{"uuid": "0b411d34-c6d6-4237-ac39-63754cdc5fc9", "vulnerability": {"vulnId": "CVE-2024-58387", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T22:40:21+02:00"}, "gcve": {"object_uuid": "0b411d34-c6d6-4237-ac39-63754cdc5fc9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T20:40:21+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T20:40:21+00:00"}, "scope": {"notes": "Inspur HCM Cloud Arbitrary File Read via file/download Endpoint | Affected: Inspur / Haiyue HCM Cloud | CVSS: 8.7 (HIGH) | EPSS: 0.00708 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-58387", "url": "https://www.cve.org/CVERecord?id=CVE-2024-58387"}, {"id": "GHSA-9FRQ-682F-P456", "url": "https://github.com/advisories/GHSA-9FRQ-682F-P456"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-58387"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inspur HCM Cloud Arbitrary File Read via file/download Endpoint", "cve_id": "CVE-2024-58387", "vendor": "Inspur", "ghsa_id": "GHSA-9FRQ-682F-P456", "product": "Haiyue HCM Cloud", "added_date": "2026-09-30T20:40:21.475Z", "cvss_score": 8.7, "epss_score": 0.00708, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-58387", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d37f3a46-397b-4c5a-9a37-0739db246356", "vulnerability": {"vulnId": "CVE-2023-54403", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T22:40:20+02:00"}, "gcve": {"object_uuid": "d37f3a46-397b-4c5a-9a37-0739db246356", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T20:40:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T20:40:20+00:00"}, "scope": {"notes": "Yonyou U8 CRM Arbitrary File Read via getemaildata.php | Affected: Yonyou / U8 CRM | CVSS: 8.7 (HIGH) | EPSS: 0.00686 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-54403", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54403"}, {"id": "GHSA-8VGX-V6GM-MHXR", "url": "https://github.com/advisories/GHSA-8VGX-V6GM-MHXR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54403"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yonyou U8 CRM Arbitrary File Read via getemaildata.php", "cve_id": "CVE-2023-54403", "vendor": "Yonyou", "ghsa_id": "GHSA-8VGX-V6GM-MHXR", "product": "U8 CRM", "added_date": "2026-09-30T20:40:20.538Z", "cvss_score": 8.7, "epss_score": 0.00686, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50872, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54403", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "433c935d-b150-4383-86ae-10596d09db9e", "vulnerability": {"vulnId": "CVE-2023-54402", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T22:30:25+02:00"}, "gcve": {"object_uuid": "433c935d-b150-4383-86ae-10596d09db9e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T20:30:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T20:30:25+00:00"}, "scope": {"notes": "iDocView SSRF via /doc/upload Endpoint Hardcoded Token | Affected: iDocView / iDocView | CVSS: 8.7 (HIGH) | EPSS: 0.00791 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-54402", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54402"}, {"id": "GHSA-2XG3-76QW-G9MM", "url": "https://github.com/advisories/GHSA-2XG3-76QW-G9MM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54402"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "iDocView SSRF via /doc/upload Endpoint Hardcoded Token", "cve_id": "CVE-2023-54402", "vendor": "iDocView", "ghsa_id": "GHSA-2XG3-76QW-G9MM", "product": "iDocView", "added_date": "2026-09-30T20:30:25.907Z", "cvss_score": 8.7, "epss_score": 0.00791, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.54671, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54402", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e1e0ab2c-a5bc-4e40-815f-d89539f046f9", "vulnerability": {"vulnId": "CVE-2018-17254", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T22:26:12+02:00"}, "gcve": {"object_uuid": "e1e0ab2c-a5bc-4e40-815f-d89539f046f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T20:26:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T20:26:12+00:00"}, "scope": {"notes": "The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter. | Affected: Arkextensions / JCK Editor | CVSS: 9.8 (CRITICAL) | EPSS: 0.82976 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-17254", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17254"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17254"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.", "cve_id": "CVE-2018-17254", "vendor": "Arkextensions", "ghsa_id": null, "product": "JCK Editor", "added_date": "2026-09-30T20:26:12.106Z", "cvss_score": 9.8, "epss_score": 0.82976, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99665, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17254", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "af86cad8-62fd-4054-a00a-e4d1dcb5f1f3", "vulnerability": {"vulnId": "CVE-2026-102490", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T20:53:04+02:00"}, "gcve": {"object_uuid": "af86cad8-62fd-4054-a00a-e4d1dcb5f1f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T18:53:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T18:53:04+00:00"}, "scope": {"notes": "Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha | Affected: Zammad / Zammad | CVSS: 8.5 (HIGH) | EPSS: 0.00319 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-102490", "url": "https://www.cve.org/CVERecord?id=CVE-2026-102490"}, {"id": "GHSA-HGFF-G8G3-4XR8", "url": "https://github.com/advisories/GHSA-HGFF-G8G3-4XR8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-102490"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha", "cve_id": "CVE-2026-102490", "vendor": "Zammad", "ghsa_id": "GHSA-HGFF-G8G3-4XR8", "product": "Zammad", "added_date": "2026-09-30T18:53:04.428Z", "cvss_score": 8.5, "epss_score": 0.00319, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.22508, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-102490", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1d50c037-c9cd-4754-8ae9-1c69cfca26ae", "vulnerability": {"vulnId": "CVE-2026-102489", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T20:52:45+02:00"}, "gcve": {"object_uuid": "1d50c037-c9cd-4754-8ae9-1c69cfca26ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T18:52:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T18:52:45+00:00"}, "scope": {"notes": "Undisclosed RCE in Zammad v6.3 and higher | Affected: Zammad / Zammad | CVSS: 8.7 (HIGH) | EPSS: 0.00709 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-102489", "url": "https://www.cve.org/CVERecord?id=CVE-2026-102489"}, {"id": "GHSA-XMW5-M2WG-4243", "url": "https://github.com/advisories/GHSA-XMW5-M2WG-4243"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-102489"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Undisclosed RCE in Zammad v6.3 and higher", "cve_id": "CVE-2026-102489", "vendor": "Zammad", "ghsa_id": "GHSA-XMW5-M2WG-4243", "product": "Zammad", "added_date": "2026-09-30T18:52:45.188Z", "cvss_score": 8.7, "epss_score": 0.00709, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51763, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-102489", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "191138e1-55dd-445d-b568-522bb956120b", "vulnerability": {"vulnId": "CVE-2026-76504", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-30T15:49:09+02:00"}, "gcve": {"object_uuid": "191138e1-55dd-445d-b568-522bb956120b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-30T13:49:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-30T13:49:09+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.01096 | Used in malware: unknown | Listed 4 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-76504", "url": "https://www.cve.org/CVERecord?id=CVE-2026-76504"}, {"id": "GHSA-XQJC-V467-8FVF", "url": "https://github.com/advisories/GHSA-XQJC-V467-8FVF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-76504"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability", "cve_id": "CVE-2026-76504", "vendor": "Cisco", "ghsa_id": "GHSA-XQJC-V467-8FVF", "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2026-09-30T13:49:09.169Z", "cvss_score": 9.8, "epss_score": 0.01096, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64334, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-76504", "ahead_of_cisa_kev": {"unit": "hour", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a42b7560-a2fa-43c3-8c11-34788e35d438", "vulnerability": {"vulnId": "CVE-2023-54400", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-29T17:30:26+02:00"}, "gcve": {"object_uuid": "a42b7560-a2fa-43c3-8c11-34788e35d438", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-29T15:30:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-29T15:30:26+00:00"}, "scope": {"notes": "Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname | Affected: Fumasoft / Fumeng Cloud | CVSS: 9.3 (CRITICAL) | EPSS: 0.00464 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-54400", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54400"}, {"id": "GHSA-39VR-225P-6CCC", "url": "https://github.com/advisories/GHSA-39VR-225P-6CCC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54400"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname", "cve_id": "CVE-2023-54400", "vendor": "Fumasoft", "ghsa_id": "GHSA-39VR-225P-6CCC", "product": "Fumeng Cloud", "added_date": "2026-09-29T15:30:26.734Z", "cvss_score": 9.3, "epss_score": 0.00464, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.37867, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54400", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f0b90996-2b29-4b73-9f28-fd30b15ec3a0", "vulnerability": {"vulnId": "CVE-2015-20122", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-29T17:10:34+02:00"}, "gcve": {"object_uuid": "f0b90996-2b29-4b73-9f28-fd30b15ec3a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-29T15:10:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-29T15:10:34+00:00"}, "scope": {"notes": "Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp | Affected: Yonyou / A6 OA | CVSS: 8.7 (HIGH) | EPSS: 0.00476 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-20122", "url": "https://www.cve.org/CVERecord?id=CVE-2015-20122"}, {"id": "GHSA-JP76-J5HR-562V", "url": "https://github.com/advisories/GHSA-JP76-J5HR-562V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-20122"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp", "cve_id": "CVE-2015-20122", "vendor": "Yonyou", "ghsa_id": "GHSA-JP76-J5HR-562V", "product": "A6 OA", "added_date": "2026-09-29T15:10:34.191Z", "cvss_score": 8.7, "epss_score": 0.00476, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.38831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-20122", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "97856b10-7719-4920-badd-6c35612f58f5", "vulnerability": {"vulnId": "CVE-2026-85520", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-29T13:40:26+02:00"}, "gcve": {"object_uuid": "97856b10-7719-4920-badd-6c35612f58f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-29T11:40:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-29T11:40:26+00:00"}, "scope": {"notes": "Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module | Affected: MyPresta / Google Merchant Center Feed | CVSS: 9.3 (CRITICAL) | EPSS: 0.00991 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-85520", "url": "https://www.cve.org/CVERecord?id=CVE-2026-85520"}, {"id": "GHSA-MXMH-VX83-QFXG", "url": "https://github.com/advisories/GHSA-MXMH-VX83-QFXG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-85520"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module", "cve_id": "CVE-2026-85520", "vendor": "MyPresta", "ghsa_id": "GHSA-MXMH-VX83-QFXG", "product": "Google Merchant Center Feed", "added_date": "2026-09-29T11:40:26.621Z", "cvss_score": 9.3, "epss_score": 0.00991, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61172, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-85520", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ef40094f-c47a-4656-bcbf-da930bf6f44d", "vulnerability": {"vulnId": "CVE-2025-62023", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-29T09:10:24+02:00"}, "gcve": {"object_uuid": "ef40094f-c47a-4656-bcbf-da930bf6f44d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-29T07:10:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-29T07:10:24+00:00"}, "scope": {"notes": "WordPress s2Member plugin <= 250905 - Remote Code Execution (RCE) vulnerability | Affected: Cristi\u00e1n L\u00e1vaque / s2Member | CVSS: 9.0 (CRITICAL) | EPSS: 0.00418 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-62023", "url": "https://www.cve.org/CVERecord?id=CVE-2025-62023"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-62023"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress s2Member plugin <= 250905 - Remote Code Execution (RCE) vulnerability", "cve_id": "CVE-2025-62023", "vendor": "Cristi\u00e1n L\u00e1vaque", "ghsa_id": null, "product": "s2Member", "added_date": "2026-09-29T07:10:24.985Z", "cvss_score": 9.0, "epss_score": 0.00418, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.3381, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-62023", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b8a76ec3-6323-4c56-9360-6ab9c79bbd7f", "vulnerability": {"vulnId": "CVE-2026-86950", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-28T21:30:46+02:00"}, "gcve": {"object_uuid": "b8a76ec3-6323-4c56-9360-6ab9c79bbd7f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-28T19:30:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-28T19:30:46+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.01242 | Used in malware: unknown | Listed 19 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-86950", "url": "https://www.cve.org/CVERecord?id=CVE-2026-86950"}, {"id": "GHSA-3CF3-H799-FJVQ", "url": "https://github.com/advisories/GHSA-3CF3-H799-FJVQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-86950"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia...", "cve_id": "CVE-2026-86950", "vendor": "Apple", "ghsa_id": "GHSA-3CF3-H799-FJVQ", "product": "iOS and iPadOS, macOS", "added_date": "2026-09-28T19:30:46.754Z", "cvss_score": 8.8, "epss_score": 0.01242, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68097, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-86950", "ahead_of_cisa_kev": {"unit": "hour", "count": 19}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dda0a464-a61f-4baa-ab9a-59f97aa9098c", "vulnerability": {"vulnId": "CVE-2026-49076", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-28T08:01:08+02:00"}, "gcve": {"object_uuid": "dda0a464-a61f-4baa-ab9a-59f97aa9098c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-28T06:01:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-28T06:01:08+00:00"}, "scope": {"notes": "WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability | Affected: Crocoblock / JetEngine | CVSS: 9.3 (CRITICAL) | EPSS: 0.004 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-49076", "url": "https://www.cve.org/CVERecord?id=CVE-2026-49076"}, {"id": "GHSA-JM3J-9P9F-953F", "url": "https://github.com/advisories/GHSA-JM3J-9P9F-953F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-49076"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability", "cve_id": "CVE-2026-49076", "vendor": "Crocoblock", "ghsa_id": "GHSA-JM3J-9P9F-953F", "product": "JetEngine", "added_date": "2026-09-28T06:01:08.926Z", "cvss_score": 9.3, "epss_score": 0.004, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.31835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-49076", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "227780c0-4c0e-4a6b-b681-356f72c8c9a4", "vulnerability": {"vulnId": "CVE-2026-42608", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-27T19:12:00+02:00"}, "gcve": {"object_uuid": "227780c0-4c0e-4a6b-b681-356f72c8c9a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-27T17:12:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-27T17:12:00+00:00"}, "scope": {"notes": "Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component. | Affected: Getgrav / grav | CVSS: 8.8 (HIGH) | EPSS: 0.00521 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-42608", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42608"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42608"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.", "cve_id": "CVE-2026-42608", "vendor": "Getgrav", "ghsa_id": null, "product": "grav", "added_date": "2026-09-27T17:12:00.000Z", "cvss_score": 8.8, "epss_score": 0.00521, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.4213, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42608", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8d44fc51-fba4-45cd-b0fe-4238152db271", "vulnerability": {"vulnId": "CVE-2026-88772", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-27T18:45:00+02:00"}, "gcve": {"object_uuid": "8d44fc51-fba4-45cd-b0fe-4238152db271", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-27T16:45:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-27T16:45:00+00:00"}, "scope": {"notes": "Memory overflow vulnerability leading to Remote Code Execution or Denial of Service | Affected: Citrix NetScaler / ADC, Gateway | CVSS: 9.5 (CRITICAL) | EPSS: 0.01301 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-88772", "url": "https://www.cve.org/CVERecord?id=CVE-2026-88772"}, {"id": "GHSA-H5XM-PF48-4C32", "url": "https://github.com/advisories/GHSA-H5XM-PF48-4C32"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-88772"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Memory overflow vulnerability leading to Remote Code Execution or Denial of Service", "cve_id": "CVE-2026-88772", "vendor": "Citrix NetScaler", "ghsa_id": "GHSA-H5XM-PF48-4C32", "product": "ADC, Gateway", "added_date": "2026-09-27T16:45:00.000Z", "cvss_score": 9.5, "epss_score": 0.01301, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69413, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-88772", "ahead_of_cisa_kev": {"unit": "hour", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9a51539b-3eb6-4a05-8ad4-4da312baa092", "vulnerability": {"vulnId": "CVE-2026-88771", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-27T18:44:00+02:00"}, "gcve": {"object_uuid": "9a51539b-3eb6-4a05-8ad4-4da312baa092", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-27T16:44:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-27T16:44:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | Affected: Citrix NetScaler / ADC, Gateway | CVSS: 9.5 (CRITICAL) | EPSS: 0.01063 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-88771", "url": "https://www.cve.org/CVERecord?id=CVE-2026-88771"}, {"id": "GHSA-MX58-P288-86QP", "url": "https://github.com/advisories/GHSA-MX58-P288-86QP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-88771"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands", "cve_id": "CVE-2026-88771", "vendor": "Citrix NetScaler", "ghsa_id": "GHSA-MX58-P288-86QP", "product": "ADC, Gateway", "added_date": "2026-09-27T16:44:00.000Z", "cvss_score": 9.5, "epss_score": 0.01063, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63393, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-88771", "ahead_of_cisa_kev": {"unit": "hour", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c54319c0-bd12-4409-b163-4308b7562b28", "vulnerability": {"vulnId": "CVE-2026-65660", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-24T14:32:16+02:00"}, "gcve": {"object_uuid": "c54319c0-bd12-4409-b163-4308b7562b28", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-24T12:32:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-24T12:32:16+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 8.8 (HIGH) | EPSS: 0.02101 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-65660", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65660"}, {"id": "GHSA-R94X-X846-RXQX", "url": "https://github.com/advisories/GHSA-R94X-X846-RXQX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-65660"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability", "cve_id": "CVE-2026-65660", "vendor": "Microsoft", "ghsa_id": "GHSA-R94X-X846-RXQX", "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-09-24T12:32:16.826Z", "cvss_score": 8.8, "epss_score": 0.02101, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.81034, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-65660", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "26df2b4d-fe15-4c57-b8b5-64b0cfda1220", "vulnerability": {"vulnId": "CVE-2026-48842", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-24T11:23:00+02:00"}, "gcve": {"object_uuid": "26df2b4d-fe15-4c57-b8b5-64b0cfda1220", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-24T09:23:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-24T09:23:00+00:00"}, "scope": {"notes": "Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace()... | Affected: Roundcube / Webmail | CVSS: 8.1 (HIGH) | EPSS: 0.00891 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-48842", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48842"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48842"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace()...", "cve_id": "CVE-2026-48842", "vendor": "Roundcube", "ghsa_id": null, "product": "Webmail", "added_date": "2026-09-24T09:23:00.000Z", "cvss_score": 8.1, "epss_score": 0.00891, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5792, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48842", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fabacc0d-7aa0-4ab5-a285-111379c4b6fa", "vulnerability": {"vulnId": "CVE-2026-67279", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-23T19:08:47+02:00"}, "gcve": {"object_uuid": "fabacc0d-7aa0-4ab5-a285-111379c4b6fa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-23T17:08:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-23T17:08:47+00:00"}, "scope": {"notes": "SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS | Affected: Mikrotik / RouterOS | CVSS: 6.9 (MEDIUM) | EPSS: 0.01027 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-67279", "url": "https://www.cve.org/CVERecord?id=CVE-2026-67279"}, {"id": "GHSA-PQP3-GJGF-83CF", "url": "https://github.com/advisories/GHSA-PQP3-GJGF-83CF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-67279"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS", "cve_id": "CVE-2026-67279", "vendor": "Mikrotik", "ghsa_id": "GHSA-PQP3-GJGF-83CF", "product": "RouterOS", "added_date": "2026-09-23T17:08:47.607Z", "cvss_score": 6.9, "epss_score": 0.01027, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62316, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-67279", "ahead_of_cisa_kev": {"unit": "day", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e42957dd-1421-4eca-b481-e204d5b6f1d0", "vulnerability": {"vulnId": "CVE-2026-87902", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-23T14:53:51+02:00"}, "gcve": {"object_uuid": "e42957dd-1421-4eca-b481-e204d5b6f1d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-23T12:53:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-23T12:53:51+00:00"}, "scope": {"notes": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active... | Affected: WordPress / WordPress | CVSS: 8.1 (HIGH) | EPSS: 0.19756 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-87902", "url": "https://www.cve.org/CVERecord?id=CVE-2026-87902"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-87902"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active...", "cve_id": "CVE-2026-87902", "vendor": "WordPress", "ghsa_id": null, "product": "WordPress", "added_date": "2026-09-23T12:53:51.266Z", "cvss_score": 8.1, "epss_score": 0.19756, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97331, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-87902", "ahead_of_cisa_kev": {"unit": "day", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "697dc20c-4433-4202-8cb0-8e0a8478342f", "vulnerability": {"vulnId": "CVE-2026-89026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-23T13:38:11+02:00"}, "gcve": {"object_uuid": "697dc20c-4433-4202-8cb0-8e0a8478342f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-23T11:38:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-23T11:38:11+00:00"}, "scope": {"notes": "Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate | Affected: Issabel / Issabel Framework | CVSS: 9.3 (CRITICAL) | EPSS: 0.00685 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-89026", "url": "https://www.cve.org/CVERecord?id=CVE-2026-89026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-89026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate", "cve_id": "CVE-2026-89026", "vendor": "Issabel", "ghsa_id": null, "product": "Issabel Framework", "added_date": "2026-09-23T11:38:11.631Z", "cvss_score": 9.3, "epss_score": 0.00685, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5084, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-89026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ead3f9c1-3e0e-46a8-b604-c3ce44d5912c", "vulnerability": {"vulnId": "CVE-2016-20080", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-23T13:15:47+02:00"}, "gcve": {"object_uuid": "ead3f9c1-3e0e-46a8-b604-c3ce44d5912c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-23T11:15:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-23T11:15:47+00:00"}, "scope": {"notes": "WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php | Affected: Brandfolder / Brandfolder | CVSS: 6.9 (MEDIUM) | EPSS: 0.0039 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-20080", "url": "https://www.cve.org/CVERecord?id=CVE-2016-20080"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-20080"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php", "cve_id": "CVE-2016-20080", "vendor": "Brandfolder", "ghsa_id": null, "product": "Brandfolder", "added_date": "2026-09-23T11:15:47.735Z", "cvss_score": 6.9, "epss_score": 0.0039, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.30621, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-20080", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "156bf92d-c88f-4aaf-aee8-f8c0f2b647e5", "vulnerability": {"vulnId": "CVE-2026-94127", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T18:21:00+02:00"}, "gcve": {"object_uuid": "156bf92d-c88f-4aaf-aee8-f8c0f2b647e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T16:21:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T16:21:00+00:00"}, "scope": {"notes": "BIG-IP APM OAuth vulnerability | Affected: F5 / BIG-IP | CVSS: 9.3 (CRITICAL) | EPSS: 0.02226 | Used in malware: unknown | Listed 3 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-94127", "url": "https://www.cve.org/CVERecord?id=CVE-2026-94127"}, {"id": "GHSA-QPPV-6JRG-HXQ4", "url": "https://github.com/advisories/GHSA-QPPV-6JRG-HXQ4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-94127"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BIG-IP APM OAuth vulnerability", "cve_id": "CVE-2026-94127", "vendor": "F5", "ghsa_id": "GHSA-QPPV-6JRG-HXQ4", "product": "BIG-IP", "added_date": "2026-09-22T16:21:00.000Z", "cvss_score": 9.3, "epss_score": 0.02226, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82095, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-94127", "ahead_of_cisa_kev": {"unit": "hour", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "420d5b58-c9a7-444f-8cd7-5846815e79a6", "vulnerability": {"vulnId": "CVE-2026-75949", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T15:50:27+02:00"}, "gcve": {"object_uuid": "420d5b58-c9a7-444f-8cd7-5846815e79a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T13:50:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T13:50:27+00:00"}, "scope": {"notes": "Joomla Extension - cmsjunkie.com -  Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 | Affected: Cmsjunkie.com / J-BusinessDirectory extension for Joomla | CVSS: 10.0 (CRITICAL) | EPSS: 0.00428 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-75949", "url": "https://www.cve.org/CVERecord?id=CVE-2026-75949"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-75949"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - cmsjunkie.com -  Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3", "cve_id": "CVE-2026-75949", "vendor": "Cmsjunkie.com", "ghsa_id": null, "product": "J-BusinessDirectory extension for Joomla", "added_date": "2026-09-22T13:50:27.661Z", "cvss_score": 10.0, "epss_score": 0.00428, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.34715, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-75949", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "54bfd4ea-9189-402e-8437-deed69ea1dbf", "vulnerability": {"vulnId": "CVE-2026-93616", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T15:50:06+02:00"}, "gcve": {"object_uuid": "54bfd4ea-9189-402e-8437-deed69ea1dbf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T13:50:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T13:50:06+00:00"}, "scope": {"notes": "Directory Traversal and File upload allows execution of arbitrary script on the Management Server | Affected: Check Point / Quantum Security Management | CVSS: 9.8 (CRITICAL) | EPSS: 0.19654 | Used in malware: unknown | Listed 6 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-93616", "url": "https://www.cve.org/CVERecord?id=CVE-2026-93616"}, {"id": "GHSA-X5GQ-4CXX-RF2R", "url": "https://github.com/advisories/GHSA-X5GQ-4CXX-RF2R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-93616"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory Traversal and File upload allows execution of arbitrary script on the Management Server", "cve_id": "CVE-2026-93616", "vendor": "Check Point", "ghsa_id": "GHSA-X5GQ-4CXX-RF2R", "product": "Quantum Security Management", "added_date": "2026-09-22T13:50:06.963Z", "cvss_score": 9.8, "epss_score": 0.19654, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-93616", "ahead_of_cisa_kev": {"unit": "hour", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9c0ae63f-fa88-453d-bb53-eefe82ff1327", "vulnerability": {"vulnId": "CVE-2026-85102", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T15:49:33+02:00"}, "gcve": {"object_uuid": "9c0ae63f-fa88-453d-bb53-eefe82ff1327", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T13:49:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T13:49:33+00:00"}, "scope": {"notes": "Improper Certificate Validation in Quantum Security Gateway | Affected: Check Point / Quantum Security Gateway | CVSS: 9.8 (CRITICAL) | EPSS: 0.07546 | Used in malware: unknown | Listed 6 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-85102", "url": "https://www.cve.org/CVERecord?id=CVE-2026-85102"}, {"id": "GHSA-3FVR-5GG9-225M", "url": "https://github.com/advisories/GHSA-3FVR-5GG9-225M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-85102"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Certificate Validation in Quantum Security Gateway", "cve_id": "CVE-2026-85102", "vendor": "Check Point", "ghsa_id": "GHSA-3FVR-5GG9-225M", "product": "Quantum Security Gateway", "added_date": "2026-09-22T13:49:33.449Z", "cvss_score": 9.8, "epss_score": 0.07546, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94328, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-85102", "ahead_of_cisa_kev": {"unit": "hour", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "af96c7fc-b4ac-4523-8856-b178fde14268", "vulnerability": {"vulnId": "CVE-2026-79756", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T13:33:20+02:00"}, "gcve": {"object_uuid": "af96c7fc-b4ac-4523-8856-b178fde14268", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T11:33:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T11:33:20+00:00"}, "scope": {"notes": "Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | Affected: Nuclio / nuclio | CVSS: 8.7 (HIGH) | EPSS: 0.07523 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-79756", "url": "https://www.cve.org/CVERecord?id=CVE-2026-79756"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-79756"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform", "cve_id": "CVE-2026-79756", "vendor": "Nuclio", "ghsa_id": null, "product": "nuclio", "added_date": "2026-09-22T11:33:20.860Z", "cvss_score": 8.7, "epss_score": 0.07523, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94315, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-79756", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "95de7790-4043-4309-9537-dc589769420f", "vulnerability": {"vulnId": "CVE-2026-54569", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T13:33:14+02:00"}, "gcve": {"object_uuid": "95de7790-4043-4309-9537-dc589769420f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T11:33:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T11:33:14+00:00"}, "scope": {"notes": "SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core | Affected: Senaite / senaite.core | CVSS: 9.8 (CRITICAL) | EPSS: 0.01156 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-54569", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54569"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-54569"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core", "cve_id": "CVE-2026-54569", "vendor": "Senaite", "ghsa_id": null, "product": "senaite.core", "added_date": "2026-09-22T11:33:14.053Z", "cvss_score": 9.8, "epss_score": 0.01156, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6587, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-54569", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5426b3cc-743e-4875-a460-8d6e02b03d67", "vulnerability": {"vulnId": "CVE-2026-56271", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T13:32:55+02:00"}, "gcve": {"object_uuid": "5426b3cc-743e-4875-a460-8d6e02b03d67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T11:32:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T11:32:55+00:00"}, "scope": {"notes": "Flowise - Weak Default JWT Secrets in Authentication Middleware | Affected: Flowise / Flowise | CVSS: 9.3 (CRITICAL) | EPSS: 0.00655 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-56271", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56271"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-56271"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise - Weak Default JWT Secrets in Authentication Middleware", "cve_id": "CVE-2026-56271", "vendor": "Flowise", "ghsa_id": null, "product": "Flowise", "added_date": "2026-09-22T11:32:55.153Z", "cvss_score": 9.3, "epss_score": 0.00655, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.49498, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-56271", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e37070c6-5f40-493c-9d01-a6633577c402", "vulnerability": {"vulnId": "CVE-2026-93952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T12:06:00+02:00"}, "gcve": {"object_uuid": "e37070c6-5f40-493c-9d01-a6633577c402", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T10:06:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T10:06:00+00:00"}, "scope": {"notes": "Security Advisory 0183 | Affected: Arista / VeloCloud Orchestrator (VCO) On-Prem | CVSS: 9.5 (CRITICAL) | EPSS: 0.01062 | Used in malware: unknown | Listed 10 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-93952", "url": "https://www.cve.org/CVERecord?id=CVE-2026-93952"}, {"id": "GHSA-FQHW-F6HF-CQ3W", "url": "https://github.com/advisories/GHSA-FQHW-F6HF-CQ3W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-93952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Security Advisory 0183", "cve_id": "CVE-2026-93952", "vendor": "Arista", "ghsa_id": "GHSA-FQHW-F6HF-CQ3W", "product": "VeloCloud Orchestrator (VCO) On-Prem", "added_date": "2026-09-22T10:06:00.365Z", "cvss_score": 9.5, "epss_score": 0.01062, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63342, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-93952", "ahead_of_cisa_kev": {"unit": "hour", "count": 10}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dd066ff7-a889-4556-9f76-08a3188c5273", "vulnerability": {"vulnId": "CVE-2026-66457", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T09:50:38+02:00"}, "gcve": {"object_uuid": "dd066ff7-a889-4556-9f76-08a3188c5273", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-22T07:50:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-22T07:50:38+00:00"}, "scope": {"notes": "WordPress Events Manager plugin <= 7.4.2 - Cross Site Scripting (XSS) vulnerability | Affected: Pixelite / Events Manager | CVSS: 7.1 (HIGH) | EPSS: 0.00251 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-66457", "url": "https://www.cve.org/CVERecord?id=CVE-2026-66457"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-66457"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Events Manager plugin <= 7.4.2 - Cross Site Scripting (XSS) vulnerability", "cve_id": "CVE-2026-66457", "vendor": "Pixelite", "ghsa_id": null, "product": "Events Manager", "added_date": "2026-09-22T07:50:38.771Z", "cvss_score": 7.1, "epss_score": 0.00251, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.14941, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-66457", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6a5bcd27-a4c4-4add-b4d9-cba2b86dfc74", "vulnerability": {"vulnId": "CVE-2026-26980", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-22T00:32:51+02:00"}, "gcve": {"object_uuid": "6a5bcd27-a4c4-4add-b4d9-cba2b86dfc74", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T22:32:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T22:32:51+00:00"}, "scope": {"notes": "Ghost has a SQL Injection in its Content API | Affected: TryGhost / Ghost | CVSS: 9.4 (CRITICAL) | EPSS: 0.04953 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-26980", "url": "https://www.cve.org/CVERecord?id=CVE-2026-26980"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-26980"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ghost has a SQL Injection in its Content API", "cve_id": "CVE-2026-26980", "vendor": "TryGhost", "ghsa_id": null, "product": "Ghost", "added_date": "2026-09-21T22:32:51.000Z", "cvss_score": 9.4, "epss_score": 0.04953, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-26980", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "79819ebf-9aa4-4b2a-9d6e-bf6fc2b23d87", "vulnerability": {"vulnId": "CVE-2026-32996", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T22:34:30+02:00"}, "gcve": {"object_uuid": "79819ebf-9aa4-4b2a-9d6e-bf6fc2b23d87", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T20:34:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T20:34:30+00:00"}, "scope": {"notes": "This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. | Affected: Veeam / Backup and Replication | CVSS: 7.3 (HIGH) | EPSS: 0.00167 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-32996", "url": "https://www.cve.org/CVERecord?id=CVE-2026-32996"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-32996"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.", "cve_id": "CVE-2026-32996", "vendor": "Veeam", "ghsa_id": null, "product": "Backup and Replication", "added_date": "2026-09-21T20:34:30.610Z", "cvss_score": 7.3, "epss_score": 0.00167, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.05347, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-32996", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e3a7eda1-37ad-4b73-8334-4fb9174e15de", "vulnerability": {"vulnId": "CVE-2024-52270", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T20:01:14+02:00"}, "gcve": {"object_uuid": "e3a7eda1-37ad-4b73-8334-4fb9174e15de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T18:01:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T18:01:14+00:00"}, "scope": {"notes": "PDF Document Spoofing in DropBox Sign(HelloSign) | Affected: DropBox(HelloSign) / DropBox Sign | CVSS: 8.2 (HIGH) | EPSS: 0.00193 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-52270", "url": "https://www.cve.org/CVERecord?id=CVE-2024-52270"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-52270"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PDF Document Spoofing in DropBox Sign(HelloSign)", "cve_id": "CVE-2024-52270", "vendor": "DropBox(HelloSign)", "ghsa_id": null, "product": "DropBox Sign", "added_date": "2026-09-21T18:01:14.657Z", "cvss_score": 8.2, "epss_score": 0.00193, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.08076, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-52270", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "742575d0-e4d1-4edf-bb8f-99f44afea4bf", "vulnerability": {"vulnId": "CVE-2026-7273", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T15:20:00+02:00"}, "gcve": {"object_uuid": "742575d0-e4d1-4edf-bb8f-99f44afea4bf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T13:20:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T13:20:00+00:00"}, "scope": {"notes": "A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through\u00a02.90(ABTQ.1)C0 could allow a... | Affected: Zyxel / GS1900-48HPv2 firmware, GS1900-8 firmware, GS1900-8HP firmware, GS1900-10HP firmware, GS1900-16 firmware, GS1900-24 firmware, GS1900-24E firmware, GS1900-24EP firmware, GS1900-24HPv2 firmware, GS1900-48 firmware | CVSS: 8.8 (HIGH) | EPSS: 0.02501 | Used in malware: unknown | Listed 6 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-7273", "url": "https://www.cve.org/CVERecord?id=CVE-2026-7273"}, {"id": "GHSA-RRV4-8JQ5-8J78", "url": "https://github.com/advisories/GHSA-RRV4-8JQ5-8J78"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-7273"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through\u00a02.90(ABTQ.1)C0 could allow a...", "cve_id": "CVE-2026-7273", "vendor": "Zyxel", "ghsa_id": "GHSA-RRV4-8JQ5-8J78", "product": "GS1900-48HPv2 firmware, GS1900-8 firmware, GS1900-8HP firmware, GS1900-10HP firmware, GS1900-16 firmware, GS1900-24 firmware, GS1900-24E firmware, GS1900-24EP firmware, GS1900-24HPv2 firmware, GS1900-48 firmware", "added_date": "2026-09-21T13:20:00.000Z", "cvss_score": 8.8, "epss_score": 0.02501, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-7273", "ahead_of_cisa_kev": {"unit": "hour", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3fdba68a-8c0a-4dcb-9249-7f67abf170c0", "vulnerability": {"vulnId": "CVE-2026-27960", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T10:06:49+02:00"}, "gcve": {"object_uuid": "3fdba68a-8c0a-4dcb-9249-7f67abf170c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T08:06:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T08:06:49+00:00"}, "scope": {"notes": "OpenCTI privilege escalation and unauthenticated access via default admin account | Affected: OpenCTI-Platform / opencti | CVSS: 9.8 (CRITICAL) | EPSS: 0.01805 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-27960", "url": "https://www.cve.org/CVERecord?id=CVE-2026-27960"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-27960"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenCTI privilege escalation and unauthenticated access via default admin account", "cve_id": "CVE-2026-27960", "vendor": "OpenCTI-Platform", "ghsa_id": null, "product": "opencti", "added_date": "2026-09-21T08:06:49.239Z", "cvss_score": 9.8, "epss_score": 0.01805, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77764, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-27960", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fcf93ac8-61c6-4868-ab1c-addad2cf4174", "vulnerability": {"vulnId": "CVE-2026-88062", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T02:00:00+02:00"}, "gcve": {"object_uuid": "fcf93ac8-61c6-4868-ab1c-addad2cf4174", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T00:00:00+00:00"}, "scope": {"notes": "OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | Affected: Diegosouzapw / OmniRoute | CVSS: 9.5 (CRITICAL) | EPSS: 0.01424 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-88062", "url": "https://www.cve.org/CVERecord?id=CVE-2026-88062"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-88062"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OmniRoute ACP Custom-Agent Remote Code Execution (RCE)", "cve_id": "CVE-2026-88062", "vendor": "Diegosouzapw", "ghsa_id": null, "product": "OmniRoute", "added_date": "2026-09-21T00:00:00.000Z", "cvss_score": 9.5, "epss_score": 0.01424, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71943, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-88062", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "de03a04c-b5e0-4b44-a2f0-d46206f296fe", "vulnerability": {"vulnId": "CVE-2021-30134", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T02:00:00+02:00"}, "gcve": {"object_uuid": "de03a04c-b5e0-4b44-a2f0-d46206f296fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T00:00:00+00:00"}, "scope": {"notes": "php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to... | Affected: Php_curl_class_project, Ht_slider_range_for_amazon_affiliates_project, Qiwi, Teamleade, Ptwooplugins, Shopello_api_project / PHP Curl Class, HT Slider Range FOR Amazon Affiliates, Woo-qiwi-payment-gateway, Teamleader CRM Forms, Invoicing With Invoicexpress FOR Woocommerce, Shopello API | CVSS: 6.1 (MEDIUM) | EPSS: 0.01261 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30134", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30134"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30134"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to...", "cve_id": "CVE-2021-30134", "vendor": "Php_curl_class_project, Ht_slider_range_for_amazon_affiliates_project, Qiwi, Teamleade, Ptwooplugins, Shopello_api_project", "ghsa_id": null, "product": "PHP Curl Class, HT Slider Range FOR Amazon Affiliates, Woo-qiwi-payment-gateway, Teamleader CRM Forms, Invoicing With Invoicexpress FOR Woocommerce, Shopello API", "added_date": "2026-09-21T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01261, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6856, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30134", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "863cac30-d1b4-431c-8944-6dae14d1ccad", "vulnerability": {"vulnId": "CVE-2018-13980", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-21T02:00:00+02:00"}, "gcve": {"object_uuid": "863cac30-d1b4-431c-8944-6dae14d1ccad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-21T00:00:00+00:00"}, "scope": {"notes": "The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin... | Affected: Zeta-producer / Zeta Producer | CVSS: 5.5 (MEDIUM) | EPSS: 0.06902 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-13980", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13980"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13980"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin...", "cve_id": "CVE-2018-13980", "vendor": "Zeta-producer", "ghsa_id": null, "product": "Zeta Producer", "added_date": "2026-09-21T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.06902, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93883, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-13980", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dcfa2f05-60de-4227-9ec7-ba36f3fb9e9c", "vulnerability": {"vulnId": "CVE-2026-32882", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T22:28:00+02:00"}, "gcve": {"object_uuid": "dcfa2f05-60de-4227-9ec7-ba36f3fb9e9c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T20:28:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T20:28:00+00:00"}, "scope": {"notes": "libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride | Affected: Strukturag / libheif | CVSS: 7.1 (HIGH) | EPSS: 0.00708 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-32882", "url": "https://www.cve.org/CVERecord?id=CVE-2026-32882"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-32882"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride", "cve_id": "CVE-2026-32882", "vendor": "Strukturag", "ghsa_id": null, "product": "libheif", "added_date": "2026-09-18T20:28:00.000Z", "cvss_score": 7.1, "epss_score": 0.00708, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-32882", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7bca8fe4-dc32-4dcd-abf8-bab042e05950", "vulnerability": {"vulnId": "CVE-2017-20284", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T21:20:49+02:00"}, "gcve": {"object_uuid": "7bca8fe4-dc32-4dcd-abf8-bab042e05950", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T19:20:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T19:20:49+00:00"}, "scope": {"notes": "Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet | Affected: Caucho Technology / Resin | CVSS: 8.7 (HIGH) | EPSS: 0.00958 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-20284", "url": "https://www.cve.org/CVERecord?id=CVE-2017-20284"}, {"id": "GHSA-X46G-Q89H-7XG3", "url": "https://github.com/advisories/GHSA-X46G-Q89H-7XG3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-20284"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet", "cve_id": "CVE-2017-20284", "vendor": "Caucho Technology", "ghsa_id": "GHSA-X46G-Q89H-7XG3", "product": "Resin", "added_date": "2026-09-18T19:20:49.638Z", "cvss_score": 8.7, "epss_score": 0.00958, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60078, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-20284", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "baac6e29-972d-4651-abd2-019583dffcb8", "vulnerability": {"vulnId": "CVE-2025-39682", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T21:20:38+02:00"}, "gcve": {"object_uuid": "baac6e29-972d-4651-abd2-019583dffcb8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T19:20:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T19:20:38+00:00"}, "scope": {"notes": "tls: fix handling of zero-length records on the rx_list | Affected: Linux / Linux | CVSS: 9.8 (CRITICAL) | EPSS: 0.0288 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-39682", "url": "https://www.cve.org/CVERecord?id=CVE-2025-39682"}, {"id": "GHSA-V2PF-75PF-9C5H", "url": "https://github.com/advisories/GHSA-V2PF-75PF-9C5H"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-39682"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "tls: fix handling of zero-length records on the rx_list", "cve_id": "CVE-2025-39682", "vendor": "Linux", "ghsa_id": "GHSA-V2PF-75PF-9C5H", "product": "Linux", "added_date": "2026-09-18T19:20:38.811Z", "cvss_score": 9.8, "epss_score": 0.0288, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86361, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-39682", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a016db6e-d62f-491b-90b1-46379b24bc84", "vulnerability": {"vulnId": "CVE-2021-48008", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T21:10:54+02:00"}, "gcve": {"object_uuid": "a016db6e-d62f-491b-90b1-46379b24bc84", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T19:10:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T19:10:54+00:00"}, "scope": {"notes": "Chanjet CRM SQL Injection via get_usedspace.php | Affected: Chanjet Information Technology / CRM | CVSS: 8.7 (HIGH) | EPSS: 0.00344 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-48008", "url": "https://www.cve.org/CVERecord?id=CVE-2021-48008"}, {"id": "GHSA-X5GC-R7QF-2H87", "url": "https://github.com/advisories/GHSA-X5GC-R7QF-2H87"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-48008"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Chanjet CRM SQL Injection via get_usedspace.php", "cve_id": "CVE-2021-48008", "vendor": "Chanjet Information Technology", "ghsa_id": "GHSA-X5GC-R7QF-2H87", "product": "CRM", "added_date": "2026-09-18T19:10:54.694Z", "cvss_score": 8.7, "epss_score": 0.00344, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.25501, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-48008", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6f739cc1-c52d-4c98-bd45-314f26b11767", "vulnerability": {"vulnId": "CVE-2023-54399", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T21:10:54+02:00"}, "gcve": {"object_uuid": "6f739cc1-c52d-4c98-bd45-314f26b11767", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T19:10:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T19:10:54+00:00"}, "scope": {"notes": "Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree | Affected: Hongjing / e-HR | CVSS: 9.3 (CRITICAL) | EPSS: 0.00416 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-54399", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54399"}, {"id": "GHSA-6J7F-83XH-J3X3", "url": "https://github.com/advisories/GHSA-6J7F-83XH-J3X3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54399"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree", "cve_id": "CVE-2023-54399", "vendor": "Hongjing", "ghsa_id": "GHSA-6J7F-83XH-J3X3", "product": "e-HR", "added_date": "2026-09-18T19:10:54.907Z", "cvss_score": 9.3, "epss_score": 0.00416, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.33573, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54399", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "309a8f9d-a5b1-4a1e-9b74-de796520fe63", "vulnerability": {"vulnId": "CVE-2019-25776", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T21:10:53+02:00"}, "gcve": {"object_uuid": "309a8f9d-a5b1-4a1e-9b74-de796520fe63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T19:10:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T19:10:53+00:00"}, "scope": {"notes": "Weaver E-cology SQL Injection via SyncUserInfo.jsp | Affected: Weaver Network / E-cology | CVSS: 8.7 (HIGH) | EPSS: 0.00361 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-25776", "url": "https://www.cve.org/CVERecord?id=CVE-2019-25776"}, {"id": "GHSA-XWCR-FG7M-3JXV", "url": "https://github.com/advisories/GHSA-XWCR-FG7M-3JXV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-25776"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology SQL Injection via SyncUserInfo.jsp", "cve_id": "CVE-2019-25776", "vendor": "Weaver Network", "ghsa_id": "GHSA-XWCR-FG7M-3JXV", "product": "E-cology", "added_date": "2026-09-18T19:10:53.862Z", "cvss_score": 8.7, "epss_score": 0.00361, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.27519, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-25776", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "863a4c01-3b8e-45b4-839a-e3781dded2f9", "vulnerability": {"vulnId": "CVE-2026-53266", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T16:30:43+02:00"}, "gcve": {"object_uuid": "863a4c01-3b8e-45b4-839a-e3781dded2f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T14:30:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T14:30:43+00:00"}, "scope": {"notes": "netfilter: bridge: make ebt_snat ARP rewrite writable | Affected: Linux / Linux | CVSS: 8.8 (HIGH) | EPSS: 0.00645 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-53266", "url": "https://www.cve.org/CVERecord?id=CVE-2026-53266"}, {"id": "GHSA-XMHG-RR34-2CHJ", "url": "https://github.com/advisories/GHSA-XMHG-RR34-2CHJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-53266"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "netfilter: bridge: make ebt_snat ARP rewrite writable", "cve_id": "CVE-2026-53266", "vendor": "Linux", "ghsa_id": "GHSA-XMHG-RR34-2CHJ", "product": "Linux", "added_date": "2026-09-18T14:30:43.435Z", "cvss_score": 8.8, "epss_score": 0.00645, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.49041, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-53266", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "65722839-bd09-49db-8000-90c9dae4a1e1", "vulnerability": {"vulnId": "CVE-2025-39964", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T16:30:42+02:00"}, "gcve": {"object_uuid": "65722839-bd09-49db-8000-90c9dae4a1e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T14:30:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T14:30:42+00:00"}, "scope": {"notes": "crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.00996 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-39964", "url": "https://www.cve.org/CVERecord?id=CVE-2025-39964"}, {"id": "GHSA-WR5G-MFHW-RPFJ", "url": "https://github.com/advisories/GHSA-WR5G-MFHW-RPFJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-39964"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg", "cve_id": "CVE-2025-39964", "vendor": "Linux", "ghsa_id": "GHSA-WR5G-MFHW-RPFJ", "product": "Linux", "added_date": "2026-09-18T14:30:42.702Z", "cvss_score": 7.8, "epss_score": 0.00996, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61324, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-39964", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3187fdc0-09ed-482a-bfa1-622ea269e915", "vulnerability": {"vulnId": "CVE-2026-0769", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T09:40:05+02:00"}, "gcve": {"object_uuid": "3187fdc0-09ed-482a-bfa1-622ea269e915", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T07:40:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T07:40:05+00:00"}, "scope": {"notes": "Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability | Affected: Langflow / Langflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.32335 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-0769", "url": "https://www.cve.org/CVERecord?id=CVE-2026-0769"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-0769"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability", "cve_id": "CVE-2026-0769", "vendor": "Langflow", "ghsa_id": null, "product": "Langflow", "added_date": "2026-09-18T07:40:05.027Z", "cvss_score": 9.8, "epss_score": 0.32335, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98279, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-0769", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "97480651-5eb4-425a-b165-85e8295dc48b", "vulnerability": {"vulnId": "CVE-2026-42796", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "97480651-5eb4-425a-b165-85e8295dc48b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T00:00:00+00:00"}, "scope": {"notes": "Arelle < 2.39.10 Unauthenticated RCE via /rest/configure | Affected: Arelle / Arelle | CVSS: 9.2 (CRITICAL) | EPSS: 0.03878 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-42796", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42796"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42796"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arelle < 2.39.10 Unauthenticated RCE via /rest/configure", "cve_id": "CVE-2026-42796", "vendor": "Arelle", "ghsa_id": null, "product": "Arelle", "added_date": "2026-09-18T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.03878, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89889, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42796", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2676dbd5-9a13-498e-af34-d998b2b4432f", "vulnerability": {"vulnId": "CVE-2024-53900", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "2676dbd5-9a13-498e-af34-d998b2b4432f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T00:00:00+00:00"}, "scope": {"notes": "Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. | Affected: Mongoosejs / Mongoose | CVSS: 9.1 (CRITICAL) | EPSS: 0.03981 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-53900", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53900"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53900"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.", "cve_id": "CVE-2024-53900", "vendor": "Mongoosejs", "ghsa_id": null, "product": "Mongoose", "added_date": "2026-09-18T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.03981, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9017, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-53900", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "12689edc-0d45-40b4-82f5-d86d4bf04a4d", "vulnerability": {"vulnId": "CVE-2023-46359", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "12689edc-0d45-40b4-82f5-d86d4bf04a4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T00:00:00+00:00"}, "scope": {"notes": "An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to... | Affected: Hardy-barth / cph2 Echarge Firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.87608 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-46359", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46359"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46359"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to...", "cve_id": "CVE-2023-46359", "vendor": "Hardy-barth", "ghsa_id": null, "product": "cph2 Echarge Firmware", "added_date": "2026-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.87608, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99756, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-46359", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "eee38a3b-6b89-45bd-a27f-1e55c46a2010", "vulnerability": {"vulnId": "CVE-2023-29827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "eee38a3b-6b89-45bd-a27f-1e55c46a2010", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-18T00:00:00+00:00"}, "scope": {"notes": "ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the... | Affected: Ejs / EJS | CVSS: 9.8 (CRITICAL) | EPSS: 0.05552 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-29827", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the...", "cve_id": "CVE-2023-29827", "vendor": "Ejs", "ghsa_id": null, "product": "EJS", "added_date": "2026-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.05552, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92597, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c740152e-d4a0-48dc-a86b-bd1d15be0e5b", "vulnerability": {"vulnId": "CVE-2026-89013", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T18:42:08+02:00"}, "gcve": {"object_uuid": "c740152e-d4a0-48dc-a86b-bd1d15be0e5b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T16:42:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T16:42:08+00:00"}, "scope": {"notes": "Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php | Affected: Dolibarr / Dolibarr | CVSS: 8.7 (HIGH) | EPSS: 0.0156 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-89013", "url": "https://www.cve.org/CVERecord?id=CVE-2026-89013"}, {"id": "GHSA-FM6P-42MR-X6JM", "url": "https://github.com/advisories/GHSA-FM6P-42MR-X6JM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-89013"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php", "cve_id": "CVE-2026-89013", "vendor": "Dolibarr", "ghsa_id": "GHSA-FM6P-42MR-X6JM", "product": "Dolibarr", "added_date": "2026-09-17T16:42:08.068Z", "cvss_score": 8.7, "epss_score": 0.0156, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-89013", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "486ab2bb-6cb9-4ad1-8cfa-64f55dc30e63", "vulnerability": {"vulnId": "CVE-2026-86538", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T18:27:22+02:00"}, "gcve": {"object_uuid": "486ab2bb-6cb9-4ad1-8cfa-64f55dc30e63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T16:27:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T16:27:22+00:00"}, "scope": {"notes": "knowns before 0.30.0 Path Traversal via templateFile parameter | Affected: Knowns-dev / knowns | CVSS: 8.7 (HIGH) | EPSS: 0.00984 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-86538", "url": "https://www.cve.org/CVERecord?id=CVE-2026-86538"}, {"id": "GHSA-G3M9-72X4-RRGV", "url": "https://github.com/advisories/GHSA-G3M9-72X4-RRGV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-86538"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "knowns before 0.30.0 Path Traversal via templateFile parameter", "cve_id": "CVE-2026-86538", "vendor": "Knowns-dev", "ghsa_id": "GHSA-G3M9-72X4-RRGV", "product": "knowns", "added_date": "2026-09-17T16:27:22.620Z", "cvss_score": 8.7, "epss_score": 0.00984, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60958, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-86538", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e8a639fa-e476-4740-b58a-2915710d095d", "vulnerability": {"vulnId": "CVE-2022-25497", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T12:28:20+02:00"}, "gcve": {"object_uuid": "e8a639fa-e476-4740-b58a-2915710d095d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T10:28:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T10:28:20+00:00"}, "scope": {"notes": "CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function. | Affected: Cuppa CMS / Cuppacms | CVSS: 5.3 (MEDIUM) | EPSS: 0.03642 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25497", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25497"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25497"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.", "cve_id": "CVE-2022-25497", "vendor": "Cuppa CMS", "ghsa_id": null, "product": "Cuppacms", "added_date": "2026-09-17T10:28:20.728Z", "cvss_score": 5.3, "epss_score": 0.03642, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89211, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25497", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f5f06c90-29c1-4235-b840-8a68f25f5845", "vulnerability": {"vulnId": "CVE-2026-40242", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "f5f06c90-29c1-4235-b840-8a68f25f5845", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T00:00:00+00:00"}, "scope": {"notes": "Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint | Affected: Getarcaneapp / arcane | CVSS: 7.2 (HIGH) | EPSS: 0.00721 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-40242", "url": "https://www.cve.org/CVERecord?id=CVE-2026-40242"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-40242"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint", "cve_id": "CVE-2026-40242", "vendor": "Getarcaneapp", "ghsa_id": null, "product": "arcane", "added_date": "2026-09-17T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.00721, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52221, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-40242", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e8445648-dbd1-4331-96c6-ed30a2d78196", "vulnerability": {"vulnId": "CVE-2016-15043", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "e8445648-dbd1-4331-96c6-ed30a2d78196", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T00:00:00+00:00"}, "scope": {"notes": "WP Mobile Detector <= 3.5 - Arbitrary File Upload | Affected: Websitez.com / WP Mobile Detector | CVSS: 9.8 (CRITICAL) | EPSS: 0.07817 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-15043", "url": "https://www.cve.org/CVERecord?id=CVE-2016-15043"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-15043"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WP Mobile Detector <= 3.5 - Arbitrary File Upload", "cve_id": "CVE-2016-15043", "vendor": "Websitez.com", "ghsa_id": null, "product": "WP Mobile Detector", "added_date": "2026-09-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07817, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94493, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-15043", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "751918ad-ed64-4cba-b961-04cb65005c27", "vulnerability": {"vulnId": "CVE-2021-24946", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "751918ad-ed64-4cba-b961-04cb65005c27", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T00:00:00+00:00"}, "scope": {"notes": "Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection | Affected: Webnus / Modern Events Calendar Lite | CVSS: 9.8 (CRITICAL) | EPSS: 0.728 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24946", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24946"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24946"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection", "cve_id": "CVE-2021-24946", "vendor": "Webnus", "ghsa_id": null, "product": "Modern Events Calendar Lite", "added_date": "2026-09-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.728, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99435, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24946", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "da339157-30e2-41f2-a138-763815afe62a", "vulnerability": {"vulnId": "CVE-2026-32255", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "da339157-30e2-41f2-a138-763815afe62a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T00:00:00+00:00"}, "scope": {"notes": "Kan is Vulnerable to Unauthenticated SSRF via Attachment Download Endpoint | Affected: Kanbn / kan | CVSS: 8.6 (HIGH) | EPSS: 0.01744 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-32255", "url": "https://www.cve.org/CVERecord?id=CVE-2026-32255"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-32255"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kan is Vulnerable to Unauthenticated SSRF via Attachment Download Endpoint", "cve_id": "CVE-2026-32255", "vendor": "Kanbn", "ghsa_id": null, "product": "kan", "added_date": "2026-09-17T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.01744, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-32255", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "46d22890-1b70-4612-a7a3-af8535516b53", "vulnerability": {"vulnId": "CVE-2022-45362", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "46d22890-1b70-4612-a7a3-af8535516b53", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-17T00:00:00+00:00"}, "scope": {"notes": "WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF) | Affected: Paytm / Paytm Payment Gateway | CVSS: 7.2 (HIGH) | EPSS: 0.41762 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-45362", "url": "https://www.cve.org/CVERecord?id=CVE-2022-45362"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-45362"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Paytm Payment Gateway Plugin <= 2.7.0 is vulnerable to Server Side Request Forgery (SSRF)", "cve_id": "CVE-2022-45362", "vendor": "Paytm", "ghsa_id": null, "product": "Paytm Payment Gateway", "added_date": "2026-09-17T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.41762, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98646, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-45362", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4291037f-ec96-4e60-b635-b491b72b5c0b", "vulnerability": {"vulnId": "CVE-2026-76460", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T21:21:00+02:00"}, "gcve": {"object_uuid": "4291037f-ec96-4e60-b635-b491b72b5c0b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T19:21:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T19:21:00+00:00"}, "scope": {"notes": "Cisco Identity Services Engine Authentication Bypass Vulnerability | Affected: Cisco / Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector | CVSS: 10.0 (CRITICAL) | EPSS: 0.14026 | Used in malware: unknown | Listed 1 hour ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-76460", "url": "https://www.cve.org/CVERecord?id=CVE-2026-76460"}, {"id": "GHSA-25WC-3W28-Q6VW", "url": "https://github.com/advisories/GHSA-25WC-3W28-Q6VW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-76460"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Identity Services Engine Authentication Bypass Vulnerability", "cve_id": "CVE-2026-76460", "vendor": "Cisco", "ghsa_id": "GHSA-25WC-3W28-Q6VW", "product": "Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector", "added_date": "2026-09-16T19:21:00.000Z", "cvss_score": 10.0, "epss_score": 0.14026, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96449, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-76460", "ahead_of_cisa_kev": {"unit": "hour", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e358992d-4f72-42e3-ae6a-410a28c49ba6", "vulnerability": {"vulnId": "CVE-2026-54196", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T13:50:30+02:00"}, "gcve": {"object_uuid": "e358992d-4f72-42e3-ae6a-410a28c49ba6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T11:50:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T11:50:30+00:00"}, "scope": {"notes": "WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability | Affected: Jetmonsters / JetFormBuilder | CVSS: 6.8 (MEDIUM) | EPSS: 0.00279 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-54196", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54196"}, {"id": "GHSA-C56P-W54Q-P2C5", "url": "https://github.com/advisories/GHSA-C56P-W54Q-P2C5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-54196"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability", "cve_id": "CVE-2026-54196", "vendor": "Jetmonsters", "ghsa_id": "GHSA-C56P-W54Q-P2C5", "product": "JetFormBuilder", "added_date": "2026-09-16T11:50:30.268Z", "cvss_score": 6.8, "epss_score": 0.00279, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.18432, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-54196", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "50330fe2-a7d3-4c33-aec6-3a8f3c16e897", "vulnerability": {"vulnId": "CVE-2026-58704", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T10:15:00+02:00"}, "gcve": {"object_uuid": "50330fe2-a7d3-4c33-aec6-3a8f3c16e897", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T08:15:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T08:15:00+00:00"}, "scope": {"notes": "In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation... | Affected: Google / Android | CVSS: 8.8 (HIGH) | EPSS: 0.00591 | Used in malware: unknown | Listed 6 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-58704", "url": "https://www.cve.org/CVERecord?id=CVE-2026-58704"}, {"id": "GHSA-CHQ2-JXGV-5VFW", "url": "https://github.com/advisories/GHSA-CHQ2-JXGV-5VFW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-58704"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation...", "cve_id": "CVE-2026-58704", "vendor": "Google", "ghsa_id": "GHSA-CHQ2-JXGV-5VFW", "product": "Android", "added_date": "2026-09-16T08:15:00.000Z", "cvss_score": 8.8, "epss_score": 0.00591, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.46292, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-58704", "ahead_of_cisa_kev": {"unit": "hour", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e66f3a21-1ae6-4d07-bf72-456fffb39726", "vulnerability": {"vulnId": "CVE-2026-5430", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T07:18:06+02:00"}, "gcve": {"object_uuid": "e66f3a21-1ae6-4d07-bf72-456fffb39726", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T05:18:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T05:18:06+00:00"}, "scope": {"notes": "Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover | Affected: WSO2 / WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Manager Rest API Utility | CVSS: 10.0 (CRITICAL) | EPSS: 0.00588 | Used in malware: unknown | Listed 8 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-5430", "url": "https://www.cve.org/CVERecord?id=CVE-2026-5430"}, {"id": "GHSA-J7VH-5W8Q-4M4X", "url": "https://github.com/advisories/GHSA-J7VH-5W8Q-4M4X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-5430"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover", "cve_id": "CVE-2026-5430", "vendor": "WSO2", "ghsa_id": "GHSA-J7VH-5W8Q-4M4X", "product": "WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Control Plane, WSO2 API Manager, WSO2 Carbon API Manager Rest API Utility", "added_date": "2026-09-16T05:18:06.000Z", "cvss_score": 10.0, "epss_score": 0.00588, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.46154, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-5430", "ahead_of_cisa_kev": {"unit": "day", "count": 8}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "23f3eec0-47b7-4025-94eb-b1007bfe345f", "vulnerability": {"vulnId": "CVE-2022-0412", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "23f3eec0-47b7-4025-94eb-b1007bfe345f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T00:00:00+00:00"}, "scope": {"notes": "TI WooCommerce Wishlist < 1.40.1 - Unauthenticated Blind SQL Injection | Affected: TemplateInvaders / TI WooCommerce Wishlist, TI WooCommerce Wishlist Pro | CVSS: 9.8 (CRITICAL) | EPSS: 0.73998 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0412", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0412"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0412"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TI WooCommerce Wishlist < 1.40.1 - Unauthenticated Blind SQL Injection", "cve_id": "CVE-2022-0412", "vendor": "TemplateInvaders", "ghsa_id": null, "product": "TI WooCommerce Wishlist, TI WooCommerce Wishlist Pro", "added_date": "2026-09-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.73998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9947, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0412", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8bf9adf9-26fc-47c3-8e05-e73535a0ce20", "vulnerability": {"vulnId": "CVE-2019-1003000", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "8bf9adf9-26fc-47c3-8e05-e73535a0ce20", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T00:00:00+00:00"}, "scope": {"notes": "A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in... | Affected: Jenkins project / Script Security Plugin | CVSS: 8.8 (HIGH) | EPSS: 0.98375 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-1003000", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1003000"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1003000"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in...", "cve_id": "CVE-2019-1003000", "vendor": "Jenkins project", "ghsa_id": null, "product": "Script Security Plugin", "added_date": "2026-09-16T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.98375, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99917, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1003000", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a7942099-7fde-439c-beb6-ae26b95153fc", "vulnerability": {"vulnId": "CVE-2022-0434", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "a7942099-7fde-439c-beb6-ae26b95153fc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-16T00:00:00+00:00"}, "scope": {"notes": "Page Views Count < 2.4.15 - Unauthenticated SQL Injection | Affected: a3rev / Page View Count | CVSS: 9.8 (CRITICAL) | EPSS: 0.14783 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0434", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0434"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0434"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Page Views Count < 2.4.15 - Unauthenticated SQL Injection", "cve_id": "CVE-2022-0434", "vendor": "a3rev", "ghsa_id": null, "product": "Page View Count", "added_date": "2026-09-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14783, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96584, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0434", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e9a27a69-d696-45af-87f8-ea9739f85374", "vulnerability": {"vulnId": "CVE-2026-87886", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T23:57:00+02:00"}, "gcve": {"object_uuid": "e9a27a69-d696-45af-87f8-ea9739f85374", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T21:57:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T21:57:00+00:00"}, "scope": {"notes": "Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux)... | Affected: Acronis / Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for Plesk, Acronis Backup plugin for DirectAdmin | CVSS: 7.8 (HIGH) | EPSS: 0.00233 | Used in malware: unknown | Listed 21 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-87886", "url": "https://www.cve.org/CVERecord?id=CVE-2026-87886"}, {"id": "GHSA-HRQ3-QGQ7-JM9X", "url": "https://github.com/advisories/GHSA-HRQ3-QGQ7-JM9X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-87886"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux)...", "cve_id": "CVE-2026-87886", "vendor": "Acronis", "ghsa_id": "GHSA-HRQ3-QGQ7-JM9X", "product": "Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for Plesk, Acronis Backup plugin for DirectAdmin", "added_date": "2026-09-15T21:57:00.000Z", "cvss_score": 7.8, "epss_score": 0.00233, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.12841, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-87886", "ahead_of_cisa_kev": {"unit": "hour", "count": 21}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4f431ff8-ecd9-408b-ac47-1576e34f70e5", "vulnerability": {"vulnId": "CVE-2026-69255", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T21:57:31+02:00"}, "gcve": {"object_uuid": "4f431ff8-ecd9-408b-ac47-1576e34f70e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T19:57:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T19:57:31+00:00"}, "scope": {"notes": "Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection \u2014 Root Shell Verified | Affected: FlowiseAI / Flowise | CVSS: 9.2 (CRITICAL) | EPSS: 0.00716 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-69255", "url": "https://www.cve.org/CVERecord?id=CVE-2026-69255"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-69255"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection \u2014 Root Shell Verified", "cve_id": "CVE-2026-69255", "vendor": "FlowiseAI", "ghsa_id": null, "product": "Flowise", "added_date": "2026-09-15T19:57:31.772Z", "cvss_score": 9.2, "epss_score": 0.00716, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.52016, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-69255", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e85f70ec-7373-4cc3-896b-f588ab676fab", "vulnerability": {"vulnId": "CVE-2024-58385", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T19:00:53+02:00"}, "gcve": {"object_uuid": "e85f70ec-7373-4cc3-896b-f588ab676fab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T17:00:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T17:00:53+00:00"}, "scope": {"notes": "Yonyou U8 CRM SQL Injection via fillbacksettingedit.php | Affected: Yonyou / U8 CRM | CVSS: 9.3 (CRITICAL) | EPSS: 0.0038 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-58385", "url": "https://www.cve.org/CVERecord?id=CVE-2024-58385"}, {"id": "GHSA-MR5W-WPQV-H82F", "url": "https://github.com/advisories/GHSA-MR5W-WPQV-H82F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-58385"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yonyou U8 CRM SQL Injection via fillbacksettingedit.php", "cve_id": "CVE-2024-58385", "vendor": "Yonyou", "ghsa_id": "GHSA-MR5W-WPQV-H82F", "product": "U8 CRM", "added_date": "2026-09-15T17:00:53.938Z", "cvss_score": 9.3, "epss_score": 0.0038, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.29541, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-58385", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e8d60cbf-d07e-460a-9e80-b362243aae86", "vulnerability": {"vulnId": "CVE-2023-54398", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T19:00:52+02:00"}, "gcve": {"object_uuid": "e8d60cbf-d07e-460a-9e80-b362243aae86", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T17:00:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T17:00:52+00:00"}, "scope": {"notes": "Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet | Affected: Yonyou / U8 Cloud | CVSS: 9.3 (CRITICAL) | EPSS: 0.00642 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-54398", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54398"}, {"id": "GHSA-R89P-QRRF-VPMC", "url": "https://github.com/advisories/GHSA-R89P-QRRF-VPMC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54398"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yonyou U8 Cloud Java Deserialization RCE via FileManageServlet", "cve_id": "CVE-2023-54398", "vendor": "Yonyou", "ghsa_id": "GHSA-R89P-QRRF-VPMC", "product": "U8 Cloud", "added_date": "2026-09-15T17:00:52.437Z", "cvss_score": 9.3, "epss_score": 0.00642, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.48897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54398", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "aab1f618-81d1-4df3-b0d6-0752e8004c60", "vulnerability": {"vulnId": "CVE-2026-39364", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T17:40:00+02:00"}, "gcve": {"object_uuid": "aab1f618-81d1-4df3-b0d6-0752e8004c60", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T15:40:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T15:40:00+00:00"}, "scope": {"notes": "Vite has a `server.fs.deny` bypass