:16.097Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.02183,
      "epss_percentile": 0.81752,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Acrobat DC",
        "Adobe Acrobat Reader DC",
        "Adobe Acrobat 2024"
      ],
      "cwes": [
        "CWE-1321"
      ],
      "description": "Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
    },
    {
      "id": "CVE-2026-21643",
      "url": "https://spydr.io/cve/CVE-2026-21643",
      "published": "2026-02-06T09:15:49.330Z",
      "modified": "2026-06-17T10:18:51.890Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.93871,
      "epss_percentile": 0.99843,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiClientEMS"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests."
    },
    {
      "id": "CVE-2025-60710",
      "url": "https://spydr.io/cve/CVE-2025-60710",
      "published": "2025-11-11T18:15:39.073Z",
      "modified": "2026-06-17T09:50:01.133Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.04598,
      "epss_percentile": 0.91383,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 Version 24H2",
        "Microsoft Windows 11 Version 25H2",
        "Microsoft Windows Server 2025",
        "Microsoft Windows Server 2025 (Server Core installation)"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally."
    },
    {
      "id": "CVE-2023-36424",
      "url": "https://spydr.io/cve/CVE-2023-36424",
      "published": "2023-11-14T18:15:45.990Z",
      "modified": "2026-06-17T06:06:15.630Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12184,
      "epss_percentile": 0.96051,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 11 version 22H3",
        "Microsoft Windows Server 2022, 23H2 Edition (Server Core installation)",
        "Microsoft Windows 11 Version 23H2",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-21529",
      "url": "https://spydr.io/cve/CVE-2023-21529",
      "published": "2023-02-14T20:15:11.743Z",
      "modified": "2026-08-19T17:18:05.870Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.59294,
      "epss_percentile": 0.99096,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Microsoft Exchange Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2020-9715",
      "url": "https://spydr.io/cve/CVE-2020-9715",
      "published": "2020-08-19T14:15:13.407Z",
      "modified": "2026-06-17T03:28:26.997Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48595,
      "epss_percentile": 0.98838,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Acrobat and Reader"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution ."
    },
    {
      "id": "CVE-2012-1854",
      "url": "https://spydr.io/cve/CVE-2012-1854",
      "published": "2012-07-10T21:55:05.587Z",
      "modified": "2026-06-16T23:40:25.993Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.21028,
      "epss_percentile": 0.97509,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft office",
        "microsoft visual basic for applications",
        "microsoft visual basic for applications sdk"
      ],
      "cwes": [
        "CWE-426"
      ],
      "description": "Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka \"Visual Basic for Applications Insecure Library Loading Vulnerability,\" as exploited in the wild in July 2012."
    },
    {
      "id": "CVE-2026-1340",
      "url": "https://spydr.io/cve/CVE-2026-1340",
      "published": "2026-01-29T22:15:53.313Z",
      "modified": "2026-06-17T10:15:37.873Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "CNA",
      "epss": 0.98639,
      "epss_percentile": 0.99923,
      "exploited": true,
      "kev": {
        "added": "2026-04-08",
        "due": "2026-04-11",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ivanti"
      ],
      "products": [
        "Ivanti Endpoint Manager Mobile"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution."
    },
    {
      "id": "CVE-2026-35616",
      "url": "https://spydr.io/cve/CVE-2026-35616",
      "published": "2026-04-04T01:16:39.720Z",
      "modified": "2026-07-24T21:10:00.143Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "fortinet.com",
      "epss": 0.09098,
      "epss_percentile": 0.95166,
      "exploited": true,
      "kev": {
        "added": "2026-04-06",
        "due": "2026-04-09",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiClientEMS"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests."
    },
    {
      "id": "CVE-2026-3502",
      "url": "https://spydr.io/cve/CVE-2026-3502",
      "published": "2026-03-30T19:16:27.053Z",
      "modified": "2026-06-17T10:43:41.010Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L",
      "score_source": "checkpoint.com",
      "epss": 0.00329,
      "epss_percentile": 0.23726,
      "exploited": true,
      "kev": {
        "added": "2026-04-02",
        "due": "2026-04-16",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TrueConf"
      ],
      "products": [
        "TrueConf Client"
      ],
      "cwes": [
        "CWE-494"
      ],
      "description": "TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user."
    },
    {
      "id": "CVE-2026-5281",
      "url": "https://spydr.io/cve/CVE-2026-5281",
      "published": "2026-04-01T05:16:01.440Z",
      "modified": "2026-07-24T21:10:00.143Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.00703,
      "epss_percentile": 0.51647,
      "exploited": true,
      "kev": {
        "added": "2026-04-01",
        "due": "2026-04-15",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2026-3055",
      "url": "https://spydr.io/cve/CVE-2026-3055",
      "published": "2026-03-23T21:17:17.477Z",
      "modified": "2026-06-17T10:42:58.157Z",
      "score": 9.3,
      "severity": "critical",
      "cvss_version": "4.0",
      "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "score_source": "CNA",
      "epss": 0.04042,
      "epss_percentile": 0.90322,
      "exploited": true,
      "kev": {
        "added": "2026-03-30",
        "due": "2026-04-02",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "NetScaler"
      ],
      "products": [
        "NetScaler ADC",
        "NetScaler Gateway"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