with queries | Affected: Vitejs / vite, vite-plus | CVSS: 8.2 (HIGH) | EPSS: 0.01535 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-39364", "url": "https://www.cve.org/CVERecord?id=CVE-2026-39364"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-39364"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vite has a `server.fs.deny` bypass with queries", "cve_id": "CVE-2026-39364", "vendor": "Vitejs", "ghsa_id": null, "product": "vite, vite-plus", "added_date": "2026-09-15T15:40:00.000Z", "cvss_score": 8.2, "epss_score": 0.01535, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7391, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-39364", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a766e5b-cc2d-465d-b7b6-8b3251b46e60", "vulnerability": {"vulnId": "CVE-2016-10760", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "2a766e5b-cc2d-465d-b7b6-8b3251b46e60", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T00:00:00+00:00"}, "scope": {"notes": "On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter. | Affected: Seowonintech / swr-300a Firmware, swr-300b Firmware, swr-300c Firmware, swr-300bg Firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.03226 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-10760", "url": "https://www.cve.org/CVERecord?id=CVE-2016-10760"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-10760"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the ping_ipaddr parameter.", "cve_id": "CVE-2016-10760", "vendor": "Seowonintech", "ghsa_id": null, "product": "swr-300a Firmware, swr-300b Firmware, swr-300c Firmware, swr-300bg Firmware", "added_date": "2026-09-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03226, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87808, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-10760", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "22db56d5-9d98-4794-8587-a04ca1ca9ea5", "vulnerability": {"vulnId": "CVE-2025-9603", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "22db56d5-9d98-4794-8587-a04ca1ca9ea5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T00:00:00+00:00"}, "scope": {"notes": "Telesquare TLR-2005KSH internet.cgi command injection | Affected: Telesquare / TLR-2005KSH | CVSS: 5.3 (MEDIUM) | EPSS: 0.07575 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-9603", "url": "https://www.cve.org/CVERecord?id=CVE-2025-9603"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-9603"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Telesquare TLR-2005KSH internet.cgi command injection", "cve_id": "CVE-2025-9603", "vendor": "Telesquare", "ghsa_id": null, "product": "TLR-2005KSH", "added_date": "2026-09-15T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.07575, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94348, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-9603", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ba8bf88e-61b5-4449-8e6c-57e6271bf173", "vulnerability": {"vulnId": "CVE-2017-7876", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "ba8bf88e-61b5-4449-8e6c-57e6271bf173", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-15T00:00:00+00:00"}, "scope": {"notes": "This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the... | Affected: Qnap / QTS | CVSS: 10.0 (CRITICAL) | EPSS: 0.03338 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-7876", "url": "https://www.cve.org/CVERecord?id=CVE-2017-7876"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-7876"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the...", "cve_id": "CVE-2017-7876", "vendor": "Qnap", "ghsa_id": null, "product": "QTS", "added_date": "2026-09-15T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.03338, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88246, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-7876", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "57e9ec58-bbcb-4f28-8839-8292525a968b", "vulnerability": {"vulnId": "CVE-2026-27540", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T20:49:14+02:00"}, "gcve": {"object_uuid": "57e9ec58-bbcb-4f28-8839-8292525a968b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T18:49:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T18:49:14+00:00"}, "scope": {"notes": "WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability | Affected: Rymera Web / Woocommerce Wholesale Lead Capture | CVSS: 9.0 (CRITICAL) | EPSS: 0.01567 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-27540", "url": "https://www.cve.org/CVERecord?id=CVE-2026-27540"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-27540"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability", "cve_id": "CVE-2026-27540", "vendor": "Rymera Web", "ghsa_id": null, "product": "Woocommerce Wholesale Lead Capture", "added_date": "2026-09-14T18:49:14.000Z", "cvss_score": 9.0, "epss_score": 0.01567, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74418, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-27540", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7fd6411f-efcb-40f8-9a25-d9018f01cd56", "vulnerability": {"vulnId": "CVE-2026-76461", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T18:00:00+02:00"}, "gcve": {"object_uuid": "7fd6411f-efcb-40f8-9a25-d9018f01cd56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T16:00:00+00:00"}, "scope": {"notes": "Cisco Secure Email Gateway SQL Injection Vulnerability | Affected: Cisco / Cisco Secure Email | CVSS: 9.8 (CRITICAL) | EPSS: 0.28269 | Used in malware: unknown | Listed 4 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-76461", "url": "https://www.cve.org/CVERecord?id=CVE-2026-76461"}, {"id": "GHSA-JWPF-JWW6-H6VR", "url": "https://github.com/advisories/GHSA-JWPF-JWW6-H6VR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-76461"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Secure Email Gateway SQL Injection Vulnerability", "cve_id": "CVE-2026-76461", "vendor": "Cisco", "ghsa_id": "GHSA-JWPF-JWW6-H6VR", "product": "Cisco Secure Email", "added_date": "2026-09-14T16:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.28269, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98065, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-76461", "ahead_of_cisa_kev": {"unit": "hour", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0d7281c-be70-4f5b-83fe-714630962b4a", "vulnerability": {"vulnId": "CVE-2026-51990", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T15:33:00+02:00"}, "gcve": {"object_uuid": "e0d7281c-be70-4f5b-83fe-714630962b4a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T13:33:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T13:33:00+00:00"}, "scope": {"notes": "An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe... | Affected: Tencent / Sogou / Sogou Input Method for Windows | CVSS: 9.8 (CRITICAL) | EPSS: 0.00926 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-51990", "url": "https://www.cve.org/CVERecord?id=CVE-2026-51990"}, {"id": "GHSA-RWR7-CC7W-2WRW", "url": "https://github.com/advisories/GHSA-RWR7-CC7W-2WRW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-51990"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe...", "cve_id": "CVE-2026-51990", "vendor": "Tencent / Sogou", "ghsa_id": "GHSA-RWR7-CC7W-2WRW", "product": "Sogou Input Method for Windows", "added_date": "2026-09-14T13:33:00.000Z", "cvss_score": 9.8, "epss_score": 0.00926, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.59042, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-51990", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ddc7f38f-be0e-4d54-b6ca-2d4967b8fbbc", "vulnerability": {"vulnId": "CVE-2026-23536", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T09:22:32+02:00"}, "gcve": {"object_uuid": "ddc7f38f-be0e-4d54-b6ca-2d4967b8fbbc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T07:22:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T07:22:32+00:00"}, "scope": {"notes": "Feast: unauthenticated arbitrary file read | Affected: Red Hat / Red Hat OpenShift AI (RHOAI) | CVSS: 7.5 (HIGH) | EPSS: 0.02409 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-23536", "url": "https://www.cve.org/CVERecord?id=CVE-2026-23536"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-23536"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Feast: unauthenticated arbitrary file read", "cve_id": "CVE-2026-23536", "vendor": "Red Hat", "ghsa_id": null, "product": "Red Hat OpenShift AI (RHOAI)", "added_date": "2026-09-14T07:22:32.883Z", "cvss_score": 7.5, "epss_score": 0.02409, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83487, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-23536", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ca171142-d38f-4a9a-a927-2608fb5eb6b0", "vulnerability": {"vulnId": "CVE-2026-55786", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T09:22:25+02:00"}, "gcve": {"object_uuid": "ca171142-d38f-4a9a-a927-2608fb5eb6b0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T07:22:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T07:22:25+00:00"}, "scope": {"notes": "Flyto2 Core - Unauthenticated OS command execution via HTTP MCP | Affected: Flyto2 / flyto-core | CVSS: 8.4 (HIGH) | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-55786", "url": "https://www.cve.org/CVERecord?id=CVE-2026-55786"}, {"id": "GHSA-H9F9-H6GM-WC85", "url": "https://github.com/advisories/GHSA-H9F9-H6GM-WC85"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-55786"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flyto2 Core - Unauthenticated OS command execution via HTTP MCP", "cve_id": "CVE-2026-55786", "vendor": "Flyto2", "ghsa_id": "GHSA-H9F9-H6GM-WC85", "product": "flyto-core", "added_date": "2026-09-14T07:22:25.586Z", "cvss_score": 8.4, "epss_score": null, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": null, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-55786", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "daa516a1-b658-423e-bc32-8044ddedb0fd", "vulnerability": {"vulnId": "CVE-2024-24112", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "daa516a1-b658-423e-bc32-8044ddedb0fd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | Affected: Exrick / Xmall | CVSS: 9.8 (CRITICAL) | EPSS: 0.03348 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-24112", "url": "https://www.cve.org/CVERecord?id=CVE-2024-24112"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-24112"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.", "cve_id": "CVE-2024-24112", "vendor": "Exrick", "ghsa_id": null, "product": "Xmall", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03348, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88277, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-24112", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4e0f084b-d68d-46bc-83df-732eed6e0f9b", "vulnerability": {"vulnId": "CVE-2017-17731", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "4e0f084b-d68d-46bc-83df-732eed6e0f9b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. | Affected: Dedecms / Dedecms | CVSS: 9.8 (CRITICAL) | EPSS: 0.13194 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-17731", "url": "https://www.cve.org/CVERecord?id=CVE-2017-17731"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-17731"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.", "cve_id": "CVE-2017-17731", "vendor": "Dedecms", "ghsa_id": null, "product": "Dedecms", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.13194, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96259, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-17731", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "30740fca-a687-4927-a257-d9267d45d96a", "vulnerability": {"vulnId": "CVE-2022-32028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "30740fca-a687-4927-a257-d9267d45d96a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=. | Affected: Car_rental_management_system_project / CAR Rental Management System | CVSS: 7.2 (HIGH) | EPSS: 0.05059 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-32028", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.", "cve_id": "CVE-2022-32028", "vendor": "Car_rental_management_system_project", "ghsa_id": null, "product": "CAR Rental Management System", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.05059, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92045, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9d4de9ea-b5db-42a5-8f29-46fea82fa216", "vulnerability": {"vulnId": "CVE-2022-30047", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "9d4de9ea-b5db-42a5-8f29-46fea82fa216", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter. | Affected: Mingsoft / Mcms | CVSS: 9.8 (CRITICAL) | EPSS: 0.0146 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-30047", "url": "https://www.cve.org/CVERecord?id=CVE-2022-30047"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-30047"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.", "cve_id": "CVE-2022-30047", "vendor": "Mingsoft", "ghsa_id": null, "product": "Mcms", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.0146, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72602, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-30047", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "59df35ec-43a0-408a-b88a-f88c0f452daa", "vulnerability": {"vulnId": "CVE-2022-32024", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "59df35ec-43a0-408a-b88a-f88c0f452daa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=. | Affected: Car_rental_management_system_project / CAR Rental Management System | CVSS: 7.2 (HIGH) | EPSS: 0.04563 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-32024", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32024"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32024"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.", "cve_id": "CVE-2022-32024", "vendor": "Car_rental_management_system_project", "ghsa_id": null, "product": "CAR Rental Management System", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.04563, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91308, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32024", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2b2ece94-67dd-40ba-997e-b439634ddf67", "vulnerability": {"vulnId": "CVE-2022-32026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "2b2ece94-67dd-40ba-997e-b439634ddf67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=. | Affected: Car_rental_management_system_project / CAR Rental Management System | CVSS: 7.2 (HIGH) | EPSS: 0.05308 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-32026", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.", "cve_id": "CVE-2022-32026", "vendor": "Car_rental_management_system_project", "ghsa_id": null, "product": "CAR Rental Management System", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.05308, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92338, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8e3ceacf-5fa8-4497-a02f-6d292aaeb59c", "vulnerability": {"vulnId": "CVE-2018-10735", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "8e3ceacf-5fa8-4497-a02f-6d292aaeb59c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter. | Affected: Nagios / Nagios XI | CVSS: 7.2 (HIGH) | EPSS: 0.4205 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10735", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10735"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10735"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.", "cve_id": "CVE-2018-10735", "vendor": "Nagios", "ghsa_id": null, "product": "Nagios XI", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.4205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98653, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10735", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5cb5e564-e867-4305-b8ad-79ced36a9ba8", "vulnerability": {"vulnId": "CVE-2022-27927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "5cb5e564-e867-4305-b8ad-79ced36a9ba8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can... | Affected: Microfinance_management_system_project / Microfinance Management System | CVSS: 9.8 (CRITICAL) | EPSS: 0.13829 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-27927", "url": "https://www.cve.org/CVERecord?id=CVE-2022-27927"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-27927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can...", "cve_id": "CVE-2022-27927", "vendor": "Microfinance_management_system_project", "ghsa_id": null, "product": "Microfinance Management System", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.13829, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96411, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-27927", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6964621b-e664-4c8d-aed9-b0616b4cdea1", "vulnerability": {"vulnId": "CVE-2024-8529", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "6964621b-e664-4c8d-aed9-b0616b4cdea1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "LearnPress \u2013 WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' | Affected: Thimpress / LearnPress \u2013 WordPress LMS Plugin | CVSS: 10.0 (CRITICAL) | EPSS: 0.12056 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8529", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8529"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8529"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LearnPress \u2013 WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'", "cve_id": "CVE-2024-8529", "vendor": "Thimpress", "ghsa_id": null, "product": "LearnPress \u2013 WordPress LMS Plugin", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.12056, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96022, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8529", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a67e8ba8-65a1-4e89-85bf-6a6568bb8b11", "vulnerability": {"vulnId": "CVE-2018-10736", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "a67e8ba8-65a1-4e89-85bf-6a6568bb8b11", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter. | Affected: Nagios / Nagios XI | CVSS: 7.2 (HIGH) | EPSS: 0.4205 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10736", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10736"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10736"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.", "cve_id": "CVE-2018-10736", "vendor": "Nagios", "ghsa_id": null, "product": "Nagios XI", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.4205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98653, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10736", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bf7524dc-0529-45ce-be0d-1f3b35f39f7b", "vulnerability": {"vulnId": "CVE-2022-32025", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "bf7524dc-0529-45ce-be0d-1f3b35f39f7b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-14T00:00:00+00:00"}, "scope": {"notes": "Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=. | Affected: Car_rental_management_system_project / CAR Rental Management System | CVSS: 7.2 (HIGH) | EPSS: 0.04563 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-32025", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32025"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32025"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.", "cve_id": "CVE-2022-32025", "vendor": "Car_rental_management_system_project", "ghsa_id": null, "product": "CAR Rental Management System", "added_date": "2026-09-14T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.04563, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91308, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32025", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "64f7275d-73ab-468d-9126-c883dad66f06", "vulnerability": {"vulnId": "CVE-2025-32969", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-13T02:00:00+02:00"}, "gcve": {"object_uuid": "64f7275d-73ab-468d-9126-c883dad66f06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-13T00:00:00+00:00"}, "scope": {"notes": "org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API | Affected: Xwiki / xwiki-platform | CVSS: 9.3 (CRITICAL) | EPSS: 0.79428 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-32969", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32969"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32969"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API", "cve_id": "CVE-2025-32969", "vendor": "Xwiki", "ghsa_id": null, "product": "xwiki-platform", "added_date": "2026-09-13T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.79428, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99594, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32969", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3c3dff54-b821-4679-8ce1-3a867249a965", "vulnerability": {"vulnId": "CVE-2021-24827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-13T02:00:00+02:00"}, "gcve": {"object_uuid": "3c3dff54-b821-4679-8ce1-3a867249a965", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-13T00:00:00+00:00"}, "scope": {"notes": "Asgaros Forum < 1.15.13 - Unauthenticated SQL Injection | Affected: Asgaros / Asgaros Forum | CVSS: 9.8 (CRITICAL) | EPSS: 0.12559 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24827", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Asgaros Forum < 1.15.13 - Unauthenticated SQL Injection", "cve_id": "CVE-2021-24827", "vendor": "Asgaros", "ghsa_id": null, "product": "Asgaros Forum", "added_date": "2026-09-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.12559, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96118, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bb545d3f-b20a-4ef0-9d03-39ed7671b961", "vulnerability": {"vulnId": "CVE-2026-85706", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-11T22:01:20+02:00"}, "gcve": {"object_uuid": "bb545d3f-b20a-4ef0-9d03-39ed7671b961", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-11T20:01:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-11T20:01:20+00:00"}, "scope": {"notes": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | Affected: GitLab / GitLab | CVSS: 10.0 (CRITICAL) | EPSS: 0.92956 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-85706", "url": "https://www.cve.org/CVERecord?id=CVE-2026-85706"}, {"id": "GHSA-F47W-MRG9-G9P2", "url": "https://github.com/advisories/GHSA-F47W-MRG9-G9P2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-85706"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab", "cve_id": "CVE-2026-85706", "vendor": "GitLab", "ghsa_id": "GHSA-F47W-MRG9-G9P2", "product": "GitLab", "added_date": "2026-09-11T20:01:20.727Z", "cvss_score": 10.0, "epss_score": 0.92956, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9983, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-85706", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b9db73a0-bfd0-4207-9548-6237e7f08c53", "vulnerability": {"vulnId": "CVE-2025-29085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "b9db73a0-bfd0-4207-9548-6237e7f08c53", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-11T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via... | Affected: Vipshop / Saturn | CVSS: 9.8 (CRITICAL) | EPSS: 0.3121 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-29085", "url": "https://www.cve.org/CVERecord?id=CVE-2025-29085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-29085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via...", "cve_id": "CVE-2025-29085", "vendor": "Vipshop", "ghsa_id": null, "product": "Saturn", "added_date": "2026-09-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.3121, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98223, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-29085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3bb10bf7-7a6a-47a7-a3c6-da03cc4dd13d", "vulnerability": {"vulnId": "CVE-2025-2636", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "3bb10bf7-7a6a-47a7-a3c6-da03cc4dd13d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-11T00:00:00+00:00"}, "scope": {"notes": "InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion | Affected: Instawp / InstaWP Connect \u2013 1-click WP Staging & Migration | CVSS: 8.1 (HIGH) | EPSS: 0.10422 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-2636", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2636"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2636"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion", "cve_id": "CVE-2025-2636", "vendor": "Instawp", "ghsa_id": null, "product": "InstaWP Connect \u2013 1-click WP Staging & Migration", "added_date": "2026-09-11T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.10422, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2636", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3c858508-a488-41bb-86ce-656ce3fc5a38", "vulnerability": {"vulnId": "CVE-2018-18084", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "3c858508-a488-41bb-86ce-656ce3fc5a38", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-11T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. | Affected: Comsenz / Duomicms | CVSS: 9.8 (CRITICAL) | EPSS: 0.01261 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-18084", "url": "https://www.cve.org/CVERecord?id=CVE-2018-18084"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-18084"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.", "cve_id": "CVE-2018-18084", "vendor": "Comsenz", "ghsa_id": null, "product": "Duomicms", "added_date": "2026-09-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01261, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68545, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-18084", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cdced7b1-93e4-4cb3-8f91-cdb10700cd5d", "vulnerability": {"vulnId": "CVE-2017-8917", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "cdced7b1-93e4-4cb3-8f91-cdb10700cd5d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-11T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. | Affected: Joomla / Joomla! | CVSS: 9.8 (CRITICAL) | EPSS: 0.99826 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-8917", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8917"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8917"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.", "cve_id": "CVE-2017-8917", "vendor": "Joomla", "ghsa_id": null, "product": "Joomla!", "added_date": "2026-09-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99826, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99959, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8917", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7090476e-befb-422e-aaa6-0ce57cad8d81", "vulnerability": {"vulnId": "CVE-2025-1661", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "7090476e-befb-422e-aaa6-0ce57cad8d81", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-11T00:00:00+00:00"}, "scope": {"notes": "HUSKY \u2013 Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion | Affected: realmag777 / HUSKY \u2013 Products Filter Professional for WooCommerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.56382 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-1661", "url": "https://www.cve.org/CVERecord?id=CVE-2025-1661"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-1661"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HUSKY \u2013 Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion", "cve_id": "CVE-2025-1661", "vendor": "realmag777", "ghsa_id": null, "product": "HUSKY \u2013 Products Filter Professional for WooCommerce", "added_date": "2026-09-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.56382, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9903, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-1661", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a6cc8aa7-8204-489f-8970-1c55a41852bd", "vulnerability": {"vulnId": "CVE-2026-67277", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T21:50:56+02:00"}, "gcve": {"object_uuid": "a6cc8aa7-8204-489f-8970-1c55a41852bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T19:50:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T19:50:56+00:00"}, "scope": {"notes": "Kernel memory disclosure and denial of service in MikroTik RouterOS btest service | Affected: Mikrotik / RouterOS | CVSS: 8.8 (HIGH) | EPSS: 0.0156 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-67277", "url": "https://www.cve.org/CVERecord?id=CVE-2026-67277"}, {"id": "GHSA-6Q2X-6FHJ-R3W8", "url": "https://github.com/advisories/GHSA-6Q2X-6FHJ-R3W8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-67277"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kernel memory disclosure and denial of service in MikroTik RouterOS btest service", "cve_id": "CVE-2026-67277", "vendor": "Mikrotik", "ghsa_id": "GHSA-6Q2X-6FHJ-R3W8", "product": "RouterOS", "added_date": "2026-09-10T19:50:56.536Z", "cvss_score": 8.8, "epss_score": 0.0156, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74329, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-67277", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e4db42f-6b35-44ac-81ed-922e60e1a081", "vulnerability": {"vulnId": "CVE-2026-42016", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T21:04:00+02:00"}, "gcve": {"object_uuid": "6e4db42f-6b35-44ac-81ed-922e60e1a081", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T19:04:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T19:04:00+00:00"}, "scope": {"notes": "Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation | Affected: Jfrog / artifactory | CVSS: 8.1 (HIGH) | EPSS: 0.08643 | Used in malware: unknown | Listed 23 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-42016", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42016"}, {"id": "GHSA-58CV-8CFM-C8R8", "url": "https://github.com/advisories/GHSA-58CV-8CFM-C8R8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42016"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation", "cve_id": "CVE-2026-42016", "vendor": "Jfrog", "ghsa_id": "GHSA-58CV-8CFM-C8R8", "product": "artifactory", "added_date": "2026-09-10T19:04:00.000Z", "cvss_score": 8.1, "epss_score": 0.08643, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94954, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42016", "ahead_of_cisa_kev": {"unit": "hour", "count": 23}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cae56ed6-2e36-4c89-90b2-8916eef95595", "vulnerability": {"vulnId": "CVE-2026-42018", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T21:04:00+02:00"}, "gcve": {"object_uuid": "cae56ed6-2e36-4c89-90b2-8916eef95595", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T19:04:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T19:04:00+00:00"}, "scope": {"notes": "Anonymous user token generation exposure in JFrog Artifactory | Affected: Jfrog / artifactory | CVSS: 7.5 (HIGH) | EPSS: 0.09805 | Used in malware: unknown | Listed 23 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-42018", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42018"}, {"id": "GHSA-3Q94-GPRH-7PWM", "url": "https://github.com/advisories/GHSA-3Q94-GPRH-7PWM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42018"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Anonymous user token generation exposure in JFrog Artifactory", "cve_id": "CVE-2026-42018", "vendor": "Jfrog", "ghsa_id": "GHSA-3Q94-GPRH-7PWM", "product": "artifactory", "added_date": "2026-09-10T19:04:00.000Z", "cvss_score": 7.5, "epss_score": 0.09805, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95408, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42018", "ahead_of_cisa_kev": {"unit": "hour", "count": 23}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d371d384-41ed-4392-a9ed-57796e9d88c1", "vulnerability": {"vulnId": "CVE-2026-86060", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T18:26:00+02:00"}, "gcve": {"object_uuid": "d371d384-41ed-4392-a9ed-57796e9d88c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T16:26:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T16:26:00+00:00"}, "scope": {"notes": "SSH session privilege manipulation via a crafted username in Mikrotik RouterOS | Affected: Mikrotik / RouterOS | CVSS: 9.2 (CRITICAL) | EPSS: 0.01849 | Used in malware: unknown | Listed 3 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-86060", "url": "https://www.cve.org/CVERecord?id=CVE-2026-86060"}, {"id": "GHSA-6425-CJXV-52GP", "url": "https://github.com/advisories/GHSA-6425-CJXV-52GP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-86060"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SSH session privilege manipulation via a crafted username in Mikrotik RouterOS", "cve_id": "CVE-2026-86060", "vendor": "Mikrotik", "ghsa_id": "GHSA-6425-CJXV-52GP", "product": "RouterOS", "added_date": "2026-09-10T16:26:00.000Z", "cvss_score": 9.2, "epss_score": 0.01849, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78321, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-86060", "ahead_of_cisa_kev": {"unit": "hour", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "04323177-8a94-4927-978f-69cbb738ff8e", "vulnerability": {"vulnId": "CVE-2026-67276", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T18:25:00+02:00"}, "gcve": {"object_uuid": "04323177-8a94-4927-978f-69cbb738ff8e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T16:25:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T16:25:00+00:00"}, "scope": {"notes": "SSH user impersonation possible in Mikrotik RouterOS | Affected: Mikrotik / RouterOS | CVSS: 9.2 (CRITICAL) | EPSS: 0.06451 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-67276", "url": "https://www.cve.org/CVERecord?id=CVE-2026-67276"}, {"id": "GHSA-J9WG-77FW-F22F", "url": "https://github.com/advisories/GHSA-J9WG-77FW-F22F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-67276"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SSH user impersonation possible in Mikrotik RouterOS", "cve_id": "CVE-2026-67276", "vendor": "Mikrotik", "ghsa_id": "GHSA-J9WG-77FW-F22F", "product": "RouterOS", "added_date": "2026-09-10T16:25:00.000Z", "cvss_score": 9.2, "epss_score": 0.06451, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9352, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-67276", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6562b02a-cc57-4a1b-aea8-22ebdd65adf8", "vulnerability": {"vulnId": "CVE-2026-42031", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T11:03:59+02:00"}, "gcve": {"object_uuid": "6562b02a-cc57-4a1b-aea8-22ebdd65adf8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T09:03:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T09:03:59+00:00"}, "scope": {"notes": "CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql` | Affected: Ckan / ckan | CVSS: 8.3 (HIGH) | EPSS: 0.02188 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-42031", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42031"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42031"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`", "cve_id": "CVE-2026-42031", "vendor": "Ckan", "ghsa_id": null, "product": "ckan", "added_date": "2026-09-10T09:03:59.303Z", "cvss_score": 8.3, "epss_score": 0.02188, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81758, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42031", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c948730f-cd18-4ca8-a2c4-ad21b136e439", "vulnerability": {"vulnId": "CVE-2026-86206", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T08:32:55+02:00"}, "gcve": {"object_uuid": "c948730f-cd18-4ca8-a2c4-ad21b136e439", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T06:32:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T06:32:55+00:00"}, "scope": {"notes": "Access control filter bypass allows unauthorised access to APIs | Affected: N-able / N-central | CVSS: 6.9 (MEDIUM) | EPSS: 0.01118 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-86206", "url": "https://www.cve.org/CVERecord?id=CVE-2026-86206"}, {"id": "GHSA-9X6X-W4XQ-RW3G", "url": "https://github.com/advisories/GHSA-9X6X-W4XQ-RW3G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-86206"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Access control filter bypass allows unauthorised access to APIs", "cve_id": "CVE-2026-86206", "vendor": "N-able", "ghsa_id": "GHSA-9X6X-W4XQ-RW3G", "product": "N-central", "added_date": "2026-09-10T06:32:55.151Z", "cvss_score": 6.9, "epss_score": 0.01118, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64891, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-86206", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3ddcb693-d33e-43f7-ba55-bb2bb6249cc6", "vulnerability": {"vulnId": "CVE-2026-71362", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T08:31:29+02:00"}, "gcve": {"object_uuid": "3ddcb693-d33e-43f7-ba55-bb2bb6249cc6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T06:31:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T06:31:29+00:00"}, "scope": {"notes": "Adobe Commerce | Incorrect Authorization (CWE-863) | Affected: Adobe / Adobe Commerce, Adobe Commerce B2B, Magento Open Source | CVSS: 9.1 (CRITICAL) | EPSS: 0.87507 | Used in malware: unknown | Listed 14 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-71362", "url": "https://www.cve.org/CVERecord?id=CVE-2026-71362"}, {"id": "GHSA-F58V-HXR9-8947", "url": "https://github.com/advisories/GHSA-F58V-HXR9-8947"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-71362"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Commerce | Incorrect Authorization (CWE-863)", "cve_id": "CVE-2026-71362", "vendor": "Adobe", "ghsa_id": "GHSA-F58V-HXR9-8947", "product": "Adobe Commerce, Adobe Commerce B2B, Magento Open Source", "added_date": "2026-09-10T06:31:29.169Z", "cvss_score": 9.1, "epss_score": 0.87507, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99755, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-71362", "ahead_of_cisa_kev": {"unit": "day", "count": 14}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b074bae6-d9c7-4bad-9b96-7d11bec2db5e", "vulnerability": {"vulnId": "CVE-2026-45695", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "b074bae6-d9c7-4bad-9b96-7d11bec2db5e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used | Affected: Kopia / kopia | CVSS: 9.8 (CRITICAL) | EPSS: 0.0161 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-45695", "url": "https://www.cve.org/CVERecord?id=CVE-2026-45695"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-45695"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used", "cve_id": "CVE-2026-45695", "vendor": "Kopia", "ghsa_id": null, "product": "kopia", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.0161, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75053, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-45695", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4f931936-5c31-470c-9dc7-4beb06c29d96", "vulnerability": {"vulnId": "CVE-2024-36412", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "4f931936-5c31-470c-9dc7-4beb06c29d96", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "SuiteCRM unauthenticated SQL Injection | Affected: Salesagility / SuiteCRM | CVSS: 10.0 (CRITICAL) | EPSS: 0.05692 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-36412", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36412"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36412"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SuiteCRM unauthenticated SQL Injection", "cve_id": "CVE-2024-36412", "vendor": "Salesagility", "ghsa_id": null, "product": "SuiteCRM", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.05692, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92766, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36412", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e005ce10-fe79-4ea5-907d-8403da80f124", "vulnerability": {"vulnId": "CVE-2022-1057", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "e005ce10-fe79-4ea5-907d-8403da80f124", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "Pricing Deals for WooCommerce <= 2.0.2.02 - Unauthenticated SQLi | Affected: Varktech / Pricing Deals for WooCommerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.08013 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1057", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1057"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1057"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pricing Deals for WooCommerce <= 2.0.2.02 - Unauthenticated SQLi", "cve_id": "CVE-2022-1057", "vendor": "Varktech", "ghsa_id": null, "product": "Pricing Deals for WooCommerce", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08013, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1057", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "96af1096-7121-4100-82d6-66c6d14ad5bb", "vulnerability": {"vulnId": "CVE-2024-50340", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "96af1096-7121-4100-82d6-66c6d14ad5bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "Ability to change environment from query in symfony/runtime | Affected: Symfony / symfony | CVSS: 7.3 (HIGH) | EPSS: 0.64802 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-50340", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50340"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50340"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ability to change environment from query in symfony/runtime", "cve_id": "CVE-2024-50340", "vendor": "Symfony", "ghsa_id": null, "product": "symfony", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.64802, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99225, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-50340", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bce7f976-0858-4a2d-9ded-657b58181cf5", "vulnerability": {"vulnId": "CVE-2019-10232", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "bce7f976-0858-4a2d-9ded-657b58181cf5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "Teclib GLPI through 9.3.3 has SQL injection via the \"cycle\" parameter in /scripts/unlock_tasks.php. | Affected: Teclib-edition / Gestionnaire Libre DE Parc Informatique | CVSS: 9.8 (CRITICAL) | EPSS: 0.22372 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-10232", "url": "https://www.cve.org/CVERecord?id=CVE-2019-10232"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-10232"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Teclib GLPI through 9.3.3 has SQL injection via the \"cycle\" parameter in /scripts/unlock_tasks.php.", "cve_id": "CVE-2019-10232", "vendor": "Teclib-edition", "ghsa_id": null, "product": "Gestionnaire Libre DE Parc Informatique", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.22372, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97627, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-10232", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4ea3bb57-d85d-4c95-a46d-ecc35e328bbe", "vulnerability": {"vulnId": "CVE-2024-5276", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "4ea3bb57-d85d-4c95-a46d-ecc35e328bbe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier) | Affected: Fortra / FileCatalyst Workflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.90067 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-5276", "url": "https://www.cve.org/CVERecord?id=CVE-2024-5276"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-5276"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)", "cve_id": "CVE-2024-5276", "vendor": "Fortra", "ghsa_id": null, "product": "FileCatalyst Workflow", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90067, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99793, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-5276", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "acd1b874-8391-48db-b6bf-b4d157193a03", "vulnerability": {"vulnId": "CVE-2024-31982", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "acd1b874-8391-48db-b6bf-b4d157193a03", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "XWiki Platform: Remote code execution as guest via DatabaseSearch | Affected: Xwiki / xwiki-platform | CVSS: 10.0 (CRITICAL) | EPSS: 0.3452 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-31982", "url": "https://www.cve.org/CVERecord?id=CVE-2024-31982"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-31982"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "XWiki Platform: Remote code execution as guest via DatabaseSearch", "cve_id": "CVE-2024-31982", "vendor": "Xwiki", "ghsa_id": null, "product": "xwiki-platform", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.3452, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98373, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-31982", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "69724cf0-7bd4-4efb-ba0e-fb764e17a3c2", "vulnerability": {"vulnId": "CVE-2022-0169", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "69724cf0-7bd4-4efb-ba0e-fb764e17a3c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-10T00:00:00+00:00"}, "scope": {"notes": "Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection | Affected: 10Web / Photo Gallery | CVSS: 9.8 (CRITICAL) | EPSS: 0.74615 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0169", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0169"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0169"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection", "cve_id": "CVE-2022-0169", "vendor": "10Web", "ghsa_id": null, "product": "Photo Gallery", "added_date": "2026-09-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74615, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99487, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0169", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "db6ab679-5ad0-4592-9ab7-8e1aab5dc5d8", "vulnerability": {"vulnId": "CVE-2026-20079", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-09T18:08:59+02:00"}, "gcve": {"object_uuid": "db6ab679-5ad0-4592-9ab7-8e1aab5dc5d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-09T16:08:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-09T16:08:59+00:00"}, "scope": {"notes": "Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability | Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | CVSS: 10.0 (CRITICAL) | EPSS: 0.8818 | Used in malware: yes | Listed 3 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20079", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20079"}, {"id": "GHSA-MV8W-C2QV-CGRG", "url": "https://github.com/advisories/GHSA-MV8W-C2QV-CGRG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20079"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability", "cve_id": "CVE-2026-20079", "vendor": "Cisco", "ghsa_id": "GHSA-MV8W-C2QV-CGRG", "product": "Cisco Secure Firewall Management Center (FMC)", "added_date": "2026-09-09T16:08:59.000Z", "cvss_score": 10.0, "epss_score": 0.8818, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99765, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-20079", "ahead_of_cisa_kev": {"unit": "hour", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1672e4f9-3da6-4964-93c3-e8c2715617b1", "vulnerability": {"vulnId": "CVE-2026-87827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-09T13:01:06+02:00"}, "gcve": {"object_uuid": "1672e4f9-3da6-4964-93c3-e8c2715617b1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-09T11:01:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-09T11:01:06+00:00"}, "scope": {"notes": "KGUARD DVR unauthenticated remote command execution vulnerability | Affected: KGUARD / KGUARD_firmware | CVSS: 10.0 (CRITICAL) | EPSS: 0.0108 | Used in malware: yes | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-87827", "url": "https://www.cve.org/CVERecord?id=CVE-2026-87827"}, {"id": "GHSA-MXWW-3QMJ-G8P3", "url": "https://github.com/advisories/GHSA-MXWW-3QMJ-G8P3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-87827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "KGUARD DVR unauthenticated remote command execution vulnerability", "cve_id": "CVE-2026-87827", "vendor": "KGUARD", "ghsa_id": "GHSA-MXWW-3QMJ-G8P3", "product": "KGUARD_firmware", "added_date": "2026-09-09T11:01:06.386Z", "cvss_score": 10.0, "epss_score": 0.0108, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63829, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-87827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c5b5c4e4-b719-4236-b60a-03c1e46c984a", "vulnerability": {"vulnId": "CVE-2026-87491", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-09T10:00:59+02:00"}, "gcve": {"object_uuid": "c5b5c4e4-b719-4236-b60a-03c1e46c984a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-09T08:00:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-09T08:00:59+00:00"}, "scope": {"notes": "Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.03142 | Used in malware: unknown | Listed 11 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-87491", "url": "https://www.cve.org/CVERecord?id=CVE-2026-87491"}, {"id": "GHSA-8X3P-8G9V-XC7M", "url": "https://github.com/advisories/GHSA-8X3P-8G9V-XC7M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-87491"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a...", "cve_id": "CVE-2026-87491", "vendor": "Google", "ghsa_id": "GHSA-8X3P-8G9V-XC7M", "product": "Chrome", "added_date": "2026-09-09T08:00:59.000Z", "cvss_score": 8.8, "epss_score": 0.03142, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87461, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-87491", "ahead_of_cisa_kev": {"unit": "hour", "count": 11}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "318569f2-a7f7-4834-acb3-d8e2f4d591e6", "vulnerability": {"vulnId": "CVE-2026-86207", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-09T09:56:22+02:00"}, "gcve": {"object_uuid": "318569f2-a7f7-4834-acb3-d8e2f4d591e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-09T07:56:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-09T07:56:22+00:00"}, "scope": {"notes": "Authentication bypass leads to unauthorised access to N-central | Affected: N-able / N-central | CVSS: 7.7 (HIGH) | EPSS: 0.01254 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-86207", "url": "https://www.cve.org/CVERecord?id=CVE-2026-86207"}, {"id": "GHSA-R94P-PW8F-8CWV", "url": "https://github.com/advisories/GHSA-R94P-PW8F-8CWV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-86207"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication bypass leads to unauthorised access to N-central", "cve_id": "CVE-2026-86207", "vendor": "N-able", "ghsa_id": "GHSA-R94P-PW8F-8CWV", "product": "N-central", "added_date": "2026-09-09T07:56:22.822Z", "cvss_score": 7.7, "epss_score": 0.01254, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68382, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-86207", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ebdf891f-217a-4f82-b105-e598005d0981", "vulnerability": {"vulnId": "CVE-2026-84869", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-09T09:51:00+02:00"}, "gcve": {"object_uuid": "ebdf891f-217a-4f82-b105-e598005d0981", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-09T07:51:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-09T07:51:00+00:00"}, "scope": {"notes": "ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions | Affected: ConnectWise / ScreenConnect | CVSS: 9.9 (CRITICAL) | EPSS: 0.00924 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-84869", "url": "https://www.cve.org/CVERecord?id=CVE-2026-84869"}, {"id": "GHSA-RC8V-F46M-JCGM", "url": "https://github.com/advisories/GHSA-RC8V-F46M-JCGM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-84869"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions", "cve_id": "CVE-2026-84869", "vendor": "ConnectWise", "ghsa_id": "GHSA-RC8V-F46M-JCGM", "product": "ScreenConnect", "added_date": "2026-09-09T07:51:00.000Z", "cvss_score": 9.9, "epss_score": 0.00924, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-84869", "ahead_of_cisa_kev": {"unit": "day", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a8366abb-ae35-4e17-b97a-42b19fc3342c", "vulnerability": {"vulnId": "CVE-2024-2851", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-09T02:00:00+02:00"}, "gcve": {"object_uuid": "a8366abb-ae35-4e17-b97a-42b19fc3342c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-09T00:00:00+00:00"}, "scope": {"notes": "Tenda AC15 setsambacfg formSetSambaConf os command injection | Affected: Tenda / AC15 | CVSS: 6.3 (MEDIUM) | EPSS: 0.04009 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-2851", "url": "https://www.cve.org/CVERecord?id=CVE-2024-2851"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-2851"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tenda AC15 setsambacfg formSetSambaConf os command injection", "cve_id": "CVE-2024-2851", "vendor": "Tenda", "ghsa_id": null, "product": "AC15", "added_date": "2026-09-09T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.04009, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90234, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-2851", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4e0b46fe-d93d-464a-bb27-f2a0f08a59f8", "vulnerability": {"vulnId": "CVE-2025-25249", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-08T17:03:00+02:00"}, "gcve": {"object_uuid": "4e0b46fe-d93d-464a-bb27-f2a0f08a59f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-08T15:03:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-08T15:03:00+00:00"}, "scope": {"notes": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11,... | Affected: Fortinet / FortiSwitchManager, FortiOS | CVSS: 7.4 (HIGH) | EPSS: 0.03859 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-25249", "url": "https://www.cve.org/CVERecord?id=CVE-2025-25249"}, {"id": "GHSA-MJ8X-M8F5-X4W8", "url": "https://github.com/advisories/GHSA-MJ8X-M8F5-X4W8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-25249"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11,...", "cve_id": "CVE-2025-25249", "vendor": "Fortinet", "ghsa_id": "GHSA-MJ8X-M8F5-X4W8", "product": "FortiSwitchManager, FortiOS", "added_date": "2026-09-08T15:03:00.000Z", "cvss_score": 7.4, "epss_score": 0.03859, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89838, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-25249", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7e32865a-63f9-4ae6-b993-92eb842d02c0", "vulnerability": {"vulnId": "GHSA-6V53-HR58-556R", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-08T09:53:59+02:00"}, "gcve": {"object_uuid": "7e32865a-63f9-4ae6-b993-92eb842d02c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-08T07:53:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-08T07:53:59+00:00"}, "scope": {"notes": "Unauthenticated Arbitrary File Read can lead to RCE | CVSS: 9.8 (critical) | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "GHSA-6V53-HR58-556R", "url": "https://github.com/advisories/GHSA-6V53-HR58-556R"}, {"id": "previdian", "url": "https://previdian.com/GHSA-6V53-HR58-556R"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Arbitrary File Read can lead to RCE", "cve_id": null, "vendor": null, "ghsa_id": "GHSA-6V53-HR58-556R", "product": null, "added_date": "2026-09-08T07:53:59.654Z", "cvss_score": 9.8, "epss_score": null, "previous_ids": [], "cvss_severity": "critical", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": null, "used_in_malware": "unknown", "vulnerability_id": "GHSA-6V53-HR58-556R", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06be0c4d-3dde-424b-ae4f-c65229194ded", "vulnerability": {"vulnId": "CVE-2026-85880", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-08T09:00:00+02:00"}, "gcve": {"object_uuid": "06be0c4d-3dde-424b-ae4f-c65229194ded", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-08T07:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-08T07:00:00+00:00"}, "scope": {"notes": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 7.8 (HIGH) | EPSS: 0.03616 | Used in malware: unknown | Listed 12 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-85880", "url": "https://www.cve.org/CVERecord?id=CVE-2026-85880"}, {"id": "GHSA-96FM-JJF3-WV64", "url": "https://github.com/advisories/GHSA-96FM-JJF3-WV64"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-85880"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-85880", "vendor": "Microsoft", "ghsa_id": "GHSA-96FM-JJF3-WV64", "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2026-09-08T07:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03616, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89136, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-85880", "ahead_of_cisa_kev": {"unit": "hour", "count": 12}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b3bc5cbc-8b70-4399-8a0c-0c306f9d36fe", "vulnerability": {"vulnId": "CVE-2026-81963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-08T09:00:00+02:00"}, "gcve": {"object_uuid": "b3bc5cbc-8b70-4399-8a0c-0c306f9d36fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-08T07:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-08T07:00:00+00:00"}, "scope": {"notes": "Windows Update Stack Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.00393 | Used in malware: unknown | Listed 12 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-81963", "url": "https://www.cve.org/CVERecord?id=CVE-2026-81963"}, {"id": "GHSA-4J4J-2WJQ-MXQJ", "url": "https://github.com/advisories/GHSA-4J4J-2WJQ-MXQJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-81963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Update Stack Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-81963", "vendor": "Microsoft", "ghsa_id": "GHSA-4J4J-2WJQ-MXQJ", "product": "Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-09-08T07:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00393, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.31085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-81963", "ahead_of_cisa_kev": {"unit": "hour", "count": 12}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "99287ac8-b71e-439e-b50b-f6164de0352b", "vulnerability": {"vulnId": "CVE-2023-37462", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "99287ac8-b71e-439e-b50b-f6164de0352b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-08T00:00:00+00:00"}, "scope": {"notes": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui | Affected: Xwiki / xwiki-platform | CVSS: 9.9 (CRITICAL) | EPSS: 0.91592 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-37462", "url": "https://www.cve.org/CVERecord?id=CVE-2023-37462"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-37462"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui", "cve_id": "CVE-2023-37462", "vendor": "Xwiki", "ghsa_id": null, "product": "xwiki-platform", "added_date": "2026-09-08T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.91592, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99812, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-37462", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "876b599c-759d-4ce3-80b3-314612854cd4", "vulnerability": {"vulnId": "CVE-2025-60687", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-07T02:00:00+02:00"}, "gcve": {"object_uuid": "876b599c-759d-4ce3-80b3-314612854cd4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-07T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi... | Affected: ToToLink / LR1200GB Router | CVSS: 6.5 (MEDIUM) | EPSS: 0.06606 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-60687", "url": "https://www.cve.org/CVERecord?id=CVE-2025-60687"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-60687"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi...", "cve_id": "CVE-2025-60687", "vendor": "ToToLink", "ghsa_id": null, "product": "LR1200GB Router", "added_date": "2026-09-07T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.06606, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93646, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-60687", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "10c506f8-2ad0-4ee3-af4a-1b4cc36f463a", "vulnerability": {"vulnId": "CVE-2025-6068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-07T02:00:00+02:00"}, "gcve": {"object_uuid": "10c506f8-2ad0-4ee3-af4a-1b4cc36f463a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-07T00:00:00+00:00"}, "scope": {"notes": "FooGallery \u2013 Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | Affected: Bradvin / FooGallery \u2013 Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | CVSS: 6.4 (MEDIUM) | EPSS: 0.00217 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-6068", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6068"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FooGallery \u2013 Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting", "cve_id": "CVE-2025-6068", "vendor": "Bradvin", "ghsa_id": null, "product": "FooGallery \u2013 Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel", "added_date": "2026-09-07T00:00:00.000Z", "cvss_score": 6.4, "epss_score": 0.00217, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.10942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6068", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "76ed7f0c-d880-4604-a4b8-5c33669948c7", "vulnerability": {"vulnId": "CVE-2023-37569", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-07T02:00:00+02:00"}, "gcve": {"object_uuid": "76ed7f0c-d880-4604-a4b8-5c33669948c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-07T00:00:00+00:00"}, "scope": {"notes": "OS Command Injection Vulnerability in Emagic Data Center Management Suite | Affected: ESDS / Emagic Data Center Management Suite | CVSS: 8.8 (HIGH) | EPSS: 0.33886 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-37569", "url": "https://www.cve.org/CVERecord?id=CVE-2023-37569"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-37569"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OS Command Injection Vulnerability in Emagic Data Center Management Suite", "cve_id": "CVE-2023-37569", "vendor": "ESDS", "ghsa_id": null, "product": "Emagic Data Center Management Suite", "added_date": "2026-09-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.33886, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-37569", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c39e77ad-2326-4e61-832b-0f637feac63d", "vulnerability": {"vulnId": "CVE-2025-14208", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-07T02:00:00+02:00"}, "gcve": {"object_uuid": "c39e77ad-2326-4e61-832b-0f637feac63d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-07T00:00:00+00:00"}, "scope": {"notes": "D-Link DIR-823X set_wan_settings sub_415028 command injection | Affected: D-Link / DIR-823X | CVSS: 5.3 (MEDIUM) | EPSS: 0.03392 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-14208", "url": "https://www.cve.org/CVERecord?id=CVE-2025-14208"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-14208"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DIR-823X set_wan_settings sub_415028 command injection", "cve_id": "CVE-2025-14208", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-823X", "added_date": "2026-09-07T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.03392, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88418, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-14208", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "750fe37e-739f-46d6-ba12-41581090a1cb", "vulnerability": {"vulnId": "CVE-2026-86218", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-06T06:15:00+02:00"}, "gcve": {"object_uuid": "750fe37e-739f-46d6-ba12-41581090a1cb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-06T04:15:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-06T04:15:00+00:00"}, "scope": {"notes": "pre-authentication remote code execution | Affected: N-able / N-central | CVSS: 10.0 (CRITICAL) | EPSS: 0.12928 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-86218", "url": "https://www.cve.org/CVERecord?id=CVE-2026-86218"}, {"id": "GHSA-5F24-G9G9-M3V8", "url": "https://github.com/advisories/GHSA-5F24-G9G9-M3V8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-86218"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "pre-authentication remote code execution", "cve_id": "CVE-2026-86218", "vendor": "N-able", "ghsa_id": "GHSA-5F24-G9G9-M3V8", "product": "N-central", "added_date": "2026-09-06T04:15:00.000Z", "cvss_score": 10.0, "epss_score": 0.12928, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96198, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-86218", "ahead_of_cisa_kev": {"unit": "day", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9373a47c-a25a-4c1e-90f7-631a3ec47757", "vulnerability": {"vulnId": "CVE-2026-75650", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-05T14:44:00+02:00"}, "gcve": {"object_uuid": "9373a47c-a25a-4c1e-90f7-631a3ec47757", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-05T12:44:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-05T12:44:00+00:00"}, "scope": {"notes": "Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) | Affected: Adobe / Adobe Commerce, Adobe Commerce B2B, Magento Open Source | CVSS: 10.0 (CRITICAL) | EPSS: 0.03949 | Used in malware: unknown | Listed 3 days ahead of CISA KEV | Not yet in CISA KEV: False | Previously: VULN-2026-0003"}, "references": [{"id": "CVE-2026-75650", "url": "https://www.cve.org/CVERecord?id=CVE-2026-75650"}, {"id": "GHSA-FJ37-XM58-MF28", "url": "https://github.com/advisories/GHSA-FJ37-XM58-MF28"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-75650"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)", "cve_id": "CVE-2026-75650", "vendor": "Adobe", "ghsa_id": "GHSA-FJ37-XM58-MF28", "product": "Adobe Commerce, Adobe Commerce B2B, Magento Open Source", "added_date": "2026-09-05T12:44:00.000Z", "cvss_score": 10.0, "epss_score": 0.03949, "previous_ids": ["VULN-2026-0003"], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.90085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-75650", "ahead_of_cisa_kev": {"unit": "day", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8d10653a-ef54-48d5-83a4-f45fc76a95f3", "vulnerability": {"vulnId": "CVE-2025-60698", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-05T02:00:00+02:00"}, "gcve": {"object_uuid": "8d10653a-ef54-48d5-83a4-f45fc76a95f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-05T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The... | Affected: D-Link / DIR-882 Router | CVSS: 7.3 (HIGH) | EPSS: 0.03929 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-60698", "url": "https://www.cve.org/CVERecord?id=CVE-2025-60698"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-60698"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The...", "cve_id": "CVE-2025-60698", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-882 Router", "added_date": "2026-09-05T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.03929, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9003, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-60698", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5f480f8a-d900-4e33-b405-e4afe1d357dc", "vulnerability": {"vulnId": "CVE-2026-58457", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-04T17:31:49+02:00"}, "gcve": {"object_uuid": "5f480f8a-d900-4e33-b405-e4afe1d357dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-04T15:31:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-04T15:31:49+00:00"}, "scope": {"notes": "Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp | Affected: Shenzhen Aitemi E Commerce / M300 Wi-Fi Repeater | CVSS: 9.3 (CRITICAL) | EPSS: 0.02939 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-58457", "url": "https://www.cve.org/CVERecord?id=CVE-2026-58457"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-58457"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp", "cve_id": "CVE-2026-58457", "vendor": "Shenzhen Aitemi E Commerce", "ghsa_id": null, "product": "M300 Wi-Fi Repeater", "added_date": "2026-09-04T15:31:49.181Z", "cvss_score": 9.3, "epss_score": 0.02939, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86633, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-58457", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d95e2bf4-40d3-42cd-a64b-601df750e49b", "vulnerability": {"vulnId": "CVE-2026-14894", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-04T13:40:31+02:00"}, "gcve": {"object_uuid": "d95e2bf4-40d3-42cd-a64b-601df750e49b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-04T11:40:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-04T11:40:31+00:00"}, "scope": {"notes": "Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value) | Affected: WebRehab / Super Forms \u2013 Drag & Drop Form Builder | CVSS: 9.8 (CRITICAL) | EPSS: 0.05087 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-14894", "url": "https://www.cve.org/CVERecord?id=CVE-2026-14894"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-14894"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)", "cve_id": "CVE-2026-14894", "vendor": "WebRehab", "ghsa_id": null, "product": "Super Forms \u2013 Drag & Drop Form Builder", "added_date": "2026-09-04T11:40:31.759Z", "cvss_score": 9.8, "epss_score": 0.05087, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92084, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-14894", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "40a2efbc-b677-49da-8161-f764f9701ffd", "vulnerability": {"vulnId": "CVE-2026-85046", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-04T09:18:47+02:00"}, "gcve": {"object_uuid": "40a2efbc-b677-49da-8161-f764f9701ffd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-04T07:18:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-04T07:18:47+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.48881 | Used in malware: unknown | Listed 10 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-85046", "url": "https://www.cve.org/CVERecord?id=CVE-2026-85046"}, {"id": "GHSA-84QV-4WJ5-WWMM", "url": "https://github.com/advisories/GHSA-84QV-4WJ5-WWMM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-85046"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted...", "cve_id": "CVE-2026-85046", "vendor": "Google", "ghsa_id": "GHSA-84QV-4WJ5-WWMM", "product": "Chrome", "added_date": "2026-09-04T07:18:47.000Z", "cvss_score": 8.8, "epss_score": 0.48881, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98844, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-85046", "ahead_of_cisa_kev": {"unit": "hour", "count": 10}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c5a1a266-8194-4cb4-b2c7-218c48ac0ece", "vulnerability": {"vulnId": "CVE-2019-10655", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-04T02:00:00+02:00"}, "gcve": {"object_uuid": "c5a1a266-8194-4cb4-b2c7-218c48ac0ece", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-04T00:00:00+00:00"}, "scope": {"notes": "Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow... | Affected: Grandstream / GAC2500 | CVSS: 9.8 (CRITICAL) | EPSS: 0.15475 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-10655", "url": "https://www.cve.org/CVERecord?id=CVE-2019-10655"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-10655"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow...", "cve_id": "CVE-2019-10655", "vendor": "Grandstream", "ghsa_id": null, "product": "GAC2500", "added_date": "2026-09-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.15475, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96703, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-10655", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9a49eac2-eaa0-4da8-94a0-d270eb4d3b95", "vulnerability": {"vulnId": "CVE-2026-19490", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-03T13:43:49+02:00"}, "gcve": {"object_uuid": "9a49eac2-eaa0-4da8-94a0-d270eb4d3b95", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-03T11:43:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-03T11:43:49+00:00"}, "scope": {"notes": "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 | Affected: NetScaler / ADC, Gateway | CVSS: 9.3 (CRITICAL) | EPSS: 0.0797 | Used in malware: unknown | Listed 6 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-19490", "url": "https://www.cve.org/CVERecord?id=CVE-2026-19490"}, {"id": "GHSA-7C6H-RHHV-WM8R", "url": "https://github.com/advisories/GHSA-7C6H-RHHV-WM8R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-19490"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490", "cve_id": "CVE-2026-19490", "vendor": "NetScaler", "ghsa_id": "GHSA-7C6H-RHHV-WM8R", "product": "ADC, Gateway", "added_date": "2026-09-03T11:43:49.815Z", "cvss_score": 9.3, "epss_score": 0.0797, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94579, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-19490", "ahead_of_cisa_kev": {"unit": "day", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2e444159-b989-4dde-b54f-d7bd07ec0028", "vulnerability": {"vulnId": "CVE-2026-0768", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-03T11:38:03+02:00"}, "gcve": {"object_uuid": "2e444159-b989-4dde-b54f-d7bd07ec0028", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-03T09:38:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-03T09:38:03+00:00"}, "scope": {"notes": "Langflow code Code Injection Remote Code Execution Vulnerability | Affected: Langflow / Langflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.08451 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-0768", "url": "https://www.cve.org/CVERecord?id=CVE-2026-0768"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-0768"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow code Code Injection Remote Code Execution Vulnerability", "cve_id": "CVE-2026-0768", "vendor": "Langflow", "ghsa_id": null, "product": "Langflow", "added_date": "2026-09-03T09:38:03.412Z", "cvss_score": 9.8, "epss_score": 0.08451, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94847, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-0768", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f910a922-33ed-4804-9c07-475e7864785f", "vulnerability": {"vulnId": "CVE-2014-3704", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-03T08:41:00+02:00"}, "gcve": {"object_uuid": "f910a922-33ed-4804-9c07-475e7864785f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-03T06:41:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-03T06:41:00+00:00"}, "scope": {"notes": "The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which... | Affected: Drupal / Drupal | CVSS: 7.5 (HIGH) | EPSS: 0.99974 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-3704", "url": "https://www.cve.org/CVERecord?id=CVE-2014-3704"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-3704"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which...", "cve_id": "CVE-2014-3704", "vendor": "Drupal", "ghsa_id": null, "product": "Drupal", "added_date": "2026-09-03T06:41:00.665Z", "cvss_score": 7.5, "epss_score": 0.99974, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99978, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-3704", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5e539a40-204e-4431-affe-7f69763a914d", "vulnerability": {"vulnId": "CVE-2026-49869", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-02T19:31:03+02:00"}, "gcve": {"object_uuid": "5e539a40-204e-4431-affe-7f69763a914d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-02T17:31:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-02T17:31:03+00:00"}, "scope": {"notes": "Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` | Affected: Kestra-io / kestra | CVSS: 10.0 (CRITICAL) | EPSS: 0.02095 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-49869", "url": "https://www.cve.org/CVERecord?id=CVE-2026-49869"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-49869"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`", "cve_id": "CVE-2026-49869", "vendor": "Kestra-io", "ghsa_id": null, "product": "kestra", "added_date": "2026-09-02T17:31:03.121Z", "cvss_score": 10.0, "epss_score": 0.02095, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.80974, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-49869", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c190dc52-84ce-4eab-8829-9db72b290d08", "vulnerability": {"vulnId": "CVE-2026-48710", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-02T19:31:02+02:00"}, "gcve": {"object_uuid": "c190dc52-84ce-4eab-8829-9db72b290d08", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-02T17:31:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-02T17:31:02+00:00"}, "scope": {"notes": "Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | Affected: Kludex / starlette | CVSS: 6.5 (MEDIUM) | EPSS: 0.07056 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48710", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48710"}, {"id": "GHSA-86QP-5C8J-P5MR", "url": "https://github.com/advisories/GHSA-86QP-5C8J-P5MR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48710"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks", "cve_id": "CVE-2026-48710", "vendor": "Kludex", "ghsa_id": "GHSA-86QP-5C8J-P5MR", "product": "starlette", "added_date": "2026-09-02T17:31:02.748Z", "cvss_score": 6.5, "epss_score": 0.07056, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94009, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48710", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a294e7d0-dd3a-40e9-86d0-68839c8fd062", "vulnerability": {"vulnId": "CVE-2026-59822", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-02T19:31:01+02:00"}, "gcve": {"object_uuid": "a294e7d0-dd3a-40e9-86d0-68839c8fd062", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-02T17:31:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-02T17:31:01+00:00"}, "scope": {"notes": "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback | Affected: BerriAI / litellm | CVSS: 8.8 (HIGH) | EPSS: 0.00836 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-59822", "url": "https://www.cve.org/CVERecord?id=CVE-2026-59822"}, {"id": "GHSA-7488-6R32-C95Q", "url": "https://github.com/advisories/GHSA-7488-6R32-C95Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-59822"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback", "cve_id": "CVE-2026-59822", "vendor": "BerriAI", "ghsa_id": "GHSA-7488-6R32-C95Q", "product": "litellm", "added_date": "2026-09-02T17:31:01.269Z", "cvss_score": 8.8, "epss_score": 0.00836, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.56171, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-59822", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "22949312-27b6-4938-b067-187838708e6b", "vulnerability": {"vulnId": "CVE-2026-32475", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-02T17:07:36+02:00"}, "gcve": {"object_uuid": "22949312-27b6-4938-b067-187838708e6b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-02T15:07:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-02T15:07:36+00:00"}, "scope": {"notes": "WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability | Affected: Elementor / Elementor Pro | CVSS: 9.0 (CRITICAL) | EPSS: 0.01711 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-32475", "url": "https://www.cve.org/CVERecord?id=CVE-2026-32475"}, {"id": "GHSA-684F-44PQ-4P6Q", "url": "https://github.com/advisories/GHSA-684F-44PQ-4P6Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-32475"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability", "cve_id": "CVE-2026-32475", "vendor": "Elementor", "ghsa_id": "GHSA-684F-44PQ-4P6Q", "product": "Elementor Pro", "added_date": "2026-09-02T15:07:36.000Z", "cvss_score": 9.0, "epss_score": 0.01711, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76516, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-32475", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f081454c-1a20-4ee2-a11b-7be4deb4473e", "vulnerability": {"vulnId": "CVE-2023-54391", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T22:57:00+02:00"}, "gcve": {"object_uuid": "f081454c-1a20-4ee2-a11b-7be4deb4473e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T20:57:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T20:57:00+00:00"}, "scope": {"notes": "Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter | Affected: Proxmox Server Solutions / Proxmox Virtual Environment (VE) | CVSS: 9.3 (CRITICAL) | EPSS: 0.03031 | Used in malware: unknown | Not yet in CISA KEV: True | Previously: VULN-2026-0002"}, "references": [{"id": "CVE-2023-54391", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54391"}, {"id": "GHSA-M457-GRCF-698X", "url": "https://github.com/advisories/GHSA-M457-GRCF-698X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54391"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter", "cve_id": "CVE-2023-54391", "vendor": "Proxmox Server Solutions", "ghsa_id": "GHSA-M457-GRCF-698X", "product": "Proxmox Virtual Environment (VE)", "added_date": "2026-09-01T20:57:00.000Z", "cvss_score": 9.3, "epss_score": 0.03031, "previous_ids": ["VULN-2026-0002"], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87027, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54391", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a81e006c-278d-422f-a6c2-778bd26960ef", "vulnerability": {"vulnId": "CVE-2026-83549", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T22:21:00+02:00"}, "gcve": {"object_uuid": "a81e006c-278d-422f-a6c2-778bd26960ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T20:21:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T20:21:00+00:00"}, "scope": {"notes": "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in... | Affected: SonicWall / SMA1000 | CVSS: 7.8 (HIGH) | EPSS: 0.1076 | Used in malware: unknown | Listed 21 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-83549", "url": "https://www.cve.org/CVERecord?id=CVE-2026-83549"}, {"id": "GHSA-VXCC-7CF2-WCGH", "url": "https://github.com/advisories/GHSA-VXCC-7CF2-WCGH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-83549"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in...", "cve_id": "CVE-2026-83549", "vendor": "SonicWall", "ghsa_id": "GHSA-VXCC-7CF2-WCGH", "product": "SMA1000", "added_date": "2026-09-01T20:21:00.000Z", "cvss_score": 7.8, "epss_score": 0.1076, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95704, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-83549", "ahead_of_cisa_kev": {"unit": "hour", "count": 21}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c725877c-b430-4f69-99f4-3b7fe38571e5", "vulnerability": {"vulnId": "CVE-2026-83548", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T22:19:00+02:00"}, "gcve": {"object_uuid": "c725877c-b430-4f69-99f4-3b7fe38571e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T20:19:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T20:19:00+00:00"}, "scope": {"notes": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote... | Affected: SonicWall / SMA1000 | CVSS: 10.0 (CRITICAL) | EPSS: 0.08757 | Used in malware: unknown | Listed 21 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-83548", "url": "https://www.cve.org/CVERecord?id=CVE-2026-83548"}, {"id": "GHSA-GHW2-CFH2-XVGC", "url": "https://github.com/advisories/GHSA-GHW2-CFH2-XVGC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-83548"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote...", "cve_id": "CVE-2026-83548", "vendor": "SonicWall", "ghsa_id": "GHSA-GHW2-CFH2-XVGC", "product": "SMA1000", "added_date": "2026-09-01T20:19:00.000Z", "cvss_score": 10.0, "epss_score": 0.08757, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9501, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-83548", "ahead_of_cisa_kev": {"unit": "hour", "count": 21}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b09662b-ff1f-4b2e-89ee-08351a3fea16", "vulnerability": {"vulnId": "CVE-2025-40553", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T14:15:41+02:00"}, "gcve": {"object_uuid": "3b09662b-ff1f-4b2e-89ee-08351a3fea16", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T12:15:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T12:15:41+00:00"}, "scope": {"notes": "SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability | Affected: SolarWinds / Web Help Desk | CVSS: 9.8 (CRITICAL) | EPSS: 0.67975 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-40553", "url": "https://www.cve.org/CVERecord?id=CVE-2025-40553"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-40553"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability", "cve_id": "CVE-2025-40553", "vendor": "SolarWinds", "ghsa_id": null, "product": "Web Help Desk", "added_date": "2026-09-01T12:15:41.982Z", "cvss_score": 9.8, "epss_score": 0.67975, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99304, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-40553", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fc01813e-f335-439c-8f74-decee8977970", "vulnerability": {"vulnId": "CVE-2026-9586", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T12:01:00+02:00"}, "gcve": {"object_uuid": "fc01813e-f335-439c-8f74-decee8977970", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T10:01:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T10:01:00+00:00"}, "scope": {"notes": "Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB | Affected: Sangoma / Switchvox SMB Edition | CVSS: 9.3 (CRITICAL) | EPSS: 0.18979 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-9586", "url": "https://www.cve.org/CVERecord?id=CVE-2026-9586"}, {"id": "GHSA-M32J-V93F-GFGC", "url": "https://github.com/advisories/GHSA-M32J-V93F-GFGC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-9586"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB", "cve_id": "CVE-2026-9586", "vendor": "Sangoma", "ghsa_id": "GHSA-M32J-V93F-GFGC", "product": "Switchvox SMB Edition", "added_date": "2026-09-01T10:01:00.000Z", "cvss_score": 9.3, "epss_score": 0.18979, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97223, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-9586", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "49346aef-204a-4c66-815e-255dfed6e715", "vulnerability": {"vulnId": "CVE-2026-41948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T11:26:43+02:00"}, "gcve": {"object_uuid": "49346aef-204a-4c66-815e-255dfed6e715", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T09:26:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T09:26:43+00:00"}, "scope": {"notes": "Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access | Affected: Langgenius / dify | CVSS: 9.3 (CRITICAL) | EPSS: 0.01892 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-41948", "url": "https://www.cve.org/CVERecord?id=CVE-2026-41948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-41948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access", "cve_id": "CVE-2026-41948", "vendor": "Langgenius", "ghsa_id": null, "product": "dify", "added_date": "2026-09-01T09:26:43.472Z", "cvss_score": 9.3, "epss_score": 0.01892, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78833, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-41948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8a6219e2-8ae4-40a4-8abf-cde96583cd4f", "vulnerability": {"vulnId": "CVE-2026-82329", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T07:31:00+02:00"}, "gcve": {"object_uuid": "8a6219e2-8ae4-40a4-8abf-cde96583cd4f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T05:31:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T05:31:00+00:00"}, "scope": {"notes": "Potential authentication bypass leading to administrative access in Artifactory | Affected: Jfrog / artifactory | CVSS: 9.8 (CRITICAL) | EPSS: 0.14121 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-82329", "url": "https://www.cve.org/CVERecord?id=CVE-2026-82329"}, {"id": "GHSA-C5PF-6P5J-GJ87", "url": "https://github.com/advisories/GHSA-C5PF-6P5J-GJ87"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-82329"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Potential authentication bypass leading to administrative access in Artifactory", "cve_id": "CVE-2026-82329", "vendor": "Jfrog", "ghsa_id": "GHSA-C5PF-6P5J-GJ87", "product": "artifactory", "added_date": "2026-09-01T05:31:00.000Z", "cvss_score": 9.8, "epss_score": 0.14121, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96465, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-82329", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb5c73ff-c444-48c2-87d2-ff0a1339dbc4", "vulnerability": {"vulnId": "CVE-2025-60702", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T02:00:00+02:00"}, "gcve": {"object_uuid": "fb5c73ff-c444-48c2-87d2-ff0a1339dbc4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The... | Affected: TOTOLINK / A950RG Router | CVSS: 6.5 (MEDIUM) | EPSS: 0.02538 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-60702", "url": "https://www.cve.org/CVERecord?id=CVE-2025-60702"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-60702"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The...", "cve_id": "CVE-2025-60702", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A950RG Router", "added_date": "2026-09-01T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.02538, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-60702", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "15e60725-5074-4a6c-b391-6e6af66d7a8d", "vulnerability": {"vulnId": "CVE-2026-78141", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T02:00:00+02:00"}, "gcve": {"object_uuid": "15e60725-5074-4a6c-b391-6e6af66d7a8d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T00:00:00+00:00"}, "scope": {"notes": "Tenda CH22 exeCommand formexeCommand command injection | Affected: Tenda / CH22 | CVSS: 5.3 (MEDIUM) | EPSS: 0.02747 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-78141", "url": "https://www.cve.org/CVERecord?id=CVE-2026-78141"}, {"id": "GHSA-9MVP-7535-P7RW", "url": "https://github.com/advisories/GHSA-9MVP-7535-P7RW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-78141"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tenda CH22 exeCommand formexeCommand command injection", "cve_id": "CVE-2026-78141", "vendor": "Tenda", "ghsa_id": "GHSA-9MVP-7535-P7RW", "product": "CH22", "added_date": "2026-09-01T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.02747, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85666, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-78141", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "44776d0f-1f67-45d9-8aa7-0d425529262a", "vulnerability": {"vulnId": "CVE-2026-1547", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T02:00:00+02:00"}, "gcve": {"object_uuid": "44776d0f-1f67-45d9-8aa7-0d425529262a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T00:00:00+00:00"}, "scope": {"notes": "Totolink A7000R cstecgi.cgi setUnloadUserData command injection | Affected: Totolink / A7000R | CVSS: 5.3 (MEDIUM) | EPSS: 0.03052 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-1547", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1547"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1547"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Totolink A7000R cstecgi.cgi setUnloadUserData command injection", "cve_id": "CVE-2026-1547", "vendor": "Totolink", "ghsa_id": null, "product": "A7000R", "added_date": "2026-09-01T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.03052, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87113, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1547", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0df72910-91c6-48f4-8d8c-c680879dd097", "vulnerability": {"vulnId": "CVE-2023-39470", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T02:00:00+02:00"}, "gcve": {"object_uuid": "0df72910-91c6-48f4-8d8c-c680879dd097", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T00:00:00+00:00"}, "scope": {"notes": "PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability | Affected: PaperCut / NG | CVSS: 7.2 (HIGH) | EPSS: 0.01756 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-39470", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39470"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39470"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability", "cve_id": "CVE-2023-39470", "vendor": "PaperCut", "ghsa_id": null, "product": "NG", "added_date": "2026-09-01T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.01756, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77121, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39470", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fd6d0148-6a9e-4f53-be6a-07b275df7f30", "vulnerability": {"vulnId": "CVE-2024-0250", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T02:00:00+02:00"}, "gcve": {"object_uuid": "fd6d0148-6a9e-4f53-be6a-07b275df7f30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T00:00:00+00:00"}, "scope": {"notes": "Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect | Affected: Analytics Insights / Analytics Insights for Google Analytics 4 | CVSS: 6.1 (MEDIUM) | EPSS: 0.01254 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0250", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0250"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0250"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Analytics Insights for Google Analytics 4 < 6.3 - Open Redirect", "cve_id": "CVE-2024-0250", "vendor": "Analytics Insights", "ghsa_id": null, "product": "Analytics Insights for Google Analytics 4", "added_date": "2026-09-01T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01254, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6839, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0250", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bc14dd47-547d-4b54-8004-3f4c8a1e2720", "vulnerability": {"vulnId": "CVE-2026-5153", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-09-01T02:00:00+02:00"}, "gcve": {"object_uuid": "bc14dd47-547d-4b54-8004-3f4c8a1e2720", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-09-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-09-01T00:00:00+00:00"}, "scope": {"notes": "Tenda CH22 WriteFacMac FormWriteFacMac command injection | Affected: Tenda / CH22 | CVSS: 5.3 (MEDIUM) | EPSS: 0.06467 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-5153", "url": "https://www.cve.org/CVERecord?id=CVE-2026-5153"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-5153"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tenda CH22 WriteFacMac FormWriteFacMac command injection", "cve_id": "CVE-2026-5153", "vendor": "Tenda", "ghsa_id": null, "product": "CH22", "added_date": "2026-09-01T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.06467, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93534, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-5153", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7eed069e-24eb-4ef5-8dfd-4ca46d2390db", "vulnerability": {"vulnId": "CVE-2026-82078", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-30T22:11:52+02:00"}, "gcve": {"object_uuid": "7eed069e-24eb-4ef5-8dfd-4ca46d2390db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-30T20:11:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-30T20:11:52+00:00"}, "scope": {"notes": "PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector | Affected: PaperCut / PaperCut MF/NG | CVSS: 9.4 (CRITICAL) | EPSS: 0.61394 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False | Previously: VULN-2026-0001"}, "references": [{"id": "CVE-2026-82078", "url": "https://www.cve.org/CVERecord?id=CVE-2026-82078"}, {"id": "GHSA-MJG5-WJ9R-9MFX", "url": "https://github.com/advisories/GHSA-MJG5-WJ9R-9MFX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-82078"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector", "cve_id": "CVE-2026-82078", "vendor": "PaperCut", "ghsa_id": "GHSA-MJG5-WJ9R-9MFX", "product": "PaperCut MF/NG", "added_date": "2026-08-30T20:11:52.468Z", "cvss_score": 9.4, "epss_score": 0.61394, "previous_ids": ["VULN-2026-0001"], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99141, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-82078", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "63152070-43e8-4134-8ed0-717b1790171f", "vulnerability": {"vulnId": "CVE-2026-2614", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-29T22:39:20+02:00"}, "gcve": {"object_uuid": "63152070-43e8-4134-8ed0-717b1790171f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-29T20:39:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-29T20:39:20+00:00"}, "scope": {"notes": "Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow | Affected: Mlflow / mlflow/mlflow | CVSS: 7.5 (HIGH) | EPSS: 0.03206 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-2614", "url": "https://www.cve.org/CVERecord?id=CVE-2026-2614"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-2614"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow", "cve_id": "CVE-2026-2614", "vendor": "Mlflow", "ghsa_id": null, "product": "mlflow/mlflow", "added_date": "2026-08-29T20:39:20.994Z", "cvss_score": 7.5, "epss_score": 0.03206, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8772, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-2614", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5893a3bb-ebfb-4e65-b4f2-92cacc9839ba", "vulnerability": {"vulnId": "CVE-2023-7330", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-29T02:00:00+02:00"}, "gcve": {"object_uuid": "5893a3bb-ebfb-4e65-b4f2-92cacc9839ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-29T00:00:00+00:00"}, "scope": {"notes": "Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php | Affected: Beijing Star-Net Ruijie Network Technology / NBR Series Routers | CVSS: 9.3 (CRITICAL) | EPSS: 0.00617 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7330", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7330"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7330"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php", "cve_id": "CVE-2023-7330", "vendor": "Beijing Star-Net Ruijie Network Technology", "ghsa_id": null, "product": "NBR Series Routers", "added_date": "2026-08-29T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.00617, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.47646, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7330", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "003363bb-8a35-4026-9bfe-b1f44dd7ecf4", "vulnerability": {"vulnId": "CVE-2024-58374", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-28T02:00:00+02:00"}, "gcve": {"object_uuid": "003363bb-8a35-4026-9bfe-b1f44dd7ecf4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-28T00:00:00+00:00"}, "scope": {"notes": "Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree | Affected: Hongjing Century / e-HR | CVSS: 8.7 (HIGH) | EPSS: 0.00745 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-58374", "url": "https://www.cve.org/CVERecord?id=CVE-2024-58374"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-58374"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hongjing e-HR Unauthenticated SQL Injection via getSdutyTree", "cve_id": "CVE-2024-58374", "vendor": "Hongjing Century", "ghsa_id": null, "product": "e-HR", "added_date": "2026-08-28T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.00745, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.53092, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-58374", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cc50101b-efb9-44c3-8c66-8e9fb5dab911", "vulnerability": {"vulnId": "CVE-2023-49105", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-27T19:00:36+02:00"}, "gcve": {"object_uuid": "cc50101b-efb9-44c3-8c66-8e9fb5dab911", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-27T17:00:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-27T17:00:36+00:00"}, "scope": {"notes": "An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the... | Affected: ownCloud / ownCloud | CVSS: 9.8 (CRITICAL) | EPSS: 0.42919 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-49105", "url": "https://www.cve.org/CVERecord?id=CVE-2023-49105"}, {"id": "GHSA-585G-F852-V6P4", "url": "https://github.com/advisories/GHSA-585G-F852-V6P4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-49105"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the...", "cve_id": "CVE-2023-49105", "vendor": "ownCloud", "ghsa_id": "GHSA-585G-F852-V6P4", "product": "ownCloud", "added_date": "2026-08-27T17:00:36.663Z", "cvss_score": 9.8, "epss_score": 0.42919, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98681, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-49105", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8134ed12-cfb7-4e2b-8a2f-8d9a56402a2d", "vulnerability": {"vulnId": "CVE-2026-66384", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-27T19:00:36+02:00"}, "gcve": {"object_uuid": "8134ed12-cfb7-4e2b-8a2f-8d9a56402a2d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-27T17:00:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-27T17:00:36+00:00"}, "scope": {"notes": "Authenticated users may write data outside the intended Docker cache path | Affected: Jfrog / artifactory | CVSS: 5.3 (MEDIUM) | EPSS: 0.00665 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-66384", "url": "https://www.cve.org/CVERecord?id=CVE-2026-66384"}, {"id": "GHSA-G2MP-X73P-93XC", "url": "https://github.com/advisories/GHSA-G2MP-X73P-93XC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-66384"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authenticated users may write data outside the intended Docker cache path", "cve_id": "CVE-2026-66384", "vendor": "Jfrog", "ghsa_id": "GHSA-G2MP-X73P-93XC", "product": "artifactory", "added_date": "2026-08-27T17:00:36.663Z", "cvss_score": 5.3, "epss_score": 0.00665, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.49949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-66384", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "678928da-75bf-4c36-a6f3-f47fb67371d2", "vulnerability": {"vulnId": "CVE-2026-53362", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-27T19:00:36+02:00"}, "gcve": {"object_uuid": "678928da-75bf-4c36-a6f3-f47fb67371d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-27T17:00:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-27T17:00:36+00:00"}, "scope": {"notes": "ipv6: account for fraggap on the paged allocation path | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.00709 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-53362", "url": "https://www.cve.org/CVERecord?id=CVE-2026-53362"}, {"id": "GHSA-3X6F-VM7X-CGM7", "url": "https://github.com/advisories/GHSA-3X6F-VM7X-CGM7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-53362"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ipv6: account for fraggap on the paged allocation path", "cve_id": "CVE-2026-53362", "vendor": "Linux", "ghsa_id": "GHSA-3X6F-VM7X-CGM7", "product": "Linux", "added_date": "2026-08-27T17:00:36.663Z", "cvss_score": 7.8, "epss_score": 0.00709, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51788, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-53362", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2b6bd9ba-556b-477f-ac93-607234682c16", "vulnerability": {"vulnId": "CVE-2026-81578", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-27T17:39:00+02:00"}, "gcve": {"object_uuid": "2b6bd9ba-556b-477f-ac93-607234682c16", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-27T15:39:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-27T15:39:00+00:00"}, "scope": {"notes": "PaperCut MF/NG: Authentication Bypass | Affected: PaperCut / PaperCut MF/NG | CVSS: 8.8 (HIGH) | EPSS: 0.85169 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-81578", "url": "https://www.cve.org/CVERecord?id=CVE-2026-81578"}, {"id": "GHSA-44WC-J6F2-7FJR", "url": "https://github.com/advisories/GHSA-44WC-J6F2-7FJR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-81578"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PaperCut MF/NG: Authentication Bypass", "cve_id": "CVE-2026-81578", "vendor": "PaperCut", "ghsa_id": "GHSA-44WC-J6F2-7FJR", "product": "PaperCut MF/NG", "added_date": "2026-08-27T15:39:00.000Z", "cvss_score": 8.8, "epss_score": 0.85169, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99709, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-81578", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "42ea3ab2-30a8-477b-a9bc-f985642cd5b2", "vulnerability": {"vulnId": "CVE-2026-61511", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-27T15:06:02+02:00"}, "gcve": {"object_uuid": "42ea3ab2-30a8-477b-a9bc-f985642cd5b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-27T13:06:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-27T13:06:02+00:00"}, "scope": {"notes": "vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php | Affected: vBulletin / vBulletin | CVSS: 9.3 (CRITICAL) | EPSS: 0.05607 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-61511", "url": "https://www.cve.org/CVERecord?id=CVE-2026-61511"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-61511"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php", "cve_id": "CVE-2026-61511", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2026-08-27T13:06:02.039Z", "cvss_score": 9.3, "epss_score": 0.05607, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92672, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-61511", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "74a0f6ca-2f8e-47ee-bad0-1a1135c5a172", "vulnerability": {"vulnId": "CVE-2023-34124", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T21:22:51+02:00"}, "gcve": {"object_uuid": "74a0f6ca-2f8e-47ee-bad0-1a1135c5a172", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T19:22:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T19:22:51+00:00"}, "scope": {"notes": "The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue... | Affected: SonicWall / GMS, Analytics | CVSS: 9.8 (CRITICAL) | EPSS: 0.50477 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34124", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34124"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34124"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue...", "cve_id": "CVE-2023-34124", "vendor": "SonicWall", "ghsa_id": null, "product": "GMS, Analytics", "added_date": "2026-08-26T19:22:51.939Z", "cvss_score": 9.8, "epss_score": 0.50477, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98881, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34124", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ccd640b6-d78b-4f0a-a25b-84c8fa8d8e3f", "vulnerability": {"vulnId": "CVE-2021-23758", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T19:00:09+02:00"}, "gcve": {"object_uuid": "ccd640b6-d78b-4f0a-a25b-84c8fa8d8e3f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T17:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T17:00:09+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data | Affected: Michaelschwarz / AjaxPro.2 | CVSS: 8.1 (HIGH) | EPSS: 0.82578 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-23758", "url": "https://www.cve.org/CVERecord?id=CVE-2021-23758"}, {"id": "GHSA-6R7C-6W96-8PVW", "url": "https://github.com/advisories/GHSA-6R7C-6W96-8PVW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-23758"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data", "cve_id": "CVE-2021-23758", "vendor": "Michaelschwarz", "ghsa_id": "GHSA-6R7C-6W96-8PVW", "product": "AjaxPro.2", "added_date": "2026-08-26T17:00:09.897Z", "cvss_score": 8.1, "epss_score": 0.82578, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99657, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-23758", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7ac652c9-e096-4165-9cca-5af91c3cc96b", "vulnerability": {"vulnId": "CVE-2015-5287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T19:00:09+02:00"}, "gcve": {"object_uuid": "7ac652c9-e096-4165-9cca-5af91c3cc96b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T17:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T17:00:09+00:00"}, "scope": {"notes": "The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges... | Affected: Red Hat / Automatic Bug Reporting Tool (ABRT) | CVSS: 7.8 (HIGH) | EPSS: 0.04962 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-5287", "url": "https://www.cve.org/CVERecord?id=CVE-2015-5287"}, {"id": "GHSA-HF8C-7P7W-MCH5", "url": "https://github.com/advisories/GHSA-HF8C-7P7W-MCH5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-5287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges...", "cve_id": "CVE-2015-5287", "vendor": "Red Hat", "ghsa_id": "GHSA-HF8C-7P7W-MCH5", "product": "Automatic Bug Reporting Tool (ABRT)", "added_date": "2026-08-26T17:00:09.897Z", "cvss_score": 7.8, "epss_score": 0.04962, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91917, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-5287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "91d947c4-4de2-4570-ae67-055156511455", "vulnerability": {"vulnId": "CVE-2019-1068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T19:00:09+02:00"}, "gcve": {"object_uuid": "91d947c4-4de2-4570-ae67-055156511455", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T17:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T17:00:09+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft... | Affected: Microsoft / Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR), Microsoft SQL Server, Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR), Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR), Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU) | CVSS: 8.8 (HIGH) | EPSS: 0.56999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1068", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1068"}, {"id": "GHSA-62PW-5PR4-GHR5", "url": "https://github.com/advisories/GHSA-62PW-5PR4-GHR5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft...", "cve_id": "CVE-2019-1068", "vendor": "Microsoft", "ghsa_id": "GHSA-62PW-5PR4-GHR5", "product": "Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR), Microsoft SQL Server, Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR), Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR), Microsoft SQL Server 2017 for x64-based Systems (GDR), Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR), Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)", "added_date": "2026-08-26T17:00:09.897Z", "cvss_score": 8.8, "epss_score": 0.56999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99043, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1068", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "900079c2-03f9-44d7-9694-cd853baf6ac3", "vulnerability": {"vulnId": "CVE-2022-0995", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T19:00:09+02:00"}, "gcve": {"object_uuid": "900079c2-03f9-44d7-9694-cd853baf6ac3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T17:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T17:00:09+00:00"}, "scope": {"notes": "An out-of-bounds (OOB) memory write flaw was found in the Linux kernel\u2019s watch_queue event notification subsystem. This flaw can overwrite parts of... | Affected: Linux / kernel | CVSS: 7.8 (HIGH) | EPSS: 0.08788 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0995", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0995"}, {"id": "GHSA-Q5P3-3MPM-HPPR", "url": "https://github.com/advisories/GHSA-Q5P3-3MPM-HPPR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0995"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds (OOB) memory write flaw was found in the Linux kernel\u2019s watch_queue event notification subsystem. This flaw can overwrite parts of...", "cve_id": "CVE-2022-0995", "vendor": "Linux", "ghsa_id": "GHSA-Q5P3-3MPM-HPPR", "product": "kernel", "added_date": "2026-08-26T17:00:09.897Z", "cvss_score": 7.8, "epss_score": 0.08788, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95025, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0995", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d91249e1-6e5d-41d6-9698-0f2bf513a3e9", "vulnerability": {"vulnId": "CVE-2015-3246", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T19:00:09+02:00"}, "gcve": {"object_uuid": "d91249e1-6e5d-41d6-9698-0f2bf513a3e9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T17:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T17:00:09+00:00"}, "scope": {"notes": "libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which... | Affected: Red Hat, Opensuse, Libuser_project / libuser | CVSS: 7.4 (HIGH) | EPSS: 0.08799 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-3246", "url": "https://www.cve.org/CVERecord?id=CVE-2015-3246"}, {"id": "GHSA-F52H-J689-X786", "url": "https://github.com/advisories/GHSA-F52H-J689-X786"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-3246"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which...", "cve_id": "CVE-2015-3246", "vendor": "Red Hat, Opensuse, Libuser_project", "ghsa_id": "GHSA-F52H-J689-X786", "product": "libuser", "added_date": "2026-08-26T17:00:09.897Z", "cvss_score": 7.4, "epss_score": 0.08799, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95031, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-3246", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "435d36d4-f634-45a4-a656-9d37588acf1e", "vulnerability": {"vulnId": "CVE-2023-34132", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-26T15:00:00+02:00"}, "gcve": {"object_uuid": "435d36d4-f634-45a4-a656-9d37588acf1e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-26T13:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-26T13:00:00+00:00"}, "scope": {"notes": "Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue... | Affected: SonicWall / GMS, Analytics | CVSS: 9.8 (CRITICAL) | EPSS: 0.0768 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34132", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34132"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34132"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue...", "cve_id": "CVE-2023-34132", "vendor": "SonicWall", "ghsa_id": null, "product": "GMS, Analytics", "added_date": "2026-08-26T13:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.0768, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34132", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d9e83665-e504-452c-8f50-5504d08fd2f3", "vulnerability": {"vulnId": "CVE-2026-21962", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-25T17:46:59+02:00"}, "gcve": {"object_uuid": "d9e83665-e504-452c-8f50-5504d08fd2f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-25T15:46:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-25T15:46:59+00:00"}, "scope": {"notes": "Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy... | Affected: Oracle / Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in | CVSS: 10.0 (CRITICAL) | EPSS: 0.70915 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21962", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21962"}, {"id": "GHSA-4WP9-CF5H-V2G5", "url": "https://github.com/advisories/GHSA-4WP9-CF5H-V2G5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21962"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy...", "cve_id": "CVE-2026-21962", "vendor": "Oracle", "ghsa_id": "GHSA-4WP9-CF5H-V2G5", "product": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in", "added_date": "2026-08-25T15:46:59.851Z", "cvss_score": 10.0, "epss_score": 0.70915, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99386, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21962", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a13d6591-30fd-4679-b866-6b19eb01e088", "vulnerability": {"vulnId": "CVE-2026-18963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-25T17:13:17+02:00"}, "gcve": {"object_uuid": "a13d6591-30fd-4679-b866-6b19eb01e088", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-25T15:13:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-25T15:13:17+00:00"}, "scope": {"notes": "Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass | Affected: Red Hat / Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.15, Red Hat build of Keycloak 26.6, Red Hat build of Keycloak 26.6.6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7 | CVSS: 9.1 (CRITICAL) | EPSS: 0.03177 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-18963", "url": "https://www.cve.org/CVERecord?id=CVE-2026-18963"}, {"id": "GHSA-4GV3-MC9P-5WQC", "url": "https://github.com/advisories/GHSA-4GV3-MC9P-5WQC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-18963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass", "cve_id": "CVE-2026-18963", "vendor": "Red Hat", "ghsa_id": "GHSA-4GV3-MC9P-5WQC", "product": "Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.15, Red Hat build of Keycloak 26.6, Red Hat build of Keycloak 26.6.6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Single Sign-On 7", "added_date": "2026-08-25T15:13:17.550Z", "cvss_score": 9.1, "epss_score": 0.03177, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87599, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-18963", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1312250d-c35d-4e51-84f4-444bccc70866", "vulnerability": {"vulnId": "CVE-2026-63520", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-25T12:53:00+02:00"}, "gcve": {"object_uuid": "1312250d-c35d-4e51-84f4-444bccc70866", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-25T10:53:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-25T10:53:00+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 8.1 (HIGH) | EPSS: 0.00956 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-63520", "url": "https://www.cve.org/CVERecord?id=CVE-2026-63520"}, {"id": "GHSA-CJ4W-V2C3-7QJR", "url": "https://github.com/advisories/GHSA-CJ4W-V2C3-7QJR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-63520"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability", "cve_id": "CVE-2026-63520", "vendor": "Microsoft", "ghsa_id": "GHSA-CJ4W-V2C3-7QJR", "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-08-25T10:53:00.000Z", "cvss_score": 8.1, "epss_score": 0.00956, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60006, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-63520", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2fe4e1d2-6bb1-43c1-80f4-94ee0517e1cd", "vulnerability": {"vulnId": "CVE-2026-60004", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-25T12:47:00+02:00"}, "gcve": {"object_uuid": "2fe4e1d2-6bb1-43c1-80f4-94ee0517e1cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-25T10:47:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-25T10:47:00+00:00"}, "scope": {"notes": "Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | Affected: Gitea / Gitea | CVSS: 9.8 (CRITICAL) | EPSS: 0.23988 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-60004", "url": "https://www.cve.org/CVERecord?id=CVE-2026-60004"}, {"id": "GHSA-RCR6-4JQH-J84M", "url": "https://github.com/advisories/GHSA-RCR6-4JQH-J84M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-60004"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.", "cve_id": "CVE-2026-60004", "vendor": "Gitea", "ghsa_id": "GHSA-RCR6-4JQH-J84M", "product": "Gitea", "added_date": "2026-08-25T10:47:00.000Z", "cvss_score": 9.8, "epss_score": 0.23988, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97774, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-60004", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8014b953-f51a-4bfd-9b38-5ea6b33e251f", "vulnerability": {"vulnId": "CVE-2026-77136", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-25T11:10:43+02:00"}, "gcve": {"object_uuid": "8014b953-f51a-4bfd-9b38-5ea6b33e251f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-25T09:10:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-25T09:10:43+00:00"}, "scope": {"notes": "Server-Side Template Injection in extension \"powermail\" (powermail) | Affected: TYPO3 / Extension \"powermail\" | CVSS: 9.5 (CRITICAL) | EPSS: 0.00968 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-77136", "url": "https://www.cve.org/CVERecord?id=CVE-2026-77136"}, {"id": "GHSA-6956-F2GQ-2C74", "url": "https://github.com/advisories/GHSA-6956-F2GQ-2C74"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-77136"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Server-Side Template Injection in extension \"powermail\" (powermail)", "cve_id": "CVE-2026-77136", "vendor": "TYPO3", "ghsa_id": "GHSA-6956-F2GQ-2C74", "product": "Extension \"powermail\"", "added_date": "2026-08-25T09:10:43.436Z", "cvss_score": 9.5, "epss_score": 0.00968, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60477, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-77136", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a9458c43-2ca9-47ca-b909-171d3e3b1841", "vulnerability": {"vulnId": "CVE-2025-55583", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "a9458c43-2ca9-47ca-b909-171d3e3b1841", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-25T00:00:00+00:00"}, "scope": {"notes": "D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi... | Affected: D-Link / DIR-868L B1 router | CVSS: 9.8 (CRITICAL) | EPSS: 0.06974 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-55583", "url": "https://www.cve.org/CVERecord?id=CVE-2025-55583"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-55583"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi...", "cve_id": "CVE-2025-55583", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-868L B1 router", "added_date": "2026-08-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06974, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-55583", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "424cfdec-5873-40ac-a639-7bdbca6d548b", "vulnerability": {"vulnId": "CVE-2024-12912", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-24T02:00:00+02:00"}, "gcve": {"object_uuid": "424cfdec-5873-40ac-a639-7bdbca6d548b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-24T00:00:00+00:00"}, "scope": {"notes": "An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution.\nRefer to the '01/02/2025... | Affected: ASUS / Router | CVSS: 7.2 (HIGH) | EPSS: 0.01238 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-12912", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12912"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12912"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution.\nRefer to the '01/02/2025...", "cve_id": "CVE-2024-12912", "vendor": "ASUS", "ghsa_id": null, "product": "Router", "added_date": "2026-08-24T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.01238, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68002, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12912", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a6082c15-5f35-431f-981a-b9a400e98bce", "vulnerability": {"vulnId": "CVE-2026-57739", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-22T18:39:12+02:00"}, "gcve": {"object_uuid": "a6082c15-5f35-431f-981a-b9a400e98bce", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-22T16:39:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-22T16:39:12+00:00"}, "scope": {"notes": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability | Affected: AcyMailing Newsletter Team / AcyMailing SMTP Newsletter | CVSS: 9.3 (CRITICAL) | EPSS: 0.004 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-57739", "url": "https://www.cve.org/CVERecord?id=CVE-2026-57739"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-57739"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability", "cve_id": "CVE-2026-57739", "vendor": "AcyMailing Newsletter Team", "ghsa_id": null, "product": "AcyMailing SMTP Newsletter", "added_date": "2026-08-22T16:39:12.742Z", "cvss_score": 9.3, "epss_score": 0.004, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.3184, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-57739", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fb36d770-0127-4120-823f-3779789e0675", "vulnerability": {"vulnId": "CVE-2026-27971", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-22T18:14:01+02:00"}, "gcve": {"object_uuid": "fb36d770-0127-4120-823f-3779789e0675", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-22T16:14:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-22T16:14:01+00:00"}, "scope": {"notes": "Qwik affected by unauthenticated RCE via server$ Deserialization | Affected: QwikDev / qwik | CVSS: 9.2 (CRITICAL) | EPSS: 0.02884 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-27971", "url": "https://www.cve.org/CVERecord?id=CVE-2026-27971"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-27971"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Qwik affected by unauthenticated RCE via server$ Deserialization", "cve_id": "CVE-2026-27971", "vendor": "QwikDev", "ghsa_id": null, "product": "qwik", "added_date": "2026-08-22T16:14:01.179Z", "cvss_score": 9.2, "epss_score": 0.02884, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86377, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-27971", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "71e4476e-22ec-4eb5-8543-08390424e57a", "vulnerability": {"vulnId": "CVE-2026-19598", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-22T10:27:29+02:00"}, "gcve": {"object_uuid": "71e4476e-22ec-4eb5-8543-08390424e57a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-22T08:27:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-22T08:27:29+00:00"}, "scope": {"notes": "Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router | Affected: sc0ttkclark / Pods \u2013 Custom Content Types and Fields | CVSS: 9.8 (CRITICAL) | EPSS: 0.03521 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-19598", "url": "https://www.cve.org/CVERecord?id=CVE-2026-19598"}, {"id": "GHSA-HMMC-48GM-3645", "url": "https://github.com/advisories/GHSA-HMMC-48GM-3645"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-19598"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router", "cve_id": "CVE-2026-19598", "vendor": "sc0ttkclark", "ghsa_id": "GHSA-HMMC-48GM-3645", "product": "Pods \u2013 Custom Content Types and Fields", "added_date": "2026-08-22T08:27:29.848Z", "cvss_score": 9.8, "epss_score": 0.03521, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88842, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-19598", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f29fac2-2f73-43c1-86d3-f138c216f6d6", "vulnerability": {"vulnId": "CVE-2019-12725", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "8f29fac2-2f73-43c1-86d3-f138c216f6d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-22T00:00:00+00:00"}, "scope": {"notes": "Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few... | Affected: Zeroshell / Zeroshell | CVSS: 9.8 (CRITICAL) | EPSS: 0.89849 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12725", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12725"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12725"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few...", "cve_id": "CVE-2019-12725", "vendor": "Zeroshell", "ghsa_id": null, "product": "Zeroshell", "added_date": "2026-08-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.89849, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99789, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12725", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b276ca61-525a-4315-9470-c2ab78a667ae", "vulnerability": {"vulnId": "CVE-2021-27691", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "b276ca61-525a-4315-9470-c2ab78a667ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-22T00:00:00+00:00"}, "scope": {"notes": "Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with... | Affected: Tenda / G0, G1, G3 routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.25183 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27691", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27691"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27691"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with...", "cve_id": "CVE-2021-27691", "vendor": "Tenda", "ghsa_id": null, "product": "G0, G1, G3 routers", "added_date": "2026-08-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.25183, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97874, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27691", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "13cf8f1c-13f6-4ff9-b615-b065c732ef54", "vulnerability": {"vulnId": "CVE-2025-10164", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "13cf8f1c-13f6-4ff9-b615-b065c732ef54", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-22T00:00:00+00:00"}, "scope": {"notes": "lmsys sglang update_weights_from_tensor main deserialization | Affected: Lmsys / sglang | CVSS: 6.9 (MEDIUM) | EPSS: 0.00404 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-10164", "url": "https://www.cve.org/CVERecord?id=CVE-2025-10164"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-10164"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "lmsys sglang update_weights_from_tensor main deserialization", "cve_id": "CVE-2025-10164", "vendor": "Lmsys", "ghsa_id": null, "product": "sglang", "added_date": "2026-08-22T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.00404, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.32274, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-10164", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e53dae92-c680-47dd-8f95-6f5c5596067b", "vulnerability": {"vulnId": "CVE-2026-77806", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-21T15:50:25+02:00"}, "gcve": {"object_uuid": "e53dae92-c680-47dd-8f95-6f5c5596067b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-21T13:50:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-21T13:50:25+00:00"}, "scope": {"notes": "SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to... | Affected: SPIP / SPIP | CVSS: 9.8 (CRITICAL) | EPSS: 0.04479 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-77806", "url": "https://www.cve.org/CVERecord?id=CVE-2026-77806"}, {"id": "GHSA-VGR8-RQWX-WQRP", "url": "https://github.com/advisories/GHSA-VGR8-RQWX-WQRP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-77806"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...", "cve_id": "CVE-2026-77806", "vendor": "SPIP", "ghsa_id": "GHSA-VGR8-RQWX-WQRP", "product": "SPIP", "added_date": "2026-08-21T13:50:25.867Z", "cvss_score": 9.8, "epss_score": 0.04479, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91156, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-77806", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "81ae04e8-e7a9-4c6e-8e55-f2467c2f3f63", "vulnerability": {"vulnId": "CVE-2026-19478", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-21T09:04:25+02:00"}, "gcve": {"object_uuid": "81ae04e8-e7a9-4c6e-8e55-f2467c2f3f63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-21T07:04:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-21T07:04:25+00:00"}, "scope": {"notes": "Improper Control of Generation of Code ('Code Injection') in GitLab | Affected: GitLab / GitLab | CVSS: 9.4 (CRITICAL) | EPSS: 0.60204 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-19478", "url": "https://www.cve.org/CVERecord?id=CVE-2026-19478"}, {"id": "GHSA-6WHR-XJJM-6PF8", "url": "https://github.com/advisories/GHSA-6WHR-XJJM-6PF8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-19478"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Control of Generation of Code ('Code Injection') in GitLab", "cve_id": "CVE-2026-19478", "vendor": "GitLab", "ghsa_id": "GHSA-6WHR-XJJM-6PF8", "product": "GitLab", "added_date": "2026-08-21T07:04:25.000Z", "cvss_score": 9.4, "epss_score": 0.60204, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99112, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-19478", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "622444a7-5a07-4809-ac91-810a55a1af32", "vulnerability": {"vulnId": "CVE-2026-77647", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-21T00:40:31+02:00"}, "gcve": {"object_uuid": "622444a7-5a07-4809-ac91-810a55a1af32", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-20T22:40:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-20T22:40:31+00:00"}, "scope": {"notes": "SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to... | Affected: SPIP / SPIP | CVSS: 9.8 (CRITICAL) | EPSS: 0.02292 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-77647", "url": "https://www.cve.org/CVERecord?id=CVE-2026-77647"}, {"id": "GHSA-WJ6G-RH9Q-6VVM", "url": "https://github.com/advisories/GHSA-WJ6G-RH9Q-6VVM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-77647"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to...", "cve_id": "CVE-2026-77647", "vendor": "SPIP", "ghsa_id": "GHSA-WJ6G-RH9Q-6VVM", "product": "SPIP", "added_date": "2026-08-20T22:40:31.553Z", "cvss_score": 9.8, "epss_score": 0.02292, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82608, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-77647", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "571543e1-69bf-4cf0-b317-eb42a93f1862", "vulnerability": {"vulnId": "CVE-2026-72530", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-20T19:00:27+02:00"}, "gcve": {"object_uuid": "571543e1-69bf-4cf0-b317-eb42a93f1862", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-20T17:00:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-20T17:00:27+00:00"}, "scope": {"notes": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to... | Affected: TrueConf / TrueConf Server | CVSS: 9.5 (CRITICAL) | EPSS: 0.01686 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-72530", "url": "https://www.cve.org/CVERecord?id=CVE-2026-72530"}, {"id": "GHSA-F8Q9-F337-2P3R", "url": "https://github.com/advisories/GHSA-F8Q9-F337-2P3R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-72530"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to...", "cve_id": "CVE-2026-72530", "vendor": "TrueConf", "ghsa_id": "GHSA-F8Q9-F337-2P3R", "product": "TrueConf Server", "added_date": "2026-08-20T17:00:27.883Z", "cvss_score": 9.5, "epss_score": 0.01686, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76181, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-72530", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3440b35a-8f04-4500-9fe4-7afacf71d353", "vulnerability": {"vulnId": "CVE-2026-72529", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-20T19:00:27+02:00"}, "gcve": {"object_uuid": "3440b35a-8f04-4500-9fe4-7afacf71d353", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-20T17:00:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-20T17:00:27+00:00"}, "scope": {"notes": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to... | Affected: TrueConf / TrueConf Server | CVSS: 9.3 (CRITICAL) | EPSS: 0.01464 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-72529", "url": "https://www.cve.org/CVERecord?id=CVE-2026-72529"}, {"id": "GHSA-XC2X-Q39J-746F", "url": "https://github.com/advisories/GHSA-XC2X-Q39J-746F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-72529"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to...", "cve_id": "CVE-2026-72529", "vendor": "TrueConf", "ghsa_id": "GHSA-XC2X-Q39J-746F", "product": "TrueConf Server", "added_date": "2026-08-20T17:00:27.883Z", "cvss_score": 9.3, "epss_score": 0.01464, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72697, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-72529", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "14841dc4-6415-4bb5-8d14-332c8bb947ca", "vulnerability": {"vulnId": "CVE-2023-25158", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-19T02:00:00+02:00"}, "gcve": {"object_uuid": "14841dc4-6415-4bb5-8d14-332c8bb947ca", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-19T00:00:00+00:00"}, "scope": {"notes": "Unfiltered SQL Injection in Geotools | Affected: Geotools / geotools | CVSS: 9.8 (CRITICAL) | EPSS: 0.01095 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-25158", "url": "https://www.cve.org/CVERecord?id=CVE-2023-25158"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-25158"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unfiltered SQL Injection in Geotools", "cve_id": "CVE-2023-25158", "vendor": "Geotools", "ghsa_id": null, "product": "geotools", "added_date": "2026-08-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01095, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64302, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-25158", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3bcfe6ab-fcd0-4276-88e1-5738f8a4fda8", "vulnerability": {"vulnId": "CVE-2026-33824", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-18T18:52:08+02:00"}, "gcve": {"object_uuid": "3bcfe6ab-fcd0-4276-88e1-5738f8a4fda8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-18T16:52:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-18T16:52:08+00:00"}, "scope": {"notes": "Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 9.8 (CRITICAL) | EPSS: 0.01619 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-33824", "url": "https://www.cve.org/CVERecord?id=CVE-2026-33824"}, {"id": "GHSA-Q6QF-3M2M-XQ4F", "url": "https://github.com/advisories/GHSA-Q6QF-3M2M-XQ4F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-33824"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability", "cve_id": "CVE-2026-33824", "vendor": "Microsoft", "ghsa_id": "GHSA-Q6QF-3M2M-XQ4F", "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-08-18T16:52:08.539Z", "cvss_score": 9.8, "epss_score": 0.01619, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7519, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-33824", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7147cc08-f485-4bd6-8aff-969c79dfb512", "vulnerability": {"vulnId": "CVE-2026-64849", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-18T15:31:00+02:00"}, "gcve": {"object_uuid": "7147cc08-f485-4bd6-8aff-969c79dfb512", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-18T13:31:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-18T13:31:00+00:00"}, "scope": {"notes": "MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | Affected: Mlflow / mlflow | CVSS: 9.3 (CRITICAL) | EPSS: 0.09839 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-64849", "url": "https://www.cve.org/CVERecord?id=CVE-2026-64849"}, {"id": "GHSA-7GWP-5PFP-969J", "url": "https://github.com/advisories/GHSA-7GWP-5PFP-969J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-64849"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)", "cve_id": "CVE-2026-64849", "vendor": "Mlflow", "ghsa_id": "GHSA-7GWP-5PFP-969J", "product": "mlflow", "added_date": "2026-08-18T13:31:00.000Z", "cvss_score": 9.3, "epss_score": 0.09839, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9542, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-64849", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "66f43ac9-ddc9-4ffb-9c60-c21532cdc776", "vulnerability": {"vulnId": "CVE-2026-76904", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-18T11:07:09+02:00"}, "gcve": {"object_uuid": "66f43ac9-ddc9-4ffb-9c60-c21532cdc776", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-18T09:07:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-18T09:07:09+00:00"}, "scope": {"notes": "GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers | Affected: Geotools / geotools | CVSS: 9.8 (CRITICAL) | EPSS: 0.02403 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-76904", "url": "https://www.cve.org/CVERecord?id=CVE-2026-76904"}, {"id": "GHSA-MQJF-5F49-2FJH", "url": "https://github.com/advisories/GHSA-MQJF-5F49-2FJH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-76904"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers", "cve_id": "CVE-2026-76904", "vendor": "Geotools", "ghsa_id": "GHSA-MQJF-5F49-2FJH", "product": "geotools", "added_date": "2026-08-18T09:07:09.639Z", "cvss_score": 9.8, "epss_score": 0.02403, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83441, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-76904", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8fd82cc4-32b8-4807-b822-10d2375bb508", "vulnerability": {"vulnId": "CVE-2025-62593", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T18:33:32+02:00"}, "gcve": {"object_uuid": "8fd82cc4-32b8-4807-b822-10d2375bb508", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T16:33:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T16:33:32+00:00"}, "scope": {"notes": "Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | Affected: Ray-project / ray | CVSS: 9.4 (CRITICAL) | EPSS: 0.62459 | Used in malware: unknown | Listed 7 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-62593", "url": "https://www.cve.org/CVERecord?id=CVE-2025-62593"}, {"id": "GHSA-Q279-JHRF-CC6V", "url": "https://github.com/advisories/GHSA-Q279-JHRF-CC6V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-62593"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack", "cve_id": "CVE-2025-62593", "vendor": "Ray-project", "ghsa_id": "GHSA-Q279-JHRF-CC6V", "product": "ray", "added_date": "2026-08-17T16:33:32.649Z", "cvss_score": 9.4, "epss_score": 0.62459, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99165, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-62593", "ahead_of_cisa_kev": {"unit": "hour", "count": 7}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "918a836b-816a-41ff-b71d-aba3af48c307", "vulnerability": {"vulnId": "CVE-2026-73570", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T11:01:25+02:00"}, "gcve": {"object_uuid": "918a836b-816a-41ff-b71d-aba3af48c307", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T09:01:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T09:01:25+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and... | Affected: Zimbra / Collaboration | CVSS: 8.9 (HIGH) | EPSS: 0.11736 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-73570", "url": "https://www.cve.org/CVERecord?id=CVE-2026-73570"}, {"id": "GHSA-JQH7-PCHH-V74J", "url": "https://github.com/advisories/GHSA-JQH7-PCHH-V74J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-73570"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and...", "cve_id": "CVE-2026-73570", "vendor": "Zimbra", "ghsa_id": "GHSA-JQH7-PCHH-V74J", "product": "Collaboration", "added_date": "2026-08-17T09:01:25.000Z", "cvss_score": 8.9, "epss_score": 0.11736, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.9595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-73570", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7c2cfb57-3b0c-4e11-b268-2bb150e0b619", "vulnerability": {"vulnId": "CVE-2026-52806", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T10:49:09+02:00"}, "gcve": {"object_uuid": "7c2cfb57-3b0c-4e11-b268-2bb150e0b619", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T08:49:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T08:49:09+00:00"}, "scope": {"notes": "Gogs: RCE via git rebase --exec argument injection in pull request merge | Affected: Gogs / gogs | CVSS: 9.9 (CRITICAL) | EPSS: 0.07934 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-52806", "url": "https://www.cve.org/CVERecord?id=CVE-2026-52806"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-52806"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gogs: RCE via git rebase --exec argument injection in pull request merge", "cve_id": "CVE-2026-52806", "vendor": "Gogs", "ghsa_id": null, "product": "gogs", "added_date": "2026-08-17T08:49:09.242Z", "cvss_score": 9.9, "epss_score": 0.07934, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94561, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-52806", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4fbc2142-3b08-4cc8-9af4-d2d406575432", "vulnerability": {"vulnId": "CVE-2026-56270", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T10:25:42+02:00"}, "gcve": {"object_uuid": "4fbc2142-3b08-4cc8-9af4-d2d406575432", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T08:25:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T08:25:42+00:00"}, "scope": {"notes": "Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint | Affected: Flowise / Flowise | CVSS: 8.7 (HIGH) | EPSS: 0.02048 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-56270", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56270"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-56270"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint", "cve_id": "CVE-2026-56270", "vendor": "Flowise", "ghsa_id": null, "product": "Flowise", "added_date": "2026-08-17T08:25:42.707Z", "cvss_score": 8.7, "epss_score": 0.02048, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80501, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-56270", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d4f2dcfd-1be4-4ea2-b8a3-a16fbe0e43ec", "vulnerability": {"vulnId": "CVE-2026-8452", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T10:04:34+02:00"}, "gcve": {"object_uuid": "d4f2dcfd-1be4-4ea2-b8a3-a16fbe0e43ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T08:04:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T08:04:34+00:00"}, "scope": {"notes": "Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service | Affected: NetScaler / ADC, Gateway | CVSS: 8.8 (HIGH) | EPSS: 0.01011 | Used in malware: unknown | Listed 9 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-8452", "url": "https://www.cve.org/CVERecord?id=CVE-2026-8452"}, {"id": "GHSA-R7WG-R5WJ-C765", "url": "https://github.com/advisories/GHSA-R7WG-R5WJ-C765"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-8452"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service", "cve_id": "CVE-2026-8452", "vendor": "NetScaler", "ghsa_id": "GHSA-R7WG-R5WJ-C765", "product": "ADC, Gateway", "added_date": "2026-08-17T08:04:34.863Z", "cvss_score": 8.8, "epss_score": 0.01011, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61847, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-8452", "ahead_of_cisa_kev": {"unit": "day", "count": 9}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f98b5cc-1dc5-4f89-a7d5-3663f12881e0", "vulnerability": {"vulnId": "CVE-2022-50973", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T02:00:00+02:00"}, "gcve": {"object_uuid": "2f98b5cc-1dc5-4f89-a7d5-3663f12881e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T00:00:00+00:00"}, "scope": {"notes": "Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet | Affected: Yonyou Network Technology / KSOA | CVSS: 9.3 (CRITICAL) | EPSS: 0.01519 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-50973", "url": "https://www.cve.org/CVERecord?id=CVE-2022-50973"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-50973"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet", "cve_id": "CVE-2022-50973", "vendor": "Yonyou Network Technology", "ghsa_id": null, "product": "KSOA", "added_date": "2026-08-17T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.01519, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.73634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-50973", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f9d5fcba-616f-491c-ae9b-83cc9f31b0d9", "vulnerability": {"vulnId": "CVE-2025-52907", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-17T02:00:00+02:00"}, "gcve": {"object_uuid": "f9d5fcba-616f-491c-ae9b-83cc9f31b0d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-17T00:00:00+00:00"}, "scope": {"notes": "TOTOLINK X6000R Security Bypass Vulnerability | Affected: TOTOLINK / X6000R | CVSS: 7.3 (HIGH) | EPSS: 0.00846 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-52907", "url": "https://www.cve.org/CVERecord?id=CVE-2025-52907"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-52907"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK X6000R Security Bypass Vulnerability", "cve_id": "CVE-2025-52907", "vendor": "TOTOLINK", "ghsa_id": null, "product": "X6000R", "added_date": "2026-08-17T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.00846, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5653, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-52907", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "049407e8-b9f6-497e-82ee-ae1626040002", "vulnerability": {"vulnId": "CVE-2026-45298", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-16T19:11:53+02:00"}, "gcve": {"object_uuid": "049407e8-b9f6-497e-82ee-ae1626040002", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-16T17:11:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-16T17:11:53+00:00"}, "scope": {"notes": "Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy) | Affected: amir20 / dozzle | CVSS: 8.6 (HIGH) | EPSS: 0.01605 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-45298", "url": "https://www.cve.org/CVERecord?id=CVE-2026-45298"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-45298"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)", "cve_id": "CVE-2026-45298", "vendor": "amir20", "ghsa_id": null, "product": "dozzle", "added_date": "2026-08-16T17:11:53.741Z", "cvss_score": 8.6, "epss_score": 0.01605, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-45298", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "74f2216d-be23-48b5-8006-82b463876998", "vulnerability": {"vulnId": "CVE-2016-5312", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-16T18:35:35+02:00"}, "gcve": {"object_uuid": "74f2216d-be23-48b5-8006-82b463876998", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-16T16:35:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-16T16:35:35+00:00"}, "scope": {"notes": "Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read... | Affected: Symantec / Messaging Gateway | CVSS: 6.5 (MEDIUM) | EPSS: 0.53702 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-5312", "url": "https://www.cve.org/CVERecord?id=CVE-2016-5312"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-5312"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read...", "cve_id": "CVE-2016-5312", "vendor": "Symantec", "ghsa_id": null, "product": "Messaging Gateway", "added_date": "2026-08-16T16:35:35.888Z", "cvss_score": 6.5, "epss_score": 0.53702, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98966, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-5312", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e5365136-6b6b-40a8-8eb8-bc63daa077c2", "vulnerability": {"vulnId": "CVE-2026-65400", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-15T09:24:04+02:00"}, "gcve": {"object_uuid": "e5365136-6b6b-40a8-8eb8-bc63daa077c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-15T07:24:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-15T07:24:04+00:00"}, "scope": {"notes": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS... | Affected: Apple / macOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.01723 | Used in malware: unknown | Listed 3 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-65400", "url": "https://www.cve.org/CVERecord?id=CVE-2026-65400"}, {"id": "GHSA-CWPH-F4W9-F4WQ", "url": "https://github.com/advisories/GHSA-CWPH-F4W9-F4WQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-65400"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS...", "cve_id": "CVE-2026-65400", "vendor": "Apple", "ghsa_id": "GHSA-CWPH-F4W9-F4WQ", "product": "macOS", "added_date": "2026-08-15T07:24:04.000Z", "cvss_score": 9.8, "epss_score": 0.01723, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76682, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-65400", "ahead_of_cisa_kev": {"unit": "day", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7236f6cd-bc5d-44b3-a3f1-bb67e3e7ad96", "vulnerability": {"vulnId": "CVE-2021-2109", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-15T02:00:00+02:00"}, "gcve": {"object_uuid": "7236f6cd-bc5d-44b3-a3f1-bb67e3e7ad96", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-15T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 7.2 (HIGH) | EPSS: 0.70447 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-2109", "url": "https://www.cve.org/CVERecord?id=CVE-2021-2109"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-2109"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...", "cve_id": "CVE-2021-2109", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2026-08-15T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.70447, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99372, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-2109", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ee9f438b-7ece-4f5c-9147-00c9c68f379f", "vulnerability": {"vulnId": "CVE-2016-20097", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T21:20:24+02:00"}, "gcve": {"object_uuid": "ee9f438b-7ece-4f5c-9147-00c9c68f379f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T19:20:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T19:20:24+00:00"}, "scope": {"notes": "Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad | Affected: Weaver Network / E-cology 8.0 | CVSS: 8.7 (HIGH) | EPSS: 0.00632 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-20097", "url": "https://www.cve.org/CVERecord?id=CVE-2016-20097"}, {"id": "GHSA-8R52-43HM-H433", "url": "https://github.com/advisories/GHSA-8R52-43HM-H433"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-20097"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad", "cve_id": "CVE-2016-20097", "vendor": "Weaver Network", "ghsa_id": "GHSA-8R52-43HM-H433", "product": "E-cology 8.0", "added_date": "2026-08-14T19:20:24.767Z", "cvss_score": 8.7, "epss_score": 0.00632, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.4839, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-20097", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f71fc17e-824f-49c4-8368-41bed417e3be", "vulnerability": {"vulnId": "CVE-2026-73533", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T19:13:03+02:00"}, "gcve": {"object_uuid": "f71fc17e-824f-49c4-8368-41bed417e3be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T17:13:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T17:13:03+00:00"}, "scope": {"notes": "Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build | Affected: WP Manage Ninja / Ninja Tables Pro | CVSS: 9.3 (CRITICAL) | EPSS: 0.00649 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-73533", "url": "https://www.cve.org/CVERecord?id=CVE-2026-73533"}, {"id": "GHSA-7WC4-82PM-HQCG", "url": "https://github.com/advisories/GHSA-7WC4-82PM-HQCG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-73533"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build", "cve_id": "CVE-2026-73533", "vendor": "WP Manage Ninja", "ghsa_id": "GHSA-7WC4-82PM-HQCG", "product": "Ninja Tables Pro", "added_date": "2026-08-14T17:13:03.486Z", "cvss_score": 9.3, "epss_score": 0.00649, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.49241, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-73533", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fac09245-080a-470b-ac6d-ceef88d0824d", "vulnerability": {"vulnId": "CVE-2026-73532", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T19:13:03+02:00"}, "gcve": {"object_uuid": "fac09245-080a-470b-ac6d-ceef88d0824d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T17:13:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T17:13:03+00:00"}, "scope": {"notes": "Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build | Affected: WP Manage Ninja / Fluent Forms Pro | CVSS: 9.3 (CRITICAL) | EPSS: 0.00671 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-73532", "url": "https://www.cve.org/CVERecord?id=CVE-2026-73532"}, {"id": "GHSA-F3V6-4MCW-WRQJ", "url": "https://github.com/advisories/GHSA-F3V6-4MCW-WRQJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-73532"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build", "cve_id": "CVE-2026-73532", "vendor": "WP Manage Ninja", "ghsa_id": "GHSA-F3V6-4MCW-WRQJ", "product": "Fluent Forms Pro", "added_date": "2026-08-14T17:13:03.323Z", "cvss_score": 9.3, "epss_score": 0.00671, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5022, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-73532", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a5c2ead7-1ec0-4cd9-b331-b48cd8654ba7", "vulnerability": {"vulnId": "CVE-2026-67595", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T19:12:30+02:00"}, "gcve": {"object_uuid": "a5c2ead7-1ec0-4cd9-b331-b48cd8654ba7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T17:12:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T17:12:30+00:00"}, "scope": {"notes": "VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php | Affected: Webreinvent / vaahcms | CVSS: 9.2 (CRITICAL) | EPSS: 0.00763 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-67595", "url": "https://www.cve.org/CVERecord?id=CVE-2026-67595"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-67595"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php", "cve_id": "CVE-2026-67595", "vendor": "Webreinvent", "ghsa_id": null, "product": "vaahcms", "added_date": "2026-08-14T17:12:30.387Z", "cvss_score": 9.2, "epss_score": 0.00763, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.53726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-67595", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2e26f6d5-eded-4012-99f4-c560163f9953", "vulnerability": {"vulnId": "CVE-2022-50997", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T19:10:46+02:00"}, "gcve": {"object_uuid": "2e26f6d5-eded-4012-99f4-c560163f9953", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T17:10:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T17:10:46+00:00"}, "scope": {"notes": "Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp | Affected: Weaver Network / E-cology 9.0, E-cology 8.0 | CVSS: 8.7 (HIGH) | EPSS: 0.00621 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-50997", "url": "https://www.cve.org/CVERecord?id=CVE-2022-50997"}, {"id": "GHSA-P597-C7C2-QJ48", "url": "https://github.com/advisories/GHSA-P597-C7C2-QJ48"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-50997"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp", "cve_id": "CVE-2022-50997", "vendor": "Weaver Network", "ghsa_id": "GHSA-P597-C7C2-QJ48", "product": "E-cology 9.0, E-cology 8.0", "added_date": "2026-08-14T17:10:46.524Z", "cvss_score": 8.7, "epss_score": 0.00621, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.47872, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-50997", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d3a92d8c-a5bb-4080-8979-cfd73ce42f97", "vulnerability": {"vulnId": "CVE-2022-4995", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T19:10:46+02:00"}, "gcve": {"object_uuid": "d3a92d8c-a5bb-4080-8979-cfd73ce42f97", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T17:10:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T17:10:46+00:00"}, "scope": {"notes": "Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp | Affected: Weaver Network / E-cology 9.0 | CVSS: 9.3 (CRITICAL) | EPSS: 0.01175 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4995", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4995"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4995"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp", "cve_id": "CVE-2022-4995", "vendor": "Weaver Network", "ghsa_id": null, "product": "E-cology 9.0", "added_date": "2026-08-14T17:10:46.107Z", "cvss_score": 9.3, "epss_score": 0.01175, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.66399, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4995", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b277379c-51e3-40e2-975f-3e7b92f7fedf", "vulnerability": {"vulnId": "CVE-2019-25765", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T15:20:44+02:00"}, "gcve": {"object_uuid": "b277379c-51e3-40e2-975f-3e7b92f7fedf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T13:20:44+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T13:20:44+00:00"}, "scope": {"notes": "ASP-CMS SQL Injection via commentList.asp id Parameter | Affected: ASP-CMS Project / ASP-CMS | CVSS: 8.7 (HIGH) | EPSS: 0.00736 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-25765", "url": "https://www.cve.org/CVERecord?id=CVE-2019-25765"}, {"id": "GHSA-H325-4HH9-393V", "url": "https://github.com/advisories/GHSA-H325-4HH9-393V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-25765"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ASP-CMS SQL Injection via commentList.asp id Parameter", "cve_id": "CVE-2019-25765", "vendor": "ASP-CMS Project", "ghsa_id": "GHSA-H325-4HH9-393V", "product": "ASP-CMS", "added_date": "2026-08-14T13:20:44.131Z", "cvss_score": 8.7, "epss_score": 0.00736, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52795, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-25765", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "314584d5-ebc2-45f2-9a14-cda30db0b7ee", "vulnerability": {"vulnId": "CVE-2026-58231", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T14:59:59+02:00"}, "gcve": {"object_uuid": "314584d5-ebc2-45f2-9a14-cda30db0b7ee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T12:59:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T12:59:59+00:00"}, "scope": {"notes": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) | Affected: SAP_SE / SAP Commerce Cloud (Data Hub Adapter) | CVSS: 10.0 (CRITICAL) | EPSS: 0.00855 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-58231", "url": "https://www.cve.org/CVERecord?id=CVE-2026-58231"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-58231"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)", "cve_id": "CVE-2026-58231", "vendor": "SAP_SE", "ghsa_id": null, "product": "SAP Commerce Cloud (Data Hub Adapter)", "added_date": "2026-08-14T12:59:59.018Z", "cvss_score": 10.0, "epss_score": 0.00855, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.56833, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-58231", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1aea515c-b888-4f96-911d-3bb2582f6c6a", "vulnerability": {"vulnId": "CVE-2021-30120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T06:30:51+02:00"}, "gcve": {"object_uuid": "1aea515c-b888-4f96-911d-3bb2582f6c6a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T04:30:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T04:30:51+00:00"}, "scope": {"notes": "2FA bypass in Kaseya VSA <= v9.5.6 | Affected: Kaseya / VSA | CVSS: 9.9 (CRITICAL) | EPSS: 0.05701 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30120", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30120"}, {"id": "GHSA-R6J9-RWX4-QCJ3", "url": "https://github.com/advisories/GHSA-R6J9-RWX4-QCJ3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "2FA bypass in Kaseya VSA <= v9.5.6", "cve_id": "CVE-2021-30120", "vendor": "Kaseya", "ghsa_id": "GHSA-R6J9-RWX4-QCJ3", "product": "VSA", "added_date": "2026-08-14T04:30:51.650Z", "cvss_score": 9.9, "epss_score": 0.05701, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92774, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30120", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e60f6b6b-3300-4d94-b5a3-4a242233329f", "vulnerability": {"vulnId": "CVE-2021-30119", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-14T06:30:51+02:00"}, "gcve": {"object_uuid": "e60f6b6b-3300-4d94-b5a3-4a242233329f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-14T04:30:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-14T04:30:51+00:00"}, "scope": {"notes": "Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6 | Affected: Kaseya / VSA | CVSS: 5.4 (MEDIUM) | EPSS: 0.50323 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30119", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30119"}, {"id": "GHSA-F43V-WH9X-RGQ6", "url": "https://github.com/advisories/GHSA-F43V-WH9X-RGQ6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30119"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authenticated Authenticated reflective XSS in Kaseya VSA <= v9.5.6", "cve_id": "CVE-2021-30119", "vendor": "Kaseya", "ghsa_id": "GHSA-F43V-WH9X-RGQ6", "product": "VSA", "added_date": "2026-08-14T04:30:51.519Z", "cvss_score": 5.4, "epss_score": 0.50323, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30119", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6a415690-f743-44eb-838c-d36bb6a2e3f8", "vulnerability": {"vulnId": "CVE-2026-26190", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-13T12:20:23+02:00"}, "gcve": {"object_uuid": "6a415690-f743-44eb-838c-d36bb6a2e3f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-13T10:20:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-13T10:20:23+00:00"}, "scope": {"notes": "Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise | Affected: Milvus-io / milvus | CVSS: 9.8 (CRITICAL) | EPSS: 0.0405 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-26190", "url": "https://www.cve.org/CVERecord?id=CVE-2026-26190"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-26190"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise", "cve_id": "CVE-2026-26190", "vendor": "Milvus-io", "ghsa_id": null, "product": "milvus", "added_date": "2026-08-13T10:20:23.409Z", "cvss_score": 9.8, "epss_score": 0.0405, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90321, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-26190", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1c4d902f-03d7-40f9-a428-0fb8587dbd7c", "vulnerability": {"vulnId": "CVE-2026-55040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-12T21:37:46+02:00"}, "gcve": {"object_uuid": "1c4d902f-03d7-40f9-a428-0fb8587dbd7c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-12T19:37:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-12T19:37:46+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 9.1 (CRITICAL) | EPSS: 0.17535 | Used in malware: unknown | Listed 7 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-55040", "url": "https://www.cve.org/CVERecord?id=CVE-2026-55040"}, {"id": "GHSA-GRXW-7CVC-96RV", "url": "https://github.com/advisories/GHSA-GRXW-7CVC-96RV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-55040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Security Feature Bypass Vulnerability", "cve_id": "CVE-2026-55040", "vendor": "Microsoft", "ghsa_id": "GHSA-GRXW-7CVC-96RV", "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-08-12T19:37:46.763Z", "cvss_score": 9.1, "epss_score": 0.17535, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97051, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-55040", "ahead_of_cisa_kev": {"unit": "day", "count": 7}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "73b79db6-6fbf-4c77-97c5-6ad2ce6cfe3b", "vulnerability": {"vulnId": "CVE-2026-59310", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-12T12:47:00+02:00"}, "gcve": {"object_uuid": "73b79db6-6fbf-4c77-97c5-6ad2ce6cfe3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-12T10:47:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-12T10:47:00+00:00"}, "scope": {"notes": "vCenter directory-traversal vulnerability | Affected: VMware / Cloud Foundation, vSphere Foundation, vCenter, Telco Cloud Infrastructure, Telco Cloud Platform | CVSS: 9.8 (CRITICAL) | EPSS: 0.02565 | Used in malware: unknown | Listed 6 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-59310", "url": "https://www.cve.org/CVERecord?id=CVE-2026-59310"}, {"id": "GHSA-V2GP-49GJ-2C9F", "url": "https://github.com/advisories/GHSA-V2GP-49GJ-2C9F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-59310"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vCenter directory-traversal vulnerability", "cve_id": "CVE-2026-59310", "vendor": "VMware", "ghsa_id": "GHSA-V2GP-49GJ-2C9F", "product": "Cloud Foundation, vSphere Foundation, vCenter, Telco Cloud Infrastructure, Telco Cloud Platform", "added_date": "2026-08-12T10:47:00.000Z", "cvss_score": 9.8, "epss_score": 0.02565, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84567, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-59310", "ahead_of_cisa_kev": {"unit": "day", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fa2f55f9-a741-4696-8c5e-3ae235bdcca5", "vulnerability": {"vulnId": "CVE-2021-21983", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-12T06:21:08+02:00"}, "gcve": {"object_uuid": "fa2f55f9-a741-4696-8c5e-3ae235bdcca5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-12T04:21:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-12T04:21:08+00:00"}, "scope": {"notes": "Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with... | Affected: VMware / VMware vRealize Operations | CVSS: 6.5 (MEDIUM) | EPSS: 0.68557 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21983", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21983"}, {"id": "GHSA-4VWX-R658-C2MG", "url": "https://github.com/advisories/GHSA-4VWX-R658-C2MG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21983"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with...", "cve_id": "CVE-2021-21983", "vendor": "VMware", "ghsa_id": "GHSA-4VWX-R658-C2MG", "product": "VMware vRealize Operations", "added_date": "2026-08-12T04:21:08.411Z", "cvss_score": 6.5, "epss_score": 0.68557, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21983", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5414b77a-2e8b-4eb3-a60c-f7137f347605", "vulnerability": {"vulnId": "CVE-2026-20349", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-11T18:39:00+02:00"}, "gcve": {"object_uuid": "5414b77a-2e8b-4eb3-a60c-f7137f347605", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-11T16:39:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-11T16:39:00+00:00"}, "scope": {"notes": "Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability | Affected: Cisco / Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software | CVSS: 8.6 (HIGH) | EPSS: 0.0101 | Used in malware: unknown | Listed 2 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20349", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20349"}, {"id": "GHSA-8X4J-5V9X-9FRV", "url": "https://github.com/advisories/GHSA-8X4J-5V9X-9FRV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20349"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability", "cve_id": "CVE-2026-20349", "vendor": "Cisco", "ghsa_id": "GHSA-8X4J-5V9X-9FRV", "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software", "added_date": "2026-08-11T16:39:00.000Z", "cvss_score": 8.6, "epss_score": 0.0101, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6182, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20349", "ahead_of_cisa_kev": {"unit": "hour", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2e9a9fad-ea48-4e23-bc76-95e0704cba82", "vulnerability": {"vulnId": "CVE-2026-33497", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-11T14:08:51+02:00"}, "gcve": {"object_uuid": "2e9a9fad-ea48-4e23-bc76-95e0704cba82", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-11T12:08:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-11T12:08:51+00:00"}, "scope": {"notes": "Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading | Affected: Langflow-ai / langflow | CVSS: 8.7 (HIGH) | EPSS: 0.02028 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-33497", "url": "https://www.cve.org/CVERecord?id=CVE-2026-33497"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-33497"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading", "cve_id": "CVE-2026-33497", "vendor": "Langflow-ai", "ghsa_id": null, "product": "langflow", "added_date": "2026-08-11T12:08:51.170Z", "cvss_score": 8.7, "epss_score": 0.02028, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-33497", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1d66b1a9-b2a4-46ee-9c06-6d2a159e740b", "vulnerability": {"vulnId": "CVE-2026-49049", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-11T10:44:44+02:00"}, "gcve": {"object_uuid": "1d66b1a9-b2a4-46ee-9c06-6d2a159e740b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-11T08:44:44+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-11T08:44:44+00:00"}, "scope": {"notes": "Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler | Affected: Joomshaper.com / Helix3 extension for Joomla | CVSS: 7.5 (HIGH) | EPSS: 0.00992 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-49049", "url": "https://www.cve.org/CVERecord?id=CVE-2026-49049"}, {"id": "GHSA-XR7R-292V-JXG8", "url": "https://github.com/advisories/GHSA-XR7R-292V-JXG8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-49049"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler", "cve_id": "CVE-2026-49049", "vendor": "Joomshaper.com", "ghsa_id": "GHSA-XR7R-292V-JXG8", "product": "Helix3 extension for Joomla", "added_date": "2026-08-11T08:44:44.938Z", "cvss_score": 7.5, "epss_score": 0.00992, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61194, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-49049", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c180951e-1620-47cd-8a6e-225ed2b8f315", "vulnerability": {"vulnId": "CVE-2025-2505", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-11T09:58:07+02:00"}, "gcve": {"object_uuid": "c180951e-1620-47cd-8a6e-225ed2b8f315", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-11T07:58:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-11T07:58:07+00:00"}, "scope": {"notes": "Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang' | Affected: Philsbury / Age Gate | CVSS: 9.8 (CRITICAL) | EPSS: 0.04884 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-2505", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2505"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2505"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang'", "cve_id": "CVE-2025-2505", "vendor": "Philsbury", "ghsa_id": null, "product": "Age Gate", "added_date": "2026-08-11T07:58:07.782Z", "cvss_score": 9.8, "epss_score": 0.04884, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91792, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2505", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f47a7f54-7988-4f0f-aff4-75a42c842313", "vulnerability": {"vulnId": "CVE-2026-68820", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-11T09:00:00+02:00"}, "gcve": {"object_uuid": "f47a7f54-7988-4f0f-aff4-75a42c842313", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-11T07:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-11T07:00:00+00:00"}, "scope": {"notes": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.00332 | Used in malware: unknown | Listed 12 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-68820", "url": "https://www.cve.org/CVERecord?id=CVE-2026-68820"}, {"id": "GHSA-C433-3382-MW5V", "url": "https://github.com/advisories/GHSA-C433-3382-MW5V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-68820"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-68820", "vendor": "Microsoft", "ghsa_id": "GHSA-C433-3382-MW5V", "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-08-11T07:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.00332, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.24012, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-68820", "ahead_of_cisa_kev": {"unit": "hour", "count": 12}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0336420d-6777-43ab-8e1a-1f30e0563972", "vulnerability": {"vulnId": "CVE-2026-72898", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-10T22:20:31+02:00"}, "gcve": {"object_uuid": "0336420d-6777-43ab-8e1a-1f30e0563972", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-10T20:20:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-10T20:20:31+00:00"}, "scope": {"notes": "Metabase SQL injection via password reset endpoint | Affected: Metabase / Metabase | CVSS: 10.0 (CRITICAL) | EPSS: 0.19048 | Used in malware: unknown | Listed 23 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-72898", "url": "https://www.cve.org/CVERecord?id=CVE-2026-72898"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-72898"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Metabase SQL injection via password reset endpoint", "cve_id": "CVE-2026-72898", "vendor": "Metabase", "ghsa_id": null, "product": "Metabase", "added_date": "2026-08-10T20:20:31.993Z", "cvss_score": 10.0, "epss_score": 0.19048, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97231, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-72898", "ahead_of_cisa_kev": {"unit": "hour", "count": 23}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6108a1c-cf9b-4f65-a984-1bb8b1440efd", "vulnerability": {"vulnId": "CVE-2026-55450", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-09T14:09:32+02:00"}, "gcve": {"object_uuid": "a6108a1c-cf9b-4f65-a984-1bb8b1440efd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-09T12:09:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-09T12:09:32+00:00"}, "scope": {"notes": "Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak | Affected: Langflow-ai / langflow | CVSS: 9.3 (CRITICAL) | EPSS: 0.0119 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-55450", "url": "https://www.cve.org/CVERecord?id=CVE-2026-55450"}, {"id": "GHSA-X223-P2GF-V735", "url": "https://github.com/advisories/GHSA-X223-P2GF-V735"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-55450"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak", "cve_id": "CVE-2026-55450", "vendor": "Langflow-ai", "ghsa_id": "GHSA-X223-P2GF-V735", "product": "langflow", "added_date": "2026-08-09T12:09:32.943Z", "cvss_score": 9.3, "epss_score": 0.0119, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.66837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-55450", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a650292f-b625-46ad-88dc-1a4ea19f8bb3", "vulnerability": {"vulnId": "CVE-2023-3722", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-09T02:00:00+02:00"}, "gcve": {"object_uuid": "a650292f-b625-46ad-88dc-1a4ea19f8bb3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-09T00:00:00+00:00"}, "scope": {"notes": "Avaya Aura Device Services Remote Code Execution | Affected: Avaya / Aura Device Services | CVSS: 8.6 (HIGH) | EPSS: 0.0386 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3722", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3722"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3722"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Avaya Aura Device Services Remote Code Execution", "cve_id": "CVE-2023-3722", "vendor": "Avaya", "ghsa_id": null, "product": "Aura Device Services", "added_date": "2026-08-09T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.0386, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8984, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3722", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "941ac593-58c6-4c8f-a97c-f6b902aa2516", "vulnerability": {"vulnId": "CVE-2013-3821", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-07T12:09:49+02:00"}, "gcve": {"object_uuid": "941ac593-58c6-4c8f-a97c-f6b902aa2516", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-07T10:09:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-07T10:09:49+00:00"}, "scope": {"notes": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote... | Affected: Oracle / PeopleSoft Products | CVSS: 6.4 (MEDIUM) | EPSS: 0.06897 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-3821", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3821"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3821"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote...", "cve_id": "CVE-2013-3821", "vendor": "Oracle", "ghsa_id": null, "product": "PeopleSoft Products", "added_date": "2026-08-07T10:09:49.510Z", "cvss_score": 6.4, "epss_score": 0.06897, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3821", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b582ee53-cf65-43b5-b53c-666dcbcac0b2", "vulnerability": {"vulnId": "CVE-2025-20282", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-07T11:10:58+02:00"}, "gcve": {"object_uuid": "b582ee53-cf65-43b5-b53c-666dcbcac0b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-07T09:10:58+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-07T09:10:58+00:00"}, "scope": {"notes": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability | Affected: Cisco / Cisco Identity Services Engine Software | CVSS: 10.0 (CRITICAL) | EPSS: 0.38719 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-20282", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20282"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20282"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability", "cve_id": "CVE-2025-20282", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Identity Services Engine Software", "added_date": "2026-08-07T09:10:58.086Z", "cvss_score": 10.0, "epss_score": 0.38719, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9854, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20282", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2d346a40-67da-4613-80ea-51b7229b2f13", "vulnerability": {"vulnId": "CVE-2026-2652", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-07T02:00:00+02:00"}, "gcve": {"object_uuid": "2d346a40-67da-4613-80ea-51b7229b2f13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-07T00:00:00+00:00"}, "scope": {"notes": "Authentication Bypass in mlflow/mlflow | Affected: Mlflow / mlflow/mlflow | CVSS: 8.6 (HIGH) | EPSS: 0.01409 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-2652", "url": "https://www.cve.org/CVERecord?id=CVE-2026-2652"}, {"id": "GHSA-75CM-X2W3-8MGF", "url": "https://github.com/advisories/GHSA-75CM-X2W3-8MGF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-2652"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass in mlflow/mlflow", "cve_id": "CVE-2026-2652", "vendor": "Mlflow", "ghsa_id": "GHSA-75CM-X2W3-8MGF", "product": "mlflow/mlflow", "added_date": "2026-08-07T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.01409, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7165, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-2652", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "18b677df-a3ab-4d1f-93ee-7fb18747b69a", "vulnerability": {"vulnId": "CVE-2018-14013", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-06T02:00:00+02:00"}, "gcve": {"object_uuid": "18b677df-a3ab-4d1f-93ee-7fb18747b69a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-06T00:00:00+00:00"}, "scope": {"notes": "Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients. | Affected: Synacor / Zimbra Collaboration Suite | CVSS: 6.1 (MEDIUM) | EPSS: 0.07436 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-14013", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14013"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14013"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.", "cve_id": "CVE-2018-14013", "vendor": "Synacor", "ghsa_id": null, "product": "Zimbra Collaboration Suite", "added_date": "2026-08-06T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.07436, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94266, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14013", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "14a85a79-2eb3-480d-95cc-b1351411c81a", "vulnerability": {"vulnId": "CVE-2026-63077", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-05T18:50:38+02:00"}, "gcve": {"object_uuid": "14a85a79-2eb3-480d-95cc-b1351411c81a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-05T16:50:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-05T16:50:38+00:00"}, "scope": {"notes": "In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | Affected: JetBrains / TeamCity | CVSS: 9.8 (CRITICAL) | EPSS: 0.8957 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-63077", "url": "https://www.cve.org/CVERecord?id=CVE-2026-63077"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-63077"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol", "cve_id": "CVE-2026-63077", "vendor": "JetBrains", "ghsa_id": null, "product": "TeamCity", "added_date": "2026-08-05T16:50:38.645Z", "cvss_score": 9.8, "epss_score": 0.8957, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99784, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-63077", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fd1dd494-3e0b-433d-bf78-e89e643352a8", "vulnerability": {"vulnId": "CVE-2025-8943", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-05T10:45:39+02:00"}, "gcve": {"object_uuid": "fd1dd494-3e0b-433d-bf78-e89e643352a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-05T08:45:39+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-05T08:45:39+00:00"}, "scope": {"notes": "Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers | Affected: Flowise / Flowise | CVSS: 9.8 (CRITICAL) | EPSS: 0.65771 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-8943", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8943"}, {"id": "GHSA-2VV2-3X8X-4GV7", "url": "https://github.com/advisories/GHSA-2VV2-3X8X-4GV7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8943"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers", "cve_id": "CVE-2025-8943", "vendor": "Flowise", "ghsa_id": "GHSA-2VV2-3X8X-4GV7", "product": "Flowise", "added_date": "2026-08-05T08:45:39.489Z", "cvss_score": 9.8, "epss_score": 0.65771, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99248, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8943", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ef1e6978-4129-4157-97c0-0bd090647864", "vulnerability": {"vulnId": "CVE-2026-9198", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-04T20:01:34+02:00"}, "gcve": {"object_uuid": "ef1e6978-4129-4157-97c0-0bd090647864", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-04T18:01:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-04T18:01:34+00:00"}, "scope": {"notes": "Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation | Affected: IBM / Langflow OSS | CVSS: 9.8 (CRITICAL) | EPSS: 0.28658 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-9198", "url": "https://www.cve.org/CVERecord?id=CVE-2026-9198"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-9198"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation", "cve_id": "CVE-2026-9198", "vendor": "IBM", "ghsa_id": null, "product": "Langflow OSS", "added_date": "2026-08-04T18:01:34.719Z", "cvss_score": 9.8, "epss_score": 0.28658, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98087, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-9198", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "86ad2889-2d6a-45a9-b2a0-1f3e526ce10c", "vulnerability": {"vulnId": "CVE-2026-34486", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-04T18:45:52+02:00"}, "gcve": {"object_uuid": "86ad2889-2d6a-45a9-b2a0-1f3e526ce10c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-04T16:45:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-04T16:45:52+00:00"}, "scope": {"notes": "Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor | Affected: Apache / Apache Tomcat | CVSS: 7.5 (HIGH) | EPSS: 0.06561 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34486", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34486"}, {"id": "GHSA-69R9-QGR7-G2WJ", "url": "https://github.com/advisories/GHSA-69R9-QGR7-G2WJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34486"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor", "cve_id": "CVE-2026-34486", "vendor": "Apache", "ghsa_id": "GHSA-69R9-QGR7-G2WJ", "product": "Apache Tomcat", "added_date": "2026-08-04T16:45:52.078Z", "cvss_score": 7.5, "epss_score": 0.06561, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9361, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34486", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d901830-6ef5-4b0e-884d-3a9e9df04996", "vulnerability": {"vulnId": "CVE-2026-54066", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-04T15:47:46+02:00"}, "gcve": {"object_uuid": "6d901830-6ef5-4b0e-884d-3a9e9df04996", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-04T13:47:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-04T13:47:46+00:00"}, "scope": {"notes": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file\u2500read) | Affected: Siyuan-note / siyuan | CVSS: 7.5 (HIGH) | EPSS: 0.02386 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-54066", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54066"}, {"id": "GHSA-P4M3-MGMM-C664", "url": "https://github.com/advisories/GHSA-P4M3-MGMM-C664"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-54066"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file\u2500read)", "cve_id": "CVE-2026-54066", "vendor": "Siyuan-note", "ghsa_id": "GHSA-P4M3-MGMM-C664", "product": "siyuan", "added_date": "2026-08-04T13:47:46.794Z", "cvss_score": 7.5, "epss_score": 0.02386, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8332, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-54066", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8267092f-8e72-4c05-9b7e-3a23d9223666", "vulnerability": {"vulnId": "CVE-2026-28496", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-04T15:25:09+02:00"}, "gcve": {"object_uuid": "8267092f-8e72-4c05-9b7e-3a23d9223666", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-04T13:25:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-04T13:25:09+00:00"}, "scope": {"notes": "FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE | Affected: FOSSBilling / FOSSBilling | CVSS: 9.4 (CRITICAL) | EPSS: 0.01905 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-28496", "url": "https://www.cve.org/CVERecord?id=CVE-2026-28496"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-28496"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE", "cve_id": "CVE-2026-28496", "vendor": "FOSSBilling", "ghsa_id": null, "product": "FOSSBilling", "added_date": "2026-08-04T13:25:09.278Z", "cvss_score": 9.4, "epss_score": 0.01905, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78983, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-28496", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "927b875d-4c96-42ca-b85f-eda71b44d8ee", "vulnerability": {"vulnId": "CVE-2026-48313", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-04T12:48:59+02:00"}, "gcve": {"object_uuid": "927b875d-4c96-42ca-b85f-eda71b44d8ee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-04T10:48:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-04T10:48:59+00:00"}, "scope": {"notes": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Affected: Adobe / ColdFusion 2025, ColdFusion 2023 | CVSS: 9.3 (CRITICAL) | EPSS: 0.02954 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-48313", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48313"}, {"id": "GHSA-68PC-WH27-VGM6", "url": "https://github.com/advisories/GHSA-68PC-WH27-VGM6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48313"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)", "cve_id": "CVE-2026-48313", "vendor": "Adobe", "ghsa_id": "GHSA-68PC-WH27-VGM6", "product": "ColdFusion 2025, ColdFusion 2023", "added_date": "2026-08-04T10:48:59.031Z", "cvss_score": 9.3, "epss_score": 0.02954, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86699, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48313", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7920ec56-8fa3-4674-a479-b6d403a19599", "vulnerability": {"vulnId": "CVE-2026-28409", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-04T02:00:00+02:00"}, "gcve": {"object_uuid": "7920ec56-8fa3-4674-a479-b6d403a19599", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-04T00:00:00+00:00"}, "scope": {"notes": "WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection | Affected: LabRedesCefetRJ / WeGIA | CVSS: 10.0 (CRITICAL) | EPSS: 0.03847 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-28409", "url": "https://www.cve.org/CVERecord?id=CVE-2026-28409"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-28409"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WeGIA Vulnerable to Remote Code Execution (RCE) via OS Command Injection", "cve_id": "CVE-2026-28409", "vendor": "LabRedesCefetRJ", "ghsa_id": null, "product": "WeGIA", "added_date": "2026-08-04T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.03847, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89807, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-28409", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b9cf4e47-a440-4232-8d54-6662e4bb1049", "vulnerability": {"vulnId": "CVE-2026-18577", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-03T19:00:56+02:00"}, "gcve": {"object_uuid": "b9cf4e47-a440-4232-8d54-6662e4bb1049", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-03T17:00:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-03T17:00:56+00:00"}, "scope": {"notes": "Incomplete patch leads to administrative account takeover | Affected: N-able / N-central | CVSS: 8.2 (HIGH) | EPSS: 0.14622 | Used in malware: unknown | Listed 2 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-18577", "url": "https://www.cve.org/CVERecord?id=CVE-2026-18577"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-18577"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incomplete patch leads to administrative account takeover", "cve_id": "CVE-2026-18577", "vendor": "N-able", "ghsa_id": null, "product": "N-central", "added_date": "2026-08-03T17:00:56.000Z", "cvss_score": 8.2, "epss_score": 0.14622, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96555, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-18577", "ahead_of_cisa_kev": {"unit": "hour", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "024c83fb-509e-4764-88d9-4ae7c0333439", "vulnerability": {"vulnId": "CVE-2023-2825", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-03T16:02:05+02:00"}, "gcve": {"object_uuid": "024c83fb-509e-4764-88d9-4ae7c0333439", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-03T14:02:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-03T14:02:05+00:00"}, "scope": {"notes": "An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal... | Affected: GitLab / GitLab | CVSS: 10.0 (CRITICAL) | EPSS: 0.71641 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-2825", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2825"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2825"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal...", "cve_id": "CVE-2023-2825", "vendor": "GitLab", "ghsa_id": null, "product": "GitLab", "added_date": "2026-08-03T14:02:05.708Z", "cvss_score": 10.0, "epss_score": 0.71641, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99404, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2825", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "89356268-3c60-4883-a451-c669d844b359", "vulnerability": {"vulnId": "CVE-2025-71324", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-03T15:51:18+02:00"}, "gcve": {"object_uuid": "89356268-3c60-4883-a451-c669d844b359", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-03T13:51:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-03T13:51:18+00:00"}, "scope": {"notes": "Flowise - Arbitrary File Read via chatId Parameter | Affected: Flowise / Flowise | CVSS: 8.7 (HIGH) | EPSS: 0.0157 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-71324", "url": "https://www.cve.org/CVERecord?id=CVE-2025-71324"}, {"id": "GHSA-4PWQ-XW7J-M297", "url": "https://github.com/advisories/GHSA-4PWQ-XW7J-M297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-71324"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise - Arbitrary File Read via chatId Parameter", "cve_id": "CVE-2025-71324", "vendor": "Flowise", "ghsa_id": "GHSA-4PWQ-XW7J-M297", "product": "Flowise", "added_date": "2026-08-03T13:51:18.656Z", "cvss_score": 8.7, "epss_score": 0.0157, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7446, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-71324", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "18a15b47-633b-4c32-a252-2a88b9eb844c", "vulnerability": {"vulnId": "CVE-2023-54359", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-03T15:35:26+02:00"}, "gcve": {"object_uuid": "18a15b47-633b-4c32-a252-2a88b9eb844c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-03T13:35:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-03T13:35:26+00:00"}, "scope": {"notes": "WordPress adivaha Travel Plugin 2.3 SQL Injection via pid | Affected: Adivaha / WordPress adivaha Travel Plugin | CVSS: 8.8 (HIGH) | EPSS: 0.00269 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-54359", "url": "https://www.cve.org/CVERecord?id=CVE-2023-54359"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-54359"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress adivaha Travel Plugin 2.3 SQL Injection via pid", "cve_id": "CVE-2023-54359", "vendor": "Adivaha", "ghsa_id": null, "product": "WordPress adivaha Travel Plugin", "added_date": "2026-08-03T13:35:26.053Z", "cvss_score": 8.8, "epss_score": 0.00269, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.17285, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-54359", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "78ba4957-4d1e-4d6e-93c7-b32cf04d1f35", "vulnerability": {"vulnId": "CVE-2026-38992", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-03T02:00:00+02:00"}, "gcve": {"object_uuid": "78ba4957-4d1e-4d6e-93c7-b32cf04d1f35", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-03T00:00:00+00:00"}, "scope": {"notes": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows... | Affected: Cockpit-HQ / Cockpit | CVSS: 9.8 (CRITICAL) | EPSS: 0.00726 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-38992", "url": "https://www.cve.org/CVERecord?id=CVE-2026-38992"}, {"id": "GHSA-FM6C-RHCF-7439", "url": "https://github.com/advisories/GHSA-FM6C-RHCF-7439"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-38992"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows...", "cve_id": "CVE-2026-38992", "vendor": "Cockpit-HQ", "ghsa_id": "GHSA-FM6C-RHCF-7439", "product": "Cockpit", "added_date": "2026-08-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.00726, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52389, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-38992", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5f30728c-1c03-423e-801e-ab7f4682ea5d", "vulnerability": {"vulnId": "CVE-2026-18556", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-01T15:51:00+02:00"}, "gcve": {"object_uuid": "5f30728c-1c03-423e-801e-ab7f4682ea5d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-01T13:51:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-01T13:51:00+00:00"}, "scope": {"notes": "Unauthenticated administrative account takeover | Affected: N-able / N-central | CVSS: 8.2 (HIGH) | EPSS: 0.07882 | Used in malware: unknown | Listed 3 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-18556", "url": "https://www.cve.org/CVERecord?id=CVE-2026-18556"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-18556"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated administrative account takeover", "cve_id": "CVE-2026-18556", "vendor": "N-able", "ghsa_id": null, "product": "N-central", "added_date": "2026-08-01T13:51:00.000Z", "cvss_score": 8.2, "epss_score": 0.07882, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94536, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-18556", "ahead_of_cisa_kev": {"unit": "day", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d907f01c-c20c-4bad-a276-3471ccfa0365", "vulnerability": {"vulnId": "CVE-2026-59800", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-01T13:09:12+02:00"}, "gcve": {"object_uuid": "d907f01c-c20c-4bad-a276-3471ccfa0365", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-01T11:09:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-01T11:09:12+00:00"}, "scope": {"notes": "9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint | Affected: Decolua / 9router | CVSS: 9.2 (CRITICAL) | EPSS: 0.02043 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-59800", "url": "https://www.cve.org/CVERecord?id=CVE-2026-59800"}, {"id": "GHSA-G6G7-PVMX-M74P", "url": "https://github.com/advisories/GHSA-G6G7-PVMX-M74P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-59800"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint", "cve_id": "CVE-2026-59800", "vendor": "Decolua", "ghsa_id": "GHSA-G6G7-PVMX-M74P", "product": "9router", "added_date": "2026-08-01T11:09:12.909Z", "cvss_score": 9.2, "epss_score": 0.02043, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80455, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-59800", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "408a822e-7989-4847-ba34-8170a8771162", "vulnerability": {"vulnId": "CVE-2024-37014", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-08-01T12:55:44+02:00"}, "gcve": {"object_uuid": "408a822e-7989-4847-ba34-8170a8771162", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-08-01T10:55:44+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-08-01T10:55:44+00:00"}, "scope": {"notes": "Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the \"POST /api/v1/custom_component\" endpoint and provide... | Affected: Langflow-ai / Langflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.63674 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-37014", "url": "https://www.cve.org/CVERecord?id=CVE-2024-37014"}, {"id": "GHSA-QG33-X2C5-6P44", "url": "https://github.com/advisories/GHSA-QG33-X2C5-6P44"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-37014"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the \"POST /api/v1/custom_component\" endpoint and provide...", "cve_id": "CVE-2024-37014", "vendor": "Langflow-ai", "ghsa_id": "GHSA-QG33-X2C5-6P44", "product": "Langflow", "added_date": "2026-08-01T10:55:44.980Z", "cvss_score": 9.8, "epss_score": 0.63674, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99195, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-37014", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "03a70206-695e-4b9f-ad55-7659bae97628", "vulnerability": {"vulnId": "CVE-2021-1472", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-30T17:50:01+02:00"}, "gcve": {"object_uuid": "03a70206-695e-4b9f-ad55-7659bae97628", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-30T15:50:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-30T15:50:01+00:00"}, "scope": {"notes": "Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 5.3 (MEDIUM) | EPSS: 0.72028 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-1472", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1472"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1472"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV Series Routers Vulnerabilities", "cve_id": "CVE-2021-1472", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2026-07-30T15:50:01.902Z", "cvss_score": 5.3, "epss_score": 0.72028, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1472", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2ed3bab9-4a67-400e-b0b2-5f7bdd15dd9f", "vulnerability": {"vulnId": "CVE-2019-8942", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-30T12:42:00+02:00"}, "gcve": {"object_uuid": "2ed3bab9-4a67-400e-b0b2-5f7bdd15dd9f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-30T10:42:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-30T10:42:00+00:00"}, "scope": {"notes": "WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an... | Affected: WordPress / WordPress | CVSS: 8.8 (HIGH) | EPSS: 0.82736 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-8942", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8942"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8942"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an...", "cve_id": "CVE-2019-8942", "vendor": "WordPress", "ghsa_id": null, "product": "WordPress", "added_date": "2026-07-30T10:42:00.000Z", "cvss_score": 8.8, "epss_score": 0.82736, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99661, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8942", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2e6f3256-2bf8-4aa0-9d5c-7198a4ddbace", "vulnerability": {"vulnId": "CVE-2026-1623", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-30T07:53:55+02:00"}, "gcve": {"object_uuid": "2e6f3256-2bf8-4aa0-9d5c-7198a4ddbace", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-30T05:53:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-30T05:53:55+00:00"}, "scope": {"notes": "Totolink A7000R cstecgi.cgi setUpgradeFW command injection | Affected: Totolink / A7000R | CVSS: 5.3 (MEDIUM) | EPSS: 0.02424 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-1623", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1623"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1623"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Totolink A7000R cstecgi.cgi setUpgradeFW command injection", "cve_id": "CVE-2026-1623", "vendor": "Totolink", "ghsa_id": null, "product": "A7000R", "added_date": "2026-07-30T05:53:55.753Z", "cvss_score": 5.3, "epss_score": 0.02424, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83603, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1623", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b20ab2c7-cbb2-4a04-bdea-3dd722408b3e", "vulnerability": {"vulnId": "CVE-2026-20316", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-29T20:45:59+02:00"}, "gcve": {"object_uuid": "b20ab2c7-cbb2-4a04-bdea-3dd722408b3e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-29T18:45:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-29T18:45:59+00:00"}, "scope": {"notes": "Cisco Secure Firewall Management Center Software Static Credential Vulnerability | Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | CVSS: 5.3 (MEDIUM) | EPSS: 0.35096 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20316", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20316"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20316"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Secure Firewall Management Center Software Static Credential Vulnerability", "cve_id": "CVE-2026-20316", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Secure Firewall Management Center (FMC)", "added_date": "2026-07-29T18:45:59.580Z", "cvss_score": 5.3, "epss_score": 0.35096, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98395, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20316", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "74e64f00-b6f5-4eb7-8e23-7c1c4c92a739", "vulnerability": {"vulnId": "CVE-2025-71334", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-28T14:54:07+02:00"}, "gcve": {"object_uuid": "74e64f00-b6f5-4eb7-8e23-7c1c4c92a739", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-28T12:54:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-28T12:54:07+00:00"}, "scope": {"notes": "Flowise - Arbitrary File Access via Missing Chat Flow ID Validation | Affected: Flowise / Flowise | CVSS: 9.3 (CRITICAL) | EPSS: 0.0436 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-71334", "url": "https://www.cve.org/CVERecord?id=CVE-2025-71334"}, {"id": "GHSA-W5R9-J49J-2M55", "url": "https://github.com/advisories/GHSA-W5R9-J49J-2M55"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-71334"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise - Arbitrary File Access via Missing Chat Flow ID Validation", "cve_id": "CVE-2025-71334", "vendor": "Flowise", "ghsa_id": "GHSA-W5R9-J49J-2M55", "product": "Flowise", "added_date": "2026-07-28T12:54:07.303Z", "cvss_score": 9.3, "epss_score": 0.0436, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90941, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-71334", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d18f87b9-c6e9-4775-ad62-4ed1a38c5375", "vulnerability": {"vulnId": "CVE-2025-68686", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-27T19:00:05+02:00"}, "gcve": {"object_uuid": "d18f87b9-c6e9-4775-ad62-4ed1a38c5375", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-27T17:00:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-27T17:00:05+00:00"}, "scope": {"notes": "An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,... | Affected: Fortinet / FortiOS | CVSS: 5.3 (MEDIUM) | EPSS: 0.29601 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-68686", "url": "https://www.cve.org/CVERecord?id=CVE-2025-68686"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-68686"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...", "cve_id": "CVE-2025-68686", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiOS", "added_date": "2026-07-27T17:00:05.726Z", "cvss_score": 5.3, "epss_score": 0.29601, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9814, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-68686", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8734ac3e-3423-411c-a5de-8638bc69693c", "vulnerability": {"vulnId": "CVE-2026-16812", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-27T18:20:55+02:00"}, "gcve": {"object_uuid": "8734ac3e-3423-411c-a5de-8638bc69693c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-27T16:20:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-27T16:20:55+00:00"}, "scope": {"notes": "VeloCloud Orchestrator OS Command Injection | Affected: Arista / VeloCloud Orchestrator On-Prem | CVSS: 10.0 (CRITICAL) | EPSS: 0.01001 | Used in malware: unknown | Listed 3 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-16812", "url": "https://www.cve.org/CVERecord?id=CVE-2026-16812"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-16812"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VeloCloud Orchestrator OS Command Injection", "cve_id": "CVE-2026-16812", "vendor": "Arista", "ghsa_id": null, "product": "VeloCloud Orchestrator On-Prem", "added_date": "2026-07-27T16:20:55.359Z", "cvss_score": 10.0, "epss_score": 0.01001, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61482, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-16812", "ahead_of_cisa_kev": {"unit": "hour", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f66005ee-e290-4cb7-b716-8a2d80f9971c", "vulnerability": {"vulnId": "CVE-2026-58138", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-27T12:20:05+02:00"}, "gcve": {"object_uuid": "f66005ee-e290-4cb7-b716-8a2d80f9971c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-27T10:20:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-27T10:20:05+00:00"}, "scope": {"notes": "Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators | Affected: Conductor-oss / conductor | CVSS: 9.3 (CRITICAL) | EPSS: 0.14687 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-58138", "url": "https://www.cve.org/CVERecord?id=CVE-2026-58138"}, {"id": "GHSA-7X5Q-8F6H-RJRC", "url": "https://github.com/advisories/GHSA-7X5Q-8F6H-RJRC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-58138"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators", "cve_id": "CVE-2026-58138", "vendor": "Conductor-oss", "ghsa_id": "GHSA-7X5Q-8F6H-RJRC", "product": "conductor", "added_date": "2026-07-27T10:20:05.791Z", "cvss_score": 9.3, "epss_score": 0.14687, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96568, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-58138", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d7015b39-eff8-4805-a9d4-4ba82a32dcd1", "vulnerability": {"vulnId": "CVE-2014-2383", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-25T13:07:06+02:00"}, "gcve": {"object_uuid": "d7015b39-eff8-4805-a9d4-4ba82a32dcd1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-25T11:07:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-25T11:07:06+00:00"}, "scope": {"notes": "dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read... | Affected: Dompdf / dompdf | CVSS: 6.8 (MEDIUM) | EPSS: 0.39231 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-2383", "url": "https://www.cve.org/CVERecord?id=CVE-2014-2383"}, {"id": "GHSA-QR6Q-W4GJ-3865", "url": "https://github.com/advisories/GHSA-QR6Q-W4GJ-3865"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-2383"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read...", "cve_id": "CVE-2014-2383", "vendor": "Dompdf", "ghsa_id": "GHSA-QR6Q-W4GJ-3865", "product": "dompdf", "added_date": "2026-07-25T11:07:06.460Z", "cvss_score": 6.8, "epss_score": 0.39231, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98559, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-2383", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4be78914-80bc-4a38-a24d-acd5b63c136f", "vulnerability": {"vulnId": "CVE-2026-16723", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-25T04:23:23+02:00"}, "gcve": {"object_uuid": "4be78914-80bc-4a38-a24d-acd5b63c136f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-25T02:23:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-25T02:23:23+00:00"}, "scope": {"notes": "Remote Code Execution in fastjson 1.2.68\u20131.2.83 | Affected: Alibaba / Fastjson | CVSS: 9.0 (CRITICAL) | EPSS: 0.00663 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-16723", "url": "https://www.cve.org/CVERecord?id=CVE-2026-16723"}, {"id": "GHSA-CRF3-V9RR-V7HJ", "url": "https://github.com/advisories/GHSA-CRF3-V9RR-V7HJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-16723"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution in fastjson 1.2.68\u20131.2.83", "cve_id": "CVE-2026-16723", "vendor": "Alibaba", "ghsa_id": "GHSA-CRF3-V9RR-V7HJ", "product": "Fastjson", "added_date": "2026-07-25T02:23:23.000Z", "cvss_score": 9.0, "epss_score": 0.00663, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.49861, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-16723", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4a6b736f-f984-4008-987d-03c73adb680a", "vulnerability": {"vulnId": "CVE-2025-4283", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-24T10:52:14+02:00"}, "gcve": {"object_uuid": "4a6b736f-f984-4008-987d-03c73adb680a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-24T08:52:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-24T08:52:14+00:00"}, "scope": {"notes": "SourceCodester/oretnom23 Stock Management System Login.php sql injection | Affected: SourceCodester, oretnom23 / Stock Management System | CVSS: 6.9 (MEDIUM) | EPSS: 0.00602 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4283", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4283"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4283"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SourceCodester/oretnom23 Stock Management System Login.php sql injection", "cve_id": "CVE-2025-4283", "vendor": "SourceCodester, oretnom23", "ghsa_id": null, "product": "Stock Management System", "added_date": "2026-07-24T08:52:14.602Z", "cvss_score": 6.9, "epss_score": 0.00602, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.46859, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4283", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "839a7531-0756-4e0c-92ff-6966f9207f54", "vulnerability": {"vulnId": "CVE-2016-3081", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-23T11:37:25+02:00"}, "gcve": {"object_uuid": "839a7531-0756-4e0c-92ff-6966f9207f54", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-23T09:37:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-23T09:37:25+00:00"}, "scope": {"notes": "Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to... | Affected: Apache / Struts | CVSS: 8.1 (HIGH) | EPSS: 0.93352 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-3081", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3081"}, {"id": "GHSA-8C6J-FFMF-Q6VM", "url": "https://github.com/advisories/GHSA-8C6J-FFMF-Q6VM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3081"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to...", "cve_id": "CVE-2016-3081", "vendor": "Apache", "ghsa_id": "GHSA-8C6J-FFMF-Q6VM", "product": "Struts", "added_date": "2026-07-23T09:37:25.728Z", "cvss_score": 8.1, "epss_score": 0.93352, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3081", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d3b5d8e6-dcb5-4034-866b-91e836f5126c", "vulnerability": {"vulnId": "CVE-2026-29059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-22T17:04:07+02:00"}, "gcve": {"object_uuid": "d3b5d8e6-dcb5-4034-866b-91e836f5126c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-22T15:04:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-22T15:04:07+00:00"}, "scope": {"notes": "Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly | Affected: Windmill-labs / windmill | CVSS: 6.9 (MEDIUM) | EPSS: 0.02122 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-29059", "url": "https://www.cve.org/CVERecord?id=CVE-2026-29059"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-29059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly", "cve_id": "CVE-2026-29059", "vendor": "Windmill-labs", "ghsa_id": null, "product": "windmill", "added_date": "2026-07-22T15:04:07.406Z", "cvss_score": 6.9, "epss_score": 0.02122, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81209, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-29059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a7a427ef-4a62-46af-b0c1-3ea33859e314", "vulnerability": {"vulnId": "CVE-2026-16232", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-22T14:00:00+02:00"}, "gcve": {"object_uuid": "a7a427ef-4a62-46af-b0c1-3ea33859e314", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-22T12:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-22T12:00:00+00:00"}, "scope": {"notes": "Authentication Bypass in the SmartConsole Login Process Using an Application Token | Affected: Check Point / Quantum Security Management, Multi-Domain Security Management | CVSS: 9.3 (CRITICAL) | EPSS: 0.77972 | Used in malware: unknown | Listed 7 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-16232", "url": "https://www.cve.org/CVERecord?id=CVE-2026-16232"}, {"id": "GHSA-M2XX-23GX-734V", "url": "https://github.com/advisories/GHSA-M2XX-23GX-734V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-16232"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass in the SmartConsole Login Process Using an Application Token", "cve_id": "CVE-2026-16232", "vendor": "Check Point", "ghsa_id": "GHSA-M2XX-23GX-734V", "product": "Quantum Security Management, Multi-Domain Security Management", "added_date": "2026-07-22T12:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.77972, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99562, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-16232", "ahead_of_cisa_kev": {"unit": "hour", "count": 7}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "40124dac-f3bd-46c0-bfca-7d4aa9f0fc66", "vulnerability": {"vulnId": "CVE-2026-36356", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-22T02:00:00+02:00"}, "gcve": {"object_uuid": "40124dac-f3bd-46c0-bfca-7d4aa9f0fc66", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-22T00:00:00+00:00"}, "scope": {"notes": "The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection... | Affected: MeiG / Smart FORGE_SLT711 | CVSS: 9.1 (CRITICAL) | EPSS: 0.03563 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-36356", "url": "https://www.cve.org/CVERecord?id=CVE-2026-36356"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-36356"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection...", "cve_id": "CVE-2026-36356", "vendor": "MeiG", "ghsa_id": null, "product": "Smart FORGE_SLT711", "added_date": "2026-07-22T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.03563, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-36356", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "953f8ec2-8fcd-4557-a26e-84f06fac2816", "vulnerability": {"vulnId": "CVE-2026-0770", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-21T17:41:59+02:00"}, "gcve": {"object_uuid": "953f8ec2-8fcd-4557-a26e-84f06fac2816", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-21T15:41:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-21T15:41:59+00:00"}, "scope": {"notes": "Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability | Affected: Langflow / Langflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.63839 | Used in malware: unknown | Listed 3 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-0770", "url": "https://www.cve.org/CVERecord?id=CVE-2026-0770"}, {"id": "GHSA-G22F-V6F7-2HRH", "url": "https://github.com/advisories/GHSA-G22F-V6F7-2HRH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-0770"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability", "cve_id": "CVE-2026-0770", "vendor": "Langflow", "ghsa_id": "GHSA-G22F-V6F7-2HRH", "product": "Langflow", "added_date": "2026-07-21T15:41:59.927Z", "cvss_score": 9.8, "epss_score": 0.63839, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-0770", "ahead_of_cisa_kev": {"unit": "hour", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "969719ef-0ea0-4e9b-b485-971d9c9ceec8", "vulnerability": {"vulnId": "CVE-2021-27137", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-21T14:00:00+02:00"}, "gcve": {"object_uuid": "969719ef-0ea0-4e9b-b485-971d9c9ceec8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-21T12:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-21T12:00:00+00:00"}, "scope": {"notes": "An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an... | Affected: DD-WRT / DD-WRT | CVSS: 8.1 (HIGH) | EPSS: 0.03995 | Used in malware: unknown | Listed 3 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27137", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27137"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27137"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an...", "cve_id": "CVE-2021-27137", "vendor": "DD-WRT", "ghsa_id": null, "product": "DD-WRT", "added_date": "2026-07-21T12:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.03995, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27137", "ahead_of_cisa_kev": {"unit": "hour", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e9fc3fcf-2a93-4797-8a1d-f6a5b47aa7b2", "vulnerability": {"vulnId": "CVE-2026-48611", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-20T09:57:22+02:00"}, "gcve": {"object_uuid": "e9fc3fcf-2a93-4797-8a1d-f6a5b47aa7b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-20T07:57:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-20T07:57:22+00:00"}, "scope": {"notes": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to... | Affected: phpBB / phpBB | CVSS: 9.8 (CRITICAL) | EPSS: 0.02888 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-48611", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48611"}, {"id": "GHSA-24PR-8GGP-H88C", "url": "https://github.com/advisories/GHSA-24PR-8GGP-H88C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48611"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to...", "cve_id": "CVE-2026-48611", "vendor": "phpBB", "ghsa_id": "GHSA-24PR-8GGP-H88C", "product": "phpBB", "added_date": "2026-07-20T07:57:22.068Z", "cvss_score": 9.8, "epss_score": 0.02888, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86392, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48611", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2f5b4110-43bb-4841-8aaa-208937b5d9f1", "vulnerability": {"vulnId": "CVE-2025-68493", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-20T02:00:00+02:00"}, "gcve": {"object_uuid": "2f5b4110-43bb-4841-8aaa-208937b5d9f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-20T00:00:00+00:00"}, "scope": {"notes": "Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component | Affected: Apache / Apache Struts | CVSS: 8.1 (HIGH) | EPSS: 0.45847 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-68493", "url": "https://www.cve.org/CVERecord?id=CVE-2025-68493"}, {"id": "GHSA-QCFC-HMRC-59X7", "url": "https://github.com/advisories/GHSA-QCFC-HMRC-59X7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-68493"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component", "cve_id": "CVE-2025-68493", "vendor": "Apache", "ghsa_id": "GHSA-QCFC-HMRC-59X7", "product": "Apache Struts", "added_date": "2026-07-20T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.45847, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98767, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-68493", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "168447b3-7aae-4424-8f95-2eeb99954be8", "vulnerability": {"vulnId": "CVE-2026-22679", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-19T02:00:00+02:00"}, "gcve": {"object_uuid": "168447b3-7aae-4424-8f95-2eeb99954be8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-19T00:00:00+00:00"}, "scope": {"notes": "Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint | Affected: Weaver Network / E-cology | CVSS: 9.3 (CRITICAL) | EPSS: 0.20359 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-22679", "url": "https://www.cve.org/CVERecord?id=CVE-2026-22679"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-22679"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint", "cve_id": "CVE-2026-22679", "vendor": "Weaver Network", "ghsa_id": null, "product": "E-cology", "added_date": "2026-07-19T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.20359, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-22679", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7399d7eb-d286-4d60-82a5-e433c3ab8ea7", "vulnerability": {"vulnId": "CVE-2026-6875", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-18T12:55:00+02:00"}, "gcve": {"object_uuid": "7399d7eb-d286-4d60-82a5-e433c3ab8ea7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-18T10:55:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-18T10:55:00+00:00"}, "scope": {"notes": "Sandbox Escape in ServiceNow AI Platform | Affected: ServiceNow / ServiceNow AI Platform | CVSS: 9.5 (CRITICAL) | EPSS: 0.01426 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-6875", "url": "https://www.cve.org/CVERecord?id=CVE-2026-6875"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-6875"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sandbox Escape in ServiceNow AI Platform", "cve_id": "CVE-2026-6875", "vendor": "ServiceNow", "ghsa_id": null, "product": "ServiceNow AI Platform", "added_date": "2026-07-18T10:55:00.000Z", "cvss_score": 9.5, "epss_score": 0.01426, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71976, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-6875", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "16db6f69-6a79-4fa7-9857-75db9bbd6db2", "vulnerability": {"vulnId": "CVE-2026-60137", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-18T00:23:03+02:00"}, "gcve": {"object_uuid": "16db6f69-6a79-4fa7-9857-75db9bbd6db2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-17T22:23:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-17T22:23:03+00:00"}, "scope": {"notes": "WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query | Affected: WordPress / WordPress | CVSS: 5.9 (MEDIUM) | EPSS: 0.05906 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-60137", "url": "https://www.cve.org/CVERecord?id=CVE-2026-60137"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-60137"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query", "cve_id": "CVE-2026-60137", "vendor": "WordPress", "ghsa_id": null, "product": "WordPress", "added_date": "2026-07-17T22:23:03.000Z", "cvss_score": 5.9, "epss_score": 0.05906, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93004, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-60137", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2fafc2ba-5c31-4252-a83f-eaf96c046d1d", "vulnerability": {"vulnId": "CVE-2026-63030", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-18T00:23:03+02:00"}, "gcve": {"object_uuid": "2fafc2ba-5c31-4252-a83f-eaf96c046d1d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-17T22:23:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-17T22:23:03+00:00"}, "scope": {"notes": "WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution | Affected: WordPress / WordPress | CVSS: 9.8 (CRITICAL) | EPSS: 0.10119 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-63030", "url": "https://www.cve.org/CVERecord?id=CVE-2026-63030"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-63030"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution", "cve_id": "CVE-2026-63030", "vendor": "WordPress", "ghsa_id": null, "product": "WordPress", "added_date": "2026-07-17T22:23:03.000Z", "cvss_score": 9.8, "epss_score": 0.10119, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.95512, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-63030", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "82ad0474-ecd8-422b-95bc-db7da9d9d322", "vulnerability": {"vulnId": "CVE-2026-50522", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-17T20:18:53+02:00"}, "gcve": {"object_uuid": "82ad0474-ecd8-422b-95bc-db7da9d9d322", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-17T18:18:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-17T18:18:53+00:00"}, "scope": {"notes": "Microsoft SharePoint Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 9.8 (CRITICAL) | EPSS: 0.03042 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-50522", "url": "https://www.cve.org/CVERecord?id=CVE-2026-50522"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-50522"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Remote Code Execution Vulnerability", "cve_id": "CVE-2026-50522", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-07-17T18:18:53.000Z", "cvss_score": 9.8, "epss_score": 0.03042, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87061, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-50522", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b2ec1cda-db7e-4d12-be90-a13eb449a11e", "vulnerability": {"vulnId": "CVE-2024-36420", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-17T10:33:53+02:00"}, "gcve": {"object_uuid": "b2ec1cda-db7e-4d12-be90-a13eb449a11e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-17T08:33:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-17T08:33:53+00:00"}, "scope": {"notes": "GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file | Affected: FlowiseAI / Flowise | CVSS: 7.5 (HIGH) | EPSS: 0.01776 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-36420", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36420"}, {"id": "GHSA-H997-3FXJ-P5J8", "url": "https://github.com/advisories/GHSA-H997-3FXJ-P5J8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36420"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file", "cve_id": "CVE-2024-36420", "vendor": "FlowiseAI", "ghsa_id": "GHSA-H997-3FXJ-P5J8", "product": "Flowise", "added_date": "2026-07-17T08:33:53.505Z", "cvss_score": 7.5, "epss_score": 0.01776, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.774, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36420", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b43b4996-a731-4829-b25d-d3e0ad78dbdf", "vulnerability": {"vulnId": "CVE-2026-46442", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-17T09:51:05+02:00"}, "gcve": {"object_uuid": "b43b4996-a731-4829-b25d-d3e0ad78dbdf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-17T07:51:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-17T07:51:05+00:00"}, "scope": {"notes": "Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape | Affected: FlowiseAI / Flowise | CVSS: 9.4 (CRITICAL) | EPSS: 0.03414 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-46442", "url": "https://www.cve.org/CVERecord?id=CVE-2026-46442"}, {"id": "GHSA-9RVC-VF7M-PGM2", "url": "https://github.com/advisories/GHSA-9RVC-VF7M-PGM2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-46442"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape", "cve_id": "CVE-2026-46442", "vendor": "FlowiseAI", "ghsa_id": "GHSA-9RVC-VF7M-PGM2", "product": "Flowise", "added_date": "2026-07-17T07:51:05.707Z", "cvss_score": 9.4, "epss_score": 0.03414, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88491, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-46442", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "72dbd234-ad52-4c8b-ab7f-c7eff2780c82", "vulnerability": {"vulnId": "CVE-2026-25089", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-16T14:00:00+02:00"}, "gcve": {"object_uuid": "72dbd234-ad52-4c8b-ab7f-c7eff2780c82", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-16T12:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-16T12:00:00+00:00"}, "scope": {"notes": "A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through... | Affected: Fortinet / FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS | CVSS: 9.1 (CRITICAL) | EPSS: 0.76112 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-25089", "url": "https://www.cve.org/CVERecord?id=CVE-2026-25089"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-25089"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through...", "cve_id": "CVE-2026-25089", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS", "added_date": "2026-07-16T12:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.76112, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99519, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-25089", "ahead_of_cisa_kev": {"unit": "hour", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c3637e7d-5b08-468b-9b0f-5b29644bd3e1", "vulnerability": {"vulnId": "CVE-2023-4346", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-15T14:00:00+02:00"}, "gcve": {"object_uuid": "c3637e7d-5b08-468b-9b0f-5b29644bd3e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-15T12:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-15T12:00:00+00:00"}, "scope": {"notes": "\nKNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users... | Affected: KNX Association / KNX Protocol Connection Authorization Option 1 | CVSS: 7.5 (HIGH) | EPSS: 0.01294 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-4346", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4346"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4346"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "\nKNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users...", "cve_id": "CVE-2023-4346", "vendor": "KNX Association", "ghsa_id": null, "product": "KNX Protocol Connection Authorization Option 1", "added_date": "2026-07-15T12:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01294, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69268, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4346", "ahead_of_cisa_kev": {"unit": "hour", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f1fcf5d7-2f32-45f4-8efb-d14bf108b731", "vulnerability": {"vulnId": "CVE-2024-29972", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-15T09:39:00+02:00"}, "gcve": {"object_uuid": "f1fcf5d7-2f32-45f4-8efb-d14bf108b731", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-15T07:39:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-15T07:39:00+00:00"}, "scope": {"notes": "** UNSUPPORTED WHEN ASSIGNED **\nThe command injection vulnerability in the CGI program \"remote_help-cgi\" in Zyxel NAS326 firmware versions before... | Affected: Zyxel / NAS326 firmware, NAS542 firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.89326 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-29972", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29972"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29972"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "** UNSUPPORTED WHEN ASSIGNED **\nThe command injection vulnerability in the CGI program \"remote_help-cgi\" in Zyxel NAS326 firmware versions before...", "cve_id": "CVE-2024-29972", "vendor": "Zyxel", "ghsa_id": null, "product": "NAS326 firmware, NAS542 firmware", "added_date": "2026-07-15T07:39:00.456Z", "cvss_score": 9.8, "epss_score": 0.89326, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9978, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29972", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "76f4d560-4dfc-4af6-9142-4f2f2d7a799b", "vulnerability": {"vulnId": "CVE-2026-15410", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-14T21:00:56+02:00"}, "gcve": {"object_uuid": "76f4d560-4dfc-4af6-9142-4f2f2d7a799b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-14T19:00:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-14T19:00:56+00:00"}, "scope": {"notes": "Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management... | Affected: SonicWall / SMA1000 | CVSS: 7.2 (HIGH) | EPSS: 0.11791 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-15410", "url": "https://www.cve.org/CVERecord?id=CVE-2026-15410"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-15410"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management...", "cve_id": "CVE-2026-15410", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA1000", "added_date": "2026-07-14T19:00:56.138Z", "cvss_score": 7.2, "epss_score": 0.11791, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-15410", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6225d6c8-8865-41cf-870a-a5df663890c4", "vulnerability": {"vulnId": "CVE-2026-15409", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-14T20:18:00+02:00"}, "gcve": {"object_uuid": "6225d6c8-8865-41cf-870a-a5df663890c4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-14T18:18:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-14T18:18:00+00:00"}, "scope": {"notes": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated... | Affected: SonicWall / SMA1000 | CVSS: 10.0 (CRITICAL) | EPSS: 0.06795 | Used in malware: unknown | Listed 1 hour ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-15409", "url": "https://www.cve.org/CVERecord?id=CVE-2026-15409"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-15409"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated...", "cve_id": "CVE-2026-15409", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA1000", "added_date": "2026-07-14T18:18:00.000Z", "cvss_score": 10.0, "epss_score": 0.06795, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.938, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-15409", "ahead_of_cisa_kev": {"unit": "hour", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76005571-bf9a-43ea-b96b-eaf7eb41ad3f", "vulnerability": {"vulnId": "CVE-2026-58644", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-14T09:00:00+02:00"}, "gcve": {"object_uuid": "76005571-bf9a-43ea-b96b-eaf7eb41ad3f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-14T07:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-14T07:00:00+00:00"}, "scope": {"notes": "Microsoft SharePoint Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 9.8 (CRITICAL) | EPSS: 0.15873 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-58644", "url": "https://www.cve.org/CVERecord?id=CVE-2026-58644"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-58644"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Remote Code Execution Vulnerability", "cve_id": "CVE-2026-58644", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-07-14T07:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.15873, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96787, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-58644", "ahead_of_cisa_kev": {"unit": "day", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76efe6ca-f928-4f8a-866e-a1023b84b121", "vulnerability": {"vulnId": "CVE-2026-56164", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-14T09:00:00+02:00"}, "gcve": {"object_uuid": "76efe6ca-f928-4f8a-866e-a1023b84b121", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-14T07:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-14T07:00:00+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 5.3 (MEDIUM) | EPSS: 0.01011 | Used in malware: unknown | Listed 11 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-56164", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56164"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-56164"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-56164", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-07-14T07:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.01011, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61842, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-56164", "ahead_of_cisa_kev": {"unit": "hour", "count": 11}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "752a8754-29ff-437b-b309-c8c6d3d18bef", "vulnerability": {"vulnId": "CVE-2026-56155", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-14T09:00:00+02:00"}, "gcve": {"object_uuid": "752a8754-29ff-437b-b309-c8c6d3d18bef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-14T07:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-14T07:00:00+00:00"}, "scope": {"notes": "Active Directory Federation Services Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.00346 | Used in malware: unknown | Listed 11 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-56155", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56155"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-56155"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Active Directory Federation Services Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-56155", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-07-14T07:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00346, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.25767, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-56155", "ahead_of_cisa_kev": {"unit": "hour", "count": 11}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "853c2d02-c110-407a-bc7b-a0842398d5b1", "vulnerability": {"vulnId": "CVE-2008-4128", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-13T19:00:17+02:00"}, "gcve": {"object_uuid": "853c2d02-c110-407a-bc7b-a0842398d5b1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-13T17:00:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-13T17:00:17+00:00"}, "scope": {"notes": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services... | Affected: Cisco / IOS | CVSS: 8.1 (HIGH) | EPSS: 0.33871 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2008-4128", "url": "https://www.cve.org/CVERecord?id=CVE-2008-4128"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-4128"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services...", "cve_id": "CVE-2008-4128", "vendor": "Cisco", "ghsa_id": null, "product": "IOS", "added_date": "2026-07-13T17:00:17.965Z", "cvss_score": 8.1, "epss_score": 0.33871, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98349, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-4128", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c62ee3f8-116b-4526-819b-82a26a3813e7", "vulnerability": {"vulnId": "CVE-2026-56291", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-10T19:00:25+02:00"}, "gcve": {"object_uuid": "c62ee3f8-116b-4526-819b-82a26a3813e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-10T17:00:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-10T17:00:25+00:00"}, "scope": {"notes": "Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 | Affected: Balbooa.com / balbooa.com Balbooa Forms extension for Joomla | CVSS: 10.0 (CRITICAL) | EPSS: 0.14854 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-56291", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56291"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-56291"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1", "cve_id": "CVE-2026-56291", "vendor": "Balbooa.com", "ghsa_id": null, "product": "balbooa.com Balbooa Forms extension for Joomla", "added_date": "2026-07-10T17:00:25.732Z", "cvss_score": 10.0, "epss_score": 0.14854, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96597, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-56291", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5d6a54fd-bf06-4625-a949-88b69928c88b", "vulnerability": {"vulnId": "CVE-2026-48939", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-10T19:00:25+02:00"}, "gcve": {"object_uuid": "5d6a54fd-bf06-4625-a949-88b69928c88b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-10T17:00:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-10T17:00:25+00:00"}, "scope": {"notes": "Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 | Affected: Icagenda.com / iCagenda extension for Joomla | CVSS: 10.0 (CRITICAL) | EPSS: 0.20069 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48939", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48939"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48939"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15", "cve_id": "CVE-2026-48939", "vendor": "Icagenda.com", "ghsa_id": null, "product": "iCagenda extension for Joomla", "added_date": "2026-07-10T17:00:25.732Z", "cvss_score": 10.0, "epss_score": 0.20069, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97377, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48939", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4809ef50-922f-4fb7-a024-577aeaafa0a0", "vulnerability": {"vulnId": "CVE-2026-2699", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-10T02:00:00+02:00"}, "gcve": {"object_uuid": "4809ef50-922f-4fb7-a024-577aeaafa0a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-10T00:00:00+00:00"}, "scope": {"notes": "EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC) | Affected: Progress Software / ShareFile Storage Zones Controller | CVSS: 9.8 (CRITICAL) | EPSS: 0.03181 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-2699", "url": "https://www.cve.org/CVERecord?id=CVE-2026-2699"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-2699"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)", "cve_id": "CVE-2026-2699", "vendor": "Progress Software", "ghsa_id": null, "product": "ShareFile Storage Zones Controller", "added_date": "2026-07-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03181, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.87616, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-2699", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ec3bf7ec-7cdb-4f90-b804-38b285cf440d", "vulnerability": {"vulnId": "CVE-2026-1207", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-09T18:15:55+02:00"}, "gcve": {"object_uuid": "ec3bf7ec-7cdb-4f90-b804-38b285cf440d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-09T16:15:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-09T16:15:55+00:00"}, "scope": {"notes": "Potential SQL injection via raster lookups on PostGIS | Affected: Djangoproject / Django | CVSS: 5.4 (MEDIUM) | EPSS: 0.13251 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-1207", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1207"}, {"id": "GHSA-MWM9-4648-F68Q", "url": "https://github.com/advisories/GHSA-MWM9-4648-F68Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1207"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Potential SQL injection via raster lookups on PostGIS", "cve_id": "CVE-2026-1207", "vendor": "Djangoproject", "ghsa_id": "GHSA-MWM9-4648-F68Q", "product": "Django", "added_date": "2026-07-09T16:15:55.777Z", "cvss_score": 5.4, "epss_score": 0.13251, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.96271, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1207", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2f43f2b1-a9df-44ed-8ed6-f554a6e34540", "vulnerability": {"vulnId": "CVE-2023-39361", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-08T02:00:00+02:00"}, "gcve": {"object_uuid": "2f43f2b1-a9df-44ed-8ed6-f554a6e34540", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-08T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated SQL Injection in graph_view.php in Cacti | Affected: Cacti / cacti | CVSS: 9.8 (CRITICAL) | EPSS: 0.88793 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-39361", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39361"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39361"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated SQL Injection in graph_view.php in Cacti", "cve_id": "CVE-2023-39361", "vendor": "Cacti", "ghsa_id": null, "product": "cacti", "added_date": "2026-07-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88793, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99774, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39361", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f72e1122-d61e-4d6f-b03b-6bb40f894ae0", "vulnerability": {"vulnId": "CVE-2026-4631", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-08T02:00:00+02:00"}, "gcve": {"object_uuid": "f72e1122-d61e-4d6f-b03b-6bb40f894ae0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-08T00:00:00+00:00"}, "scope": {"notes": "Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection | Affected: Red Hat / Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 | CVSS: 9.8 (CRITICAL) | EPSS: 0.09216 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-4631", "url": "https://www.cve.org/CVERecord?id=CVE-2026-4631"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-4631"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection", "cve_id": "CVE-2026-4631", "vendor": "Red Hat", "ghsa_id": null, "product": "Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8", "added_date": "2026-07-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.09216, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95202, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-4631", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a436ec03-aea2-491b-8e5f-0a338707b592", "vulnerability": {"vulnId": "CVE-2026-48908", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-07T19:00:54+02:00"}, "gcve": {"object_uuid": "a436ec03-aea2-491b-8e5f-0a338707b592", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-07T17:00:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-07T17:00:54+00:00"}, "scope": {"notes": "Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 | Affected: Joomshaper.net / SP Page Builder extension for Joomla | CVSS: 10.0 (CRITICAL) | EPSS: 0.88512 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48908", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48908"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48908"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2", "cve_id": "CVE-2026-48908", "vendor": "Joomshaper.net", "ghsa_id": null, "product": "SP Page Builder extension for Joomla", "added_date": "2026-07-07T17:00:54.263Z", "cvss_score": 10.0, "epss_score": 0.88512, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48908", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "072afe7e-f761-4a9c-843c-f6a0dcefd0dd", "vulnerability": {"vulnId": "CVE-2026-56290", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-07T19:00:54+02:00"}, "gcve": {"object_uuid": "072afe7e-f761-4a9c-843c-f6a0dcefd0dd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-07T17:00:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-07T17:00:54+00:00"}, "scope": {"notes": "Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 | Affected: Joomlack.fr / JoomlaCK.fr Page Builder CK extension for Joomla | CVSS: 10.0 (CRITICAL) | EPSS: 0.30866 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-56290", "url": "https://www.cve.org/CVERecord?id=CVE-2026-56290"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-56290"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0", "cve_id": "CVE-2026-56290", "vendor": "Joomlack.fr", "ghsa_id": null, "product": "JoomlaCK.fr Page Builder CK extension for Joomla", "added_date": "2026-07-07T17:00:54.263Z", "cvss_score": 10.0, "epss_score": 0.30866, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98203, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-56290", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "baa4368d-c96b-4ec7-9852-81cc009eefdf", "vulnerability": {"vulnId": "CVE-2026-55255", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-07T19:00:54+02:00"}, "gcve": {"object_uuid": "baa4368d-c96b-4ec7-9852-81cc009eefdf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-07T17:00:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-07T17:00:54+00:00"}, "scope": {"notes": "Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow | Affected: Langflow-ai / langflow | CVSS: 8.4 (HIGH) | EPSS: 0.00887 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-55255", "url": "https://www.cve.org/CVERecord?id=CVE-2026-55255"}, {"id": "GHSA-QRPV-Q767-XQQ2", "url": "https://github.com/advisories/GHSA-QRPV-Q767-XQQ2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-55255"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow", "cve_id": "CVE-2026-55255", "vendor": "Langflow-ai", "ghsa_id": "GHSA-QRPV-Q767-XQQ2", "product": "langflow", "added_date": "2026-07-07T17:00:54.263Z", "cvss_score": 8.4, "epss_score": 0.00887, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.57803, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-55255", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4ee52240-2a07-4079-a9ff-9a23af54b09a", "vulnerability": {"vulnId": "CVE-2022-50992", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "4ee52240-2a07-4079-a9ff-9a23af54b09a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-06T00:00:00+00:00"}, "scope": {"notes": "Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet | Affected: Weaver Network / E-cology | CVSS: 8.7 (HIGH) | EPSS: 0.00705 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-50992", "url": "https://www.cve.org/CVERecord?id=CVE-2022-50992"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-50992"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet", "cve_id": "CVE-2022-50992", "vendor": "Weaver Network", "ghsa_id": null, "product": "E-cology", "added_date": "2026-07-06T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.00705, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51618, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-50992", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "871fc752-e77e-47e5-a95c-18a8037714fe", "vulnerability": {"vulnId": "CVE-2026-48282", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-02T20:20:12+02:00"}, "gcve": {"object_uuid": "871fc752-e77e-47e5-a95c-18a8037714fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-02T18:20:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-02T18:20:12+00:00"}, "scope": {"notes": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Affected: Adobe / ColdFusion 2025, ColdFusion 2023 | CVSS: 10.0 (CRITICAL) | EPSS: 0.42388 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48282", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48282"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48282"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)", "cve_id": "CVE-2026-48282", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion 2025, ColdFusion 2023", "added_date": "2026-07-02T18:20:12.605Z", "cvss_score": 10.0, "epss_score": 0.42388, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.98664, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48282", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eae4076c-ecaa-4e33-8a96-e81a9b6add17", "vulnerability": {"vulnId": "CVE-2026-1125", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-02T02:00:00+02:00"}, "gcve": {"object_uuid": "eae4076c-ecaa-4e33-8a96-e81a9b6add17", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-02T00:00:00+00:00"}, "scope": {"notes": "D-Link DIR-823X set_wifidog_settings sub_412E7C command injection | Affected: D-Link / DIR-823X | CVSS: 6.9 (MEDIUM) | EPSS: 0.1574 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-1125", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1125"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1125"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DIR-823X set_wifidog_settings sub_412E7C command injection", "cve_id": "CVE-2026-1125", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-823X", "added_date": "2026-07-02T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.1574, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96765, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1125", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ca10f976-851b-456f-b2ef-a8dc3cda7b1b", "vulnerability": {"vulnId": "CVE-2026-8451", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-01T23:50:00+02:00"}, "gcve": {"object_uuid": "ca10f976-851b-456f-b2ef-a8dc3cda7b1b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-01T21:50:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-01T21:50:00+00:00"}, "scope": {"notes": "Insufficient input validation leading to memory overread | Affected: NetScaler / ADC, Gateway | CVSS: 8.8 (HIGH) | EPSS: 0.00502 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-8451", "url": "https://www.cve.org/CVERecord?id=CVE-2026-8451"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-8451"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient input validation leading to memory overread", "cve_id": "CVE-2026-8451", "vendor": "NetScaler", "ghsa_id": null, "product": "ADC, Gateway", "added_date": "2026-07-01T21:50:00.000Z", "cvss_score": 8.8, "epss_score": 0.00502, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.40713, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-8451", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "00e1da95-c7b0-4204-acdd-a0d6b262104c", "vulnerability": {"vulnId": "CVE-2026-45659", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-01T21:00:06+02:00"}, "gcve": {"object_uuid": "00e1da95-c7b0-4204-acdd-a0d6b262104c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-01T19:00:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-01T19:00:06+00:00"}, "scope": {"notes": "Microsoft SharePoint Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 8.8 (HIGH) | EPSS: 0.02704 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-45659", "url": "https://www.cve.org/CVERecord?id=CVE-2026-45659"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-45659"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Remote Code Execution Vulnerability", "cve_id": "CVE-2026-45659", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-07-01T19:00:06.901Z", "cvss_score": 8.8, "epss_score": 0.02704, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85431, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-45659", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "680b67c5-4edf-4ac9-b245-059f3db48a91", "vulnerability": {"vulnId": "CVE-2026-8037", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-07-01T16:51:57+02:00"}, "gcve": {"object_uuid": "680b67c5-4edf-4ac9-b245-059f3db48a91", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-07-01T14:51:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-07-01T14:51:57+00:00"}, "scope": {"notes": "OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF | Affected: Progress Software / LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF | CVSS: 9.6 (CRITICAL) | EPSS: 0.77362 | Used in malware: unknown | Listed 37 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-8037", "url": "https://www.cve.org/CVERecord?id=CVE-2026-8037"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-8037"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF", "cve_id": "CVE-2026-8037", "vendor": "Progress Software", "ghsa_id": null, "product": "LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF", "added_date": "2026-07-01T14:51:57.959Z", "cvss_score": 9.6, "epss_score": 0.77362, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99545, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-8037", "ahead_of_cisa_kev": {"unit": "day", "count": 37}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "130652e4-0953-4fa0-b7b0-e17d1b075cfd", "vulnerability": {"vulnId": "CVE-2026-52813", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-30T18:02:32+02:00"}, "gcve": {"object_uuid": "130652e4-0953-4fa0-b7b0-e17d1b075cfd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-30T16:02:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-30T16:02:32+00:00"}, "scope": {"notes": "Gogs: Path Traversal in organization name results in RCE through Git hooks | Affected: Gogs / gogs | CVSS: 10.0 (CRITICAL) | EPSS: 0.01107 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-52813", "url": "https://www.cve.org/CVERecord?id=CVE-2026-52813"}, {"id": "GHSA-C39W-43GM-34H5", "url": "https://github.com/advisories/GHSA-C39W-43GM-34H5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-52813"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gogs: Path Traversal in organization name results in RCE through Git hooks", "cve_id": "CVE-2026-52813", "vendor": "Gogs", "ghsa_id": "GHSA-C39W-43GM-34H5", "product": "gogs", "added_date": "2026-06-30T16:02:32.752Z", "cvss_score": 10.0, "epss_score": 0.01107, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.64613, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-52813", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d2d17ee0-cf2b-46f9-90eb-e539613b0062", "vulnerability": {"vulnId": "CVE-2026-46817", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-29T17:45:00+02:00"}, "gcve": {"object_uuid": "d2d17ee0-cf2b-46f9-90eb-e539613b0062", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-29T15:45:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-29T15:45:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are... | Affected: Oracle / Oracle Payments | CVSS: 9.8 (CRITICAL) | EPSS: 0.00814 | Used in malware: unknown | Listed 16 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-46817", "url": "https://www.cve.org/CVERecord?id=CVE-2026-46817"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-46817"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are...", "cve_id": "CVE-2026-46817", "vendor": "Oracle", "ghsa_id": null, "product": "Oracle Payments", "added_date": "2026-06-29T15:45:00.000Z", "cvss_score": 9.8, "epss_score": 0.00814, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.55465, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-46817", "ahead_of_cisa_kev": {"unit": "day", "count": 16}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d34774e1-3a23-4501-95d5-3287f6ab9fff", "vulnerability": {"vulnId": "CVE-2026-48558", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "d34774e1-3a23-4501-95d5-3287f6ab9fff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-29T00:00:00+00:00"}, "scope": {"notes": "SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification | Affected: SimpleHelp / SimpleHelp | CVSS: 9.5 (CRITICAL) | EPSS: 0.05719 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48558", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48558"}, {"id": "GHSA-M93H-GJV2-FMQ2", "url": "https://github.com/advisories/GHSA-M93H-GJV2-FMQ2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48558"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification", "cve_id": "CVE-2026-48558", "vendor": "SimpleHelp", "ghsa_id": "GHSA-M93H-GJV2-FMQ2", "product": "SimpleHelp", "added_date": "2026-06-29T00:00:00.000Z", "cvss_score": 9.5, "epss_score": 0.05719, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92797, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48558", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "863d915c-88eb-41cc-a6dd-7cb63471579c", "vulnerability": {"vulnId": "CVE-2026-8054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-27T16:36:50+02:00"}, "gcve": {"object_uuid": "863d915c-88eb-41cc-a6dd-7cb63471579c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-27T14:36:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-27T14:36:50+00:00"}, "scope": {"notes": "Unauthenticated SQL Injection in dotCMS Publish Audit API | Affected: dotCMS / dotCMS Core | CVSS: 10.0 (CRITICAL) | EPSS: 0.01623 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-8054", "url": "https://www.cve.org/CVERecord?id=CVE-2026-8054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-8054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated SQL Injection in dotCMS Publish Audit API", "cve_id": "CVE-2026-8054", "vendor": "dotCMS", "ghsa_id": null, "product": "dotCMS Core", "added_date": "2026-06-27T14:36:50.219Z", "cvss_score": 10.0, "epss_score": 0.01623, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.75227, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-8054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "49378f15-f64d-4fb0-8e0b-8d538054b650", "vulnerability": {"vulnId": "CVE-2023-6567", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-27T16:36:38+02:00"}, "gcve": {"object_uuid": "49378f15-f64d-4fb0-8e0b-8d538054b650", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-27T14:36:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-27T14:36:38+00:00"}, "scope": {"notes": "The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018order_by\u2019 parameter in all versions up to, and including,... | Affected: Thimpress / LearnPress \u2013 WordPress LMS Plugin | CVSS: 9.8 (CRITICAL) | EPSS: 0.51394 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6567", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6567"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6567"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018order_by\u2019 parameter in all versions up to, and including,...", "cve_id": "CVE-2023-6567", "vendor": "Thimpress", "ghsa_id": null, "product": "LearnPress \u2013 WordPress LMS Plugin", "added_date": "2026-06-27T14:36:38.919Z", "cvss_score": 9.8, "epss_score": 0.51394, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98909, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6567", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "67c9264a-0948-4875-806d-4c5d217324bd", "vulnerability": {"vulnId": "CVE-2026-12569", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "67c9264a-0948-4875-806d-4c5d217324bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-25T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution (RCE) vulnerability in Windchill PDMlink | Affected: PTC / Windchill PDMLink, FlexPLM | CVSS: 9.3 (CRITICAL) | EPSS: 0.46049 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-12569", "url": "https://www.cve.org/CVERecord?id=CVE-2026-12569"}, {"id": "GHSA-F345-WXWR-FXFH", "url": "https://github.com/advisories/GHSA-F345-WXWR-FXFH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-12569"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution (RCE) vulnerability in Windchill PDMlink", "cve_id": "CVE-2026-12569", "vendor": "PTC", "ghsa_id": "GHSA-F345-WXWR-FXFH", "product": "Windchill PDMLink, FlexPLM", "added_date": "2026-06-25T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.46049, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98773, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-12569", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d963dc0-2ed8-4b87-a4f6-3cb59e2d4f56", "vulnerability": {"vulnId": "CVE-2026-20230", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-24T00:20:36+02:00"}, "gcve": {"object_uuid": "3d963dc0-2ed8-4b87-a4f6-3cb59e2d4f56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-23T22:20:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-23T22:20:36+00:00"}, "scope": {"notes": "Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability | Affected: Cisco / Cisco Unified Communications Manager | CVSS: 8.6 (HIGH) | EPSS: 0.882 | Used in malware: unknown | Listed 2 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20230", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20230"}, {"id": "GHSA-FCV7-PCHJ-75C2", "url": "https://github.com/advisories/GHSA-FCV7-PCHJ-75C2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20230"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability", "cve_id": "CVE-2026-20230", "vendor": "Cisco", "ghsa_id": "GHSA-FCV7-PCHJ-75C2", "product": "Cisco Unified Communications Manager", "added_date": "2026-06-23T22:20:36.536Z", "cvss_score": 8.6, "epss_score": 0.882, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99766, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20230", "ahead_of_cisa_kev": {"unit": "day", "count": 2}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d97b924-4f8e-442b-983f-86b70e2a6f76", "vulnerability": {"vulnId": "CVE-2025-67038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "9d97b924-4f8e-442b-983f-86b70e2a6f76", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-23T00:00:00+00:00"}, "scope": {"notes": "Lantronix EDS5000, G520, and X300 OS Command Injection | Affected: Lantronix / EDS5000 series, G520 series, X300 series, E210 series, E220 series | CVSS: 9.3 (CRITICAL) | EPSS: 0.1926 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-67038", "url": "https://www.cve.org/CVERecord?id=CVE-2025-67038"}, {"id": "GHSA-55GQ-23MV-CW8R", "url": "https://github.com/advisories/GHSA-55GQ-23MV-CW8R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-67038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Lantronix EDS5000, G520, and X300 OS Command Injection", "cve_id": "CVE-2025-67038", "vendor": "Lantronix", "ghsa_id": "GHSA-55GQ-23MV-CW8R", "product": "EDS5000 series, G520 series, X300 series, E210 series, E220 series", "added_date": "2026-06-23T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.1926, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97261, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-67038", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3dc44f7e-d5e9-41cd-96dd-7c8f48359ec0", "vulnerability": {"vulnId": "CVE-2026-48907", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-16T02:00:00+02:00"}, "gcve": {"object_uuid": "3dc44f7e-d5e9-41cd-96dd-7c8f48359ec0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-16T00:00:00+00:00"}, "scope": {"notes": "Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5 | Affected: Joomlacontenteditor.net / Joomla Content Editor (JCE) extension for Joomla | CVSS: 10.0 (CRITICAL) | EPSS: 0.1619 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48907", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48907"}, {"id": "GHSA-C3F5-4G7F-QJQJ", "url": "https://github.com/advisories/GHSA-C3F5-4G7F-QJQJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48907"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5", "cve_id": "CVE-2026-48907", "vendor": "Joomlacontenteditor.net", "ghsa_id": "GHSA-C3F5-4G7F-QJQJ", "product": "Joomla Content Editor (JCE) extension for Joomla", "added_date": "2026-06-16T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.1619, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96844, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48907", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "19625416-25be-4fd0-9fd2-6686c80ba83f", "vulnerability": {"vulnId": "CVE-2026-39813", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T14:48:52+02:00"}, "gcve": {"object_uuid": "19625416-25be-4fd0-9fd2-6686c80ba83f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T12:48:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T12:48:52+00:00"}, "scope": {"notes": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to... | Affected: Fortinet / FortiSandbox, FortiSandbox Cloud | CVSS: 9.1 (CRITICAL) | EPSS: 0.0072 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-39813", "url": "https://www.cve.org/CVERecord?id=CVE-2026-39813"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-39813"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to...", "cve_id": "CVE-2026-39813", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiSandbox, FortiSandbox Cloud", "added_date": "2026-06-15T12:48:52.791Z", "cvss_score": 9.1, "epss_score": 0.0072, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.52183, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-39813", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f4f71aab-3924-4641-9c63-a1a0c823c76d", "vulnerability": {"vulnId": "CVE-2026-53435", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T11:02:00+02:00"}, "gcve": {"object_uuid": "f4f71aab-3924-4641-9c63-a1a0c823c76d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T09:02:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T09:02:00+00:00"}, "scope": {"notes": "In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins... | Affected: Jenkins Project / Jenkins | CVSS: 8.8 (HIGH) | EPSS: 0.02163 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-53435", "url": "https://www.cve.org/CVERecord?id=CVE-2026-53435"}, {"id": "GHSA-G2XQ-2V27-4RH3", "url": "https://github.com/advisories/GHSA-G2XQ-2V27-4RH3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-53435"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins...", "cve_id": "CVE-2026-53435", "vendor": "Jenkins Project", "ghsa_id": "GHSA-G2XQ-2V27-4RH3", "product": "Jenkins", "added_date": "2026-06-15T09:02:00.000Z", "cvss_score": 8.8, "epss_score": 0.02163, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81564, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-53435", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d2a3e024-6dda-4563-92fa-1866d3582479", "vulnerability": {"vulnId": "CVE-2026-20253", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T07:15:25+02:00"}, "gcve": {"object_uuid": "d2a3e024-6dda-4563-92fa-1866d3582479", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T05:15:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T05:15:25+00:00"}, "scope": {"notes": "Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise | Affected: Splunk / Splunk Enterprise | CVSS: 9.8 (CRITICAL) | EPSS: 0.96939 | Used in malware: unknown | Listed 3 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20253", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20253"}, {"id": "GHSA-XGM5-JH99-WC4V", "url": "https://github.com/advisories/GHSA-XGM5-JH99-WC4V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20253"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise", "cve_id": "CVE-2026-20253", "vendor": "Splunk", "ghsa_id": "GHSA-XGM5-JH99-WC4V", "product": "Splunk Enterprise", "added_date": "2026-06-15T05:15:25.399Z", "cvss_score": 9.8, "epss_score": 0.96939, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99889, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20253", "ahead_of_cisa_kev": {"unit": "day", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e689bdb4-f769-4d78-b31b-dced0be85b3d", "vulnerability": {"vulnId": "CVE-2025-27222", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "e689bdb4-f769-4d78-b31b-dced0be85b3d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't... | Affected: Rocket Software / TRUfusion Enterprise | CVSS: 8.6 (HIGH) | EPSS: 0.02001 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-27222", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27222"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27222"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't...", "cve_id": "CVE-2025-27222", "vendor": "Rocket Software", "ghsa_id": null, "product": "TRUfusion Enterprise", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.02001, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80014, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27222", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6fca6237-6f17-45dd-91cf-b13fb5cef5a6", "vulnerability": {"vulnId": "CVE-2017-9833", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "6fca6237-6f17-45dd-91cf-b13fb5cef5a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of \"../..\" using the FILECAMERA variable (sent by GET) to read files with root privileges.... | Affected: Boa / Boa Web Server | CVSS: 7.5 (HIGH) | EPSS: 0.68464 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-9833", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9833"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9833"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of \"../..\" using the FILECAMERA variable (sent by GET) to read files with root privileges....", "cve_id": "CVE-2017-9833", "vendor": "Boa", "ghsa_id": null, "product": "Boa Web Server", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.68464, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99317, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9833", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "207c7e06-332d-4a65-a20a-963412df3922", "vulnerability": {"vulnId": "CVE-2020-24949", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "207c7e06-332d-4a65-a20a-963412df3922", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server... | Affected: PHP-Fusion / PHP-Fusion | CVSS: 8.8 (HIGH) | EPSS: 0.67516 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-24949", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24949"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24949"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server...", "cve_id": "CVE-2020-24949", "vendor": "PHP-Fusion", "ghsa_id": null, "product": "PHP-Fusion", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.67516, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99292, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24949", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "df42d743-e0f0-4202-9c7f-5cbae8b42543", "vulnerability": {"vulnId": "CVE-2024-27497", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "df42d743-e0f0-4202-9c7f-5cbae8b42543", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file. | Affected: Linksys / E2000 | CVSS: 8.8 (HIGH) | EPSS: 0.26657 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-27497", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27497"}, {"id": "GHSA-VQW3-3GM8-35VM", "url": "https://github.com/advisories/GHSA-VQW3-3GM8-35VM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27497"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.", "cve_id": "CVE-2024-27497", "vendor": "Linksys", "ghsa_id": "GHSA-VQW3-3GM8-35VM", "product": "E2000", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.26657, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97965, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27497", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "62c0014e-123b-4407-9813-8341b73f9ce6", "vulnerability": {"vulnId": "CVE-2017-15363", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "62c0014e-123b-4407-9813-8341b73f9ce6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension... | Affected: Luracast / Restler | CVSS: 7.5 (HIGH) | EPSS: 0.15333 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-15363", "url": "https://www.cve.org/CVERecord?id=CVE-2017-15363"}, {"id": "GHSA-RVMG-XC29-RVXF", "url": "https://github.com/advisories/GHSA-RVMG-XC29-RVXF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-15363"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension...", "cve_id": "CVE-2017-15363", "vendor": "Luracast", "ghsa_id": "GHSA-RVMG-XC29-RVXF", "product": "Restler", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.15333, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96676, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-15363", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4f95ef73-83d6-4ca0-a470-05cd45f48292", "vulnerability": {"vulnId": "CVE-2023-31059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "4f95ef73-83d6-4ca0-a470-05cd45f48292", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php. | Affected: Repetier / Repetier Server | CVSS: 7.5 (HIGH) | EPSS: 0.05574 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-31059", "url": "https://www.cve.org/CVERecord?id=CVE-2023-31059"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-31059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.", "cve_id": "CVE-2023-31059", "vendor": "Repetier", "ghsa_id": null, "product": "Repetier Server", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.05574, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92629, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-31059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fe18c57b-15d1-4a53-af97-ecc6fdad780c", "vulnerability": {"vulnId": "CVE-2026-20262", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "fe18c57b-15d1-4a53-af97-ecc6fdad780c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 6.5 (MEDIUM) | EPSS: 0.28171 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20262", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20262"}, {"id": "GHSA-P45R-GCC9-FR7F", "url": "https://github.com/advisories/GHSA-P45R-GCC9-FR7F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20262"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability", "cve_id": "CVE-2026-20262", "vendor": "Cisco", "ghsa_id": "GHSA-P45R-GCC9-FR7F", "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.28171, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98059, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20262", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "48322c94-4830-4c77-97bd-00781b66d09a", "vulnerability": {"vulnId": "CVE-2024-32738", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "48322c94-4830-4c77-97bd-00781b66d09a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "CyberPower PowerPanel Enterprise SQL Injection | Affected: CyberPower / CyberPower PowerPanel Enterprise | CVSS: 7.5 (HIGH) | EPSS: 0.04553 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-32738", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32738"}, {"id": "GHSA-V2HV-5634-VCQ8", "url": "https://github.com/advisories/GHSA-V2HV-5634-VCQ8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32738"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CyberPower PowerPanel Enterprise SQL Injection", "cve_id": "CVE-2024-32738", "vendor": "CyberPower", "ghsa_id": "GHSA-V2HV-5634-VCQ8", "product": "CyberPower PowerPanel Enterprise", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.04553, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91295, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32738", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a4e0ff02-39ec-4dca-bd25-0a22dfa0fd69", "vulnerability": {"vulnId": "CVE-2022-25486", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "a4e0ff02-39ec-4dca-bd25-0a22dfa0fd69", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. | Affected: Cuppa CMS / CuppaCMS | CVSS: 7.8 (HIGH) | EPSS: 0.09966 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25486", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25486"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25486"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.", "cve_id": "CVE-2022-25486", "vendor": "Cuppa CMS", "ghsa_id": null, "product": "CuppaCMS", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09966, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95462, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25486", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3cbd0225-51e7-4006-9111-7b2ec30f2aae", "vulnerability": {"vulnId": "CVE-2024-31750", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "3cbd0225-51e7-4006-9111-7b2ec30f2aae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. | Affected: F-logic / datacube3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.1927 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-31750", "url": "https://www.cve.org/CVERecord?id=CVE-2024-31750"}, {"id": "GHSA-X8VW-8MW4-42V9", "url": "https://github.com/advisories/GHSA-X8VW-8MW4-42V9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-31750"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.", "cve_id": "CVE-2024-31750", "vendor": "F-logic", "ghsa_id": "GHSA-X8VW-8MW4-42V9", "product": "datacube3", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1927, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97263, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-31750", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "82c90655-1b44-42af-8d47-d1db96cac659", "vulnerability": {"vulnId": "CVE-2022-25485", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-15T02:00:00+02:00"}, "gcve": {"object_uuid": "82c90655-1b44-42af-8d47-d1db96cac659", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-15T00:00:00+00:00"}, "scope": {"notes": "CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. | Affected: Cuppa CMS / CuppaCMS | CVSS: 7.8 (HIGH) | EPSS: 0.07927 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25485", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25485"}, {"id": "GHSA-357F-63VR-35FH", "url": "https://github.com/advisories/GHSA-357F-63VR-35FH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25485"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.", "cve_id": "CVE-2022-25485", "vendor": "Cuppa CMS", "ghsa_id": "GHSA-357F-63VR-35FH", "product": "CuppaCMS", "added_date": "2026-06-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07927, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94556, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25485", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f200eb49-bf74-4a94-b1ab-3fd75a370cd4", "vulnerability": {"vulnId": "CVE-2026-54420", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-14T06:01:15+02:00"}, "gcve": {"object_uuid": "f200eb49-bf74-4a94-b1ab-3fd75a370cd4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-14T04:01:15+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-14T04:01:15+00:00"}, "scope": {"notes": "LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web... | Affected: LiteSpeed Technologies / cPanel Plugin | CVSS: 8.5 (HIGH) | EPSS: 0.00806 | Used in malware: unknown | Listed 20 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-54420", "url": "https://www.cve.org/CVERecord?id=CVE-2026-54420"}, {"id": "GHSA-3G44-C4QC-CXM8", "url": "https://github.com/advisories/GHSA-3G44-C4QC-CXM8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-54420"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web...", "cve_id": "CVE-2026-54420", "vendor": "LiteSpeed Technologies", "ghsa_id": "GHSA-3G44-C4QC-CXM8", "product": "cPanel Plugin", "added_date": "2026-06-14T04:01:15.820Z", "cvss_score": 8.5, "epss_score": 0.00806, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55223, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-54420", "ahead_of_cisa_kev": {"unit": "hour", "count": 20}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eec49cfa-be8e-43a1-b728-384b1f4bb19a", "vulnerability": {"vulnId": "CVE-2023-39796", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-14T02:00:00+02:00"}, "gcve": {"object_uuid": "eec49cfa-be8e-43a1-b728-384b1f4bb19a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-14T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the... | Affected: WBCE / WBCE CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.06146 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-39796", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39796"}, {"id": "GHSA-JWPQ-F263-R9PH", "url": "https://github.com/advisories/GHSA-JWPQ-F263-R9PH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39796"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the...", "cve_id": "CVE-2023-39796", "vendor": "WBCE", "ghsa_id": "GHSA-JWPQ-F263-R9PH", "product": "WBCE CMS", "added_date": "2026-06-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06146, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93246, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39796", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7ad9d39f-09d7-4df2-87b3-24af6b345f98", "vulnerability": {"vulnId": "CVE-2022-38296", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "7ad9d39f-09d7-4df2-87b3-24af6b345f98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-13T00:00:00+00:00"}, "scope": {"notes": "Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. | Affected: Cuppa CMS / Cuppa CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.05137 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-38296", "url": "https://www.cve.org/CVERecord?id=CVE-2022-38296"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-38296"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.", "cve_id": "CVE-2022-38296", "vendor": "Cuppa CMS", "ghsa_id": null, "product": "Cuppa CMS", "added_date": "2026-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.05137, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92141, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-38296", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fc31248f-ee2f-4374-9a78-60996bfd59b4", "vulnerability": {"vulnId": "CVE-2026-39808", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-12T15:59:12+02:00"}, "gcve": {"object_uuid": "fc31248f-ee2f-4374-9a78-60996bfd59b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-12T13:59:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-12T13:59:12+00:00"}, "scope": {"notes": "A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through... | Affected: Fortinet / FortiSandbox, FortiSandbox PaaS | CVSS: 9.1 (CRITICAL) | EPSS: 0.47362 | Used in malware: unknown | Listed 34 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-39808", "url": "https://www.cve.org/CVERecord?id=CVE-2026-39808"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-39808"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through...", "cve_id": "CVE-2026-39808", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiSandbox, FortiSandbox PaaS", "added_date": "2026-06-12T13:59:12.791Z", "cvss_score": 9.1, "epss_score": 0.47362, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.98804, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-39808", "ahead_of_cisa_kev": {"unit": "day", "count": 34}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1a8f3864-51bd-41ce-8bee-ba1b61fba451", "vulnerability": {"vulnId": "CVE-2026-4020", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-12T02:35:27+02:00"}, "gcve": {"object_uuid": "1a8f3864-51bd-41ce-8bee-ba1b61fba451", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-12T00:35:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-12T00:35:27+00:00"}, "scope": {"notes": "Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API | Affected: RocketGenius / Gravity SMTP | CVSS: 7.5 (HIGH) | EPSS: 0.02236 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-4020", "url": "https://www.cve.org/CVERecord?id=CVE-2026-4020"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-4020"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API", "cve_id": "CVE-2026-4020", "vendor": "RocketGenius", "ghsa_id": null, "product": "Gravity SMTP", "added_date": "2026-06-12T00:35:27.121Z", "cvss_score": 7.5, "epss_score": 0.02236, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.82181, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-4020", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b49098c4-7dc5-4a31-a7fd-9b51cf91fab9", "vulnerability": {"vulnId": "CVE-2021-31805", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-12T02:32:51+02:00"}, "gcve": {"object_uuid": "b49098c4-7dc5-4a31-a7fd-9b51cf91fab9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-12T00:32:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-12T00:32:51+00:00"}, "scope": {"notes": "Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE. | Affected: Apache / Apache Struts | CVSS: 9.8 (CRITICAL) | EPSS: 0.85433 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-31805", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31805"}, {"id": "GHSA-V8J6-6C2R-R27C", "url": "https://github.com/advisories/GHSA-V8J6-6C2R-R27C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31805"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.", "cve_id": "CVE-2021-31805", "vendor": "Apache", "ghsa_id": "GHSA-V8J6-6C2R-R27C", "product": "Apache Struts", "added_date": "2026-06-12T00:32:51.325Z", "cvss_score": 9.8, "epss_score": 0.85433, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99715, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31805", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "47151fd9-48b9-4977-87e4-fc67a379f24e", "vulnerability": {"vulnId": "CVE-2021-30128", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-12T02:32:50+02:00"}, "gcve": {"object_uuid": "47151fd9-48b9-4977-87e4-fc67a379f24e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-12T00:32:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-12T00:32:50+00:00"}, "scope": {"notes": "Unsafe deserialization in Apache OFBiz | Affected: Apache / Apache OFBiz | CVSS: 9.8 (CRITICAL) | EPSS: 0.81209 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30128", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30128"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30128"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unsafe deserialization in Apache OFBiz", "cve_id": "CVE-2021-30128", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2026-06-12T00:32:50.259Z", "cvss_score": 9.8, "epss_score": 0.81209, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99627, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30128", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5a7a9c90-3e30-4147-91f4-1b8078723d4e", "vulnerability": {"vulnId": "CVE-2020-6286", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-12T02:32:46+02:00"}, "gcve": {"object_uuid": "5a7a9c90-3e30-4147-91f4-1b8078723d4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-12T00:32:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-12T00:32:46+00:00"}, "scope": {"notes": "The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,... | Affected: SAP SE / SAP NetWeaver AS JAVA (LM Configuration Wizard) | CVSS: 5.3 (MEDIUM) | EPSS: 0.28312 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-6286", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6286"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6286"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The insufficient input path validation of certain parameter in the web service of SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30,...", "cve_id": "CVE-2020-6286", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP NetWeaver AS JAVA (LM Configuration Wizard)", "added_date": "2026-06-12T00:32:46.583Z", "cvss_score": 5.3, "epss_score": 0.28312, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.98067, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6286", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5500d724-b230-42cb-8731-08d10e92f16a", "vulnerability": {"vulnId": "CVE-2026-35273", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-11T22:20:23+02:00"}, "gcve": {"object_uuid": "5500d724-b230-42cb-8731-08d10e92f16a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-11T20:20:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-11T20:20:23+00:00"}, "scope": {"notes": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions... | Affected: Oracle / PeopleSoft Enterprise PeopleTools | CVSS: 9.8 (CRITICAL) | EPSS: 0.09444 | Used in malware: yes | Listed 4 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-35273", "url": "https://www.cve.org/CVERecord?id=CVE-2026-35273"}, {"id": "GHSA-25MW-359M-F6RJ", "url": "https://github.com/advisories/GHSA-25MW-359M-F6RJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-35273"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions...", "cve_id": "CVE-2026-35273", "vendor": "Oracle", "ghsa_id": "GHSA-25MW-359M-F6RJ", "product": "PeopleSoft Enterprise PeopleTools", "added_date": "2026-06-11T20:20:23.651Z", "cvss_score": 9.8, "epss_score": 0.09444, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.95276, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-35273", "ahead_of_cisa_kev": {"unit": "hour", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a760609-27a6-459a-a5f4-ee83d424c5e2", "vulnerability": {"vulnId": "CVE-2026-10795", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-11T09:20:32+02:00"}, "gcve": {"object_uuid": "6a760609-27a6-459a-a5f4-ee83d424c5e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-11T07:20:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-11T07:20:32+00:00"}, "scope": {"notes": "UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc | Affected: David Anderson / UpdraftPlus: WP Backup & Migration Plugin | CVSS: 8.1 (HIGH) | EPSS: 0.03635 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-10795", "url": "https://www.cve.org/CVERecord?id=CVE-2026-10795"}, {"id": "GHSA-HC7F-QWFJ-7FCF", "url": "https://github.com/advisories/GHSA-HC7F-QWFJ-7FCF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-10795"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc", "cve_id": "CVE-2026-10795", "vendor": "David Anderson", "ghsa_id": "GHSA-HC7F-QWFJ-7FCF", "product": "UpdraftPlus: WP Backup & Migration Plugin", "added_date": "2026-06-11T07:20:32.076Z", "cvss_score": 8.1, "epss_score": 0.03635, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89186, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-10795", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "412f60e3-d434-44af-a930-2587e39f38a4", "vulnerability": {"vulnId": "CVE-2025-5821", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-11T02:20:49+02:00"}, "gcve": {"object_uuid": "412f60e3-d434-44af-a930-2587e39f38a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-11T00:20:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-11T00:20:49+00:00"}, "scope": {"notes": "Case Theme User <= 1.0.3 - Authentication Bypass via Social Login | Affected: Case-Themes / Case Theme User | CVSS: 9.8 (CRITICAL) | EPSS: 0.00741 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-5821", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5821"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5821"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Case Theme User <= 1.0.3 - Authentication Bypass via Social Login", "cve_id": "CVE-2025-5821", "vendor": "Case-Themes", "ghsa_id": null, "product": "Case Theme User", "added_date": "2026-06-11T00:20:49.551Z", "cvss_score": 9.8, "epss_score": 0.00741, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5821", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a01e3d88-fd49-4b75-b0ae-598a753eaba6", "vulnerability": {"vulnId": "CVE-2026-5027", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-10T18:20:36+02:00"}, "gcve": {"object_uuid": "a01e3d88-fd49-4b75-b0ae-598a753eaba6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-10T16:20:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-10T16:20:36+00:00"}, "scope": {"notes": "Langflow - Path Traversal Arbitrary File Write via upload_user_file | Affected: Langflow-ai / langflow | CVSS: 8.8 (HIGH) | EPSS: 0.04758 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-5027", "url": "https://www.cve.org/CVERecord?id=CVE-2026-5027"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-5027"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow - Path Traversal Arbitrary File Write via upload_user_file", "cve_id": "CVE-2026-5027", "vendor": "Langflow-ai", "ghsa_id": null, "product": "langflow", "added_date": "2026-06-10T16:20:36.494Z", "cvss_score": 8.8, "epss_score": 0.04758, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-5027", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3f871785-a5aa-4903-ae04-003bb146580a", "vulnerability": {"vulnId": "CVE-2026-10520", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-10T11:50:00+02:00"}, "gcve": {"object_uuid": "3f871785-a5aa-4903-ae04-003bb146580a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-10T09:50:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-10T09:50:00+00:00"}, "scope": {"notes": "An OS Command Injection vulnerability\u00a0in Ivanti\u00a0Sentry before\u00a0the\u00a0R10.5.2, R10.6.2 and R10.7.1\u00a0versions\u00a0allows\u00a0a remote unauthenticated user to... | Affected: Ivanti / Sentry | CVSS: 10.0 (CRITICAL) | EPSS: 0.99915 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-10520", "url": "https://www.cve.org/CVERecord?id=CVE-2026-10520"}, {"id": "GHSA-V2VC-RGVQ-3PWF", "url": "https://github.com/advisories/GHSA-V2VC-RGVQ-3PWF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-10520"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS Command Injection vulnerability\u00a0in Ivanti\u00a0Sentry before\u00a0the\u00a0R10.5.2, R10.6.2 and R10.7.1\u00a0versions\u00a0allows\u00a0a remote unauthenticated user to...", "cve_id": "CVE-2026-10520", "vendor": "Ivanti", "ghsa_id": "GHSA-V2VC-RGVQ-3PWF", "product": "Sentry", "added_date": "2026-06-10T09:50:00.000Z", "cvss_score": 10.0, "epss_score": 0.99915, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99967, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-10520", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a177b0ec-18d6-4631-af9f-caeec405aaed", "vulnerability": {"vulnId": "CVE-2026-11645", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-09T15:20:17+02:00"}, "gcve": {"object_uuid": "a177b0ec-18d6-4631-af9f-caeec405aaed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-09T13:20:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-09T13:20:17+00:00"}, "scope": {"notes": "Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.0219 | Used in malware: unknown | Listed 5 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-11645", "url": "https://www.cve.org/CVERecord?id=CVE-2026-11645"}, {"id": "GHSA-X2HH-W9MW-3VQ2", "url": "https://github.com/advisories/GHSA-X2HH-W9MW-3VQ2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-11645"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox...", "cve_id": "CVE-2026-11645", "vendor": "Google", "ghsa_id": "GHSA-X2HH-W9MW-3VQ2", "product": "Chrome", "added_date": "2026-06-09T13:20:17.736Z", "cvss_score": 8.8, "epss_score": 0.0219, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81779, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-11645", "ahead_of_cisa_kev": {"unit": "hour", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e0da23f-4c7d-4147-937e-b7cdcabc78d8", "vulnerability": {"vulnId": "CVE-2026-34910", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-09T10:18:00+02:00"}, "gcve": {"object_uuid": "6e0da23f-4c7d-4147-937e-b7cdcabc78d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-09T08:18:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-09T08:18:00+00:00"}, "scope": {"notes": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a... | Affected: Ubiquiti / UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial | CVSS: 10.0 (CRITICAL) | EPSS: 0.45768 | Used in malware: unknown | Listed 14 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34910", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34910"}, {"id": "GHSA-FVGM-JGWH-QWX7", "url": "https://github.com/advisories/GHSA-FVGM-JGWH-QWX7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34910"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a...", "cve_id": "CVE-2026-34910", "vendor": "Ubiquiti", "ghsa_id": "GHSA-FVGM-JGWH-QWX7", "product": "UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial", "added_date": "2026-06-09T08:18:00.000Z", "cvss_score": 10.0, "epss_score": 0.45768, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.98765, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34910", "ahead_of_cisa_kev": {"unit": "day", "count": 14}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "730a12e2-a579-49a5-bfa0-738f38fd3bf8", "vulnerability": {"vulnId": "CVE-2026-34909", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-09T09:29:00+02:00"}, "gcve": {"object_uuid": "730a12e2-a579-49a5-bfa0-738f38fd3bf8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-09T07:29:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-09T07:29:00+00:00"}, "scope": {"notes": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the... | Affected: Ubiquiti / UniFi OS Server, Express, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial | CVSS: 10.0 (CRITICAL) | EPSS: 0.01793 | Used in malware: unknown | Listed 14 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34909", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34909"}, {"id": "GHSA-95FP-244G-G3VR", "url": "https://github.com/advisories/GHSA-95FP-244G-G3VR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34909"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the...", "cve_id": "CVE-2026-34909", "vendor": "Ubiquiti", "ghsa_id": "GHSA-95FP-244G-G3VR", "product": "UniFi OS Server, Express, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial", "added_date": "2026-06-09T07:29:00.000Z", "cvss_score": 10.0, "epss_score": 0.01793, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34909", "ahead_of_cisa_kev": {"unit": "day", "count": 14}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d6f6832-ade7-4504-b27a-69f5cf5c6f74", "vulnerability": {"vulnId": "CVE-2026-34908", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-09T09:27:00+02:00"}, "gcve": {"object_uuid": "6d6f6832-ade7-4504-b27a-69f5cf5c6f74", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-09T07:27:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-09T07:27:00+00:00"}, "scope": {"notes": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized... | Affected: Ubiquiti / UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial | CVSS: 10.0 (CRITICAL) | EPSS: 0.15207 | Used in malware: unknown | Listed 14 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34908", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34908"}, {"id": "GHSA-P8C5-XWRC-584F", "url": "https://github.com/advisories/GHSA-P8C5-XWRC-584F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34908"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized...", "cve_id": "CVE-2026-34908", "vendor": "Ubiquiti", "ghsa_id": "GHSA-P8C5-XWRC-584F", "product": "UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial", "added_date": "2026-06-09T07:27:00.000Z", "cvss_score": 10.0, "epss_score": 0.15207, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96655, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34908", "ahead_of_cisa_kev": {"unit": "day", "count": 14}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0b274372-0e26-44a7-999c-e4d196b09910", "vulnerability": {"vulnId": "CVE-2026-42271", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-08T20:00:45+02:00"}, "gcve": {"object_uuid": "0b274372-0e26-44a7-999c-e4d196b09910", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-08T18:00:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-08T18:00:45+00:00"}, "scope": {"notes": "LiteLLM: Authenticated command execution via MCP stdio test endpoints | Affected: BerriAI / litellm | CVSS: 8.7 (HIGH) | EPSS: 0.9257 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-42271", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42271"}, {"id": "GHSA-V4P8-MG3P-G94G", "url": "https://github.com/advisories/GHSA-V4P8-MG3P-G94G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42271"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LiteLLM: Authenticated command execution via MCP stdio test endpoints", "cve_id": "CVE-2026-42271", "vendor": "BerriAI", "ghsa_id": "GHSA-V4P8-MG3P-G94G", "product": "litellm", "added_date": "2026-06-08T18:00:45.030Z", "cvss_score": 8.7, "epss_score": 0.9257, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99825, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42271", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d7df3a5f-8a65-4119-b3f2-15d0f7447358", "vulnerability": {"vulnId": "CVE-2026-50751", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-08T16:20:34+02:00"}, "gcve": {"object_uuid": "d7df3a5f-8a65-4119-b3f2-15d0f7447358", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-08T14:20:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-08T14:20:34+00:00"}, "scope": {"notes": "User Authentication Bypass in VPN Remote Access and Mobile Access | Affected: Check Point / Quantum Security Gateway, Spark Firewalls | CVSS: 9.3 (CRITICAL) | EPSS: 0.06301 | Used in malware: yes | Listed 6 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-50751", "url": "https://www.cve.org/CVERecord?id=CVE-2026-50751"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-50751"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "User Authentication Bypass in VPN Remote Access and Mobile Access", "cve_id": "CVE-2026-50751", "vendor": "Check Point", "ghsa_id": null, "product": "Quantum Security Gateway, Spark Firewalls", "added_date": "2026-06-08T14:20:34.968Z", "cvss_score": 9.3, "epss_score": 0.06301, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93391, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-50751", "ahead_of_cisa_kev": {"unit": "hour", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a0b452c2-9d77-4a03-a8c8-04f0f6783ea1", "vulnerability": {"vulnId": "CVE-2025-8085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "a0b452c2-9d77-4a03-a8c8-04f0f6783ea1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-08T00:00:00+00:00"}, "scope": {"notes": "Ditty < 3.1.58 - Unauthenticated SSRF | Affected: Ditty / Ditty WordPress plugin | CVSS: 8.6 (HIGH) | EPSS: 0.1819 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-8085", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ditty < 3.1.58 - Unauthenticated SSRF", "cve_id": "CVE-2025-8085", "vendor": "Ditty", "ghsa_id": null, "product": "Ditty WordPress plugin", "added_date": "2026-06-08T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.1819, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97124, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a0d009bf-94cc-4f9c-8bfa-45e639b3a1d9", "vulnerability": {"vulnId": "CVE-2025-61666", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "a0d009bf-94cc-4f9c-8bfa-45e639b3a1d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-08T00:00:00+00:00"}, "scope": {"notes": "Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File | Affected: Traccar / traccar | CVSS: 8.7 (HIGH) | EPSS: 0.01282 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-61666", "url": "https://www.cve.org/CVERecord?id=CVE-2025-61666"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-61666"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File", "cve_id": "CVE-2025-61666", "vendor": "Traccar", "ghsa_id": null, "product": "traccar", "added_date": "2026-06-08T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.01282, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69007, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-61666", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6ae607ee-4e0d-49fe-84a7-fb8979384d5f", "vulnerability": {"vulnId": "CVE-2021-33544", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "6ae607ee-4e0d-49fe-84a7-fb8979384d5f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-08T00:00:00+00:00"}, "scope": {"notes": "UDP Technology/Geutebr\u00fcck camera devices: command injection leading to RCE | Affected: Geutebr\u00fcck / E2 Series, Encoder G-Code | CVSS: 7.2 (HIGH) | EPSS: 0.953 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-33544", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33544"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33544"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "UDP Technology/Geutebr\u00fcck camera devices: command injection leading to RCE", "cve_id": "CVE-2021-33544", "vendor": "Geutebr\u00fcck", "ghsa_id": null, "product": "E2 Series, Encoder G-Code", "added_date": "2026-06-08T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.953, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99865, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33544", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f1473b5-ea19-4159-bb56-b4672fd6c287", "vulnerability": {"vulnId": "CVE-2022-3801", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "8f1473b5-ea19-4159-bb56-b4672fd6c287", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "IBAX go-ibax rowsInfo sql injection | Affected: IBAX / go-ibax | CVSS: 6.3 (MEDIUM) | EPSS: 0.30082 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-3801", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3801"}, {"id": "GHSA-M738-584H-26P6", "url": "https://github.com/advisories/GHSA-M738-584H-26P6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3801"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBAX go-ibax rowsInfo sql injection", "cve_id": "CVE-2022-3801", "vendor": "IBAX", "ghsa_id": "GHSA-M738-584H-26P6", "product": "go-ibax", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.30082, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98166, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3801", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f58707fb-f2e8-48ef-baa0-014a738f3518", "vulnerability": {"vulnId": "CVE-2022-34753", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "f58707fb-f2e8-48ef-baa0-014a738f3518", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote... | Affected: Schneider Electric / SpaceLogic C-Bus Home Controller | CVSS: 8.8 (HIGH) | EPSS: 0.7048 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-34753", "url": "https://www.cve.org/CVERecord?id=CVE-2022-34753"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-34753"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote...", "cve_id": "CVE-2022-34753", "vendor": "Schneider Electric", "ghsa_id": null, "product": "SpaceLogic C-Bus Home Controller", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.7048, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99373, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-34753", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3209b44e-4785-44fd-8541-98a700e4b088", "vulnerability": {"vulnId": "CVE-2024-55457", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "3209b44e-4785-44fd-8541-98a700e4b088", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by... | Affected: MasterSAM / Star Gate 11 | CVSS: 6.5 (MEDIUM) | EPSS: 0.0312 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-55457", "url": "https://www.cve.org/CVERecord?id=CVE-2024-55457"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-55457"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by...", "cve_id": "CVE-2024-55457", "vendor": "MasterSAM", "ghsa_id": null, "product": "Star Gate 11", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.0312, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87379, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-55457", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c125665e-4ae0-41bd-8c3d-9491f88fa9b2", "vulnerability": {"vulnId": "CVE-2021-41569", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "c125665e-4ae0-41bd-8c3d-9491f88fa9b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows... | Affected: SAS Institute / SAS/Intrnet | CVSS: 7.5 (HIGH) | EPSS: 0.07968 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-41569", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41569"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41569"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows...", "cve_id": "CVE-2021-41569", "vendor": "SAS Institute", "ghsa_id": null, "product": "SAS/Intrnet", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.07968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94577, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41569", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8b73f7cc-a3b0-4ebb-81d0-f57132b559a8", "vulnerability": {"vulnId": "CVE-2023-4490", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "8b73f7cc-a3b0-4ebb-81d0-f57132b559a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "WP Job Portal < 2.0.6 - Unauthenticated SQLi | Affected: WP Job Portal / WP Job Portal | CVSS: 9.8 (CRITICAL) | EPSS: 0.03596 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-4490", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4490"}, {"id": "GHSA-62P6-QFVG-F279", "url": "https://github.com/advisories/GHSA-62P6-QFVG-F279"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4490"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WP Job Portal < 2.0.6 - Unauthenticated SQLi", "cve_id": "CVE-2023-4490", "vendor": "WP Job Portal", "ghsa_id": "GHSA-62P6-QFVG-F279", "product": "WP Job Portal", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03596, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89075, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4490", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ee28dce8-11b8-4819-b199-57416c9978cc", "vulnerability": {"vulnId": "CVE-2021-27358", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "ee28dce8-11b8-4819-b199-57416c9978cc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API... | Affected: Grafana / Grafana | CVSS: 7.5 (HIGH) | EPSS: 0.83042 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27358", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27358"}, {"id": "GHSA-H5RH-W6VM-9GHC", "url": "https://github.com/advisories/GHSA-H5RH-W6VM-9GHC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27358"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API...", "cve_id": "CVE-2021-27358", "vendor": "Grafana", "ghsa_id": "GHSA-H5RH-W6VM-9GHC", "product": "Grafana", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.83042, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99666, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27358", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "efc94b30-dd27-45d9-b019-54adeba5d003", "vulnerability": {"vulnId": "CVE-2017-10974", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "efc94b30-dd27-45d9-b019-54adeba5d003", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of... | Affected: Yaws / Yaws | CVSS: 7.5 (HIGH) | EPSS: 0.81159 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-10974", "url": "https://www.cve.org/CVERecord?id=CVE-2017-10974"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-10974"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of...", "cve_id": "CVE-2017-10974", "vendor": "Yaws", "ghsa_id": null, "product": "Yaws", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.81159, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99626, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-10974", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "43786982-cf05-4c2d-9cf3-83f4dc2e9352", "vulnerability": {"vulnId": "CVE-2022-34121", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "43786982-cf05-4c2d-9cf3-83f4dc2e9352", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php. | Affected: Cuppa CMS / Cuppa CMS | CVSS: 7.5 (HIGH) | EPSS: 0.03702 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-34121", "url": "https://www.cve.org/CVERecord?id=CVE-2022-34121"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-34121"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.", "cve_id": "CVE-2022-34121", "vendor": "Cuppa CMS", "ghsa_id": null, "product": "Cuppa CMS", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03702, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-34121", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "921636b3-1528-42af-98c2-09b026a2c35f", "vulnerability": {"vulnId": "CVE-2021-20166", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "921636b3-1528-42af-98c2-09b026a2c35f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router... | Affected: Netgear / RAX43 | CVSS: 8.8 (HIGH) | EPSS: 0.02195 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-20166", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20166"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20166"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router...", "cve_id": "CVE-2021-20166", "vendor": "Netgear", "ghsa_id": null, "product": "RAX43", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.02195, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81833, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20166", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5731b5b5-d45e-4ffa-b57a-2fa352134611", "vulnerability": {"vulnId": "CVE-2021-3577", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "5731b5b5-d45e-4ffa-b57a-2fa352134611", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker... | Affected: Motorola / Binatone Hubble Cameras | CVSS: 8.8 (HIGH) | EPSS: 0.60158 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-3577", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3577"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3577"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker...", "cve_id": "CVE-2021-3577", "vendor": "Motorola", "ghsa_id": null, "product": "Binatone Hubble Cameras", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.60158, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99111, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3577", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bb454947-f3d5-4f49-8cfc-03a1c4fbd14b", "vulnerability": {"vulnId": "CVE-2024-8752", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "bb454947-f3d5-4f49-8cfc-03a1c4fbd14b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability | Affected: Smart HMI / WebIQ | CVSS: 9.3 (CRITICAL) | EPSS: 0.11759 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8752", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8752"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8752"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability", "cve_id": "CVE-2024-8752", "vendor": "Smart HMI", "ghsa_id": null, "product": "WebIQ", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.11759, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95953, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8752", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4a9c3e64-3076-4f04-b72d-89f65880ea0e", "vulnerability": {"vulnId": "CVE-2024-39713", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "4a9c3e64-3076-4f04-b72d-89f65880ea0e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. | Affected: Rocket.Chat / Rocket.Chat | CVSS: 8.6 (HIGH) | EPSS: 0.03201 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-39713", "url": "https://www.cve.org/CVERecord?id=CVE-2024-39713"}, {"id": "GHSA-FFXG-5F8M-H72J", "url": "https://github.com/advisories/GHSA-FFXG-5F8M-H72J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-39713"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.", "cve_id": "CVE-2024-39713", "vendor": "Rocket.Chat", "ghsa_id": "GHSA-FFXG-5F8M-H72J", "product": "Rocket.Chat", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.03201, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87694, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-39713", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "04058ce7-b07d-4dc2-8b4b-c7750e1a3e84", "vulnerability": {"vulnId": "CVE-2021-24227", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "04058ce7-b07d-4dc2-8b4b-c7750e1a3e84", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure | Affected: Patreon / Patreon | CVSS: 7.5 (HIGH) | EPSS: 0.05927 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24227", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24227"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24227"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Patreon WordPress < 1.7.0 - Unauthenticated Local File Disclosure", "cve_id": "CVE-2021-24227", "vendor": "Patreon", "ghsa_id": null, "product": "Patreon", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.05927, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93028, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24227", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7ec16dde-9bc1-41a3-b62a-f98a9abc73f5", "vulnerability": {"vulnId": "CVE-2026-1405", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "7ec16dde-9bc1-41a3-b62a-f98a9abc73f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-07T00:00:00+00:00"}, "scope": {"notes": "Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload | Affected: Franchidesign / Slider Future | CVSS: 9.8 (CRITICAL) | EPSS: 0.03177 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-1405", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1405"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1405"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2026-1405", "vendor": "Franchidesign", "ghsa_id": null, "product": "Slider Future", "added_date": "2026-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03177, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87597, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1405", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "679067e4-61f4-4e96-b5f2-d1ab2fee657a", "vulnerability": {"vulnId": "CVE-2021-4458", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "679067e4-61f4-4e96-b5f2-d1ab2fee657a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-06T00:00:00+00:00"}, "scope": {"notes": "Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection | Affected: Webnus / Modern Events Calendar Lite | CVSS: 5.9 (MEDIUM) | EPSS: 0.00354 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-4458", "url": "https://www.cve.org/CVERecord?id=CVE-2021-4458"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-4458"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Modern Events Calendar Lite <= 6.3.0 - Unauthenticated SQL Injection", "cve_id": "CVE-2021-4458", "vendor": "Webnus", "ghsa_id": null, "product": "Modern Events Calendar Lite", "added_date": "2026-06-06T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.00354, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.26699, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-4458", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "086b923e-d811-4103-9086-f80559427cdc", "vulnerability": {"vulnId": "CVE-2021-21805", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "086b923e-d811-4103-9086-f80559427cdc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-06T00:00:00+00:00"}, "scope": {"notes": "An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted... | Affected: Advantech / R-SeeNet | CVSS: 9.8 (CRITICAL) | EPSS: 0.69842 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21805", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21805"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21805"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted...", "cve_id": "CVE-2021-21805", "vendor": "Advantech", "ghsa_id": null, "product": "R-SeeNet", "added_date": "2026-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.69842, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99355, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21805", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "76e67663-1f21-4884-a25c-0c311e82774d", "vulnerability": {"vulnId": "CVE-2022-29078", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "76e67663-1f21-4884-a25c-0c311e82774d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-06T00:00:00+00:00"}, "scope": {"notes": "The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view... | Affected: Mde / ejs | CVSS: 9.8 (CRITICAL) | EPSS: 0.32808 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29078", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29078"}, {"id": "GHSA-PHWQ-J96M-2C2Q", "url": "https://github.com/advisories/GHSA-PHWQ-J96M-2C2Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29078"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view...", "cve_id": "CVE-2022-29078", "vendor": "Mde", "ghsa_id": "GHSA-PHWQ-J96M-2C2Q", "product": "ejs", "added_date": "2026-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.32808, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98305, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29078", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7db992c8-1023-48a3-a1da-108e2b566452", "vulnerability": {"vulnId": "CVE-2022-1390", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "7db992c8-1023-48a3-a1da-108e2b566452", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-06T00:00:00+00:00"}, "scope": {"notes": "Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read | Affected: Admin Word Count Column / Admin Word Count Column | CVSS: 9.8 (CRITICAL) | EPSS: 0.21881 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1390", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1390"}, {"id": "GHSA-35FP-65CR-47Q7", "url": "https://github.com/advisories/GHSA-35FP-65CR-47Q7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1390"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Admin Word Count Column <= 2.2 - Unauthenticated Arbitrary File Read", "cve_id": "CVE-2022-1390", "vendor": "Admin Word Count Column", "ghsa_id": "GHSA-35FP-65CR-47Q7", "product": "Admin Word Count Column", "added_date": "2026-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.21881, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97582, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1390", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "edcdd99a-6f3c-4db4-a374-185acc39c742", "vulnerability": {"vulnId": "CVE-2021-27670", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "edcdd99a-6f3c-4db4-a374-185acc39c742", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-06T00:00:00+00:00"}, "scope": {"notes": "Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. | Affected: Appspace / Appspace 6.2.4 | CVSS: 9.8 (CRITICAL) | EPSS: 0.61274 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27670", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27670"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27670"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.", "cve_id": "CVE-2021-27670", "vendor": "Appspace", "ghsa_id": null, "product": "Appspace 6.2.4", "added_date": "2026-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.61274, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99139, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27670", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b471f3e9-62be-41c1-b28f-cb65575faf25", "vulnerability": {"vulnId": "CVE-2026-28318", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T20:00:36+02:00"}, "gcve": {"object_uuid": "b471f3e9-62be-41c1-b28f-cb65575faf25", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T18:00:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T18:00:36+00:00"}, "scope": {"notes": "SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability | Affected: SolarWinds / Serv-U | CVSS: 7.5 (HIGH) | EPSS: 0.01942 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-28318", "url": "https://www.cve.org/CVERecord?id=CVE-2026-28318"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-28318"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability", "cve_id": "CVE-2026-28318", "vendor": "SolarWinds", "ghsa_id": null, "product": "Serv-U", "added_date": "2026-06-05T18:00:36.180Z", "cvss_score": 7.5, "epss_score": 0.01942, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79409, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-28318", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "51147bde-f378-44d7-a860-cf91b43ccff1", "vulnerability": {"vulnId": "CVE-2026-7473", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T18:40:23+02:00"}, "gcve": {"object_uuid": "51147bde-f378-44d7-a860-cf91b43ccff1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T16:40:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T16:40:23+00:00"}, "scope": {"notes": "Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass | Affected: Arista / EOS | CVSS: 6.9 (MEDIUM) | EPSS: 0.00649 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-7473", "url": "https://www.cve.org/CVERecord?id=CVE-2026-7473"}, {"id": "GHSA-MCX4-VM6V-R473", "url": "https://github.com/advisories/GHSA-MCX4-VM6V-R473"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-7473"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass", "cve_id": "CVE-2026-7473", "vendor": "Arista", "ghsa_id": "GHSA-MCX4-VM6V-R473", "product": "EOS", "added_date": "2026-06-05T16:40:23.554Z", "cvss_score": 6.9, "epss_score": 0.00649, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.49199, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-7473", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "53d8b0ba-1241-410b-9ae7-f7bcae66a527", "vulnerability": {"vulnId": "CVE-2026-3300", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T11:20:13+02:00"}, "gcve": {"object_uuid": "53d8b0ba-1241-410b-9ae7-f7bcae66a527", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T09:20:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T09:20:13+00:00"}, "scope": {"notes": "Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field | Affected: WPEverest / Everest Forms Pro | CVSS: 9.8 (CRITICAL) | EPSS: 0.04431 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-3300", "url": "https://www.cve.org/CVERecord?id=CVE-2026-3300"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-3300"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field", "cve_id": "CVE-2026-3300", "vendor": "WPEverest", "ghsa_id": null, "product": "Everest Forms Pro", "added_date": "2026-06-05T09:20:13.225Z", "cvss_score": 9.8, "epss_score": 0.04431, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91068, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-3300", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b95031d5-c944-45da-b1a3-a3b5459f6097", "vulnerability": {"vulnId": "CVE-2026-20245", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T08:24:20+02:00"}, "gcve": {"object_uuid": "b95031d5-c944-45da-b1a3-a3b5459f6097", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T06:24:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T06:24:20+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager | CVSS: 7.8 (HIGH) | EPSS: 0.25323 | Used in malware: unknown | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20245", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20245"}, {"id": "GHSA-H4C6-CM2M-H5F6", "url": "https://github.com/advisories/GHSA-H4C6-CM2M-H5F6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20245"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability", "cve_id": "CVE-2026-20245", "vendor": "Cisco", "ghsa_id": "GHSA-H4C6-CM2M-H5F6", "product": "Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-05T06:24:20.000Z", "cvss_score": 7.8, "epss_score": 0.25323, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97883, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20245", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e1ec531e-bdfe-4260-8e2b-f16a8bde143d", "vulnerability": {"vulnId": "CVE-2025-30567", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "e1ec531e-bdfe-4260-8e2b-f16a8bde143d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T00:00:00+00:00"}, "scope": {"notes": "WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability | Affected: WP01 / WP01 | CVSS: 7.5 (HIGH) | EPSS: 0.02834 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-30567", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30567"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30567"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability", "cve_id": "CVE-2025-30567", "vendor": "WP01", "ghsa_id": null, "product": "WP01", "added_date": "2026-06-05T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02834, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86141, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30567", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "61585ba9-6434-43a8-88fb-41e395ee36d1", "vulnerability": {"vulnId": "CVE-2024-27564", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "61585ba9-6434-43a8-88fb-41e395ee36d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T00:00:00+00:00"}, "scope": {"notes": "pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy... | Affected: dirk1983 / mm1.ltd source code | CVSS: 5.8 (MEDIUM) | EPSS: 0.40637 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-27564", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27564"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27564"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy...", "cve_id": "CVE-2024-27564", "vendor": "dirk1983", "ghsa_id": null, "product": "mm1.ltd source code", "added_date": "2026-06-05T00:00:00.000Z", "cvss_score": 5.8, "epss_score": 0.40637, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27564", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6327991b-0389-4872-8d44-fd01efa9a7c0", "vulnerability": {"vulnId": "CVE-2024-45309", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "6327991b-0389-4872-8d44-fd01efa9a7c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-05T00:00:00+00:00"}, "scope": {"notes": "OneDev vulnerable to arbitrary file reading for unauthenticated user | Affected: Theonedev / onedev | CVSS: 8.7 (HIGH) | EPSS: 0.24531 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-45309", "url": "https://www.cve.org/CVERecord?id=CVE-2024-45309"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-45309"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OneDev vulnerable to arbitrary file reading for unauthenticated user", "cve_id": "CVE-2024-45309", "vendor": "Theonedev", "ghsa_id": null, "product": "onedev", "added_date": "2026-06-05T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.24531, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97817, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-45309", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4441b827-371f-4a8f-94f7-b8ce3330e4de", "vulnerability": {"vulnId": "CVE-2025-67303", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "4441b827-371f-4a8f-94f7-b8ce3330e4de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-04T00:00:00+00:00"}, "scope": {"notes": "An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was... | Affected: Comfy-Org / ComfyUI-Manager | CVSS: 7.5 (HIGH) | EPSS: 0.01412 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-67303", "url": "https://www.cve.org/CVERecord?id=CVE-2025-67303"}, {"id": "GHSA-95PQ-HR8P-F5G7", "url": "https://github.com/advisories/GHSA-95PQ-HR8P-F5G7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-67303"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was...", "cve_id": "CVE-2025-67303", "vendor": "Comfy-Org", "ghsa_id": "GHSA-95PQ-HR8P-F5G7", "product": "ComfyUI-Manager", "added_date": "2026-06-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01412, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71718, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-67303", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6c6832c7-2ec5-47da-aff8-c5ab0d8654da", "vulnerability": {"vulnId": "CVE-2022-24716", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "6c6832c7-2ec5-47da-aff8-c5ab0d8654da", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-04T00:00:00+00:00"}, "scope": {"notes": "Path traversal in Icinga Web 2 | Affected: Icinga / icingaweb2 | CVSS: 7.5 (HIGH) | EPSS: 0.89378 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-24716", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24716"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24716"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path traversal in Icinga Web 2", "cve_id": "CVE-2022-24716", "vendor": "Icinga", "ghsa_id": null, "product": "icingaweb2", "added_date": "2026-06-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.89378, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99781, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24716", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "124443a9-a990-46b0-833d-cb11402abab4", "vulnerability": {"vulnId": "CVE-2020-13379", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "124443a9-a990-46b0-833d-cb11402abab4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-04T00:00:00+00:00"}, "scope": {"notes": "The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated... | Affected: Grafana / Grafana | CVSS: 8.2 (HIGH) | EPSS: 0.99856 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-13379", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13379"}, {"id": "GHSA-WC9W-WVQ2-FFM9", "url": "https://github.com/advisories/GHSA-WC9W-WVQ2-FFM9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13379"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated...", "cve_id": "CVE-2020-13379", "vendor": "Grafana", "ghsa_id": "GHSA-WC9W-WVQ2-FFM9", "product": "Grafana", "added_date": "2026-06-04T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.99856, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9996, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13379", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "588bb319-773f-4c0f-aa02-51fcb2032786", "vulnerability": {"vulnId": "CVE-2023-6875", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "588bb319-773f-4c0f-aa02-51fcb2032786", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-04T00:00:00+00:00"}, "scope": {"notes": "The POST SMTP Mailer \u2013 Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to... | Affected: WPExperts.io / POST SMTP \u2013 The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications | CVSS: 9.8 (CRITICAL) | EPSS: 0.90339 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6875", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6875"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6875"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The POST SMTP Mailer \u2013 Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to...", "cve_id": "CVE-2023-6875", "vendor": "WPExperts.io", "ghsa_id": null, "product": "POST SMTP \u2013 The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications", "added_date": "2026-06-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90339, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99797, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6875", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "80a2ae60-30f5-4065-9c70-117f7ca96633", "vulnerability": {"vulnId": "CVE-2024-6671", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "80a2ae60-30f5-4065-9c70-117f7ca96633", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-04T00:00:00+00:00"}, "scope": {"notes": "WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability | Affected: Progress Software / WhatsUp Gold | CVSS: 9.8 (CRITICAL) | EPSS: 0.18988 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6671", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6671"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6671"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability", "cve_id": "CVE-2024-6671", "vendor": "Progress Software", "ghsa_id": null, "product": "WhatsUp Gold", "added_date": "2026-06-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.18988, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97224, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6671", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "12e0e32c-e8c7-4d7b-b939-9647f081c92e", "vulnerability": {"vulnId": "CVE-2023-22620", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "12e0e32c-e8c7-4d7b-b939-9647f081c92e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-04T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an... | Affected: SecurePoint / UTM | CVSS: 7.5 (HIGH) | EPSS: 0.0392 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-22620", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22620"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22620"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an...", "cve_id": "CVE-2023-22620", "vendor": "SecurePoint", "ghsa_id": null, "product": "UTM", "added_date": "2026-06-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0392, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90007, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-22620", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e6feafe9-f36c-4b4a-a2b7-84f1dc0df378", "vulnerability": {"vulnId": "CVE-2026-45247", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T20:00:21+02:00"}, "gcve": {"object_uuid": "e6feafe9-f36c-4b4a-a2b7-84f1dc0df378", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T18:00:21+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T18:00:21+00:00"}, "scope": {"notes": "Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection | Affected: Mirasvit / Full Page Cache Warmer for Magento 2 | CVSS: 9.3 (CRITICAL) | EPSS: 0.02085 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-45247", "url": "https://www.cve.org/CVERecord?id=CVE-2026-45247"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-45247"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection", "cve_id": "CVE-2026-45247", "vendor": "Mirasvit", "ghsa_id": null, "product": "Full Page Cache Warmer for Magento 2", "added_date": "2026-06-03T18:00:21.829Z", "cvss_score": 9.3, "epss_score": 0.02085, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80875, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-45247", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8ff42f1d-bf9f-4c1a-adfd-915e6e00b7d6", "vulnerability": {"vulnId": "CVE-2025-48827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T12:06:54+02:00"}, "gcve": {"object_uuid": "8ff42f1d-bf9f-4c1a-adfd-915e6e00b7d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T10:06:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T10:06:54+00:00"}, "scope": {"notes": "vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP... | Affected: vBulletin / vBulletin | CVSS: 10.0 (CRITICAL) | EPSS: 0.75844 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-48827", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP...", "cve_id": "CVE-2025-48827", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2026-06-03T10:06:54.268Z", "cvss_score": 10.0, "epss_score": 0.75844, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99512, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "abc89a83-f375-4108-bd69-78d4eed4ea70", "vulnerability": {"vulnId": "CVE-2026-8206", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T10:20:48+02:00"}, "gcve": {"object_uuid": "abc89a83-f375-4108-bd69-78d4eed4ea70", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T08:20:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T08:20:48+00:00"}, "scope": {"notes": "Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password' | Affected: Themeum / Kirki \u2013 Freeform Page Builder, Website Builder & Customizer | CVSS: 9.8 (CRITICAL) | EPSS: 0.00772 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-8206", "url": "https://www.cve.org/CVERecord?id=CVE-2026-8206"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-8206"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'", "cve_id": "CVE-2026-8206", "vendor": "Themeum", "ghsa_id": null, "product": "Kirki \u2013 Freeform Page Builder, Website Builder & Customizer", "added_date": "2026-06-03T08:20:48.478Z", "cvss_score": 9.8, "epss_score": 0.00772, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.54029, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-8206", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "905ccf8e-7ea6-491c-8828-0893732fc2d7", "vulnerability": {"vulnId": "CVE-2025-9316", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T02:00:00+02:00"}, "gcve": {"object_uuid": "905ccf8e-7ea6-491c-8828-0893732fc2d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T00:00:00+00:00"}, "scope": {"notes": "N-central unauthenticated sessionID generation | Affected: N-able / N-central | CVSS: 6.9 (MEDIUM) | EPSS: 0.36287 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-9316", "url": "https://www.cve.org/CVERecord?id=CVE-2025-9316"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-9316"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "N-central unauthenticated sessionID generation", "cve_id": "CVE-2025-9316", "vendor": "N-able", "ghsa_id": null, "product": "N-central", "added_date": "2026-06-03T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.36287, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98439, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-9316", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bee07377-b5c6-4d42-b046-bad7fca6a6c1", "vulnerability": {"vulnId": "CVE-2026-41176", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T02:00:00+02:00"}, "gcve": {"object_uuid": "bee07377-b5c6-4d42-b046-bad7fca6a6c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T00:00:00+00:00"}, "scope": {"notes": "Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution | Affected: Rclone / rclone | CVSS: 9.2 (CRITICAL) | EPSS: 0.03216 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-41176", "url": "https://www.cve.org/CVERecord?id=CVE-2026-41176"}, {"id": "GHSA-25QR-6MPR-F7QX", "url": "https://github.com/advisories/GHSA-25QR-6MPR-F7QX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-41176"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution", "cve_id": "CVE-2026-41176", "vendor": "Rclone", "ghsa_id": "GHSA-25QR-6MPR-F7QX", "product": "rclone", "added_date": "2026-06-03T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.03216, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87765, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-41176", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e1e27452-7075-497f-923b-9580b2b931f7", "vulnerability": {"vulnId": "CVE-2023-6909", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T02:00:00+02:00"}, "gcve": {"object_uuid": "e1e27452-7075-497f-923b-9580b2b931f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T00:00:00+00:00"}, "scope": {"notes": "Path Traversal: '\\..\\filename' in mlflow/mlflow | Affected: Mlflow / mlflow/mlflow | CVSS: 7.5 (HIGH) | EPSS: 0.89716 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6909", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6909"}, {"id": "GHSA-5R3Q-93Q3-F978", "url": "https://github.com/advisories/GHSA-5R3Q-93Q3-F978"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6909"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path Traversal: '\\..\\filename' in mlflow/mlflow", "cve_id": "CVE-2023-6909", "vendor": "Mlflow", "ghsa_id": "GHSA-5R3Q-93Q3-F978", "product": "mlflow/mlflow", "added_date": "2026-06-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.89716, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99787, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6909", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9d737c23-0683-41eb-9be5-d8221a79ff2b", "vulnerability": {"vulnId": "CVE-2022-4059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-03T02:00:00+02:00"}, "gcve": {"object_uuid": "9d737c23-0683-41eb-9be5-d8221a79ff2b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-03T00:00:00+00:00"}, "scope": {"notes": "Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi | Affected: Cryptocurrency Widgets Pack / Cryptocurrency Widgets Pack | CVSS: 9.8 (CRITICAL) | EPSS: 0.04795 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4059", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4059"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi", "cve_id": "CVE-2022-4059", "vendor": "Cryptocurrency Widgets Pack", "ghsa_id": null, "product": "Cryptocurrency Widgets Pack", "added_date": "2026-06-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04795, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91661, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ad20e2f1-a766-4459-b2a8-86183c26699d", "vulnerability": {"vulnId": "CVE-2022-0492", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-02T20:00:02+02:00"}, "gcve": {"object_uuid": "ad20e2f1-a766-4459-b2a8-86183c26699d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-02T18:00:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-02T18:00:02+00:00"}, "scope": {"notes": "A vulnerability was found in the Linux kernel\u2019s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain... | Affected: Linux / kernel | CVSS: 7.8 (HIGH) | EPSS: 0.05528 | Used in malware: unknown | Listed 1 hour ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0492", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0492"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0492"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability was found in the Linux kernel\u2019s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain...", "cve_id": "CVE-2022-0492", "vendor": "Linux", "ghsa_id": null, "product": "kernel", "added_date": "2026-06-02T18:00:02.476Z", "cvss_score": 7.8, "epss_score": 0.05528, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92564, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0492", "ahead_of_cisa_kev": {"unit": "hour", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7cfc8233-220b-48c3-88f7-e1fe49e6a322", "vulnerability": {"vulnId": "CVE-2025-48595", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-02T14:15:00+02:00"}, "gcve": {"object_uuid": "7cfc8233-220b-48c3-88f7-e1fe49e6a322", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-02T12:15:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-02T12:15:00+00:00"}, "scope": {"notes": "In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of... | Affected: Google / Android | CVSS: 8.4 (HIGH) | EPSS: 0.01714 | Used in malware: unknown | Listed 6 hours ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48595", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48595"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48595"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of...", "cve_id": "CVE-2025-48595", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2026-06-02T12:15:00.000Z", "cvss_score": 8.4, "epss_score": 0.01714, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76562, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48595", "ahead_of_cisa_kev": {"unit": "hour", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b1627b53-b217-4c94-b676-c75dfe55b507", "vulnerability": {"vulnId": "CVE-2024-21182", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T20:00:02+02:00"}, "gcve": {"object_uuid": "b1627b53-b217-4c94-b676-c75dfe55b507", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T18:00:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T18:00:02+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 7.5 (HIGH) | EPSS: 0.74162 | Used in malware: unknown | Listed 1 hour ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21182", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21182"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21182"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are...", "cve_id": "CVE-2024-21182", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2026-06-01T18:00:02.554Z", "cvss_score": 7.5, "epss_score": 0.74162, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99474, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21182", "ahead_of_cisa_kev": {"unit": "hour", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a951d712-ab8c-477b-94c5-c39fede4a6eb", "vulnerability": {"vulnId": "CVE-2023-43000", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:30:35+02:00"}, "gcve": {"object_uuid": "a951d712-ab8c-477b-94c5-c39fede4a6eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:30:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:30:35+00:00"}, "scope": {"notes": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari... | Affected: Apple / macOS, iOS and iPadOS, Safari | CVSS: 8.8 (HIGH) | EPSS: 0.03898 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-43000", "url": "https://www.cve.org/CVERecord?id=CVE-2023-43000"}, {"id": "GHSA-96FF-3RWM-724G", "url": "https://github.com/advisories/GHSA-96FF-3RWM-724G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-43000"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari...", "cve_id": "CVE-2023-43000", "vendor": "Apple", "ghsa_id": "GHSA-96FF-3RWM-724G", "product": "macOS, iOS and iPadOS, Safari", "added_date": "2026-06-01T13:30:35.576Z", "cvss_score": 8.8, "epss_score": 0.03898, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89933, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-43000", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a48ed27-fcc2-41a7-ad7e-10f17d5986a8", "vulnerability": {"vulnId": "CVE-2025-31277", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:30:35+02:00"}, "gcve": {"object_uuid": "6a48ed27-fcc2-41a7-ad7e-10f17d5986a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:30:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:30:35+00:00"}, "scope": {"notes": "The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6,... | Affected: Apple / Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 8.8 (HIGH) | EPSS: 0.01604 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-31277", "url": "https://www.cve.org/CVERecord?id=CVE-2025-31277"}, {"id": "GHSA-VRFH-8V52-6452", "url": "https://github.com/advisories/GHSA-VRFH-8V52-6452"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-31277"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6,...", "cve_id": "CVE-2025-31277", "vendor": "Apple", "ghsa_id": "GHSA-VRFH-8V52-6452", "product": "Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2026-06-01T13:30:35.304Z", "cvss_score": 8.8, "epss_score": 0.01604, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-31277", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "49eb10b1-af11-4a00-9cd5-c0b0c827ded7", "vulnerability": {"vulnId": "CVE-2026-9082", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:38+02:00"}, "gcve": {"object_uuid": "49eb10b1-af11-4a00-9cd5-c0b0c827ded7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:38+00:00"}, "scope": {"notes": "Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 | Affected: Drupal / Drupal core | CVSS: 9.8 (CRITICAL) | EPSS: 0.15701 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-9082", "url": "https://www.cve.org/CVERecord?id=CVE-2026-9082"}, {"id": "GHSA-GHWC-95X2-682J", "url": "https://github.com/advisories/GHSA-GHWC-95X2-682J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-9082"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Drupal core - Highly critical - SQL injection - SA-CORE-2026-004", "cve_id": "CVE-2026-9082", "vendor": "Drupal", "ghsa_id": "GHSA-GHWC-95X2-682J", "product": "Drupal core", "added_date": "2026-06-01T13:29:38.047Z", "cvss_score": 9.8, "epss_score": 0.15701, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.96759, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-9082", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a336713b-5f1c-42a0-8f98-52c3b99ab9d9", "vulnerability": {"vulnId": "CVE-2026-48172", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:31+02:00"}, "gcve": {"object_uuid": "a336713b-5f1c-42a0-8f98-52c3b99ab9d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:31+00:00"}, "scope": {"notes": "LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is... | Affected: LiteSpeed Technologies / cPanel Plugin, WHM Plugin | CVSS: 10.0 (CRITICAL) | EPSS: 0.01011 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48172", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48172"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48172"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is...", "cve_id": "CVE-2026-48172", "vendor": "LiteSpeed Technologies", "ghsa_id": null, "product": "cPanel Plugin, WHM Plugin", "added_date": "2026-06-01T13:29:31.681Z", "cvss_score": 10.0, "epss_score": 0.01011, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-48172", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e7b7427a-faaa-4127-a324-53fc2ead4811", "vulnerability": {"vulnId": "CVE-2026-34926", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:30+02:00"}, "gcve": {"object_uuid": "e7b7427a-faaa-4127-a324-53fc2ead4811", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:30+00:00"}, "scope": {"notes": "A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the... | Affected: Trend Micro / TrendAI Apex One, TrendAI Apex One as a Service | CVSS: 6.7 (MEDIUM) | EPSS: 0.00538 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34926", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34926"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34926"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the...", "cve_id": "CVE-2026-34926", "vendor": "Trend Micro", "ghsa_id": null, "product": "TrendAI Apex One, TrendAI Apex One as a Service", "added_date": "2026-06-01T13:29:30.761Z", "cvss_score": 6.7, "epss_score": 0.00538, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.43185, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34926", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dc642cda-5f00-4db2-ac56-59041e2debbe", "vulnerability": {"vulnId": "CVE-2025-34291", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:30+02:00"}, "gcve": {"object_uuid": "dc642cda-5f00-4db2-ac56-59041e2debbe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:30+00:00"}, "scope": {"notes": "Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE | Affected: Langflow / Langflow | CVSS: 9.4 (CRITICAL) | EPSS: 0.92808 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-34291", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34291"}, {"id": "GHSA-577H-P2HH-V4MV", "url": "https://github.com/advisories/GHSA-577H-P2HH-V4MV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34291"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE", "cve_id": "CVE-2025-34291", "vendor": "Langflow", "ghsa_id": "GHSA-577H-P2HH-V4MV", "product": "Langflow", "added_date": "2026-06-01T13:29:30.499Z", "cvss_score": 9.4, "epss_score": 0.92808, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99828, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34291", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "122bbb77-ff7a-4c6d-bab6-20bd3dd549a4", "vulnerability": {"vulnId": "CVE-2026-41091", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:26+02:00"}, "gcve": {"object_uuid": "122bbb77-ff7a-4c6d-bab6-20bd3dd549a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:26+00:00"}, "scope": {"notes": "Microsoft Defender Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Malware Protection Engine | CVSS: 7.8 (HIGH) | EPSS: 0.00443 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-41091", "url": "https://www.cve.org/CVERecord?id=CVE-2026-41091"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-41091"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Defender Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-41091", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Malware Protection Engine", "added_date": "2026-06-01T13:29:26.114Z", "cvss_score": 7.8, "epss_score": 0.00443, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.36229, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-41091", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "da081582-c19c-4969-93ee-f0023175ea70", "vulnerability": {"vulnId": "CVE-2026-45498", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:26+02:00"}, "gcve": {"object_uuid": "da081582-c19c-4969-93ee-f0023175ea70", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:26+00:00"}, "scope": {"notes": "Microsoft Defender Denial of Service Vulnerability | Affected: Microsoft / Microsoft Defender Antimalware Platform | CVSS: 4.0 (MEDIUM) | EPSS: 0.01267 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-45498", "url": "https://www.cve.org/CVERecord?id=CVE-2026-45498"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-45498"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Defender Denial of Service Vulnerability", "cve_id": "CVE-2026-45498", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Defender Antimalware Platform", "added_date": "2026-06-01T13:29:26.865Z", "cvss_score": 4.0, "epss_score": 0.01267, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68692, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-45498", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "39d43169-1c8d-493b-b7f3-557b786168c2", "vulnerability": {"vulnId": "CVE-2026-34234", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:18+02:00"}, "gcve": {"object_uuid": "39d43169-1c8d-493b-b7f3-557b786168c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:18+00:00"}, "scope": {"notes": "CtrlPanel: Unauthenticated RCE using installer script | Affected: Ctrlpanel-gg / panel | CVSS: 10.0 (CRITICAL) | EPSS: 0.04539 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-34234", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34234"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34234"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CtrlPanel: Unauthenticated RCE using installer script", "cve_id": "CVE-2026-34234", "vendor": "Ctrlpanel-gg", "ghsa_id": null, "product": "panel", "added_date": "2026-06-01T13:29:18.130Z", "cvss_score": 10.0, "epss_score": 0.04539, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91257, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34234", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8d7a07cd-3c45-434f-9828-6bdcee637c48", "vulnerability": {"vulnId": "CVE-2026-42897", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:29:03+02:00"}, "gcve": {"object_uuid": "8d7a07cd-3c45-434f-9828-6bdcee637c48", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:29:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:29:03+00:00"}, "scope": {"notes": "Microsoft Exchange Server Spoofing Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM | CVSS: 8.1 (HIGH) | EPSS: 0.00519 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-42897", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42897"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42897"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Spoofing Vulnerability", "cve_id": "CVE-2026-42897", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM", "added_date": "2026-06-01T13:29:03.497Z", "cvss_score": 8.1, "epss_score": 0.00519, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.42013, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42897", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a82c28bf-d985-4025-8e9e-b8dea9cb5588", "vulnerability": {"vulnId": "CVE-2026-42208", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:26:37+02:00"}, "gcve": {"object_uuid": "a82c28bf-d985-4025-8e9e-b8dea9cb5588", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:26:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:26:37+00:00"}, "scope": {"notes": "LiteLLM: SQL injection in Proxy API key verification | Affected: BerriAI / litellm | CVSS: 9.3 (CRITICAL) | EPSS: 0.05772 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-42208", "url": "https://www.cve.org/CVERecord?id=CVE-2026-42208"}, {"id": "GHSA-R75F-5X8P-QVMC", "url": "https://github.com/advisories/GHSA-R75F-5X8P-QVMC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-42208"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LiteLLM: SQL injection in Proxy API key verification", "cve_id": "CVE-2026-42208", "vendor": "BerriAI", "ghsa_id": "GHSA-R75F-5X8P-QVMC", "product": "litellm", "added_date": "2026-06-01T13:26:37.184Z", "cvss_score": 9.3, "epss_score": 0.05772, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92857, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-42208", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bfe4d246-5fad-4de4-8ced-2b88b87321ed", "vulnerability": {"vulnId": "CVE-2026-6973", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:26:33+02:00"}, "gcve": {"object_uuid": "bfe4d246-5fad-4de4-8ced-2b88b87321ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:26:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:26:33+00:00"}, "scope": {"notes": "An Improper Input Validation in Ivanti EPMM\u00a0before\u00a0versions 12.6.1.1, 12.7.0.1, and 12.8.0.1\u00a0allows\u00a0a remotely authenticated user... | Affected: Ivanti / Endpoint Manager Mobile | CVSS: 7.2 (HIGH) | EPSS: 0.02537 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-6973", "url": "https://www.cve.org/CVERecord?id=CVE-2026-6973"}, {"id": "GHSA-36FG-FFJJ-H5P6", "url": "https://github.com/advisories/GHSA-36FG-FFJJ-H5P6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-6973"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Input Validation in Ivanti EPMM\u00a0before\u00a0versions 12.6.1.1, 12.7.0.1, and 12.8.0.1\u00a0allows\u00a0a remotely authenticated user...", "cve_id": "CVE-2026-6973", "vendor": "Ivanti", "ghsa_id": "GHSA-36FG-FFJJ-H5P6", "product": "Endpoint Manager Mobile", "added_date": "2026-06-01T13:26:33.373Z", "cvss_score": 7.2, "epss_score": 0.02537, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84384, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-6973", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7b3b31a5-916c-4212-a282-f19bf942dc93", "vulnerability": {"vulnId": "CVE-2026-44742", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:26:33+02:00"}, "gcve": {"object_uuid": "7b3b31a5-916c-4212-a282-f19bf942dc93", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:26:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:26:33+00:00"}, "scope": {"notes": "Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May... | Affected: Postorius project / Postorius | CVSS: 7.2 (HIGH) | EPSS: 0.00334 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-44742", "url": "https://www.cve.org/CVERecord?id=CVE-2026-44742"}, {"id": "GHSA-R7C9-7PJQ-HMM8", "url": "https://github.com/advisories/GHSA-R7C9-7PJQ-HMM8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-44742"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May...", "cve_id": "CVE-2026-44742", "vendor": "Postorius project", "ghsa_id": "GHSA-R7C9-7PJQ-HMM8", "product": "Postorius", "added_date": "2026-06-01T13:26:33.175Z", "cvss_score": 7.2, "epss_score": 0.00334, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.24338, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-44742", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "29b1bf21-c6b3-4304-9851-c4669ac22fea", "vulnerability": {"vulnId": "CVE-2026-0300", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:26:25+02:00"}, "gcve": {"object_uuid": "29b1bf21-c6b3-4304-9851-c4669ac22fea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:26:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:26:25+00:00"}, "scope": {"notes": "PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID\u2122 Authentication Portal | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 9.3 (CRITICAL) | EPSS: 0.31725 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-0300", "url": "https://www.cve.org/CVERecord?id=CVE-2026-0300"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-0300"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID\u2122 Authentication Portal", "cve_id": "CVE-2026-0300", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2026-06-01T13:26:25.457Z", "cvss_score": 9.3, "epss_score": 0.31725, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98247, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-0300", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b6c67852-93e4-424a-97b5-ef6b2adc0aab", "vulnerability": {"vulnId": "CVE-2026-31431", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:26:07+02:00"}, "gcve": {"object_uuid": "b6c67852-93e4-424a-97b5-ef6b2adc0aab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:26:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:26:07+00:00"}, "scope": {"notes": "crypto: algif_aead - Revert to operating out-of-place | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.03437 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-31431", "url": "https://www.cve.org/CVERecord?id=CVE-2026-31431"}, {"id": "GHSA-2274-3HGR-WXV6", "url": "https://github.com/advisories/GHSA-2274-3HGR-WXV6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-31431"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "crypto: algif_aead - Revert to operating out-of-place", "cve_id": "CVE-2026-31431", "vendor": "Linux", "ghsa_id": "GHSA-2274-3HGR-WXV6", "product": "Linux", "added_date": "2026-06-01T13:26:07.375Z", "cvss_score": 7.8, "epss_score": 0.03437, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88569, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-31431", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "277fa3ea-1273-43df-b0fc-a4acedb3707b", "vulnerability": {"vulnId": "CVE-2026-32202", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:25:49+02:00"}, "gcve": {"object_uuid": "277fa3ea-1273-43df-b0fc-a4acedb3707b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:25:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:25:49+00:00"}, "scope": {"notes": "Windows Shell Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 4.3 (MEDIUM) | EPSS: 0.04902 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-32202", "url": "https://www.cve.org/CVERecord?id=CVE-2026-32202"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-32202"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Shell Spoofing Vulnerability", "cve_id": "CVE-2026-32202", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T13:25:49.558Z", "cvss_score": 4.3, "epss_score": 0.04902, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9182, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-32202", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "23cfc02d-fc39-4689-87c5-ca116ab65146", "vulnerability": {"vulnId": "CVE-2024-1708", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:24:35+02:00"}, "gcve": {"object_uuid": "23cfc02d-fc39-4689-87c5-ca116ab65146", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:24:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:24:35+00:00"}, "scope": {"notes": "Improper limitation of a pathname to a restricted directory (\u201cpath traversal\u201d) | Affected: ConnectWise / ScreenConnect | CVSS: 8.4 (HIGH) | EPSS: 0.95436 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-1708", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1708"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1708"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper limitation of a pathname to a restricted directory (\u201cpath traversal\u201d)", "cve_id": "CVE-2024-1708", "vendor": "ConnectWise", "ghsa_id": null, "product": "ScreenConnect", "added_date": "2026-06-01T13:24:35.769Z", "cvss_score": 8.4, "epss_score": 0.95436, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99868, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-1708", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "000c0f5b-95ed-405e-b790-86c7fa566cfb", "vulnerability": {"vulnId": "CVE-2024-57726", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:23:43+02:00"}, "gcve": {"object_uuid": "000c0f5b-95ed-405e-b790-86c7fa566cfb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:23:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:23:43+00:00"}, "scope": {"notes": "SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive... | Affected: SimpleHelp / SimpleHelp remote support software | CVSS: 9.9 (CRITICAL) | EPSS: 0.66601 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-57726", "url": "https://www.cve.org/CVERecord?id=CVE-2024-57726"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-57726"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive...", "cve_id": "CVE-2024-57726", "vendor": "SimpleHelp", "ghsa_id": null, "product": "SimpleHelp remote support software", "added_date": "2026-06-01T13:23:43.375Z", "cvss_score": 9.9, "epss_score": 0.66601, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99268, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-57726", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a364cd9e-9bf1-4433-8244-8f54502bb55a", "vulnerability": {"vulnId": "CVE-2024-7399", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:23:43+02:00"}, "gcve": {"object_uuid": "a364cd9e-9bf1-4433-8244-8f54502bb55a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:23:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:23:43+00:00"}, "scope": {"notes": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to... | Affected: Samsung Electronics / MagicINFO 9 Server | CVSS: 8.8 (HIGH) | EPSS: 0.91941 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-7399", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7399"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7399"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to...", "cve_id": "CVE-2024-7399", "vendor": "Samsung Electronics", "ghsa_id": null, "product": "MagicINFO 9 Server", "added_date": "2026-06-01T13:23:43.436Z", "cvss_score": 8.8, "epss_score": 0.91941, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99817, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7399", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ebeb21b-1270-4ced-87a2-099d33e3e3fb", "vulnerability": {"vulnId": "CVE-2024-57728", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:23:43+02:00"}, "gcve": {"object_uuid": "2ebeb21b-1270-4ced-87a2-099d33e3e3fb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:23:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:23:43+00:00"}, "scope": {"notes": "SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a... | Affected: SimpleHelp / SimpleHelp remote support software | CVSS: 7.2 (HIGH) | EPSS: 0.64664 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-57728", "url": "https://www.cve.org/CVERecord?id=CVE-2024-57728"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-57728"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a...", "cve_id": "CVE-2024-57728", "vendor": "SimpleHelp", "ghsa_id": null, "product": "SimpleHelp remote support software", "added_date": "2026-06-01T13:23:43.404Z", "cvss_score": 7.2, "epss_score": 0.64664, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99221, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-57728", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "04ae674a-133d-4f0a-9bba-ff27aa68b106", "vulnerability": {"vulnId": "CVE-2025-29635", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:23:43+02:00"}, "gcve": {"object_uuid": "04ae674a-133d-4f0a-9bba-ff27aa68b106", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:23:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:23:43+00:00"}, "scope": {"notes": "A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote... | Affected: D-Link / DIR-823X | CVSS: 7.2 (HIGH) | EPSS: 0.87944 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-29635", "url": "https://www.cve.org/CVERecord?id=CVE-2025-29635"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-29635"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote...", "cve_id": "CVE-2025-29635", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-823X", "added_date": "2026-06-01T13:23:43.718Z", "cvss_score": 7.2, "epss_score": 0.87944, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99762, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-29635", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4cd1433f-12ad-41a5-bbff-eb6bdd4312b3", "vulnerability": {"vulnId": "CVE-2026-39987", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:23:39+02:00"}, "gcve": {"object_uuid": "4cd1433f-12ad-41a5-bbff-eb6bdd4312b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:23:39+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:23:39+00:00"}, "scope": {"notes": "marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass | Affected: Marimo-team / marimo | CVSS: 9.3 (CRITICAL) | EPSS: 0.37865 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-39987", "url": "https://www.cve.org/CVERecord?id=CVE-2026-39987"}, {"id": "GHSA-2679-6MX9-H9XC", "url": "https://github.com/advisories/GHSA-2679-6MX9-H9XC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-39987"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass", "cve_id": "CVE-2026-39987", "vendor": "Marimo-team", "ghsa_id": "GHSA-2679-6MX9-H9XC", "product": "marimo", "added_date": "2026-06-01T13:23:39.702Z", "cvss_score": 9.3, "epss_score": 0.37865, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98505, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-39987", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0d1f8b01-c3ba-4b2c-a230-81a173598f5c", "vulnerability": {"vulnId": "CVE-2026-33825", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:36+02:00"}, "gcve": {"object_uuid": "0d1f8b01-c3ba-4b2c-a230-81a173598f5c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:36+00:00"}, "scope": {"notes": "Microsoft Defender Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Defender Antimalware Platform | CVSS: 7.8 (HIGH) | EPSS: 0.00399 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-33825", "url": "https://www.cve.org/CVERecord?id=CVE-2026-33825"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-33825"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Defender Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-33825", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Defender Antimalware Platform", "added_date": "2026-06-01T13:22:36.497Z", "cvss_score": 7.8, "epss_score": 0.00399, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.31704, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-33825", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "855fe039-7346-4af3-abb7-56ca48e4a034", "vulnerability": {"vulnId": "CVE-2026-20122", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "855fe039-7346-4af3-abb7-56ca48e4a034", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 5.4 (MEDIUM) | EPSS: 0.24978 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20122", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20122"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20122"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability", "cve_id": "CVE-2026-20122", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-01T13:22:22.601Z", "cvss_score": 5.4, "epss_score": 0.24978, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97854, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20122", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "64db0bc9-4d38-4f89-85ce-ec95a7dcb7f9", "vulnerability": {"vulnId": "CVE-2023-27351", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "64db0bc9-4d38-4f89-85ce-ec95a7dcb7f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication... | Affected: PaperCut / NG | CVSS: 7.5 (HIGH) | EPSS: 0.78052 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-27351", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27351"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27351"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication...", "cve_id": "CVE-2023-27351", "vendor": "PaperCut", "ghsa_id": null, "product": "NG", "added_date": "2026-06-01T13:22:22.013Z", "cvss_score": 7.5, "epss_score": 0.78052, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99564, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-27351", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3f469482-4af9-4a1a-a315-a0bb9f30b0be", "vulnerability": {"vulnId": "CVE-2025-48700", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "3f469482-4af9-4a1a-a315-a0bb9f30b0be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra... | Affected: Zimbra / Zimbra Collaboration (ZCS) | CVSS: 6.1 (MEDIUM) | EPSS: 0.01713 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48700", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48700"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48700"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra...", "cve_id": "CVE-2025-48700", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration (ZCS)", "added_date": "2026-06-01T13:22:22.416Z", "cvss_score": 6.1, "epss_score": 0.01713, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76545, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48700", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "664381a5-9b23-4192-bb8d-5fcfa5ee13d2", "vulnerability": {"vulnId": "CVE-2025-2749", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "664381a5-9b23-4192-bb8d-5fcfa5ee13d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE | Affected: Kentico / Xperience | CVSS: 7.2 (HIGH) | EPSS: 0.04054 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-2749", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2749"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2749"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE", "cve_id": "CVE-2025-2749", "vendor": "Kentico", "ghsa_id": null, "product": "Xperience", "added_date": "2026-06-01T13:22:22.312Z", "cvss_score": 7.2, "epss_score": 0.04054, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90332, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2749", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0796736-39fb-45bc-be38-f4f732870fa1", "vulnerability": {"vulnId": "CVE-2026-20133", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "e0796736-39fb-45bc-be38-f4f732870fa1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected... | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 6.5 (MEDIUM) | EPSS: 0.31829 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20133", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20133"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20133"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected...", "cve_id": "CVE-2026-20133", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-01T13:22:22.662Z", "cvss_score": 6.5, "epss_score": 0.31829, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98252, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20133", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4025d904-0924-4e19-acff-cf3cb6004738", "vulnerability": {"vulnId": "CVE-2026-20128", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "4025d904-0924-4e19-acff-cf3cb6004738", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 7.5 (HIGH) | EPSS: 0.07064 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20128", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20128"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20128"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability", "cve_id": "CVE-2026-20128", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-01T13:22:22.629Z", "cvss_score": 7.5, "epss_score": 0.07064, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94013, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20128", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bf4dfeb9-c89d-4719-a510-3543f3429200", "vulnerability": {"vulnId": "CVE-2025-32975", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:22:22+02:00"}, "gcve": {"object_uuid": "bf4dfeb9-c89d-4719-a510-3543f3429200", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:22:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:22:22+00:00"}, "scope": {"notes": "Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch... | Affected: Quest / KACE Systems Management Appliance | CVSS: 10.0 (CRITICAL) | EPSS: 0.02487 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32975", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32975"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32975"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch...", "cve_id": "CVE-2025-32975", "vendor": "Quest", "ghsa_id": null, "product": "KACE Systems Management Appliance", "added_date": "2026-06-01T13:22:22.342Z", "cvss_score": 10.0, "epss_score": 0.02487, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8405, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32975", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f60e5492-a313-4076-b719-5c80d2f4631f", "vulnerability": {"vulnId": "CVE-2026-32201", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:07:19+02:00"}, "gcve": {"object_uuid": "f60e5492-a313-4076-b719-5c80d2f4631f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:07:19+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:07:19+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Spoofing Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 6.5 (MEDIUM) | EPSS: 0.00983 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-32201", "url": "https://www.cve.org/CVERecord?id=CVE-2026-32201"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-32201"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Spoofing Vulnerability", "cve_id": "CVE-2026-32201", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-06-01T13:07:19.548Z", "cvss_score": 6.5, "epss_score": 0.00983, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60934, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-32201", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bdd8dff7-7701-440d-9c2b-ca30a90b5b74", "vulnerability": {"vulnId": "CVE-2026-34621", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:07:13+02:00"}, "gcve": {"object_uuid": "bdd8dff7-7701-440d-9c2b-ca30a90b5b74", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:07:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:07:13+00:00"}, "scope": {"notes": "Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321) | Affected: Adobe / Acrobat DC, Acrobat Reader DC, Acrobat 2024 | CVSS: 8.6 (HIGH) | EPSS: 0.02183 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34621", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34621"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34621"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)", "cve_id": "CVE-2026-34621", "vendor": "Adobe", "ghsa_id": null, "product": "Acrobat DC, Acrobat Reader DC, Acrobat 2024", "added_date": "2026-06-01T13:07:13.584Z", "cvss_score": 8.6, "epss_score": 0.02183, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81719, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34621", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5a8076b-f944-4110-a8fc-3a42670684e6", "vulnerability": {"vulnId": "CVE-2025-60710", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:07:10+02:00"}, "gcve": {"object_uuid": "a5a8076b-f944-4110-a8fc-3a42670684e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:07:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:07:10+00:00"}, "scope": {"notes": "Host Process for Windows Tasks Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.04598 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-60710", "url": "https://www.cve.org/CVERecord?id=CVE-2025-60710"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-60710"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Host Process for Windows Tasks Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-60710", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T13:07:10.908Z", "cvss_score": 7.8, "epss_score": 0.04598, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91366, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-60710", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "97a6e74e-5da7-4272-9340-514438bc305e", "vulnerability": {"vulnId": "CVE-2023-21529", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:07:10+02:00"}, "gcve": {"object_uuid": "97a6e74e-5da7-4272-9340-514438bc305e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:07:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:07:10+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12 | CVSS: 8.8 (HIGH) | EPSS: 0.59294 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21529", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21529"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21529"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2023-21529", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12", "added_date": "2026-06-01T13:07:10.012Z", "cvss_score": 8.8, "epss_score": 0.59294, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99093, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-21529", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "89b6d4b8-9fde-4e3f-aecd-127e5d999c71", "vulnerability": {"vulnId": "CVE-2023-36424", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:07:10+02:00"}, "gcve": {"object_uuid": "89b6d4b8-9fde-4e3f-aecd-127e5d999c71", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:07:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:07:10+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.12184 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36424", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36424"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36424"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-36424", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2026-06-01T13:07:10.027Z", "cvss_score": 7.8, "epss_score": 0.12184, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96043, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36424", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d17defa5-364e-43ee-95ed-51d97b0bf8ed", "vulnerability": {"vulnId": "CVE-2020-9715", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:07:09+02:00"}, "gcve": {"object_uuid": "d17defa5-364e-43ee-95ed-51d97b0bf8ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:07:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:07:09+00:00"}, "scope": {"notes": "Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an... | Affected: Adobe / Adobe Acrobat and Reader | CVSS: 7.8 (HIGH) | EPSS: 0.48595 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9715", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9715"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9715"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an...", "cve_id": "CVE-2020-9715", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Acrobat and Reader", "added_date": "2026-06-01T13:07:09.997Z", "cvss_score": 7.8, "epss_score": 0.48595, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9715", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6001262c-6ee3-4336-8d1f-5ed5abf37297", "vulnerability": {"vulnId": "CVE-2026-1340", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T15:06:56+02:00"}, "gcve": {"object_uuid": "6001262c-6ee3-4336-8d1f-5ed5abf37297", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T13:06:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T13:06:56+00:00"}, "scope": {"notes": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Affected: Ivanti / Endpoint Manager Mobile | CVSS: 9.8 (CRITICAL) | EPSS: 0.98639 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-1340", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1340"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1340"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.", "cve_id": "CVE-2026-1340", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager Mobile", "added_date": "2026-06-01T13:06:56.355Z", "cvss_score": 9.8, "epss_score": 0.98639, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99923, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1340", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "de81618e-3a64-490a-a2c7-efd14daf8d27", "vulnerability": {"vulnId": "CVE-2026-3502", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:42:57+02:00"}, "gcve": {"object_uuid": "de81618e-3a64-490a-a2c7-efd14daf8d27", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:42:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:42:57+00:00"}, "scope": {"notes": "TrueConf Client Update Integrity Verification Bypass | Affected: TrueConf / TrueConf Client | CVSS: 7.8 (HIGH) | EPSS: 0.00329 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-3502", "url": "https://www.cve.org/CVERecord?id=CVE-2026-3502"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-3502"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TrueConf Client Update Integrity Verification Bypass", "cve_id": "CVE-2026-3502", "vendor": "TrueConf", "ghsa_id": null, "product": "TrueConf Client", "added_date": "2026-06-01T12:42:57.616Z", "cvss_score": 7.8, "epss_score": 0.00329, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.23601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-3502", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e078033-47c5-4c16-86ff-5fd9c0e6c072", "vulnerability": {"vulnId": "CVE-2026-5281", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:42:47+02:00"}, "gcve": {"object_uuid": "6e078033-47c5-4c16-86ff-5fd9c0e6c072", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:42:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:42:47+00:00"}, "scope": {"notes": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.00703 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-5281", "url": "https://www.cve.org/CVERecord?id=CVE-2026-5281"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-5281"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute...", "cve_id": "CVE-2026-5281", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T12:42:47.145Z", "cvss_score": 8.8, "epss_score": 0.00703, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51543, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-5281", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ea6e32c2-e666-4e75-81fd-290e61ca9d7f", "vulnerability": {"vulnId": "CVE-2025-53521", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:26:16+02:00"}, "gcve": {"object_uuid": "ea6e32c2-e666-4e75-81fd-290e61ca9d7f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:26:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:26:16+00:00"}, "scope": {"notes": "BigIP APM Vulnerability | Affected: F5 / BIG-IP | CVSS: 9.3 (CRITICAL) | EPSS: 0.02295 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-53521", "url": "https://www.cve.org/CVERecord?id=CVE-2025-53521"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-53521"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BigIP APM Vulnerability", "cve_id": "CVE-2025-53521", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2026-06-01T12:26:16.067Z", "cvss_score": 9.3, "epss_score": 0.02295, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82636, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-53521", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac72de19-b1b5-4426-952f-796befd02084", "vulnerability": {"vulnId": "CVE-2026-33634", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:26:13+02:00"}, "gcve": {"object_uuid": "ac72de19-b1b5-4426-952f-796befd02084", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:26:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:26:13+00:00"}, "scope": {"notes": "Trivy ecosystem supply chain briefly compromised | Affected: Aquasecurity, BerriAI, Team-telnyx / setup-trivy, trivy-action, trivy, LiteLLM, telnyx | CVSS: 9.4 (CRITICAL) | EPSS: 0.01683 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-33634", "url": "https://www.cve.org/CVERecord?id=CVE-2026-33634"}, {"id": "GHSA-69FQ-XP46-6X23", "url": "https://github.com/advisories/GHSA-69FQ-XP46-6X23"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-33634"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Trivy ecosystem supply chain briefly compromised", "cve_id": "CVE-2026-33634", "vendor": "Aquasecurity, BerriAI, Team-telnyx", "ghsa_id": "GHSA-69FQ-XP46-6X23", "product": "setup-trivy, trivy-action, trivy, LiteLLM, telnyx", "added_date": "2026-06-01T12:26:13.195Z", "cvss_score": 9.4, "epss_score": 0.01683, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76131, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-33634", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9a5d8ad1-afb6-4595-bec4-ef6fcd2e0bc8", "vulnerability": {"vulnId": "CVE-2026-33017", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:26:07+02:00"}, "gcve": {"object_uuid": "9a5d8ad1-afb6-4595-bec4-ef6fcd2e0bc8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:26:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:26:07+00:00"}, "scope": {"notes": "Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint | Affected: Langflow-ai / langflow | CVSS: 9.3 (CRITICAL) | EPSS: 0.24755 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-33017", "url": "https://www.cve.org/CVERecord?id=CVE-2026-33017"}, {"id": "GHSA-VWMF-PQ79-VJVX", "url": "https://github.com/advisories/GHSA-VWMF-PQ79-VJVX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-33017"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint", "cve_id": "CVE-2026-33017", "vendor": "Langflow-ai", "ghsa_id": "GHSA-VWMF-PQ79-VJVX", "product": "langflow", "added_date": "2026-06-01T12:26:07.241Z", "cvss_score": 9.3, "epss_score": 0.24755, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-33017", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7e637c9e-9ff2-405a-80da-652ed2f604f7", "vulnerability": {"vulnId": "CVE-2025-43520", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:25:49+02:00"}, "gcve": {"object_uuid": "7e637c9e-9ff2-405a-80da-652ed2f604f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:25:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:25:49+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.00425 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-43520", "url": "https://www.cve.org/CVERecord?id=CVE-2025-43520"}, {"id": "GHSA-C46J-8P94-C85X", "url": "https://github.com/advisories/GHSA-C46J-8P94-C85X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-43520"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS...", "cve_id": "CVE-2025-43520", "vendor": "Apple", "ghsa_id": "GHSA-C46J-8P94-C85X", "product": "iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2026-06-01T12:25:49.913Z", "cvss_score": 5.5, "epss_score": 0.00425, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.34474, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-43520", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fd696921-281d-4218-a014-f59ae1e4c1be", "vulnerability": {"vulnId": "CVE-2025-54068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:25:49+02:00"}, "gcve": {"object_uuid": "fd696921-281d-4218-a014-f59ae1e4c1be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:25:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:25:49+00:00"}, "scope": {"notes": "Livewire vulnerable to remote command execution during property update hydration | Affected: Livewire / livewire | CVSS: 9.2 (CRITICAL) | EPSS: 0.97072 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-54068", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54068"}, {"id": "GHSA-29CQ-5W36-X7W3", "url": "https://github.com/advisories/GHSA-29CQ-5W36-X7W3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Livewire vulnerable to remote command execution during property update hydration", "cve_id": "CVE-2025-54068", "vendor": "Livewire", "ghsa_id": "GHSA-29CQ-5W36-X7W3", "product": "livewire", "added_date": "2026-06-01T12:25:49.925Z", "cvss_score": 9.2, "epss_score": 0.97072, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99891, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54068", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9fbaab0d-d558-4099-b80a-2658d730bfda", "vulnerability": {"vulnId": "CVE-2025-43510", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:25:49+02:00"}, "gcve": {"object_uuid": "9fbaab0d-d558-4099-b80a-2658d730bfda", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:25:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:25:49+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.00355 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-43510", "url": "https://www.cve.org/CVERecord?id=CVE-2025-43510"}, {"id": "GHSA-JW27-39XW-8FJX", "url": "https://github.com/advisories/GHSA-JW27-39XW-8FJX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-43510"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS...", "cve_id": "CVE-2025-43510", "vendor": "Apple", "ghsa_id": "GHSA-JW27-39XW-8FJX", "product": "iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2026-06-01T12:25:49.900Z", "cvss_score": 7.8, "epss_score": 0.00355, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.26916, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-43510", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0d58551e-561c-4815-8ecb-d7af797f76f8", "vulnerability": {"vulnId": "CVE-2025-32432", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:33+02:00"}, "gcve": {"object_uuid": "0d58551e-561c-4815-8ecb-d7af797f76f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:33+00:00"}, "scope": {"notes": "Craft CMS Allows Remote Code Execution | Affected: Craftcms / cms | CVSS: 10.0 (CRITICAL) | EPSS: 0.99785 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32432", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32432"}, {"id": "GHSA-F3GW-9WW9-JMC3", "url": "https://github.com/advisories/GHSA-F3GW-9WW9-JMC3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32432"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Craft CMS Allows Remote Code Execution", "cve_id": "CVE-2025-32432", "vendor": "Craftcms", "ghsa_id": "GHSA-F3GW-9WW9-JMC3", "product": "cms", "added_date": "2026-06-01T12:10:33.975Z", "cvss_score": 10.0, "epss_score": 0.99785, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99955, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32432", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "37f0a37e-5ee8-4165-9383-6487bfc5bbe3", "vulnerability": {"vulnId": "CVE-2026-20131", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:30+02:00"}, "gcve": {"object_uuid": "37f0a37e-5ee8-4165-9383-6487bfc5bbe3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:30+00:00"}, "scope": {"notes": "Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability | Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | CVSS: 10.0 (CRITICAL) | EPSS: 0.42665 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20131", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20131"}, {"id": "GHSA-R229-MJ76-G2QX", "url": "https://github.com/advisories/GHSA-R229-MJ76-G2QX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20131"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability", "cve_id": "CVE-2026-20131", "vendor": "Cisco", "ghsa_id": "GHSA-R229-MJ76-G2QX", "product": "Cisco Secure Firewall Management Center (FMC)", "added_date": "2026-06-01T12:10:30.171Z", "cvss_score": 10.0, "epss_score": 0.42665, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98672, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-20131", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "068cff49-2209-48b3-a227-a5c33db51fc9", "vulnerability": {"vulnId": "CVE-2026-20963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:26+02:00"}, "gcve": {"object_uuid": "068cff49-2209-48b3-a227-a5c33db51fc9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:26+00:00"}, "scope": {"notes": "Microsoft SharePoint Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 9.8 (CRITICAL) | EPSS: 0.29582 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20963", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20963"}, {"id": "GHSA-5VR8-9CF6-R7PX", "url": "https://github.com/advisories/GHSA-5VR8-9CF6-R7PX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Remote Code Execution Vulnerability", "cve_id": "CVE-2026-20963", "vendor": "Microsoft", "ghsa_id": "GHSA-5VR8-9CF6-R7PX", "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-06-01T12:10:26.788Z", "cvss_score": 9.8, "epss_score": 0.29582, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98139, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20963", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "46135b25-a20b-4072-ab5c-77af258ba11b", "vulnerability": {"vulnId": "CVE-2025-66376", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:26+02:00"}, "gcve": {"object_uuid": "46135b25-a20b-4072-ab5c-77af258ba11b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:26+00:00"}, "scope": {"notes": "Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import... | Affected: Zimbra / Collaboration | CVSS: 7.2 (HIGH) | EPSS: 0.19559 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-66376", "url": "https://www.cve.org/CVERecord?id=CVE-2025-66376"}, {"id": "GHSA-H7WG-85FJ-3C6G", "url": "https://github.com/advisories/GHSA-H7WG-85FJ-3C6G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-66376"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import...", "cve_id": "CVE-2025-66376", "vendor": "Zimbra", "ghsa_id": "GHSA-H7WG-85FJ-3C6G", "product": "Collaboration", "added_date": "2026-06-01T12:10:26.616Z", "cvss_score": 7.2, "epss_score": 0.19559, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97307, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-66376", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fea9b44f-3200-4101-a1e9-3c3f4874d712", "vulnerability": {"vulnId": "CVE-2025-47813", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:18+02:00"}, "gcve": {"object_uuid": "fea9b44f-3200-4101-a1e9-3c3f4874d712", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:18+00:00"}, "scope": {"notes": "loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. | Affected: Wftpserver / Wing FTP Server | CVSS: 4.3 (MEDIUM) | EPSS: 0.63107 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-47813", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47813"}, {"id": "GHSA-2VVG-J984-HH8P", "url": "https://github.com/advisories/GHSA-2VVG-J984-HH8P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47813"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.", "cve_id": "CVE-2025-47813", "vendor": "Wftpserver", "ghsa_id": "GHSA-2VVG-J984-HH8P", "product": "Wing FTP Server", "added_date": "2026-06-01T12:10:18.847Z", "cvss_score": 4.3, "epss_score": 0.63107, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99182, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47813", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "34d685e7-8960-4ed5-bec9-9a1612c66396", "vulnerability": {"vulnId": "CVE-2026-3910", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:11+02:00"}, "gcve": {"object_uuid": "34d685e7-8960-4ed5-bec9-9a1612c66396", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:11+00:00"}, "scope": {"notes": "Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.01026 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-3910", "url": "https://www.cve.org/CVERecord?id=CVE-2026-3910"}, {"id": "GHSA-69WH-543J-25H6", "url": "https://github.com/advisories/GHSA-69WH-543J-25H6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-3910"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via...", "cve_id": "CVE-2026-3910", "vendor": "Google", "ghsa_id": "GHSA-69WH-543J-25H6", "product": "Chrome", "added_date": "2026-06-01T12:10:11.496Z", "cvss_score": 8.8, "epss_score": 0.01026, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62298, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-3910", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4437c948-e59b-4c94-9d20-1b29e0752be7", "vulnerability": {"vulnId": "CVE-2026-3909", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:10:11+02:00"}, "gcve": {"object_uuid": "4437c948-e59b-4c94-9d20-1b29e0752be7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:10:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:10:11+00:00"}, "scope": {"notes": "Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.00704 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-3909", "url": "https://www.cve.org/CVERecord?id=CVE-2026-3909"}, {"id": "GHSA-VMC5-XPP6-2J82", "url": "https://github.com/advisories/GHSA-VMC5-XPP6-2J82"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-3909"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted...", "cve_id": "CVE-2026-3909", "vendor": "Google", "ghsa_id": "GHSA-VMC5-XPP6-2J82", "product": "Chrome", "added_date": "2026-06-01T12:10:11.478Z", "cvss_score": 8.8, "epss_score": 0.00704, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51593, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-3909", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ddb811dc-c3ba-493b-ad22-5248a345ad3d", "vulnerability": {"vulnId": "CVE-2025-68613", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:09:59+02:00"}, "gcve": {"object_uuid": "ddb811dc-c3ba-493b-ad22-5248a345ad3d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:09:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:09:59+00:00"}, "scope": {"notes": "n8n Vulnerable to Remote Code Execution via Expression Injection | Affected: n8n-io / n8n | CVSS: 9.9 (CRITICAL) | EPSS: 0.98994 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-68613", "url": "https://www.cve.org/CVERecord?id=CVE-2025-68613"}, {"id": "GHSA-V98V-FF95-F3CP", "url": "https://github.com/advisories/GHSA-V98V-FF95-F3CP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-68613"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "n8n Vulnerable to Remote Code Execution via Expression Injection", "cve_id": "CVE-2025-68613", "vendor": "n8n-io", "ghsa_id": "GHSA-V98V-FF95-F3CP", "product": "n8n", "added_date": "2026-06-01T12:09:59.340Z", "cvss_score": 9.9, "epss_score": 0.98994, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-68613", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "183c8f01-3593-4a48-b2c2-4556f96ce950", "vulnerability": {"vulnId": "CVE-2025-26399", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:09:49+02:00"}, "gcve": {"object_uuid": "183c8f01-3593-4a48-b2c2-4556f96ce950", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:09:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:09:49+00:00"}, "scope": {"notes": "SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability | Affected: SolarWinds / Web Help Desk | CVSS: 9.8 (CRITICAL) | EPSS: 0.895 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-26399", "url": "https://www.cve.org/CVERecord?id=CVE-2025-26399"}, {"id": "GHSA-VFRJ-F292-3F24", "url": "https://github.com/advisories/GHSA-VFRJ-F292-3F24"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-26399"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability", "cve_id": "CVE-2025-26399", "vendor": "SolarWinds", "ghsa_id": "GHSA-VFRJ-F292-3F24", "product": "Web Help Desk", "added_date": "2026-06-01T12:09:49.246Z", "cvss_score": 9.8, "epss_score": 0.895, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99783, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-26399", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "12394f45-b338-4932-af3a-fa0262f3e4cf", "vulnerability": {"vulnId": "CVE-2026-1603", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:09:49+02:00"}, "gcve": {"object_uuid": "12394f45-b338-4932-af3a-fa0262f3e4cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:09:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:09:49+00:00"}, "scope": {"notes": "An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored... | Affected: Ivanti / Endpoint Manager | CVSS: 8.6 (HIGH) | EPSS: 0.8794 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-1603", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1603"}, {"id": "GHSA-2J3G-J6QJ-X9Q2", "url": "https://github.com/advisories/GHSA-2J3G-J6QJ-X9Q2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1603"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored...", "cve_id": "CVE-2026-1603", "vendor": "Ivanti", "ghsa_id": "GHSA-2J3G-J6QJ-X9Q2", "product": "Endpoint Manager", "added_date": "2026-06-01T12:09:49.879Z", "cvss_score": 8.6, "epss_score": 0.8794, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99761, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1603", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e193bb78-27f3-44d2-bb88-a572c2e0489c", "vulnerability": {"vulnId": "CVE-2021-22054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T14:09:48+02:00"}, "gcve": {"object_uuid": "e193bb78-27f3-44d2-bb88-a572c2e0489c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T12:09:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T12:09:48+00:00"}, "scope": {"notes": "VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37... | Affected: VMware / VMware Workspace ONE UEM console | CVSS: 7.5 (HIGH) | EPSS: 0.99677 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22054", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22054"}, {"id": "GHSA-XQXH-CQ77-R6QH", "url": "https://github.com/advisories/GHSA-XQXH-CQ77-R6QH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37...", "cve_id": "CVE-2021-22054", "vendor": "VMware", "ghsa_id": "GHSA-XQXH-CQ77-R6QH", "product": "VMware Workspace ONE UEM console", "added_date": "2026-06-01T12:09:48.998Z", "cvss_score": 7.5, "epss_score": 0.99677, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22054", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0c8a8519-2017-4277-a1e5-d5927e9d569f", "vulnerability": {"vulnId": "CVE-2021-30952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:38:00+02:00"}, "gcve": {"object_uuid": "0c8a8519-2017-4277-a1e5-d5927e9d569f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:38:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:38:00+00:00"}, "scope": {"notes": "An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and... | Affected: Apple / watchOS, iOS and iPadOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.06964 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30952", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and...", "cve_id": "CVE-2021-30952", "vendor": "Apple", "ghsa_id": null, "product": "watchOS, iOS and iPadOS, macOS", "added_date": "2026-06-01T11:38:00.160Z", "cvss_score": 7.8, "epss_score": 0.06964, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9393, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30952", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e9eb26ee-40dd-428a-8f76-b570e2d898f0", "vulnerability": {"vulnId": "CVE-2023-41974", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:38:00+02:00"}, "gcve": {"object_uuid": "e9eb26ee-40dd-428a-8f76-b570e2d898f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:38:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:38:00+00:00"}, "scope": {"notes": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An... | Affected: Apple / iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.01939 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41974", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41974"}, {"id": "GHSA-58C3-HJFX-2GMQ", "url": "https://github.com/advisories/GHSA-58C3-HJFX-2GMQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41974"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An...", "cve_id": "CVE-2023-41974", "vendor": "Apple", "ghsa_id": "GHSA-58C3-HJFX-2GMQ", "product": "iOS and iPadOS", "added_date": "2026-06-01T11:38:00.681Z", "cvss_score": 7.8, "epss_score": 0.01939, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79375, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41974", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8916bdda-d2c9-4827-9ad0-ec2fdf665122", "vulnerability": {"vulnId": "CVE-2021-22681", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:38:00+02:00"}, "gcve": {"object_uuid": "8916bdda-d2c9-4827-9ad0-ec2fdf665122", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:38:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:38:00+00:00"}, "scope": {"notes": "Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers... | Affected: Rockwell Automation / Studio 5000 Logix Designer, RSLogix 5000 | CVSS: 9.8 (CRITICAL) | EPSS: 0.6363 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22681", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22681"}, {"id": "GHSA-PVH9-P4PW-H78Q", "url": "https://github.com/advisories/GHSA-PVH9-P4PW-H78Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22681"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers...", "cve_id": "CVE-2021-22681", "vendor": "Rockwell Automation", "ghsa_id": "GHSA-PVH9-P4PW-H78Q", "product": "Studio 5000 Logix Designer, RSLogix 5000", "added_date": "2026-06-01T11:38:00.140Z", "cvss_score": 9.8, "epss_score": 0.6363, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99194, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22681", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d3cda94-073a-4532-931f-fc9c72fb01db", "vulnerability": {"vulnId": "CVE-2017-7921", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:37:59+02:00"}, "gcve": {"object_uuid": "6d3cda94-073a-4532-931f-fc9c72fb01db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:37:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:37:59+00:00"}, "scope": {"notes": "An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series... | Affected: Hikvision / DS-2CD2xx2F-I Series, DS-2CD2xx0F-I Series, DS-2CD2xx2FWD Series, DS-2CD4x2xFWD Series, DS-2CD4xx5 Series, DS-2DFx Series, DS-2CD63xx Series | CVSS: 9.8 (CRITICAL) | EPSS: 0.99998 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-7921", "url": "https://www.cve.org/CVERecord?id=CVE-2017-7921"}, {"id": "GHSA-82R9-7WW3-JR86", "url": "https://github.com/advisories/GHSA-82R9-7WW3-JR86"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-7921"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series...", "cve_id": "CVE-2017-7921", "vendor": "Hikvision", "ghsa_id": "GHSA-82R9-7WW3-JR86", "product": "DS-2CD2xx2F-I Series, DS-2CD2xx0F-I Series, DS-2CD2xx2FWD Series, DS-2CD4x2xFWD Series, DS-2CD4xx5 Series, DS-2DFx Series, DS-2CD63xx Series", "added_date": "2026-06-01T11:37:59.079Z", "cvss_score": 9.8, "epss_score": 0.99998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9999, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-7921", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4d6eea9e-ba25-4950-8244-612ffddd72d5", "vulnerability": {"vulnId": "CVE-2026-21385", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:37:52+02:00"}, "gcve": {"object_uuid": "4d6eea9e-ba25-4950-8244-612ffddd72d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:37:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:37:52+00:00"}, "scope": {"notes": "Integer Overflow or Wraparound in Graphics | Affected: Qualcomm / Snapdragon | CVSS: 7.8 (HIGH) | EPSS: 0.01265 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21385", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21385"}, {"id": "GHSA-WWWQ-962J-M7X8", "url": "https://github.com/advisories/GHSA-WWWQ-962J-M7X8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21385"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer Overflow or Wraparound in Graphics", "cve_id": "CVE-2026-21385", "vendor": "Qualcomm", "ghsa_id": "GHSA-WWWQ-962J-M7X8", "product": "Snapdragon", "added_date": "2026-06-01T11:37:52.823Z", "cvss_score": 7.8, "epss_score": 0.01265, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68651, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21385", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1ad3ee0f-9828-407c-933e-e58d22269720", "vulnerability": {"vulnId": "CVE-2026-22719", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:37:52+02:00"}, "gcve": {"object_uuid": "1ad3ee0f-9828-407c-933e-e58d22269720", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:37:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:37:52+00:00"}, "scope": {"notes": "VMware Aria Operations command injection vulnerability | Affected: VMware / VMware Aria Operations, VMware Cloud Foundation Operations, Telco Cloud Platform, Telco Cloud Infrastructure | CVSS: 8.1 (HIGH) | EPSS: 0.17713 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-22719", "url": "https://www.cve.org/CVERecord?id=CVE-2026-22719"}, {"id": "GHSA-2HP7-6CR6-JVXH", "url": "https://github.com/advisories/GHSA-2HP7-6CR6-JVXH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-22719"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Aria Operations command injection vulnerability", "cve_id": "CVE-2026-22719", "vendor": "VMware", "ghsa_id": "GHSA-2HP7-6CR6-JVXH", "product": "VMware Aria Operations, VMware Cloud Foundation Operations, Telco Cloud Platform, Telco Cloud Infrastructure", "added_date": "2026-06-01T11:37:52.871Z", "cvss_score": 8.1, "epss_score": 0.17713, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97073, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-22719", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d0738fbb-8c63-4b46-b65d-5b3e873f81ab", "vulnerability": {"vulnId": "CVE-2026-20127", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:10:29+02:00"}, "gcve": {"object_uuid": "d0738fbb-8c63-4b46-b65d-5b3e873f81ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:10:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:10:29+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 10.0 (CRITICAL) | EPSS: 0.88476 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20127", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20127"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20127"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability", "cve_id": "CVE-2026-20127", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-01T11:10:29.431Z", "cvss_score": 10.0, "epss_score": 0.88476, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99769, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20127", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb20a0f2-6865-49e5-81f8-426d5065d0df", "vulnerability": {"vulnId": "CVE-2022-20775", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:08:34+02:00"}, "gcve": {"object_uuid": "fb20a0f2-6865-49e5-81f8-426d5065d0df", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:08:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:08:34+00:00"}, "scope": {"notes": "Cisco SD-WAN Software Privilege Escalation Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN, Cisco Catalyst SD-WAN Manager, Cisco SD-WAN vContainer, Cisco SD-WAN vEdge Cloud, Cisco SD-WAN vEdge Router | CVSS: 7.8 (HIGH) | EPSS: 0.12475 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20775", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20775"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20775"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco SD-WAN Software Privilege Escalation Vulnerability", "cve_id": "CVE-2022-20775", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN, Cisco Catalyst SD-WAN Manager, Cisco SD-WAN vContainer, Cisco SD-WAN vEdge Cloud, Cisco SD-WAN vEdge Router", "added_date": "2026-06-01T11:08:34.723Z", "cvss_score": 7.8, "epss_score": 0.12475, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96099, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20775", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ce8e7c82-015f-475f-a4b4-92f1ce80cd28", "vulnerability": {"vulnId": "CVE-2026-25108", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:08:28+02:00"}, "gcve": {"object_uuid": "ce8e7c82-015f-475f-a4b4-92f1ce80cd28", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:08:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:08:28+00:00"}, "scope": {"notes": "FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially... | Affected: Soliton Systems K.K / FileZen | CVSS: 8.7 (HIGH) | EPSS: 0.05066 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-25108", "url": "https://www.cve.org/CVERecord?id=CVE-2026-25108"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-25108"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially...", "cve_id": "CVE-2026-25108", "vendor": "Soliton Systems K.K", "ghsa_id": null, "product": "FileZen", "added_date": "2026-06-01T11:08:28.984Z", "cvss_score": 8.7, "epss_score": 0.05066, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92055, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-25108", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fe7de4f0-85a4-4e18-92da-750a86dc4c98", "vulnerability": {"vulnId": "CVE-2025-68461", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:03:59+02:00"}, "gcve": {"object_uuid": "fe7de4f0-85a4-4e18-92da-750a86dc4c98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:03:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:03:59+00:00"}, "scope": {"notes": "Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. | Affected: Roundcube / Webmail | CVSS: 7.2 (HIGH) | EPSS: 0.26842 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-68461", "url": "https://www.cve.org/CVERecord?id=CVE-2025-68461"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-68461"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.", "cve_id": "CVE-2025-68461", "vendor": "Roundcube", "ghsa_id": null, "product": "Webmail", "added_date": "2026-06-01T11:03:59.125Z", "cvss_score": 7.2, "epss_score": 0.26842, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-68461", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "469a647f-6787-4154-a410-ba548873ed04", "vulnerability": {"vulnId": "CVE-2025-49113", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T13:03:57+02:00"}, "gcve": {"object_uuid": "469a647f-6787-4154-a410-ba548873ed04", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T11:03:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T11:03:57+00:00"}, "scope": {"notes": "Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is... | Affected: Roundcube / Webmail | CVSS: 9.9 (CRITICAL) | EPSS: 0.98897 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-49113", "url": "https://www.cve.org/CVERecord?id=CVE-2025-49113"}, {"id": "GHSA-8J8W-WWQC-X596", "url": "https://github.com/advisories/GHSA-8J8W-WWQC-X596"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-49113"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is...", "cve_id": "CVE-2025-49113", "vendor": "Roundcube", "ghsa_id": "GHSA-8J8W-WWQC-X596", "product": "Webmail", "added_date": "2026-06-01T11:03:57.946Z", "cvss_score": 9.9, "epss_score": 0.98897, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-49113", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4394dd0d-6a66-4b48-963c-af4c3d5130b6", "vulnerability": {"vulnId": "CVE-2026-22769", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:59:33+02:00"}, "gcve": {"object_uuid": "4394dd0d-6a66-4b48-963c-af4c3d5130b6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:59:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:59:33+00:00"}, "scope": {"notes": "Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as... | Affected: Dell / RecoverPoint for Virtual Machines | CVSS: 10.0 (CRITICAL) | EPSS: 0.13345 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-22769", "url": "https://www.cve.org/CVERecord?id=CVE-2026-22769"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-22769"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as...", "cve_id": "CVE-2026-22769", "vendor": "Dell", "ghsa_id": null, "product": "RecoverPoint for Virtual Machines", "added_date": "2026-06-01T10:59:33.007Z", "cvss_score": 10.0, "epss_score": 0.13345, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96298, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-22769", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b14aee7-283f-49fa-b3a8-a8017978ea7d", "vulnerability": {"vulnId": "CVE-2021-22175", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:59:30+02:00"}, "gcve": {"object_uuid": "8b14aee7-283f-49fa-b3a8-a8017978ea7d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:59:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:59:30+00:00"}, "scope": {"notes": "When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions... | Affected: GitLab / GitLab | CVSS: 6.8 (MEDIUM) | EPSS: 0.53372 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22175", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22175"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22175"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions...", "cve_id": "CVE-2021-22175", "vendor": "GitLab", "ghsa_id": null, "product": "GitLab", "added_date": "2026-06-01T10:59:30.940Z", "cvss_score": 6.8, "epss_score": 0.53372, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98957, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22175", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ba5c0220-1078-48f7-87d1-bc8d2202172f", "vulnerability": {"vulnId": "CVE-2026-2441", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:57:11+02:00"}, "gcve": {"object_uuid": "ba5c0220-1078-48f7-87d1-bc8d2202172f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:57:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:57:11+00:00"}, "scope": {"notes": "Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.55101 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-2441", "url": "https://www.cve.org/CVERecord?id=CVE-2026-2441"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-2441"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...", "cve_id": "CVE-2026-2441", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T10:57:11.873Z", "cvss_score": 8.8, "epss_score": 0.55101, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99001, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-2441", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "75628928-eb44-4947-8bce-91f6f9b1a60a", "vulnerability": {"vulnId": "CVE-2024-7694", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:57:09+02:00"}, "gcve": {"object_uuid": "75628928-eb44-4947-8bce-91f6f9b1a60a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:57:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:57:09+00:00"}, "scope": {"notes": "TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File Upload | Affected: TeamT5 / ThreatSonar Anti-Ransomware | CVSS: 7.2 (HIGH) | EPSS: 0.01792 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-7694", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7694"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7694"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TeamT5 ThreatSonar Anti-Ransomware - Arbitrary File Upload", "cve_id": "CVE-2024-7694", "vendor": "TeamT5", "ghsa_id": null, "product": "ThreatSonar Anti-Ransomware", "added_date": "2026-06-01T10:57:09.931Z", "cvss_score": 7.2, "epss_score": 0.01792, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77592, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7694", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9547f5b1-accb-4871-9a91-b82181ffe776", "vulnerability": {"vulnId": "CVE-2026-1731", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:51:06+02:00"}, "gcve": {"object_uuid": "9547f5b1-accb-4871-9a91-b82181ffe776", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:51:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:51:06+00:00"}, "scope": {"notes": "Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) | Affected: BeyondTrust / Remote Support(RS) & Privileged Remote Access(PRA) | CVSS: 9.9 (CRITICAL) | EPSS: 0.90963 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-1731", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1731"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1731"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)", "cve_id": "CVE-2026-1731", "vendor": "BeyondTrust", "ghsa_id": null, "product": "Remote Support(RS) & Privileged Remote Access(PRA)", "added_date": "2026-06-01T10:51:06.572Z", "cvss_score": 9.9, "epss_score": 0.90963, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99805, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-1731", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0d16b082-4443-466a-8a1f-996ab6568f3b", "vulnerability": {"vulnId": "CVE-2025-15556", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:56+02:00"}, "gcve": {"object_uuid": "0d16b082-4443-466a-8a1f-996ab6568f3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:56+00:00"}, "scope": {"notes": "Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification | Affected: Notepad-plus-plus / notepad-plus-plus | CVSS: 7.7 (HIGH) | EPSS: 0.01747 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-15556", "url": "https://www.cve.org/CVERecord?id=CVE-2025-15556"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-15556"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification", "cve_id": "CVE-2025-15556", "vendor": "Notepad-plus-plus", "ghsa_id": null, "product": "notepad-plus-plus", "added_date": "2026-06-01T10:50:56.130Z", "cvss_score": 7.7, "epss_score": 0.01747, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76985, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-15556", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "010c199e-8096-460b-8f0d-36fd5a691f23", "vulnerability": {"vulnId": "CVE-2025-40536", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:56+02:00"}, "gcve": {"object_uuid": "010c199e-8096-460b-8f0d-36fd5a691f23", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:56+00:00"}, "scope": {"notes": "SolarWinds Web Help Desk Security Control Bypass Vulnerability | Affected: SolarWinds / Web Help Desk | CVSS: 8.1 (HIGH) | EPSS: 0.73562 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-40536", "url": "https://www.cve.org/CVERecord?id=CVE-2025-40536"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-40536"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Web Help Desk Security Control Bypass Vulnerability", "cve_id": "CVE-2025-40536", "vendor": "SolarWinds", "ghsa_id": null, "product": "Web Help Desk", "added_date": "2026-06-01T10:50:56.244Z", "cvss_score": 8.1, "epss_score": 0.73562, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99456, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-40536", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "014bd18a-a0b5-4772-ab5e-25efb1dd6182", "vulnerability": {"vulnId": "CVE-2024-43468", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:56+02:00"}, "gcve": {"object_uuid": "014bd18a-a0b5-4772-ab5e-25efb1dd6182", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:56+00:00"}, "scope": {"notes": "Microsoft Configuration Manager Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Configuration Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.80912 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43468", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43468"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43468"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Configuration Manager Remote Code Execution Vulnerability", "cve_id": "CVE-2024-43468", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Configuration Manager", "added_date": "2026-06-01T10:50:56.032Z", "cvss_score": 9.8, "epss_score": 0.80912, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99621, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43468", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "535338cc-0397-469d-a9de-47d2bd9096c8", "vulnerability": {"vulnId": "CVE-2026-20700", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:52+02:00"}, "gcve": {"object_uuid": "535338cc-0397-469d-a9de-47d2bd9096c8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:52+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.01372 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20700", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20700"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20700"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS...", "cve_id": "CVE-2026-20700", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2026-06-01T10:50:52.423Z", "cvss_score": 7.8, "epss_score": 0.01372, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.70956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20700", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f948355d-1d39-42f8-8cbd-4f3f85f4d577", "vulnerability": {"vulnId": "CVE-2026-21510", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:47+02:00"}, "gcve": {"object_uuid": "f948355d-1d39-42f8-8cbd-4f3f85f4d577", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:47+00:00"}, "scope": {"notes": "Windows Shell Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.24226 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21510", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21510"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21510"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Shell Security Feature Bypass Vulnerability", "cve_id": "CVE-2026-21510", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:50:47.605Z", "cvss_score": 8.8, "epss_score": 0.24226, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97791, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21510", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb9e0ba4-5d50-4cda-bae5-9f210431d57c", "vulnerability": {"vulnId": "CVE-2026-21513", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:47+02:00"}, "gcve": {"object_uuid": "fb9e0ba4-5d50-4cda-bae5-9f210431d57c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:47+00:00"}, "scope": {"notes": "MSHTML Framework Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.15642 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21513", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21513"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21513"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MSHTML Framework Security Feature Bypass Vulnerability", "cve_id": "CVE-2026-21513", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:50:47.633Z", "cvss_score": 8.8, "epss_score": 0.15642, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96748, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21513", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e63fdba8-6f1b-4e7a-8aea-91ebde25f9ae", "vulnerability": {"vulnId": "CVE-2026-21525", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:47+02:00"}, "gcve": {"object_uuid": "e63fdba8-6f1b-4e7a-8aea-91ebde25f9ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:47+00:00"}, "scope": {"notes": "Windows Remote Access Connection Manager Denial of Service Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 6.2 (MEDIUM) | EPSS: 0.04797 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21525", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21525"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21525"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Remote Access Connection Manager Denial of Service Vulnerability", "cve_id": "CVE-2026-21525", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:50:47.728Z", "cvss_score": 6.2, "epss_score": 0.04797, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91665, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21525", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c75b14aa-3a0c-4c41-8e27-69b0f282be01", "vulnerability": {"vulnId": "CVE-2026-21533", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:47+02:00"}, "gcve": {"object_uuid": "c75b14aa-3a0c-4c41-8e27-69b0f282be01", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:47+00:00"}, "scope": {"notes": "Windows Remote Desktop Services Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.04125 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21533", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21533"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21533"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-21533", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:50:47.778Z", "cvss_score": 7.8, "epss_score": 0.04125, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90485, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21533", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e1d8b13e-4d4f-4f75-aa10-7a2a01be60d2", "vulnerability": {"vulnId": "CVE-2026-21519", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:47+02:00"}, "gcve": {"object_uuid": "e1d8b13e-4d4f-4f75-aa10-7a2a01be60d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:47+00:00"}, "scope": {"notes": "Desktop Window Manager Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.02462 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21519", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21519"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21519"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Desktop Window Manager Elevation of Privilege Vulnerability", "cve_id": "CVE-2026-21519", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows 11 Version 26H1, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:50:47.687Z", "cvss_score": 7.8, "epss_score": 0.02462, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83882, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21519", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bc43ef74-26df-4e06-a211-aa1ed7a4dbaa", "vulnerability": {"vulnId": "CVE-2026-21514", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:47+02:00"}, "gcve": {"object_uuid": "bc43ef74-26df-4e06-a211-aa1ed7a4dbaa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:47+00:00"}, "scope": {"notes": "Microsoft Word Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024 | CVSS: 7.8 (HIGH) | EPSS: 0.01578 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21514", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21514"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21514"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Word Security Feature Bypass Vulnerability", "cve_id": "CVE-2026-21514", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC for Mac 2024", "added_date": "2026-06-01T10:50:47.655Z", "cvss_score": 7.8, "epss_score": 0.01578, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74584, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21514", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e61199b-4fbc-48c1-a8c3-531378846252", "vulnerability": {"vulnId": "CVE-2026-25815", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:28+02:00"}, "gcve": {"object_uuid": "8e61199b-4fbc-48c1-a8c3-531378846252", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:28+00:00"}, "scope": {"notes": "Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from... | Affected: Fortinet / FortiOS | CVSS: 3.2 (LOW) | EPSS: 0.00094 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-25815", "url": "https://www.cve.org/CVERecord?id=CVE-2026-25815"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-25815"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from...", "cve_id": "CVE-2026-25815", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiOS", "added_date": "2026-06-01T10:50:28.686Z", "cvss_score": 3.2, "epss_score": 0.00094, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.00554, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-25815", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "df2f83ac-57f7-434e-8322-db9d10f2d6ea", "vulnerability": {"vulnId": "CVE-2026-24423", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:28+02:00"}, "gcve": {"object_uuid": "df2f83ac-57f7-434e-8322-db9d10f2d6ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:28+00:00"}, "scope": {"notes": "SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API | Affected: SmarterTools / SmarterMail | CVSS: 9.3 (CRITICAL) | EPSS: 0.88177 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-24423", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24423"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-24423"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API", "cve_id": "CVE-2026-24423", "vendor": "SmarterTools", "ghsa_id": null, "product": "SmarterMail", "added_date": "2026-06-01T10:50:28.476Z", "cvss_score": 9.3, "epss_score": 0.88177, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99765, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-24423", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f86b7e10-5e91-413b-a79c-6cf4ba35838f", "vulnerability": {"vulnId": "CVE-2025-11953", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:27+02:00"}, "gcve": {"object_uuid": "f86b7e10-5e91-413b-a79c-6cf4ba35838f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:27+00:00"}, "scope": {"notes": "Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests | Affected: React Native Community / React Native Community CLI | CVSS: 9.8 (CRITICAL) | EPSS: 0.9398 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-11953", "url": "https://www.cve.org/CVERecord?id=CVE-2025-11953"}, {"id": "GHSA-399J-VXMF-HJVR", "url": "https://github.com/advisories/GHSA-399J-VXMF-HJVR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-11953"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests", "cve_id": "CVE-2025-11953", "vendor": "React Native Community", "ghsa_id": "GHSA-399J-VXMF-HJVR", "product": "React Native Community CLI", "added_date": "2026-06-01T10:50:27.842Z", "cvss_score": 9.8, "epss_score": 0.9398, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-11953", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aba47a74-f251-4b29-87d1-a6a693ed7372", "vulnerability": {"vulnId": "CVE-2025-64328", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:19+02:00"}, "gcve": {"object_uuid": "aba47a74-f251-4b29-87d1-a6a693ed7372", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:19+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:19+00:00"}, "scope": {"notes": "FreePBX Administration GUI is Vulnerable to Authenticated Command Injection | Affected: FreePBX / filestore | CVSS: 8.6 (HIGH) | EPSS: 0.84618 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-64328", "url": "https://www.cve.org/CVERecord?id=CVE-2025-64328"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-64328"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FreePBX Administration GUI is Vulnerable to Authenticated Command Injection", "cve_id": "CVE-2025-64328", "vendor": "FreePBX", "ghsa_id": null, "product": "filestore", "added_date": "2026-06-01T10:50:19.182Z", "cvss_score": 8.6, "epss_score": 0.84618, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99698, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-64328", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4b78ac9e-74d1-45c7-8a65-e6aaf617e2b2", "vulnerability": {"vulnId": "CVE-2021-39935", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:18+02:00"}, "gcve": {"object_uuid": "4b78ac9e-74d1-45c7-8a65-e6aaf617e2b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:18+00:00"}, "scope": {"notes": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before... | Affected: GitLab / GitLab | CVSS: 6.8 (MEDIUM) | EPSS: 0.35649 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-39935", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39935"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39935"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before...", "cve_id": "CVE-2021-39935", "vendor": "GitLab", "ghsa_id": null, "product": "GitLab", "added_date": "2026-06-01T10:50:18.236Z", "cvss_score": 6.8, "epss_score": 0.35649, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98416, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39935", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "af4fc706-8772-42f5-a67d-1e545079d9d0", "vulnerability": {"vulnId": "CVE-2025-40551", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:18+02:00"}, "gcve": {"object_uuid": "af4fc706-8772-42f5-a67d-1e545079d9d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:18+00:00"}, "scope": {"notes": "SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability | Affected: SolarWinds / Web Help Desk | CVSS: 9.8 (CRITICAL) | EPSS: 0.84181 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-40551", "url": "https://www.cve.org/CVERecord?id=CVE-2025-40551"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-40551"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability", "cve_id": "CVE-2025-40551", "vendor": "SolarWinds", "ghsa_id": null, "product": "Web Help Desk", "added_date": "2026-06-01T10:50:18.579Z", "cvss_score": 9.8, "epss_score": 0.84181, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-40551", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cb533c1c-25f9-49c9-8130-c4e4cdc1994f", "vulnerability": {"vulnId": "CVE-2019-19006", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:17+02:00"}, "gcve": {"object_uuid": "cb533c1c-25f9-49c9-8130-c4e4cdc1994f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:17+00:00"}, "scope": {"notes": "Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. | Affected: Sangoma / FreePBX | CVSS: 9.8 (CRITICAL) | EPSS: 0.55946 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-19006", "url": "https://www.cve.org/CVERecord?id=CVE-2019-19006"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-19006"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.", "cve_id": "CVE-2019-19006", "vendor": "Sangoma", "ghsa_id": null, "product": "FreePBX", "added_date": "2026-06-01T10:50:17.725Z", "cvss_score": 9.8, "epss_score": 0.55946, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-19006", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7b0d0c25-d524-446f-a767-7a5b1bd867cf", "vulnerability": {"vulnId": "CVE-2026-1281", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:50:03+02:00"}, "gcve": {"object_uuid": "7b0d0c25-d524-446f-a767-7a5b1bd867cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:50:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:50:03+00:00"}, "scope": {"notes": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Affected: Ivanti / Endpoint Manager Mobile | CVSS: 9.8 (CRITICAL) | EPSS: 0.98688 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-1281", "url": "https://www.cve.org/CVERecord?id=CVE-2026-1281"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-1281"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.", "cve_id": "CVE-2026-1281", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager Mobile", "added_date": "2026-06-01T10:50:03.087Z", "cvss_score": 9.8, "epss_score": 0.98688, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99924, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-1281", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "89aed5d5-7b3d-4ec7-9b6c-7873ba8f1557", "vulnerability": {"vulnId": "CVE-2026-24858", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:56+02:00"}, "gcve": {"object_uuid": "89aed5d5-7b3d-4ec7-9b6c-7873ba8f1557", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:56+00:00"}, "scope": {"notes": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5,... | Affected: Fortinet / FortiWeb, FortiNAC-F, FortiOS, FortiAnalyzer, FortiProxy, FortiManager | CVSS: 9.8 (CRITICAL) | EPSS: 0.85796 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-24858", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24858"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-24858"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5,...", "cve_id": "CVE-2026-24858", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiWeb, FortiNAC-F, FortiOS, FortiAnalyzer, FortiProxy, FortiManager", "added_date": "2026-06-01T10:49:56.043Z", "cvss_score": 9.8, "epss_score": 0.85796, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-24858", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dfa367b7-7f2e-4f86-af8a-77237ee70775", "vulnerability": {"vulnId": "CVE-2026-24061", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:50+02:00"}, "gcve": {"object_uuid": "dfa367b7-7f2e-4f86-af8a-77237ee70775", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:50+00:00"}, "scope": {"notes": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable. | Affected: GNU / Inetutils | CVSS: 9.8 (CRITICAL) | EPSS: 0.98984 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-24061", "url": "https://www.cve.org/CVERecord?id=CVE-2026-24061"}, {"id": "GHSA-PF97-P8FF-FJ35", "url": "https://github.com/advisories/GHSA-PF97-P8FF-FJ35"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-24061"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.", "cve_id": "CVE-2026-24061", "vendor": "GNU", "ghsa_id": "GHSA-PF97-P8FF-FJ35", "product": "Inetutils", "added_date": "2026-06-01T10:49:50.064Z", "cvss_score": 9.8, "epss_score": 0.98984, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99929, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-24061", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fe706956-d9ad-4d84-a33b-31234aa3cb2d", "vulnerability": {"vulnId": "CVE-2026-21509", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:49+02:00"}, "gcve": {"object_uuid": "fe706956-d9ad-4d84-a33b-31234aa3cb2d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:49+00:00"}, "scope": {"notes": "Microsoft Office Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024 | CVSS: 7.8 (HIGH) | EPSS: 0.70795 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21509", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21509"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21509"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office Security Feature Bypass Vulnerability", "cve_id": "CVE-2026-21509", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Office LTSC 2024", "added_date": "2026-06-01T10:49:49.668Z", "cvss_score": 7.8, "epss_score": 0.70795, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99384, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21509", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b1e6b62a-134a-4961-86de-687e144d8155", "vulnerability": {"vulnId": "CVE-2026-23760", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:49+02:00"}, "gcve": {"object_uuid": "b1e6b62a-134a-4961-86de-687e144d8155", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:49+00:00"}, "scope": {"notes": "SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API | Affected: SmarterTools / SmarterMail | CVSS: 9.3 (CRITICAL) | EPSS: 0.96544 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-23760", "url": "https://www.cve.org/CVERecord?id=CVE-2026-23760"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-23760"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API", "cve_id": "CVE-2026-23760", "vendor": "SmarterTools", "ghsa_id": null, "product": "SmarterMail", "added_date": "2026-06-01T10:49:49.943Z", "cvss_score": 9.3, "epss_score": 0.96544, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99881, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-23760", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb92ecf6-6431-4065-9aa7-d866ddfe24f6", "vulnerability": {"vulnId": "CVE-2025-52691", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:47+02:00"}, "gcve": {"object_uuid": "fb92ecf6-6431-4065-9aa7-d866ddfe24f6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:47+00:00"}, "scope": {"notes": "Upload Arbitrary Files | Affected: SmarterTools / SmarterMail | CVSS: 10.0 (CRITICAL) | EPSS: 0.85655 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-52691", "url": "https://www.cve.org/CVERecord?id=CVE-2025-52691"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-52691"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Upload Arbitrary Files", "cve_id": "CVE-2025-52691", "vendor": "SmarterTools", "ghsa_id": null, "product": "SmarterMail", "added_date": "2026-06-01T10:49:47.987Z", "cvss_score": 10.0, "epss_score": 0.85655, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99719, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-52691", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d9238ce4-f6e6-42db-94cc-27b7e294a570", "vulnerability": {"vulnId": "CVE-2018-14634", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:47+02:00"}, "gcve": {"object_uuid": "d9238ce4-f6e6-42db-94cc-27b7e294a570", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:47+00:00"}, "scope": {"notes": "An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise... | Affected: Linux / kernel | CVSS: 7.8 (HIGH) | EPSS: 0.14689 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-14634", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14634"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14634"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise...", "cve_id": "CVE-2018-14634", "vendor": "Linux", "ghsa_id": null, "product": "kernel", "added_date": "2026-06-01T10:49:47.154Z", "cvss_score": 7.8, "epss_score": 0.14689, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96569, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14634", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "43e6582b-f769-44bb-8e48-5b0c19ae60a0", "vulnerability": {"vulnId": "CVE-2024-37079", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:38+02:00"}, "gcve": {"object_uuid": "43e6582b-f769-44bb-8e48-5b0c19ae60a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:38+00:00"}, "scope": {"notes": "vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to... | Affected: VMware / vCenter Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.22377 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-37079", "url": "https://www.cve.org/CVERecord?id=CVE-2024-37079"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-37079"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to...", "cve_id": "CVE-2024-37079", "vendor": "VMware", "ghsa_id": null, "product": "vCenter Server", "added_date": "2026-06-01T10:49:38.439Z", "cvss_score": 9.8, "epss_score": 0.22377, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97628, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-37079", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "71283947-113c-40d1-8ebb-3db13d09617b", "vulnerability": {"vulnId": "CVE-2025-31125", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:32+02:00"}, "gcve": {"object_uuid": "71283947-113c-40d1-8ebb-3db13d09617b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:32+00:00"}, "scope": {"notes": "Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | Affected: Vitejs / vite | CVSS: 5.3 (MEDIUM) | EPSS: 0.64688 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-31125", "url": "https://www.cve.org/CVERecord?id=CVE-2025-31125"}, {"id": "GHSA-4R4M-QW57-CHR8", "url": "https://github.com/advisories/GHSA-4R4M-QW57-CHR8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-31125"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query", "cve_id": "CVE-2025-31125", "vendor": "Vitejs", "ghsa_id": "GHSA-4R4M-QW57-CHR8", "product": "vite", "added_date": "2026-06-01T10:49:32.672Z", "cvss_score": 5.3, "epss_score": 0.64688, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99222, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-31125", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c18646e-1f32-4e4a-b87f-7804c8cbcecf", "vulnerability": {"vulnId": "CVE-2025-34026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:32+02:00"}, "gcve": {"object_uuid": "4c18646e-1f32-4e4a-b87f-7804c8cbcecf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:32+00:00"}, "scope": {"notes": "Versa Concerto Actuator Authentication Bypass Information Leak | Affected: Versa / Concerto | CVSS: 9.2 (CRITICAL) | EPSS: 0.8194 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-34026", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Versa Concerto Actuator Authentication Bypass Information Leak", "cve_id": "CVE-2025-34026", "vendor": "Versa", "ghsa_id": null, "product": "Concerto", "added_date": "2026-06-01T10:49:32.706Z", "cvss_score": 9.2, "epss_score": 0.8194, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99642, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34026", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2bad6a7c-b875-4562-a381-72cb7582699a", "vulnerability": {"vulnId": "CVE-2025-54313", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:32+02:00"}, "gcve": {"object_uuid": "2bad6a7c-b875-4562-a381-72cb7582699a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:32+00:00"}, "scope": {"notes": "eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package... | Affected: Prettier / eslint-config-prettier | CVSS: 7.5 (HIGH) | EPSS: 0.04522 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-54313", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54313"}, {"id": "GHSA-F29H-PXVX-F335", "url": "https://github.com/advisories/GHSA-F29H-PXVX-F335"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54313"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package...", "cve_id": "CVE-2025-54313", "vendor": "Prettier", "ghsa_id": "GHSA-F29H-PXVX-F335", "product": "eslint-config-prettier", "added_date": "2026-06-01T10:49:32.926Z", "cvss_score": 7.5, "epss_score": 0.04522, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91231, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54313", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8bf91e97-db0a-4890-938d-d9a5cdbae1e8", "vulnerability": {"vulnId": "CVE-2026-20045", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:49:29+02:00"}, "gcve": {"object_uuid": "8bf91e97-db0a-4890-938d-d9a5cdbae1e8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:49:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:49:29+00:00"}, "scope": {"notes": "Cisco Unified Communications Products Remote Code Execution Vulnerability | Affected: Cisco / Cisco Unified Communications Manager, Cisco Unified Communications Manager IM and Presence Service, Cisco Unity Connection | CVSS: 8.2 (HIGH) | EPSS: 0.04541 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20045", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20045"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20045"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Unified Communications Products Remote Code Execution Vulnerability", "cve_id": "CVE-2026-20045", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Unified Communications Manager, Cisco Unified Communications Manager IM and Presence Service, Cisco Unity Connection", "added_date": "2026-06-01T10:49:29.465Z", "cvss_score": 8.2, "epss_score": 0.04541, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91262, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20045", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "707f2db1-d592-40d8-a83c-1d5a22865b23", "vulnerability": {"vulnId": "CVE-2026-20805", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:48:47+02:00"}, "gcve": {"object_uuid": "707f2db1-d592-40d8-a83c-1d5a22865b23", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:48:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:48:47+00:00"}, "scope": {"notes": "Desktop Window Manager Information Disclosure Vulnerability | Affected: Microsoft / Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 5.5 (MEDIUM) | EPSS: 0.07203 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20805", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20805"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20805"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Desktop Window Manager Information Disclosure Vulnerability", "cve_id": "CVE-2026-20805", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:48:47.515Z", "cvss_score": 5.5, "epss_score": 0.07203, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94122, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20805", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1d38e2c8-e6a2-4ee1-adcc-cd1d53fe1dab", "vulnerability": {"vulnId": "CVE-2025-37164", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:48:30+02:00"}, "gcve": {"object_uuid": "1d38e2c8-e6a2-4ee1-adcc-cd1d53fe1dab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:48:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:48:30+00:00"}, "scope": {"notes": "A remote code execution issue exists in HPE OneView. | Affected: Hewlett Packard Enterprise (HPE) / HPE OneView | CVSS: 10.0 (CRITICAL) | EPSS: 0.90193 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-37164", "url": "https://www.cve.org/CVERecord?id=CVE-2025-37164"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-37164"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution issue exists in HPE OneView.", "cve_id": "CVE-2025-37164", "vendor": "Hewlett Packard Enterprise (HPE)", "ghsa_id": null, "product": "HPE OneView", "added_date": "2026-06-01T10:48:30.125Z", "cvss_score": 10.0, "epss_score": 0.90193, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99795, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-37164", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1726c545-47ad-4640-b63a-cc9a606423ef", "vulnerability": {"vulnId": "CVE-2026-0625", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:47:41+02:00"}, "gcve": {"object_uuid": "1726c545-47ad-4640-b63a-cc9a606423ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:47:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:47:41+00:00"}, "scope": {"notes": "D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint | Affected: D-Link / DSL-2640B, DSL-2740R, DSL-2780B, DSL-526B, DSL-2640T, DSL-500, DSL-500G, DSL-502G, DIR-905L, DIR-600, DIR-608, DIR-610, DIR-611, DIR-615, DNS-320, DNS-325, DNS-345 | CVSS: 9.3 (CRITICAL) | EPSS: 0.00972 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-0625", "url": "https://www.cve.org/CVERecord?id=CVE-2026-0625"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-0625"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint", "cve_id": "CVE-2026-0625", "vendor": "D-Link", "ghsa_id": null, "product": "DSL-2640B, DSL-2740R, DSL-2780B, DSL-526B, DSL-2640T, DSL-500, DSL-500G, DSL-502G, DIR-905L, DIR-600, DIR-608, DIR-610, DIR-611, DIR-615, DNS-320, DNS-325, DNS-345", "added_date": "2026-06-01T10:47:41.999Z", "cvss_score": 9.3, "epss_score": 0.00972, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60581, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-0625", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f264e344-bbab-4f8f-9d70-ad7405c21274", "vulnerability": {"vulnId": "CVE-2025-14847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:47:16+02:00"}, "gcve": {"object_uuid": "f264e344-bbab-4f8f-9d70-ad7405c21274", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:47:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:47:16+00:00"}, "scope": {"notes": "Zlib compressed protocol header length confusion may allow memory read | Affected: MongoDB / MongoDB Server | CVSS: 8.7 (HIGH) | EPSS: 0.83218 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-14847", "url": "https://www.cve.org/CVERecord?id=CVE-2025-14847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-14847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zlib compressed protocol header length confusion may allow memory read", "cve_id": "CVE-2025-14847", "vendor": "MongoDB", "ghsa_id": null, "product": "MongoDB Server", "added_date": "2026-06-01T10:47:16.660Z", "cvss_score": 8.7, "epss_score": 0.83218, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99671, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-14847", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "84a40f29-19b2-4b38-a5d0-d3120ae8a0a1", "vulnerability": {"vulnId": "CVE-2023-52163", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:47+02:00"}, "gcve": {"object_uuid": "84a40f29-19b2-4b38-a5d0-d3120ae8a0a1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:47+00:00"}, "scope": {"notes": "Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no... | Affected: Digiever / DS-2105 Pro | CVSS: 8.8 (HIGH) | EPSS: 0.96921 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-52163", "url": "https://www.cve.org/CVERecord?id=CVE-2023-52163"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-52163"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no...", "cve_id": "CVE-2023-52163", "vendor": "Digiever", "ghsa_id": null, "product": "DS-2105 Pro", "added_date": "2026-06-01T10:46:47.886Z", "cvss_score": 8.8, "epss_score": 0.96921, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99888, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-52163", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0f6caa69-6811-4f65-83c7-8341bf4f638c", "vulnerability": {"vulnId": "CVE-2025-14733", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:40+02:00"}, "gcve": {"object_uuid": "0f6caa69-6811-4f65-83c7-8341bf4f638c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:40+00:00"}, "scope": {"notes": "WatchGuard Firebox iked Out of Bounds Write Vulnerability | Affected: WatchGuard / Fireware OS | CVSS: 9.3 (CRITICAL) | EPSS: 0.2651 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-14733", "url": "https://www.cve.org/CVERecord?id=CVE-2025-14733"}, {"id": "GHSA-HV82-JJ64-JF47", "url": "https://github.com/advisories/GHSA-HV82-JJ64-JF47"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-14733"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WatchGuard Firebox iked Out of Bounds Write Vulnerability", "cve_id": "CVE-2025-14733", "vendor": "WatchGuard", "ghsa_id": "GHSA-HV82-JJ64-JF47", "product": "Fireware OS", "added_date": "2026-06-01T10:46:40.736Z", "cvss_score": 9.3, "epss_score": 0.2651, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97955, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-14733", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "89faa7a4-a545-414e-9daa-5ee1406f8312", "vulnerability": {"vulnId": "CVE-2025-40602", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:36+02:00"}, "gcve": {"object_uuid": "89faa7a4-a545-414e-9daa-5ee1406f8312", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:36+00:00"}, "scope": {"notes": "A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | Affected: SonicWall / SMA1000 | CVSS: 6.6 (MEDIUM) | EPSS: 0.02756 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-40602", "url": "https://www.cve.org/CVERecord?id=CVE-2025-40602"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-40602"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).", "cve_id": "CVE-2025-40602", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA1000", "added_date": "2026-06-01T10:46:36.396Z", "cvss_score": 6.6, "epss_score": 0.02756, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-40602", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6ae6a56a-998f-4c1d-afde-3322bf97936d", "vulnerability": {"vulnId": "CVE-2025-59374", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:31+02:00"}, "gcve": {"object_uuid": "6ae6a56a-998f-4c1d-afde-3322bf97936d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:31+00:00"}, "scope": {"notes": "\"UNSUPPORTED WHEN ASSIGNED\"\u00a0Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced... | Affected: ASUS / live update | CVSS: 9.3 (CRITICAL) | EPSS: 0.01197 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-59374", "url": "https://www.cve.org/CVERecord?id=CVE-2025-59374"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-59374"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "\"UNSUPPORTED WHEN ASSIGNED\"\u00a0Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced...", "cve_id": "CVE-2025-59374", "vendor": "ASUS", "ghsa_id": null, "product": "live update", "added_date": "2026-06-01T10:46:31.422Z", "cvss_score": 9.3, "epss_score": 0.01197, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.66995, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-59374", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b505690-2ebb-4a5b-8287-7c3e2c6b483b", "vulnerability": {"vulnId": "CVE-2025-43529", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:30+02:00"}, "gcve": {"object_uuid": "3b505690-2ebb-4a5b-8287-7c3e2c6b483b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:30+00:00"}, "scope": {"notes": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2... | Affected: Apple / Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 8.8 (HIGH) | EPSS: 0.08763 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-43529", "url": "https://www.cve.org/CVERecord?id=CVE-2025-43529"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-43529"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2...", "cve_id": "CVE-2025-43529", "vendor": "Apple", "ghsa_id": null, "product": "Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2026-06-01T10:46:30.893Z", "cvss_score": 8.8, "epss_score": 0.08763, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95016, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-43529", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "366e65d1-32d2-4548-87f8-08a400761723", "vulnerability": {"vulnId": "CVE-2025-20393", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:29+02:00"}, "gcve": {"object_uuid": "366e65d1-32d2-4548-87f8-08a400761723", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:29+00:00"}, "scope": {"notes": "Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability | Affected: Cisco / Cisco Secure Email, Cisco Secure Email and Web Manager | CVSS: 10.0 (CRITICAL) | EPSS: 0.32392 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-20393", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20393"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20393"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability", "cve_id": "CVE-2025-20393", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Secure Email, Cisco Secure Email and Web Manager", "added_date": "2026-06-01T10:46:29.170Z", "cvss_score": 10.0, "epss_score": 0.32392, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98284, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20393", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f1d98ad3-066e-4429-ab7d-8911cd9671dd", "vulnerability": {"vulnId": "CVE-2025-59718", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:24+02:00"}, "gcve": {"object_uuid": "f1d98ad3-066e-4429-ab7d-8911cd9671dd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:24+00:00"}, "scope": {"notes": "A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS... | Affected: Fortinet / FortiSwitchManager, FortiOS, FortiProxy | CVSS: 9.8 (CRITICAL) | EPSS: 0.68293 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-59718", "url": "https://www.cve.org/CVERecord?id=CVE-2025-59718"}, {"id": "GHSA-FJJ2-P33C-F8QQ", "url": "https://github.com/advisories/GHSA-FJJ2-P33C-F8QQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-59718"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS...", "cve_id": "CVE-2025-59718", "vendor": "Fortinet", "ghsa_id": "GHSA-FJJ2-P33C-F8QQ", "product": "FortiSwitchManager, FortiOS, FortiProxy", "added_date": "2026-06-01T10:46:24.196Z", "cvss_score": 9.8, "epss_score": 0.68293, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99313, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-59718", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4be47d58-2f73-411e-9648-04b317a749ae", "vulnerability": {"vulnId": "CVE-2025-14611", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:18+02:00"}, "gcve": {"object_uuid": "4be47d58-2f73-411e-9648-04b317a749ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:18+00:00"}, "scope": {"notes": "Gladinet CentreStack and TrioFox Hard Coded AES Keys | Affected: Gladinet / CentreStack and TrioFox | CVSS: 7.1 (HIGH) | EPSS: 0.53302 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-14611", "url": "https://www.cve.org/CVERecord?id=CVE-2025-14611"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-14611"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gladinet CentreStack and TrioFox Hard Coded AES Keys", "cve_id": "CVE-2025-14611", "vendor": "Gladinet", "ghsa_id": null, "product": "CentreStack and TrioFox", "added_date": "2026-06-01T10:46:18.575Z", "cvss_score": 7.1, "epss_score": 0.53302, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98953, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-14611", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "68bf7baa-22b8-4e8e-81ea-f7d3186460ba", "vulnerability": {"vulnId": "CVE-2025-14174", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:09+02:00"}, "gcve": {"object_uuid": "68bf7baa-22b8-4e8e-81ea-f7d3186460ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:09+00:00"}, "scope": {"notes": "Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.22327 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-14174", "url": "https://www.cve.org/CVERecord?id=CVE-2025-14174"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-14174"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory...", "cve_id": "CVE-2025-14174", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T10:46:09.100Z", "cvss_score": 8.8, "epss_score": 0.22327, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97622, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-14174", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d9d5c36-9bc1-43f2-9c5e-669edac1e083", "vulnerability": {"vulnId": "CVE-2018-4063", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:08+02:00"}, "gcve": {"object_uuid": "6d9d5c36-9bc1-43f2-9c5e-669edac1e083", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:08+00:00"}, "scope": {"notes": "An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially... | Affected: Sierra Wireless / Sierra Wireless | CVSS: 8.8 (HIGH) | EPSS: 0.27059 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-4063", "url": "https://www.cve.org/CVERecord?id=CVE-2018-4063"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-4063"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially...", "cve_id": "CVE-2018-4063", "vendor": "Sierra Wireless", "ghsa_id": null, "product": "Sierra Wireless", "added_date": "2026-06-01T10:46:08.186Z", "cvss_score": 8.8, "epss_score": 0.27059, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-4063", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0de27987-872a-4d1d-81e2-4766e43d4a82", "vulnerability": {"vulnId": "CVE-2025-8110", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:46:00+02:00"}, "gcve": {"object_uuid": "0de27987-872a-4d1d-81e2-4766e43d4a82", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:46:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:46:00+00:00"}, "scope": {"notes": "File overwrite in file update API in Gogs | Affected: Gogs / Gogs | CVSS: 8.7 (HIGH) | EPSS: 0.85202 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-8110", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8110"}, {"id": "GHSA-MQ8M-42GH-WQ7R", "url": "https://github.com/advisories/GHSA-MQ8M-42GH-WQ7R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8110"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "File overwrite in file update API in Gogs", "cve_id": "CVE-2025-8110", "vendor": "Gogs", "ghsa_id": "GHSA-MQ8M-42GH-WQ7R", "product": "Gogs", "added_date": "2026-06-01T10:46:00.080Z", "cvss_score": 8.7, "epss_score": 0.85202, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9971, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8110", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "25c6cf1e-9b39-450e-a73f-194e5ca34635", "vulnerability": {"vulnId": "CVE-2025-62221", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:52+02:00"}, "gcve": {"object_uuid": "25c6cf1e-9b39-450e-a73f-194e5ca34635", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:52+00:00"}, "scope": {"notes": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.02505 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-62221", "url": "https://www.cve.org/CVERecord?id=CVE-2025-62221"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-62221"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-62221", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:45:52.438Z", "cvss_score": 7.8, "epss_score": 0.02505, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84162, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-62221", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "42232e27-016f-43f9-a74d-5ad68d5942c5", "vulnerability": {"vulnId": "CVE-2025-6218", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:52+02:00"}, "gcve": {"object_uuid": "42232e27-016f-43f9-a74d-5ad68d5942c5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:52+00:00"}, "scope": {"notes": "RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability | Affected: RARLAB / WinRAR | CVSS: 7.8 (HIGH) | EPSS: 0.90479 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-6218", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6218"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6218"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability", "cve_id": "CVE-2025-6218", "vendor": "RARLAB", "ghsa_id": null, "product": "WinRAR", "added_date": "2026-06-01T10:45:52.319Z", "cvss_score": 7.8, "epss_score": 0.90479, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99799, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6218", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "679322b2-7783-4d76-8525-31bf6cd886d7", "vulnerability": {"vulnId": "CVE-2025-48633", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:51+02:00"}, "gcve": {"object_uuid": "679322b2-7783-4d76-8525-31bf6cd886d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:51+00:00"}, "scope": {"notes": "In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error... | Affected: Google / Android | CVSS: 5.5 (MEDIUM) | EPSS: 0.00262 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48633", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48633"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48633"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error...", "cve_id": "CVE-2025-48633", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2026-06-01T10:45:51.594Z", "cvss_score": 5.5, "epss_score": 0.00262, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.163, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48633", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dc358027-8f8d-472f-b841-002872c50a68", "vulnerability": {"vulnId": "CVE-2025-48572", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:45+02:00"}, "gcve": {"object_uuid": "dc358027-8f8d-472f-b841-002872c50a68", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:45+00:00"}, "scope": {"notes": "In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.00259 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48572", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48572"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48572"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local...", "cve_id": "CVE-2025-48572", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2026-06-01T10:45:45.287Z", "cvss_score": 7.8, "epss_score": 0.00259, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.15925, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48572", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1b44de6e-b493-4aa7-8127-4e3d85e0a09b", "vulnerability": {"vulnId": "CVE-2022-37055", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:43+02:00"}, "gcve": {"object_uuid": "1b44de6e-b493-4aa7-8127-4e3d85e0a09b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:43+00:00"}, "scope": {"notes": "D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, | Affected: D-Link / Go-RT-AC750 | CVSS: 9.8 (CRITICAL) | EPSS: 0.55531 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-37055", "url": "https://www.cve.org/CVERecord?id=CVE-2022-37055"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-37055"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,", "cve_id": "CVE-2022-37055", "vendor": "D-Link", "ghsa_id": null, "product": "Go-RT-AC750", "added_date": "2026-06-01T10:45:43.741Z", "cvss_score": 9.8, "epss_score": 0.55531, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9901, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-37055", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1fc559f0-bd0d-4393-914e-e3bc5217f62b", "vulnerability": {"vulnId": "CVE-2025-66644", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:37+02:00"}, "gcve": {"object_uuid": "1fc559f0-bd0d-4393-914e-e3bc5217f62b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:37+00:00"}, "scope": {"notes": "Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. | Affected: Array Networks / ArrayOS AG | CVSS: 7.2 (HIGH) | EPSS: 0.03415 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-66644", "url": "https://www.cve.org/CVERecord?id=CVE-2025-66644"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-66644"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.", "cve_id": "CVE-2025-66644", "vendor": "Array Networks", "ghsa_id": null, "product": "ArrayOS AG", "added_date": "2026-06-01T10:45:37.791Z", "cvss_score": 7.2, "epss_score": 0.03415, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88495, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-66644", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7fdbf7c8-2de1-46be-9f67-e20989cfb652", "vulnerability": {"vulnId": "CVE-2021-26828", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:29+02:00"}, "gcve": {"object_uuid": "7fdbf7c8-2de1-46be-9f67-e20989cfb652", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:29+00:00"}, "scope": {"notes": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files... | Affected: OpenPLC / ScadaBR | CVSS: 8.8 (HIGH) | EPSS: 0.39356 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26828", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26828"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26828"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files...", "cve_id": "CVE-2021-26828", "vendor": "OpenPLC", "ghsa_id": null, "product": "ScadaBR", "added_date": "2026-06-01T10:45:29.301Z", "cvss_score": 8.8, "epss_score": 0.39356, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98564, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-26828", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e611a06c-0c08-44d5-9022-2acb6beac1c2", "vulnerability": {"vulnId": "CVE-2021-26829", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:45:14+02:00"}, "gcve": {"object_uuid": "e611a06c-0c08-44d5-9022-2acb6beac1c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:45:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:45:14+00:00"}, "scope": {"notes": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | Affected: OpenPLC / ScadaBR | CVSS: 5.4 (MEDIUM) | EPSS: 0.4805 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26829", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26829"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26829"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.", "cve_id": "CVE-2021-26829", "vendor": "OpenPLC", "ghsa_id": null, "product": "ScadaBR", "added_date": "2026-06-01T10:45:14.727Z", "cvss_score": 5.4, "epss_score": 0.4805, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-26829", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eceb19c9-010b-43b0-a4f9-98e4695e79db", "vulnerability": {"vulnId": "CVE-2025-61757", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:54+02:00"}, "gcve": {"object_uuid": "eceb19c9-010b-43b0-a4f9-98e4695e79db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:54+00:00"}, "scope": {"notes": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).  Supported versions that are affected are... | Affected: Oracle / Identity Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.88647 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-61757", "url": "https://www.cve.org/CVERecord?id=CVE-2025-61757"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-61757"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices).  Supported versions that are affected are...", "cve_id": "CVE-2025-61757", "vendor": "Oracle", "ghsa_id": null, "product": "Identity Manager", "added_date": "2026-06-01T10:44:54.382Z", "cvss_score": 9.8, "epss_score": 0.88647, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99772, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-61757", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "50e44b24-c25f-410d-bd86-9c729ce7ec39", "vulnerability": {"vulnId": "CVE-2025-13223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:40+02:00"}, "gcve": {"object_uuid": "50e44b24-c25f-410d-bd86-9c729ce7ec39", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:40+00:00"}, "scope": {"notes": "Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.05026 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-13223", "url": "https://www.cve.org/CVERecord?id=CVE-2025-13223"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-13223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2025-13223", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T10:44:40.499Z", "cvss_score": 8.8, "epss_score": 0.05026, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91995, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-13223", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "08364445-df74-4f72-8651-f91b08cdf18d", "vulnerability": {"vulnId": "CVE-2025-58034", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:37+02:00"}, "gcve": {"object_uuid": "08364445-df74-4f72-8651-f91b08cdf18d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:37+00:00"}, "scope": {"notes": "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet... | Affected: Fortinet / FortiWeb | CVSS: 7.2 (HIGH) | EPSS: 0.5558 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-58034", "url": "https://www.cve.org/CVERecord?id=CVE-2025-58034"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-58034"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet...", "cve_id": "CVE-2025-58034", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiWeb", "added_date": "2026-06-01T10:44:37.322Z", "cvss_score": 7.2, "epss_score": 0.5558, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99011, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-58034", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5f28acf-78cb-4316-b994-0bbc1db43037", "vulnerability": {"vulnId": "CVE-2025-64446", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:27+02:00"}, "gcve": {"object_uuid": "a5f28acf-78cb-4316-b994-0bbc1db43037", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:27+00:00"}, "scope": {"notes": "A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9,... | Affected: Fortinet / FortiWeb | CVSS: 9.8 (CRITICAL) | EPSS: 0.91838 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-64446", "url": "https://www.cve.org/CVERecord?id=CVE-2025-64446"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-64446"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9,...", "cve_id": "CVE-2025-64446", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiWeb", "added_date": "2026-06-01T10:44:27.410Z", "cvss_score": 9.8, "epss_score": 0.91838, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99815, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-64446", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e79f95a9-1c4d-41bb-a9f5-a85f3a6064dd", "vulnerability": {"vulnId": "CVE-2025-62215", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:18+02:00"}, "gcve": {"object_uuid": "e79f95a9-1c4d-41bb-a9f5-a85f3a6064dd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:18+00:00"}, "scope": {"notes": "Windows Kernel Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.05985 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-62215", "url": "https://www.cve.org/CVERecord?id=CVE-2025-62215"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-62215"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-62215", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:44:18.788Z", "cvss_score": 7.0, "epss_score": 0.05985, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-62215", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "53072fc3-b3b9-4ddf-9dc2-647698ab7289", "vulnerability": {"vulnId": "CVE-2025-9242", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:15+02:00"}, "gcve": {"object_uuid": "53072fc3-b3b9-4ddf-9dc2-647698ab7289", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:15+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:15+00:00"}, "scope": {"notes": "WatchGuard Firebox iked Out of Bounds Write Vulnerability | Affected: WatchGuard / Fireware OS | CVSS: 9.3 (CRITICAL) | EPSS: 0.913 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-9242", "url": "https://www.cve.org/CVERecord?id=CVE-2025-9242"}, {"id": "GHSA-G6Q4-CHQV-724Q", "url": "https://github.com/advisories/GHSA-G6Q4-CHQV-724Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-9242"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WatchGuard Firebox iked Out of Bounds Write Vulnerability", "cve_id": "CVE-2025-9242", "vendor": "WatchGuard", "ghsa_id": "GHSA-G6Q4-CHQV-724Q", "product": "Fireware OS", "added_date": "2026-06-01T10:44:15.178Z", "cvss_score": 9.3, "epss_score": 0.913, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99809, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-9242", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "30ee86de-5f1f-4dec-9a1e-60af6cc117e6", "vulnerability": {"vulnId": "CVE-2025-12480", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:14+02:00"}, "gcve": {"object_uuid": "30ee86de-5f1f-4dec-9a1e-60af6cc117e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:14+00:00"}, "scope": {"notes": "Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after... | Affected: TrioFox / TrioFox | CVSS: 9.1 (CRITICAL) | EPSS: 0.95428 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-12480", "url": "https://www.cve.org/CVERecord?id=CVE-2025-12480"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-12480"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after...", "cve_id": "CVE-2025-12480", "vendor": "TrioFox", "ghsa_id": null, "product": "TrioFox", "added_date": "2026-06-01T10:44:14.076Z", "cvss_score": 9.1, "epss_score": 0.95428, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99868, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-12480", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f302e9ea-5e58-4d06-9415-89be6406953d", "vulnerability": {"vulnId": "CVE-2025-21042", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:11+02:00"}, "gcve": {"object_uuid": "f302e9ea-5e58-4d06-9415-89be6406953d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:11+00:00"}, "scope": {"notes": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 8.8 (HIGH) | EPSS: 0.3317 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21042", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21042"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21042"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.", "cve_id": "CVE-2025-21042", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2026-06-01T10:44:11.029Z", "cvss_score": 8.8, "epss_score": 0.3317, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9832, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21042", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7ec582de-2e24-4c1c-b93d-3343ed6b79e6", "vulnerability": {"vulnId": "CVE-2023-7305", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:44:04+02:00"}, "gcve": {"object_uuid": "7ec582de-2e24-4c1c-b93d-3343ed6b79e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:44:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:44:04+00:00"}, "scope": {"notes": "SmartBI RMIServlet Unrestricted File Upload RCE | Affected: Guangzhou Smart Software / SmartBI | CVSS: 9.2 (CRITICAL) | EPSS: 0.00532 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7305", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7305"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7305"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SmartBI RMIServlet Unrestricted File Upload RCE", "cve_id": "CVE-2023-7305", "vendor": "Guangzhou Smart Software", "ghsa_id": null, "product": "SmartBI", "added_date": "2026-06-01T10:44:04.051Z", "cvss_score": 9.2, "epss_score": 0.00532, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.42836, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7305", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a9595b26-810e-45fc-a294-3515108894c5", "vulnerability": {"vulnId": "CVE-2025-48703", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:43:53+02:00"}, "gcve": {"object_uuid": "a9595b26-810e-45fc-a294-3515108894c5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:43:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:43:53+00:00"}, "scope": {"notes": "CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the... | Affected: CentOS Web Panel / CentOS Web Panel | CVSS: 9.0 (CRITICAL) | EPSS: 0.99655 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48703", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48703"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48703"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the...", "cve_id": "CVE-2025-48703", "vendor": "CentOS Web Panel", "ghsa_id": null, "product": "CentOS Web Panel", "added_date": "2026-06-01T10:43:53.018Z", "cvss_score": 9.0, "epss_score": 0.99655, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48703", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f89b1ff7-68c9-4557-a7cb-0e61e831c997", "vulnerability": {"vulnId": "CVE-2025-11371", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:43:51+02:00"}, "gcve": {"object_uuid": "f89b1ff7-68c9-4557-a7cb-0e61e831c997", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:43:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:43:51+00:00"}, "scope": {"notes": "Gladinet CentreStack and TrioFox Local File Inclusion Flaw | Affected: Gladinet / CentreStack and TrioFox | CVSS: 7.5 (HIGH) | EPSS: 0.92137 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-11371", "url": "https://www.cve.org/CVERecord?id=CVE-2025-11371"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-11371"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gladinet CentreStack and TrioFox Local File Inclusion Flaw", "cve_id": "CVE-2025-11371", "vendor": "Gladinet", "ghsa_id": null, "product": "CentreStack and TrioFox", "added_date": "2026-06-01T10:43:51.348Z", "cvss_score": 7.5, "epss_score": 0.92137, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-11371", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0144cf49-16c2-4a0e-95a6-f4564896f64c", "vulnerability": {"vulnId": "CVE-2025-41244", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:43:11+02:00"}, "gcve": {"object_uuid": "0144cf49-16c2-4a0e-95a6-f4564896f64c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:43:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:43:11+00:00"}, "scope": {"notes": "VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) | Affected: VMware / VCF operations, VMware tools, VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | CVSS: 7.8 (HIGH) | EPSS: 0.08438 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-41244", "url": "https://www.cve.org/CVERecord?id=CVE-2025-41244"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-41244"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)", "cve_id": "CVE-2025-41244", "vendor": "VMware", "ghsa_id": null, "product": "VCF operations, VMware tools, VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure", "added_date": "2026-06-01T10:43:11.593Z", "cvss_score": 7.8, "epss_score": 0.08438, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94839, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-41244", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c9f0ce23-cceb-48e1-ad86-1cf514daebe8", "vulnerability": {"vulnId": "CVE-2025-6204", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:43:05+02:00"}, "gcve": {"object_uuid": "c9f0ce23-cceb-48e1-ad86-1cf514daebe8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:43:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:43:05+00:00"}, "scope": {"notes": "Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 | Affected: Dassault Syst\u00e8mes / DELMIA Apriso | CVSS: 8.0 (HIGH) | EPSS: 0.77957 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-6204", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6204"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6204"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025", "cve_id": "CVE-2025-6204", "vendor": "Dassault Syst\u00e8mes", "ghsa_id": null, "product": "DELMIA Apriso", "added_date": "2026-06-01T10:43:05.088Z", "cvss_score": 8.0, "epss_score": 0.77957, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99561, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6204", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "db5e70a8-e2cf-45a2-bf8b-7843d58ad2af", "vulnerability": {"vulnId": "CVE-2025-59287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:54+02:00"}, "gcve": {"object_uuid": "db5e70a8-e2cf-45a2-bf8b-7843d58ad2af", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:54+00:00"}, "scope": {"notes": "Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Affected: Microsoft / Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 9.8 (CRITICAL) | EPSS: 0.9998 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-59287", "url": "https://www.cve.org/CVERecord?id=CVE-2025-59287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-59287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Server Update Service (WSUS) Remote Code Execution Vulnerability", "cve_id": "CVE-2025-59287", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:42:54.681Z", "cvss_score": 9.8, "epss_score": 0.9998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99981, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-59287", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a164d1d-b983-439d-9add-a322526edf70", "vulnerability": {"vulnId": "CVE-2025-61932", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:47+02:00"}, "gcve": {"object_uuid": "6a164d1d-b983-439d-9add-a322526edf70", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:47+00:00"}, "scope": {"notes": "Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests,... | Affected: MOTEX / Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) | CVSS: 9.3 (CRITICAL) | EPSS: 0.02768 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-61932", "url": "https://www.cve.org/CVERecord?id=CVE-2025-61932"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-61932"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests,...", "cve_id": "CVE-2025-61932", "vendor": "MOTEX", "ghsa_id": null, "product": "Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA))", "added_date": "2026-06-01T10:42:47.391Z", "cvss_score": 9.3, "epss_score": 0.02768, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85793, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-61932", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f2e61d23-e3e6-4fc6-a077-c42afd0201ed", "vulnerability": {"vulnId": "CVE-2024-58274", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:46+02:00"}, "gcve": {"object_uuid": "f2e61d23-e3e6-4fc6-a077-c42afd0201ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:46+00:00"}, "scope": {"notes": "Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in... | Affected: Hikvision / CSMP iSecure Center | CVSS: 8.3 (HIGH) | EPSS: 0.19085 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-58274", "url": "https://www.cve.org/CVERecord?id=CVE-2024-58274"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-58274"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in...", "cve_id": "CVE-2024-58274", "vendor": "Hikvision", "ghsa_id": null, "product": "CSMP iSecure Center", "added_date": "2026-06-01T10:42:46.061Z", "cvss_score": 8.3, "epss_score": 0.19085, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9724, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-58274", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b762a23a-ae62-489e-b32f-953cfa3d2f1b", "vulnerability": {"vulnId": "CVE-2016-15048", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:45+02:00"}, "gcve": {"object_uuid": "b762a23a-ae62-489e-b32f-953cfa3d2f1b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:45+00:00"}, "scope": {"notes": "AMTT HiBOS Command Injection RCE via server_ping.php | Affected: Anmei Century (Beijing) Technology / Hotel Broadband Operation System (HiBOS) | CVSS: 10.0 (CRITICAL) | EPSS: 0.07357 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-15048", "url": "https://www.cve.org/CVERecord?id=CVE-2016-15048"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-15048"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "AMTT HiBOS Command Injection RCE via server_ping.php", "cve_id": "CVE-2016-15048", "vendor": "Anmei Century (Beijing) Technology", "ghsa_id": null, "product": "Hotel Broadband Operation System (HiBOS)", "added_date": "2026-06-01T10:42:45.689Z", "cvss_score": 10.0, "epss_score": 0.07357, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94221, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-15048", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "904f9f8b-1b2a-4be0-a73f-be99730511cc", "vulnerability": {"vulnId": "CVE-2023-53691", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:45+02:00"}, "gcve": {"object_uuid": "904f9f8b-1b2a-4be0-a73f-be99730511cc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:45+00:00"}, "scope": {"notes": "Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory... | Affected: Hikvision / CSMP iSecure Center | CVSS: 8.3 (HIGH) | EPSS: 0.01286 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-53691", "url": "https://www.cve.org/CVERecord?id=CVE-2023-53691"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-53691"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory...", "cve_id": "CVE-2023-53691", "vendor": "Hikvision", "ghsa_id": null, "product": "CSMP iSecure Center", "added_date": "2026-06-01T10:42:45.843Z", "cvss_score": 8.3, "epss_score": 0.01286, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6908, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-53691", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e8e02d9f-38c9-4d90-927a-3ba8e56135ea", "vulnerability": {"vulnId": "CVE-2025-2746", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:30+02:00"}, "gcve": {"object_uuid": "e8e02d9f-38c9-4d90-927a-3ba8e56135ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:30+00:00"}, "scope": {"notes": "Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass | Affected: Kentico / Xperience | CVSS: 9.8 (CRITICAL) | EPSS: 0.7304 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-2746", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2746"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2746"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass", "cve_id": "CVE-2025-2746", "vendor": "Kentico", "ghsa_id": null, "product": "Xperience", "added_date": "2026-06-01T10:42:30.527Z", "cvss_score": 9.8, "epss_score": 0.7304, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99442, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2746", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3bb46557-0de1-4e89-9dcd-4570c061007d", "vulnerability": {"vulnId": "CVE-2025-2747", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:30+02:00"}, "gcve": {"object_uuid": "3bb46557-0de1-4e89-9dcd-4570c061007d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:30+00:00"}, "scope": {"notes": "Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass | Affected: Kentico / Xperience | CVSS: 9.8 (CRITICAL) | EPSS: 0.97166 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-2747", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2747"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2747"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass", "cve_id": "CVE-2025-2747", "vendor": "Kentico", "ghsa_id": null, "product": "Xperience", "added_date": "2026-06-01T10:42:30.542Z", "cvss_score": 9.8, "epss_score": 0.97166, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99894, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2747", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5e581d11-fe69-4fc1-95f3-ef2c0be1a7bc", "vulnerability": {"vulnId": "CVE-2025-33073", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:30+02:00"}, "gcve": {"object_uuid": "5e581d11-fe69-4fc1-95f3-ef2c0be1a7bc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:30+00:00"}, "scope": {"notes": "Windows SMB Client Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.82699 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-33073", "url": "https://www.cve.org/CVERecord?id=CVE-2025-33073"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-33073"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows SMB Client Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-33073", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:42:30.561Z", "cvss_score": 8.8, "epss_score": 0.82699, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99659, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-33073", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8fd363c0-263c-4808-8901-3434c87e7e4c", "vulnerability": {"vulnId": "CVE-2022-48503", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:30+02:00"}, "gcve": {"object_uuid": "8fd363c0-263c-4808-8901-3434c87e7e4c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:30+00:00"}, "scope": {"notes": "The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5,... | Affected: Apple / macOS, tvOS, Safari, watchOS, iOS and iPadOS | CVSS: 8.8 (HIGH) | EPSS: 0.03213 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-48503", "url": "https://www.cve.org/CVERecord?id=CVE-2022-48503"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-48503"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5,...", "cve_id": "CVE-2022-48503", "vendor": "Apple", "ghsa_id": null, "product": "macOS, tvOS, Safari, watchOS, iOS and iPadOS", "added_date": "2026-06-01T10:42:30.268Z", "cvss_score": 8.8, "epss_score": 0.03213, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-48503", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "56fa1f91-584e-452e-b2e0-0a7fda4e3d4d", "vulnerability": {"vulnId": "CVE-2025-61884", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:20+02:00"}, "gcve": {"object_uuid": "56fa1f91-584e-452e-b2e0-0a7fda4e3d4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:20+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI).  Supported versions that are affected are... | Affected: Oracle / Oracle Configurator | CVSS: 7.5 (HIGH) | EPSS: 0.95891 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-61884", "url": "https://www.cve.org/CVERecord?id=CVE-2025-61884"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-61884"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI).  Supported versions that are affected are...", "cve_id": "CVE-2025-61884", "vendor": "Oracle", "ghsa_id": null, "product": "Oracle Configurator", "added_date": "2026-06-01T10:42:20.696Z", "cvss_score": 7.5, "epss_score": 0.95891, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99873, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-61884", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "682fa006-d18f-47f6-ad7e-91eab17f9b4c", "vulnerability": {"vulnId": "CVE-2025-54253", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:16+02:00"}, "gcve": {"object_uuid": "682fa006-d18f-47f6-ad7e-91eab17f9b4c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:16+00:00"}, "scope": {"notes": "Adobe Experience Manager | Incorrect Authorization (CWE-863) | Affected: Adobe / Adobe Experience Manager | CVSS: 10.0 (CRITICAL) | EPSS: 0.87989 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-54253", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54253"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54253"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Experience Manager | Incorrect Authorization (CWE-863)", "cve_id": "CVE-2025-54253", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Experience Manager", "added_date": "2026-06-01T10:42:16.439Z", "cvss_score": 10.0, "epss_score": 0.87989, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99762, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54253", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c3f36ce9-774e-44f9-adef-d41ee43647ab", "vulnerability": {"vulnId": "CVE-2025-59230", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:11+02:00"}, "gcve": {"object_uuid": "c3f36ce9-774e-44f9-adef-d41ee43647ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:11+00:00"}, "scope": {"notes": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.02657 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-59230", "url": "https://www.cve.org/CVERecord?id=CVE-2025-59230"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-59230"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-59230", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:42:11.329Z", "cvss_score": 7.8, "epss_score": 0.02657, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85148, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-59230", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d49b65ea-82b3-46f5-bfa7-7f359b11575d", "vulnerability": {"vulnId": "CVE-2025-47827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:10+02:00"}, "gcve": {"object_uuid": "d49b65ea-82b3-46f5-bfa7-7f359b11575d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:10+00:00"}, "scope": {"notes": "In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a... | Affected: IGEL / IGEL OS | CVSS: 4.6 (MEDIUM) | EPSS: 0.04927 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-47827", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a...", "cve_id": "CVE-2025-47827", "vendor": "IGEL", "ghsa_id": null, "product": "IGEL OS", "added_date": "2026-06-01T10:42:10.399Z", "cvss_score": 4.6, "epss_score": 0.04927, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91859, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47827", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8815ece8-bffe-4d20-94b2-105be5b2d62d", "vulnerability": {"vulnId": "CVE-2025-24990", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:09+02:00"}, "gcve": {"object_uuid": "8815ece8-bffe-4d20-94b2-105be5b2d62d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:09+00:00"}, "scope": {"notes": "Windows Agere Modem Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.06369 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24990", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24990"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24990"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Agere Modem Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-24990", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:42:09.927Z", "cvss_score": 7.8, "epss_score": 0.06369, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93447, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24990", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a55d76c7-f126-49d2-812a-55688a9922f7", "vulnerability": {"vulnId": "CVE-2016-7836", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:42:08+02:00"}, "gcve": {"object_uuid": "a55d76c7-f126-49d2-812a-55688a9922f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:42:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:42:08+00:00"}, "scope": {"notes": "SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the... | Affected: Sky / SKYSEA Client View | CVSS: 9.8 (CRITICAL) | EPSS: 0.1923 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7836", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7836"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7836"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the...", "cve_id": "CVE-2016-7836", "vendor": "Sky", "ghsa_id": null, "product": "SKYSEA Client View", "added_date": "2026-06-01T10:42:08.181Z", "cvss_score": 9.8, "epss_score": 0.1923, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97257, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7836", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d15b4ed0-67c8-402c-9df2-ca0d05695593", "vulnerability": {"vulnId": "CVE-2021-43798", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:56+02:00"}, "gcve": {"object_uuid": "d15b4ed0-67c8-402c-9df2-ca0d05695593", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:56+00:00"}, "scope": {"notes": "Grafana path traversal | Affected: Grafana / grafana | CVSS: 7.5 (HIGH) | EPSS: 0.88503 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-43798", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43798"}, {"id": "GHSA-8PJX-JJ86-J47P", "url": "https://github.com/advisories/GHSA-8PJX-JJ86-J47P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43798"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Grafana path traversal", "cve_id": "CVE-2021-43798", "vendor": "Grafana", "ghsa_id": "GHSA-8PJX-JJ86-J47P", "product": "grafana", "added_date": "2026-06-01T10:41:56.485Z", "cvss_score": 7.5, "epss_score": 0.88503, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-43798", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ad915d7a-7dac-4542-8774-ce92676e62ff", "vulnerability": {"vulnId": "CVE-2025-27915", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:51+02:00"}, "gcve": {"object_uuid": "ad915d7a-7dac-4542-8774-ce92676e62ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:51+00:00"}, "scope": {"notes": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the... | Affected: Zimbra / Zimbra Collaboration (ZCS) | CVSS: 5.4 (MEDIUM) | EPSS: 0.03986 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-27915", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27915"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27915"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the...", "cve_id": "CVE-2025-27915", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration (ZCS)", "added_date": "2026-06-01T10:41:51.425Z", "cvss_score": 5.4, "epss_score": 0.03986, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90182, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27915", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "04e60446-79cf-41a1-af58-22168eaac540", "vulnerability": {"vulnId": "CVE-2021-43226", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:42+02:00"}, "gcve": {"object_uuid": "04e60446-79cf-41a1-af58-22168eaac540", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:42+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.03072 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-43226", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43226"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43226"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-43226", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2026-06-01T10:41:42.845Z", "cvss_score": 7.8, "epss_score": 0.03072, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87194, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-43226", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bda358be-dadf-4165-952b-1eddfd0ed3bf", "vulnerability": {"vulnId": "CVE-2021-22555", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:42+02:00"}, "gcve": {"object_uuid": "bda358be-dadf-4165-952b-1eddfd0ed3bf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:42+00:00"}, "scope": {"notes": "Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE | Affected: Linux / Linux Kernel | CVSS: 8.3 (HIGH) | EPSS: 0.78684 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22555", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22555"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22555"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE", "cve_id": "CVE-2021-22555", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2026-06-01T10:41:42.825Z", "cvss_score": 8.3, "epss_score": 0.78684, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99578, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22555", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1bd628b4-a1ff-4b15-bbd9-cc78e164c168", "vulnerability": {"vulnId": "CVE-2014-6278", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:37+02:00"}, "gcve": {"object_uuid": "1bd628b4-a1ff-4b15-bbd9-cc78e164c168", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:37+00:00"}, "scope": {"notes": "GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers... | Affected: GNU / Bash | CVSS: 8.8 (HIGH) | EPSS: 0.99603 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-6278", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6278"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6278"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers...", "cve_id": "CVE-2014-6278", "vendor": "GNU", "ghsa_id": null, "product": "Bash", "added_date": "2026-06-01T10:41:37.382Z", "cvss_score": 8.8, "epss_score": 0.99603, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99947, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6278", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fc40f647-21eb-4a7f-be72-0cc26641e16d", "vulnerability": {"vulnId": "CVE-2017-1000353", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:37+02:00"}, "gcve": {"object_uuid": "fc40f647-21eb-4a7f-be72-0cc26641e16d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:37+00:00"}, "scope": {"notes": "Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated... | Affected: Jenkins / Jenkins | CVSS: 9.8 (CRITICAL) | EPSS: 0.99679 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-1000353", "url": "https://www.cve.org/CVERecord?id=CVE-2017-1000353"}, {"id": "GHSA-26WC-3WQP-G3RP", "url": "https://github.com/advisories/GHSA-26WC-3WQP-G3RP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-1000353"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated...", "cve_id": "CVE-2017-1000353", "vendor": "Jenkins", "ghsa_id": "GHSA-26WC-3WQP-G3RP", "product": "Jenkins", "added_date": "2026-06-01T10:41:37.417Z", "cvss_score": 9.8, "epss_score": 0.99679, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9995, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-1000353", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "004da370-c3b9-40be-b019-278e33184b8a", "vulnerability": {"vulnId": "CVE-2025-21043", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:37+02:00"}, "gcve": {"object_uuid": "004da370-c3b9-40be-b019-278e33184b8a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:37+00:00"}, "scope": {"notes": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 8.8 (HIGH) | EPSS: 0.0214 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21043", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21043"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21043"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.", "cve_id": "CVE-2025-21043", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2026-06-01T10:41:37.610Z", "cvss_score": 8.8, "epss_score": 0.0214, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81366, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21043", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3027d2fc-87aa-41f2-ae05-42f09247655b", "vulnerability": {"vulnId": "CVE-2025-4008", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:37+02:00"}, "gcve": {"object_uuid": "3027d2fc-87aa-41f2-ae05-42f09247655b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:37+00:00"}, "scope": {"notes": "Arbitrary Command Injection in Smartbedded MeteoBridge | Affected: Smartbedded / MeteoBridge | CVSS: 8.7 (HIGH) | EPSS: 0.93667 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-4008", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4008"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4008"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary Command Injection in Smartbedded MeteoBridge", "cve_id": "CVE-2025-4008", "vendor": "Smartbedded", "ghsa_id": null, "product": "MeteoBridge", "added_date": "2026-06-01T10:41:37.811Z", "cvss_score": 8.7, "epss_score": 0.93667, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99841, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4008", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e1b3f677-d826-4a7f-ace9-968575f75e72", "vulnerability": {"vulnId": "CVE-2015-7755", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:37+02:00"}, "gcve": {"object_uuid": "e1b3f677-d826-4a7f-ace9-968575f75e72", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:37+00:00"}, "scope": {"notes": "Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before... | Affected: Juniper Networks / ScreenOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.61139 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-7755", "url": "https://www.cve.org/CVERecord?id=CVE-2015-7755"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-7755"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before...", "cve_id": "CVE-2015-7755", "vendor": "Juniper Networks", "ghsa_id": null, "product": "ScreenOS", "added_date": "2026-06-01T10:41:37.403Z", "cvss_score": 9.8, "epss_score": 0.61139, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99137, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-7755", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1770276f-0973-4b2e-ae00-8ee9cdc390d5", "vulnerability": {"vulnId": "CVE-2025-32463", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:17+02:00"}, "gcve": {"object_uuid": "1770276f-0973-4b2e-ae00-8ee9cdc390d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:17+00:00"}, "scope": {"notes": "Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot... | Affected: Sudo project / Sudo | CVSS: 9.3 (CRITICAL) | EPSS: 0.61039 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32463", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32463"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32463"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot...", "cve_id": "CVE-2025-32463", "vendor": "Sudo project", "ghsa_id": null, "product": "Sudo", "added_date": "2026-06-01T10:41:17.141Z", "cvss_score": 9.3, "epss_score": 0.61039, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99132, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32463", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c659c5d8-4daf-4c64-ba38-d1940a50a3aa", "vulnerability": {"vulnId": "CVE-2025-59689", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:17+02:00"}, "gcve": {"object_uuid": "c659c5d8-4daf-4c64-ba38-d1940a50a3aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:17+00:00"}, "scope": {"notes": "Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in... | Affected: Libraesva / Email Security Gateway | CVSS: 6.1 (MEDIUM) | EPSS: 0.01864 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-59689", "url": "https://www.cve.org/CVERecord?id=CVE-2025-59689"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-59689"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in...", "cve_id": "CVE-2025-59689", "vendor": "Libraesva", "ghsa_id": null, "product": "Email Security Gateway", "added_date": "2026-06-01T10:41:17.159Z", "cvss_score": 6.1, "epss_score": 0.01864, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78514, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-59689", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2a2017e8-a09c-4cb2-b15f-dcc8a7cd8bc4", "vulnerability": {"vulnId": "CVE-2025-20352", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:17+02:00"}, "gcve": {"object_uuid": "2a2017e8-a09c-4cb2-b15f-dcc8a7cd8bc4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:17+00:00"}, "scope": {"notes": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the... | Affected: Cisco / IOS, Cisco IOS XE Software, Cisco IOS XE Catalyst SD-WAN | CVSS: 7.7 (HIGH) | EPSS: 0.39447 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-20352", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20352"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20352"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the...", "cve_id": "CVE-2025-20352", "vendor": "Cisco", "ghsa_id": null, "product": "IOS, Cisco IOS XE Software, Cisco IOS XE Catalyst SD-WAN", "added_date": "2026-06-01T10:41:17.122Z", "cvss_score": 7.7, "epss_score": 0.39447, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98568, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20352", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2c59926e-f0a5-40a2-adc9-1e637bc40ee0", "vulnerability": {"vulnId": "CVE-2021-21311", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:16+02:00"}, "gcve": {"object_uuid": "2c59926e-f0a5-40a2-adc9-1e637bc40ee0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:16+00:00"}, "scope": {"notes": "SSRF in adminer | Affected: Vrana / adminer | CVSS: 7.2 (HIGH) | EPSS: 0.98464 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21311", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21311"}, {"id": "GHSA-X5R2-HJ5C-8JX6", "url": "https://github.com/advisories/GHSA-X5R2-HJ5C-8JX6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21311"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SSRF in adminer", "cve_id": "CVE-2021-21311", "vendor": "Vrana", "ghsa_id": "GHSA-X5R2-HJ5C-8JX6", "product": "adminer", "added_date": "2026-06-01T10:41:16.891Z", "cvss_score": 7.2, "epss_score": 0.98464, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99918, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21311", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b8c63c4-2a13-46d1-af6b-e10049649809", "vulnerability": {"vulnId": "CVE-2025-10035", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:16+02:00"}, "gcve": {"object_uuid": "3b8c63c4-2a13-46d1-af6b-e10049649809", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:16+00:00"}, "scope": {"notes": "Deserialization Vulnerability in GoAnywhere MFT's License Servlet | Affected: Fortra / GoAnywhere MFT | CVSS: 10.0 (CRITICAL) | EPSS: 0.99799 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-10035", "url": "https://www.cve.org/CVERecord?id=CVE-2025-10035"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-10035"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization Vulnerability in GoAnywhere MFT's License Servlet", "cve_id": "CVE-2025-10035", "vendor": "Fortra", "ghsa_id": null, "product": "GoAnywhere MFT", "added_date": "2026-06-01T10:41:16.918Z", "cvss_score": 10.0, "epss_score": 0.99799, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99956, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-10035", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18f90eb5-d217-4b6c-b971-af4f41fe6b40", "vulnerability": {"vulnId": "CVE-2025-20362", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:10+02:00"}, "gcve": {"object_uuid": "18f90eb5-d217-4b6c-b971-af4f41fe6b40", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:10+00:00"}, "scope": {"notes": "Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD... | Affected: Cisco / Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software | CVSS: 6.5 (MEDIUM) | EPSS: 0.87085 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-20362", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20362"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20362"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD...", "cve_id": "CVE-2025-20362", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software", "added_date": "2026-06-01T10:41:10.568Z", "cvss_score": 6.5, "epss_score": 0.87085, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20362", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac8120da-cc27-41c4-b26d-800520ba3610", "vulnerability": {"vulnId": "CVE-2025-20333", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:10+02:00"}, "gcve": {"object_uuid": "ac8120da-cc27-41c4-b26d-800520ba3610", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:10+00:00"}, "scope": {"notes": "A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense... | Affected: Cisco / Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software | CVSS: 9.9 (CRITICAL) | EPSS: 0.70651 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-20333", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20333"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20333"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense...", "cve_id": "CVE-2025-20333", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software", "added_date": "2026-06-01T10:41:10.527Z", "cvss_score": 9.9, "epss_score": 0.70651, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99377, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20333", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "527dc796-2f93-4745-9aab-f12dfef961e8", "vulnerability": {"vulnId": "CVE-2025-10585", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:41:06+02:00"}, "gcve": {"object_uuid": "527dc796-2f93-4745-9aab-f12dfef961e8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:41:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:41:06+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 9.8 (CRITICAL) | EPSS: 0.05391 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-10585", "url": "https://www.cve.org/CVERecord?id=CVE-2025-10585"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-10585"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2025-10585", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T10:41:06.791Z", "cvss_score": 9.8, "epss_score": 0.05391, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92426, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-10585", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "07874b70-d451-4700-a616-d655cf24a143", "vulnerability": {"vulnId": "CVE-2022-4980", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:52+02:00"}, "gcve": {"object_uuid": "07874b70-d451-4700-a616-d655cf24a143", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:52+00:00"}, "scope": {"notes": "General Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin Page | Affected: General Bytes / Crypto Application Server (CAS) | CVSS: 9.3 (CRITICAL) | EPSS: 0.0067 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4980", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4980"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4980"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "General Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default-installation/First-admin Page", "cve_id": "CVE-2022-4980", "vendor": "General Bytes", "ghsa_id": null, "product": "Crypto Application Server (CAS)", "added_date": "2026-06-01T10:40:52.140Z", "cvss_score": 9.3, "epss_score": 0.0067, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50152, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4980", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d24d016e-6156-4320-ad82-ff426fea7f80", "vulnerability": {"vulnId": "CVE-2025-5086", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:27+02:00"}, "gcve": {"object_uuid": "d24d016e-6156-4320-ad82-ff426fea7f80", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:27+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 | Affected: Dassault Syst\u00e8mes / DELMIA Apriso | CVSS: 9.0 (CRITICAL) | EPSS: 0.96915 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-5086", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5086"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5086"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025", "cve_id": "CVE-2025-5086", "vendor": "Dassault Syst\u00e8mes", "ghsa_id": null, "product": "DELMIA Apriso", "added_date": "2026-06-01T10:40:27.301Z", "cvss_score": 9.0, "epss_score": 0.96915, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99888, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5086", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ea33efba-4d7e-453a-a4f6-7546f4f6a6d6", "vulnerability": {"vulnId": "CVE-2025-53690", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:06+02:00"}, "gcve": {"object_uuid": "ea33efba-4d7e-453a-a4f6-7546f4f6a6d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:06+00:00"}, "scope": {"notes": "Sitecore Products ViewState Deserialization Vulnerability | Affected: Sitecore / Experience Manager (XM), Experience Platform (XP) | CVSS: 9.0 (CRITICAL) | EPSS: 0.51094 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-53690", "url": "https://www.cve.org/CVERecord?id=CVE-2025-53690"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-53690"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sitecore Products ViewState Deserialization Vulnerability", "cve_id": "CVE-2025-53690", "vendor": "Sitecore", "ghsa_id": null, "product": "Experience Manager (XM), Experience Platform (XP)", "added_date": "2026-06-01T10:40:06.074Z", "cvss_score": 9.0, "epss_score": 0.51094, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-53690", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "92ba57c0-cfda-4c8d-b338-bce346897f54", "vulnerability": {"vulnId": "CVE-2025-48543", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:05+02:00"}, "gcve": {"object_uuid": "92ba57c0-cfda-4c8d-b338-bce346897f54", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:05+00:00"}, "scope": {"notes": "In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to... | Affected: Google / Android | CVSS: 8.8 (HIGH) | EPSS: 0.00543 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48543", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48543"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48543"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to...", "cve_id": "CVE-2025-48543", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2026-06-01T10:40:05.962Z", "cvss_score": 8.8, "epss_score": 0.00543, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.43557, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48543", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ccac2863-31df-4ff8-b6d4-7e3f4d65e1ac", "vulnerability": {"vulnId": "CVE-2025-38352", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:05+02:00"}, "gcve": {"object_uuid": "ccac2863-31df-4ff8-b6d4-7e3f4d65e1ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:05+00:00"}, "scope": {"notes": "posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.01289 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-38352", "url": "https://www.cve.org/CVERecord?id=CVE-2025-38352"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-38352"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()", "cve_id": "CVE-2025-38352", "vendor": "Linux", "ghsa_id": null, "product": "Linux", "added_date": "2026-06-01T10:40:05.482Z", "cvss_score": 7.8, "epss_score": 0.01289, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-38352", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f169865-d47a-4854-8c15-2ce12a9f9344", "vulnerability": {"vulnId": "CVE-2025-9377", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:02+02:00"}, "gcve": {"object_uuid": "2f169865-d47a-4854-8c15-2ce12a9f9344", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:02+00:00"}, "scope": {"notes": "Authenticated RCE via Parental Control command injection | Affected: TP-Link / Archer C7(EU) V2, TL-WR841N/ND(MS) V9 | CVSS: 8.6 (HIGH) | EPSS: 0.33524 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-9377", "url": "https://www.cve.org/CVERecord?id=CVE-2025-9377"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-9377"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authenticated RCE via Parental Control command injection", "cve_id": "CVE-2025-9377", "vendor": "TP-Link", "ghsa_id": null, "product": "Archer C7(EU) V2, TL-WR841N/ND(MS) V9", "added_date": "2026-06-01T10:40:02.944Z", "cvss_score": 8.6, "epss_score": 0.33524, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98336, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-9377", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ddb2c96-6ae3-4176-9269-ac6156dcce6d", "vulnerability": {"vulnId": "CVE-2023-50224", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:40:01+02:00"}, "gcve": {"object_uuid": "2ddb2c96-6ae3-4176-9269-ac6156dcce6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:40:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:40:01+00:00"}, "scope": {"notes": "TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability | Affected: TP-Link / TL-WR841N, TL-WR841ND, TL-MR6400, Archer C5, Archer C7, TL-WDR3600, TL-WDR4300, TL-WDR3500, TL-WR740N, TL-WR741ND, TL-WR749N, TL-MR3420, TL-WR1043ND, TL-WR1045ND, TL-WR840N, TL-WR842N, TL-WR842ND, TL-WR845N, TL-WR941ND, TL-WR945N, TL-WA801ND, TL-WA901ND | CVSS: 6.5 (MEDIUM) | EPSS: 0.15558 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-50224", "url": "https://www.cve.org/CVERecord?id=CVE-2023-50224"}, {"id": "GHSA-G654-HW9F-49W6", "url": "https://github.com/advisories/GHSA-G654-HW9F-49W6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-50224"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability", "cve_id": "CVE-2023-50224", "vendor": "TP-Link", "ghsa_id": "GHSA-G654-HW9F-49W6", "product": "TL-WR841N, TL-WR841ND, TL-MR6400, Archer C5, Archer C7, TL-WDR3600, TL-WDR4300, TL-WDR3500, TL-WR740N, TL-WR741ND, TL-WR749N, TL-MR3420, TL-WR1043ND, TL-WR1045ND, TL-WR840N, TL-WR842N, TL-WR842ND, TL-WR845N, TL-WR941ND, TL-WR945N, TL-WA801ND, TL-WA901ND", "added_date": "2026-06-01T10:40:01.833Z", "cvss_score": 6.5, "epss_score": 0.15558, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96733, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-50224", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5bb6c79c-4de3-45de-ba41-baca8c198b13", "vulnerability": {"vulnId": "CVE-2020-24363", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:51+02:00"}, "gcve": {"object_uuid": "5bb6c79c-4de3-45de-ba41-baca8c198b13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:51+00:00"}, "scope": {"notes": "TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a... | Affected: TP-Link / TL-WA855RE | CVSS: 8.8 (HIGH) | EPSS: 0.20689 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-24363", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24363"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24363"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a...", "cve_id": "CVE-2020-24363", "vendor": "TP-Link", "ghsa_id": null, "product": "TL-WA855RE", "added_date": "2026-06-01T10:39:51.028Z", "cvss_score": 8.8, "epss_score": 0.20689, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97464, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24363", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ccf9665-9a19-4d70-b8c1-84c6301a5856", "vulnerability": {"vulnId": "CVE-2025-57819", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:48+02:00"}, "gcve": {"object_uuid": "2ccf9665-9a19-4d70-b8c1-84c6301a5856", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:48+00:00"}, "scope": {"notes": "FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE | Affected: FreePBX / endpoint | CVSS: 10.0 (CRITICAL) | EPSS: 0.85463 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-57819", "url": "https://www.cve.org/CVERecord?id=CVE-2025-57819"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-57819"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE", "cve_id": "CVE-2025-57819", "vendor": "FreePBX", "ghsa_id": null, "product": "endpoint", "added_date": "2026-06-01T10:39:48.629Z", "cvss_score": 10.0, "epss_score": 0.85463, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99716, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-57819", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9c9668df-2998-4994-ab90-d9f7de80b92f", "vulnerability": {"vulnId": "CVE-2025-55177", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:48+02:00"}, "gcve": {"object_uuid": "9c9668df-2998-4994-ab90-d9f7de80b92f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:48+00:00"}, "scope": {"notes": "Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78,... | Affected: Facebook / WhatsApp Desktop for Mac, WhatsApp Business for iOS, WhatsApp for iOS | CVSS: 5.4 (MEDIUM) | EPSS: 0.04304 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-55177", "url": "https://www.cve.org/CVERecord?id=CVE-2025-55177"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-55177"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78,...", "cve_id": "CVE-2025-55177", "vendor": "Facebook", "ghsa_id": null, "product": "WhatsApp Desktop for Mac, WhatsApp Business for iOS, WhatsApp for iOS", "added_date": "2026-06-01T10:39:48.575Z", "cvss_score": 5.4, "epss_score": 0.04304, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90836, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-55177", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "80b4f25e-6dff-46a0-b6c5-d3ab3a95d65a", "vulnerability": {"vulnId": "CVE-2025-7775", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:36+02:00"}, "gcve": {"object_uuid": "80b4f25e-6dff-46a0-b6c5-d3ab3a95d65a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:36+00:00"}, "scope": {"notes": "Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service | Affected: NetScaler / ADC, Gateway | CVSS: 9.2 (CRITICAL) | EPSS: 0.19631 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-7775", "url": "https://www.cve.org/CVERecord?id=CVE-2025-7775"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-7775"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service", "cve_id": "CVE-2025-7775", "vendor": "NetScaler", "ghsa_id": null, "product": "ADC, Gateway", "added_date": "2026-06-01T10:39:36.518Z", "cvss_score": 9.2, "epss_score": 0.19631, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97313, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-7775", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ee7ceae2-de7e-415c-8d5e-0ded4dac8ef2", "vulnerability": {"vulnId": "CVE-2025-48384", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:30+02:00"}, "gcve": {"object_uuid": "ee7ceae2-de7e-415c-8d5e-0ded4dac8ef2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:30+00:00"}, "scope": {"notes": "Git allows arbitrary code execution through broken config quoting | Affected: Git / git | CVSS: 8.0 (HIGH) | EPSS: 0.042 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48384", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48384"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48384"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Git allows arbitrary code execution through broken config quoting", "cve_id": "CVE-2025-48384", "vendor": "Git", "ghsa_id": null, "product": "git", "added_date": "2026-06-01T10:39:30.704Z", "cvss_score": 8.0, "epss_score": 0.042, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90642, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48384", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "354e4186-657b-4ef9-9a08-d0d6d327d628", "vulnerability": {"vulnId": "CVE-2024-8069", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:30+02:00"}, "gcve": {"object_uuid": "354e4186-657b-4ef9-9a08-d0d6d327d628", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:30+00:00"}, "scope": {"notes": "Limited remote code execution with privilege of a NetworkService Account access | Affected: Citrix Session Recording / Citrix Session Recording | CVSS: 5.1 (MEDIUM) | EPSS: 0.14643 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-8069", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8069"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8069"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Limited remote code execution with privilege of a NetworkService Account access", "cve_id": "CVE-2024-8069", "vendor": "Citrix Session Recording", "ghsa_id": null, "product": "Citrix Session Recording", "added_date": "2026-06-01T10:39:30.357Z", "cvss_score": 5.1, "epss_score": 0.14643, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96559, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8069", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ffb24d10-3aac-4b2d-8ee0-4691850f14e1", "vulnerability": {"vulnId": "CVE-2024-8068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:30+02:00"}, "gcve": {"object_uuid": "ffb24d10-3aac-4b2d-8ee0-4691850f14e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:30+00:00"}, "scope": {"notes": "Privilege escalation to NetworkService Account access | Affected: Citrix / Citrix Session Recording | CVSS: 5.1 (MEDIUM) | EPSS: 0.03481 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-8068", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8068"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Privilege escalation to NetworkService Account access", "cve_id": "CVE-2024-8068", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix Session Recording", "added_date": "2026-06-01T10:39:30.332Z", "cvss_score": 5.1, "epss_score": 0.03481, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8872, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8068", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1ec4a7c1-56c7-484c-bb8f-a38bb930504b", "vulnerability": {"vulnId": "CVE-2025-43300", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:39:18+02:00"}, "gcve": {"object_uuid": "1ec4a7c1-56c7-484c-bb8f-a38bb930504b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:39:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:39:18+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and... | Affected: Apple / iOS and iPadOS, iPadOS, macOS | CVSS: 10.0 (CRITICAL) | EPSS: 0.32498 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-43300", "url": "https://www.cve.org/CVERecord?id=CVE-2025-43300"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-43300"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and...", "cve_id": "CVE-2025-43300", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, iPadOS, macOS", "added_date": "2026-06-01T10:39:18.439Z", "cvss_score": 10.0, "epss_score": 0.32498, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9829, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-43300", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "45e9a888-3391-48b8-8123-4456695bd95c", "vulnerability": {"vulnId": "CVE-2025-8876", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:55+02:00"}, "gcve": {"object_uuid": "45e9a888-3391-48b8-8123-4456695bd95c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:55+00:00"}, "scope": {"notes": "Command Injection Vulnerability | Affected: N-able / N-central | CVSS: 9.4 (CRITICAL) | EPSS: 0.03448 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-8876", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8876"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8876"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection Vulnerability", "cve_id": "CVE-2025-8876", "vendor": "N-able", "ghsa_id": null, "product": "N-central", "added_date": "2026-06-01T10:38:55.953Z", "cvss_score": 9.4, "epss_score": 0.03448, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8876", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f862ea79-be07-4bb9-9272-404c71c0ed8f", "vulnerability": {"vulnId": "CVE-2025-8875", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:55+02:00"}, "gcve": {"object_uuid": "f862ea79-be07-4bb9-9272-404c71c0ed8f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:55+00:00"}, "scope": {"notes": "Insecure Deserialization Vulnerability | Affected: N-able / N-central | CVSS: 9.4 (CRITICAL) | EPSS: 0.01899 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-8875", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8875"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8875"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insecure Deserialization Vulnerability", "cve_id": "CVE-2025-8875", "vendor": "N-able", "ghsa_id": null, "product": "N-central", "added_date": "2026-06-01T10:38:55.932Z", "cvss_score": 9.4, "epss_score": 0.01899, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78924, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8875", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5a61989f-976f-4fb6-85a7-082de155d09c", "vulnerability": {"vulnId": "CVE-2025-54948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:51+02:00"}, "gcve": {"object_uuid": "5a61989f-976f-4fb6-85a7-082de155d09c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:51+00:00"}, "scope": {"notes": "A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code... | Affected: Trend Micro / Trend Micro Apex One | CVSS: 9.4 (CRITICAL) | EPSS: 0.2204 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-54948", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code...", "cve_id": "CVE-2025-54948", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex One", "added_date": "2026-06-01T10:38:51.174Z", "cvss_score": 9.4, "epss_score": 0.2204, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97599, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54948", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f5f437be-0dd4-40d8-b46c-6af293f83017", "vulnerability": {"vulnId": "CVE-2013-3893", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:43+02:00"}, "gcve": {"object_uuid": "f5f437be-0dd4-40d8-b46c-6af293f83017", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:43+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.87526 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3893", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3893"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3893"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote...", "cve_id": "CVE-2013-3893", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2026-06-01T10:38:43.906Z", "cvss_score": 8.8, "epss_score": 0.87526, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99755, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3893", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "11fa6ac2-a76e-44cf-874d-33b83914b025", "vulnerability": {"vulnId": "CVE-2007-0671", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:43+02:00"}, "gcve": {"object_uuid": "11fa6ac2-a76e-44cf-874d-33b83914b025", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:43+00:00"}, "scope": {"notes": "Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted... | Affected: Microsoft / Excel | CVSS: 8.8 (HIGH) | EPSS: 0.43241 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2007-0671", "url": "https://www.cve.org/CVERecord?id=CVE-2007-0671"}, {"id": "previdian", "url": "https://previdian.com/CVE-2007-0671"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted...", "cve_id": "CVE-2007-0671", "vendor": "Microsoft", "ghsa_id": null, "product": "Excel", "added_date": "2026-06-01T10:38:43.853Z", "cvss_score": 8.8, "epss_score": 0.43241, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98688, "used_in_malware": "unknown", "vulnerability_id": "CVE-2007-0671", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1208180b-c37f-4096-b56f-e71a49b56f0d", "vulnerability": {"vulnId": "CVE-2025-8088", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:35+02:00"}, "gcve": {"object_uuid": "1208180b-c37f-4096-b56f-e71a49b56f0d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:35+00:00"}, "scope": {"notes": "Path traversal vulnerability in WinRAR | Affected: Win.rar / WinRAR | CVSS: 8.4 (HIGH) | EPSS: 0.94051 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-8088", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8088"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8088"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path traversal vulnerability in WinRAR", "cve_id": "CVE-2025-8088", "vendor": "Win.rar", "ghsa_id": null, "product": "WinRAR", "added_date": "2026-06-01T10:38:35.408Z", "cvss_score": 8.4, "epss_score": 0.94051, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8088", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fa16ec81-a613-47b1-8ffd-8c852fa1211e", "vulnerability": {"vulnId": "CVE-2022-40799", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:24+02:00"}, "gcve": {"object_uuid": "fa16ec81-a613-47b1-8ffd-8c852fa1211e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:24+00:00"}, "scope": {"notes": "Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the... | Affected: D-Link / DNR-322L | CVSS: 8.8 (HIGH) | EPSS: 0.3365 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-40799", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40799"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40799"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the...", "cve_id": "CVE-2022-40799", "vendor": "D-Link", "ghsa_id": null, "product": "DNR-322L", "added_date": "2026-06-01T10:38:24.413Z", "cvss_score": 8.8, "epss_score": 0.3365, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98341, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40799", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "05e99af8-e72b-4ee9-9a7c-c4d0ba9a3421", "vulnerability": {"vulnId": "CVE-2020-25078", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:24+02:00"}, "gcve": {"object_uuid": "05e99af8-e72b-4ee9-9a7c-c4d0ba9a3421", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:24+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint... | Affected: D-Link / DCS-2530L, DCS-2670L | CVSS: 7.5 (HIGH) | EPSS: 0.97511 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-25078", "url": "https://www.cve.org/CVERecord?id=CVE-2020-25078"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-25078"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint...", "cve_id": "CVE-2020-25078", "vendor": "D-Link", "ghsa_id": null, "product": "DCS-2530L, DCS-2670L", "added_date": "2026-06-01T10:38:24.387Z", "cvss_score": 7.5, "epss_score": 0.97511, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.999, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-25078", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d77840c-75c1-434c-80b1-49472598170a", "vulnerability": {"vulnId": "CVE-2020-25079", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:24+02:00"}, "gcve": {"object_uuid": "6d77840c-75c1-434c-80b1-49472598170a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:24+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated... | Affected: D-Link / DCS-2530L, DCS-2670L | CVSS: 8.8 (HIGH) | EPSS: 0.54007 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-25079", "url": "https://www.cve.org/CVERecord?id=CVE-2020-25079"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-25079"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated...", "cve_id": "CVE-2020-25079", "vendor": "D-Link", "ghsa_id": null, "product": "DCS-2530L, DCS-2670L", "added_date": "2026-06-01T10:38:24.400Z", "cvss_score": 8.8, "epss_score": 0.54007, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98974, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-25079", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "25833348-d550-4fd2-85cd-eae03b8981b9", "vulnerability": {"vulnId": "CVE-2023-44976", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:13+02:00"}, "gcve": {"object_uuid": "25833348-d550-4fd2-85cd-eae03b8981b9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:13+00:00"}, "scope": {"notes": "Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via... | Affected: Hangzhou Shunwang / Rentdrv2 | CVSS: 3.2 (LOW) | EPSS: 0.00179 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-44976", "url": "https://www.cve.org/CVERecord?id=CVE-2023-44976"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-44976"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via...", "cve_id": "CVE-2023-44976", "vendor": "Hangzhou Shunwang", "ghsa_id": null, "product": "Rentdrv2", "added_date": "2026-06-01T10:38:13.436Z", "cvss_score": 3.2, "epss_score": 0.00179, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.06678, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-44976", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "89f65aba-98db-4bbc-878f-c570925effbb", "vulnerability": {"vulnId": "CVE-2014-125123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:38:09+02:00"}, "gcve": {"object_uuid": "89f65aba-98db-4bbc-878f-c570925effbb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:38:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:38:09+00:00"}, "scope": {"notes": "Kloxo < 6.1.12 Unauthenticated SQL Injection RCE | Affected: LXCenter / Kloxo | CVSS: 10.0 (CRITICAL) | EPSS: 0.01038 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-125123", "url": "https://www.cve.org/CVERecord?id=CVE-2014-125123"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-125123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kloxo < 6.1.12 Unauthenticated SQL Injection RCE", "cve_id": "CVE-2014-125123", "vendor": "LXCenter", "ghsa_id": null, "product": "Kloxo", "added_date": "2026-06-01T10:38:09.412Z", "cvss_score": 10.0, "epss_score": 0.01038, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62647, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-125123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a6d81b8d-1f58-4338-ab73-1ba9c49b16ec", "vulnerability": {"vulnId": "CVE-2025-4632", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:52+02:00"}, "gcve": {"object_uuid": "a6d81b8d-1f58-4338-ab73-1ba9c49b16ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:52+00:00"}, "scope": {"notes": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to... | Affected: Samsung Electronics / MagicINFO 9 Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.24295 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-4632", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4632"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4632"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to...", "cve_id": "CVE-2025-4632", "vendor": "Samsung Electronics", "ghsa_id": null, "product": "MagicINFO 9 Server", "added_date": "2026-06-01T10:37:52.172Z", "cvss_score": 9.8, "epss_score": 0.24295, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97798, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4632", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3e91a754-8bbe-47c9-8f64-1de20377c163", "vulnerability": {"vulnId": "CVE-2025-47729", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:52+02:00"}, "gcve": {"object_uuid": "3e91a754-8bbe-47c9-8f64-1de20377c163", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:52+00:00"}, "scope": {"notes": "The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is... | Affected: TeleMessage / archiving backend | CVSS: 1.9 (LOW) | EPSS: 0.00428 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-47729", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47729"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47729"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is...", "cve_id": "CVE-2025-47729", "vendor": "TeleMessage", "ghsa_id": null, "product": "archiving backend", "added_date": "2026-06-01T10:37:52.207Z", "cvss_score": 1.9, "epss_score": 0.00428, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.3473, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47729", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "74abc1ab-1c52-4cf8-b6f2-2daea1d291a8", "vulnerability": {"vulnId": "CVE-2025-42999", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:52+02:00"}, "gcve": {"object_uuid": "74abc1ab-1c52-4cf8-b6f2-2daea1d291a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:52+00:00"}, "scope": {"notes": "Insecure Deserialization in SAP NetWeaver (Visual Composer development server) | Affected: SAP_SE / SAP NetWeaver (Visual Composer development server) | CVSS: 9.1 (CRITICAL) | EPSS: 0.13868 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-42999", "url": "https://www.cve.org/CVERecord?id=CVE-2025-42999"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-42999"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insecure Deserialization in SAP NetWeaver (Visual Composer development server)", "cve_id": "CVE-2025-42999", "vendor": "SAP_SE", "ghsa_id": null, "product": "SAP NetWeaver (Visual Composer development server)", "added_date": "2026-06-01T10:37:52.113Z", "cvss_score": 9.1, "epss_score": 0.13868, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96418, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-42999", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5a70b680-1920-4369-8d60-b3883fe8fdd1", "vulnerability": {"vulnId": "CVE-2025-32756", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:50+02:00"}, "gcve": {"object_uuid": "5a70b680-1920-4369-8d60-b3883fe8fdd1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:50+00:00"}, "scope": {"notes": "A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions,... | Affected: Fortinet / FortiNDR, FortiCamera, FortiRecorder, FortiVoice, FortiMail | CVSS: 9.8 (CRITICAL) | EPSS: 0.29812 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32756", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32756"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32756"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions,...", "cve_id": "CVE-2025-32756", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiNDR, FortiCamera, FortiRecorder, FortiVoice, FortiMail", "added_date": "2026-06-01T10:37:50.198Z", "cvss_score": 9.8, "epss_score": 0.29812, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98151, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32756", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "037c119d-59d0-4863-a161-454f1914a036", "vulnerability": {"vulnId": "CVE-2023-2533", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:36+02:00"}, "gcve": {"object_uuid": "037c119d-59d0-4863-a161-454f1914a036", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:36+00:00"}, "scope": {"notes": "PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF | Affected: PaperCut / PaperCut NG/MF | CVSS: 8.4 (HIGH) | EPSS: 0.28621 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-2533", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2533"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2533"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF", "cve_id": "CVE-2023-2533", "vendor": "PaperCut", "ghsa_id": null, "product": "PaperCut NG/MF", "added_date": "2026-06-01T10:37:36.480Z", "cvss_score": 8.4, "epss_score": 0.28621, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2533", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "70036c36-2eef-4649-aef9-29ede5ac6c6f", "vulnerability": {"vulnId": "CVE-2025-20281", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:36+02:00"}, "gcve": {"object_uuid": "70036c36-2eef-4649-aef9-29ede5ac6c6f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:36+00:00"}, "scope": {"notes": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability | Affected: Cisco / Cisco Identity Services Engine Software | CVSS: 10.0 (CRITICAL) | EPSS: 0.97601 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-20281", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20281"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20281"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability", "cve_id": "CVE-2025-20281", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Identity Services Engine Software", "added_date": "2026-06-01T10:37:36.522Z", "cvss_score": 10.0, "epss_score": 0.97601, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99901, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20281", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3c4ef79e-7158-44bc-a79a-2819dfc6cdc2", "vulnerability": {"vulnId": "CVE-2025-20337", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:36+02:00"}, "gcve": {"object_uuid": "3c4ef79e-7158-44bc-a79a-2819dfc6cdc2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:36+00:00"}, "scope": {"notes": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability | Affected: Cisco / Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector | CVSS: 10.0 (CRITICAL) | EPSS: 0.67825 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-20337", "url": "https://www.cve.org/CVERecord?id=CVE-2025-20337"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-20337"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability", "cve_id": "CVE-2025-20337", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector", "added_date": "2026-06-01T10:37:36.546Z", "cvss_score": 10.0, "epss_score": 0.67825, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-20337", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "409c4376-c325-4398-a70e-0c495968f948", "vulnerability": {"vulnId": "CVE-2025-49706", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:23+02:00"}, "gcve": {"object_uuid": "409c4376-c325-4398-a70e-0c495968f948", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:23+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Spoofing Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 6.5 (MEDIUM) | EPSS: 0.99076 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-49706", "url": "https://www.cve.org/CVERecord?id=CVE-2025-49706"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-49706"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Spoofing Vulnerability", "cve_id": "CVE-2025-49706", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-06-01T10:37:23.318Z", "cvss_score": 6.5, "epss_score": 0.99076, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99932, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-49706", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3eadccb6-c12a-48a4-9e2f-f44adad4913a", "vulnerability": {"vulnId": "CVE-2025-6558", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:23+02:00"}, "gcve": {"object_uuid": "3eadccb6-c12a-48a4-9e2f-f44adad4913a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:23+00:00"}, "scope": {"notes": "Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.09585 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-6558", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6558"}, {"id": "GHSA-5W32-633G-38JH", "url": "https://github.com/advisories/GHSA-5W32-633G-38JH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6558"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially...", "cve_id": "CVE-2025-6558", "vendor": "Google", "ghsa_id": "GHSA-5W32-633G-38JH", "product": "Chrome", "added_date": "2026-06-01T10:37:23.924Z", "cvss_score": 8.8, "epss_score": 0.09585, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95332, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6558", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6a9494b-76f5-4746-b495-64ff2af7ac08", "vulnerability": {"vulnId": "CVE-2025-49704", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:23+02:00"}, "gcve": {"object_uuid": "a6a9494b-76f5-4746-b495-64ff2af7ac08", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:23+00:00"}, "scope": {"notes": "Microsoft SharePoint Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 | CVSS: 8.8 (HIGH) | EPSS: 0.99995 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-49704", "url": "https://www.cve.org/CVERecord?id=CVE-2025-49704"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-49704"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Remote Code Execution Vulnerability", "cve_id": "CVE-2025-49704", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019", "added_date": "2026-06-01T10:37:23.293Z", "cvss_score": 8.8, "epss_score": 0.99995, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99988, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-49704", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e186d62-9cf4-46e5-a359-15595b7eaf46", "vulnerability": {"vulnId": "CVE-2025-2775", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:22+02:00"}, "gcve": {"object_uuid": "6e186d62-9cf4-46e5-a359-15595b7eaf46", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:22+00:00"}, "scope": {"notes": "SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection | Affected: SysAid / SysAid On-Prem | CVSS: 9.3 (CRITICAL) | EPSS: 0.42952 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-2775", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2775"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2775"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection", "cve_id": "CVE-2025-2775", "vendor": "SysAid", "ghsa_id": null, "product": "SysAid On-Prem", "added_date": "2026-06-01T10:37:22.521Z", "cvss_score": 9.3, "epss_score": 0.42952, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98682, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2775", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7269f925-6397-4aa5-8f8c-8d6255d23f69", "vulnerability": {"vulnId": "CVE-2025-2776", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:22+02:00"}, "gcve": {"object_uuid": "7269f925-6397-4aa5-8f8c-8d6255d23f69", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:22+00:00"}, "scope": {"notes": "SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection | Affected: SysAid / SysAid On-Prem | CVSS: 9.3 (CRITICAL) | EPSS: 0.64397 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-2776", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2776"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2776"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection", "cve_id": "CVE-2025-2776", "vendor": "SysAid", "ghsa_id": null, "product": "SysAid On-Prem", "added_date": "2026-06-01T10:37:22.535Z", "cvss_score": 9.3, "epss_score": 0.64397, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99213, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2776", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "80725c6d-8f68-4b46-9184-525970ec7f29", "vulnerability": {"vulnId": "CVE-2025-53770", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:19+02:00"}, "gcve": {"object_uuid": "80725c6d-8f68-4b46-9184-525970ec7f29", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:19+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:19+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 9.8 (CRITICAL) | EPSS: 0.99998 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-53770", "url": "https://www.cve.org/CVERecord?id=CVE-2025-53770"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-53770"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability", "cve_id": "CVE-2025-53770", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2026-06-01T10:37:19.166Z", "cvss_score": 9.8, "epss_score": 0.99998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99991, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-53770", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cea243a6-8a50-4227-9974-c5ad32820f8a", "vulnerability": {"vulnId": "CVE-2025-54309", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:37:11+02:00"}, "gcve": {"object_uuid": "cea243a6-8a50-4227-9974-c5ad32820f8a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:37:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:37:11+00:00"}, "scope": {"notes": "CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote... | Affected: CrushFTP / CrushFTP | CVSS: 9.0 (CRITICAL) | EPSS: 0.94905 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-54309", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54309"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54309"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote...", "cve_id": "CVE-2025-54309", "vendor": "CrushFTP", "ghsa_id": null, "product": "CrushFTP", "added_date": "2026-06-01T10:37:11.050Z", "cvss_score": 9.0, "epss_score": 0.94905, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99859, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54309", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3526d9dd-9ef6-467f-acf7-12fe71e287c5", "vulnerability": {"vulnId": "CVE-2025-47812", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:56+02:00"}, "gcve": {"object_uuid": "3526d9dd-9ef6-467f-acf7-12fe71e287c5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:56+00:00"}, "scope": {"notes": "In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\\0' bytes, ultimately allowing injection of arbitrary Lua code into... | Affected: Wftpserver / Wing FTP Server | CVSS: 10.0 (CRITICAL) | EPSS: 0.93235 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-47812", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47812"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47812"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\\0' bytes, ultimately allowing injection of arbitrary Lua code into...", "cve_id": "CVE-2025-47812", "vendor": "Wftpserver", "ghsa_id": null, "product": "Wing FTP Server", "added_date": "2026-06-01T10:36:56.791Z", "cvss_score": 10.0, "epss_score": 0.93235, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99834, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47812", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3675b9ca-2f8b-497a-bb3d-04fed85cc4d1", "vulnerability": {"vulnId": "CVE-2014-3931", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:30+02:00"}, "gcve": {"object_uuid": "3675b9ca-2f8b-497a-bb3d-04fed85cc4d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:30+00:00"}, "scope": {"notes": "fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption. | Affected: MRLG / Multi-Router Looking Glass | CVSS: 9.8 (CRITICAL) | EPSS: 0.28978 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-3931", "url": "https://www.cve.org/CVERecord?id=CVE-2014-3931"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-3931"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.", "cve_id": "CVE-2014-3931", "vendor": "MRLG", "ghsa_id": null, "product": "Multi-Router Looking Glass", "added_date": "2026-06-01T10:36:30.780Z", "cvss_score": 9.8, "epss_score": 0.28978, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98109, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-3931", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "34eed024-3267-4b45-b2ae-f47f6986cd21", "vulnerability": {"vulnId": "CVE-2019-5418", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:30+02:00"}, "gcve": {"object_uuid": "34eed024-3267-4b45-b2ae-f47f6986cd21", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:30+00:00"}, "scope": {"notes": "There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted... | Affected: Rails / https://github.com/rails/rails | CVSS: 7.5 (HIGH) | EPSS: 0.98507 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-5418", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5418"}, {"id": "GHSA-86G5-2WH3-GC9J", "url": "https://github.com/advisories/GHSA-86G5-2WH3-GC9J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5418"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted...", "cve_id": "CVE-2019-5418", "vendor": "Rails", "ghsa_id": "GHSA-86G5-2WH3-GC9J", "product": "https://github.com/rails/rails", "added_date": "2026-06-01T10:36:30.850Z", "cvss_score": 7.5, "epss_score": 0.98507, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99919, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5418", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72632f3a-abc8-4f2c-affe-29ed65f71255", "vulnerability": {"vulnId": "CVE-2019-9621", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:30+02:00"}, "gcve": {"object_uuid": "72632f3a-abc8-4f2c-affe-29ed65f71255", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:30+00:00"}, "scope": {"notes": "Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows... | Affected: Zimbra / Zimbra Collaboration Suite | CVSS: 7.5 (HIGH) | EPSS: 0.81037 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-9621", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9621"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9621"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows...", "cve_id": "CVE-2019-9621", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration Suite", "added_date": "2026-06-01T10:36:30.865Z", "cvss_score": 7.5, "epss_score": 0.81037, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99623, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9621", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bef26d47-bd9a-436d-8f60-3d9e9028daa9", "vulnerability": {"vulnId": "CVE-2016-10033", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:30+02:00"}, "gcve": {"object_uuid": "bef26d47-bd9a-436d-8f60-3d9e9028daa9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:30+00:00"}, "scope": {"notes": "The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command... | Affected: PHPMailer / PHPMailer | CVSS: 9.8 (CRITICAL) | EPSS: 0.99714 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-10033", "url": "https://www.cve.org/CVERecord?id=CVE-2016-10033"}, {"id": "GHSA-5F37-GXVH-23V6", "url": "https://github.com/advisories/GHSA-5F37-GXVH-23V6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-10033"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command...", "cve_id": "CVE-2016-10033", "vendor": "PHPMailer", "ghsa_id": "GHSA-5F37-GXVH-23V6", "product": "PHPMailer", "added_date": "2026-06-01T10:36:30.804Z", "cvss_score": 9.8, "epss_score": 0.99714, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99951, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-10033", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3e7a8871-6fa7-45af-824a-2759128673cc", "vulnerability": {"vulnId": "CVE-2025-6554", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:20+02:00"}, "gcve": {"object_uuid": "3e7a8871-6fa7-45af-824a-2759128673cc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:20+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.... | Affected: Google / Chrome | CVSS: 8.1 (HIGH) | EPSS: 0.12564 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-6554", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6554"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6554"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page....", "cve_id": "CVE-2025-6554", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T10:36:20.047Z", "cvss_score": 8.1, "epss_score": 0.12564, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96118, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6554", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0185135-e12d-4611-a6d1-58be5c5df806", "vulnerability": {"vulnId": "CVE-2025-48927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:17+02:00"}, "gcve": {"object_uuid": "f0185135-e12d-4611-a6d1-58be5c5df806", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:17+00:00"}, "scope": {"notes": "The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in... | Affected: TeleMessage / service | CVSS: 5.3 (MEDIUM) | EPSS: 0.11104 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48927", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48927"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in...", "cve_id": "CVE-2025-48927", "vendor": "TeleMessage", "ghsa_id": null, "product": "service", "added_date": "2026-06-01T10:36:17.235Z", "cvss_score": 5.3, "epss_score": 0.11104, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95805, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48927", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4e96a4c1-5c16-4273-bc50-266d38adaa84", "vulnerability": {"vulnId": "CVE-2025-48928", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:17+02:00"}, "gcve": {"object_uuid": "4e96a4c1-5c16-4273-bc50-266d38adaa84", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:17+00:00"}, "scope": {"notes": "The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a \"core dump\" in which... | Affected: TeleMessage / service | CVSS: 4.0 (MEDIUM) | EPSS: 0.00553 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-48928", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48928"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48928"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a \"core dump\" in which...", "cve_id": "CVE-2025-48928", "vendor": "TeleMessage", "ghsa_id": null, "product": "service", "added_date": "2026-06-01T10:36:17.248Z", "cvss_score": 4.0, "epss_score": 0.00553, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.4413, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48928", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "504b8f8e-a56a-4088-a79d-1ead815ce0a3", "vulnerability": {"vulnId": "CVE-2025-6543", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:36:14+02:00"}, "gcve": {"object_uuid": "504b8f8e-a56a-4088-a79d-1ead815ce0a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:36:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:36:14+00:00"}, "scope": {"notes": "Memory overflow vulnerability leading to unintended control flow and Denial of Service | Affected: NetScaler / ADC, Gateway | CVSS: 9.2 (CRITICAL) | EPSS: 0.10562 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-6543", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6543"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6543"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Memory overflow vulnerability leading to unintended control flow and Denial of Service", "cve_id": "CVE-2025-6543", "vendor": "NetScaler", "ghsa_id": null, "product": "ADC, Gateway", "added_date": "2026-06-01T10:36:14.774Z", "cvss_score": 9.2, "epss_score": 0.10562, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95648, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6543", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b3419fee-dbc8-4922-a3a6-b5721bd002f8", "vulnerability": {"vulnId": "CVE-2024-0769", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:34:26+02:00"}, "gcve": {"object_uuid": "b3419fee-dbc8-4922-a3a6-b5721bd002f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:34:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:34:26+00:00"}, "scope": {"notes": "D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal | Affected: D-Link / DIR-859 | CVSS: 5.3 (MEDIUM) | EPSS: 0.82714 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-0769", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0769"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0769"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal", "cve_id": "CVE-2024-0769", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-859", "added_date": "2026-06-01T10:34:26.142Z", "cvss_score": 5.3, "epss_score": 0.82714, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9966, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0769", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "906654f0-cf99-4c5b-a169-0dcabfc7800f", "vulnerability": {"vulnId": "CVE-2024-54085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:34:02+02:00"}, "gcve": {"object_uuid": "906654f0-cf99-4c5b-a169-0dcabfc7800f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:34:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:34:02+00:00"}, "scope": {"notes": "Redfish Authentication Bypass | Affected: AMI / MegaRAC-SPx | CVSS: 10.0 (CRITICAL) | EPSS: 0.60747 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-54085", "url": "https://www.cve.org/CVERecord?id=CVE-2024-54085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-54085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Redfish Authentication Bypass", "cve_id": "CVE-2024-54085", "vendor": "AMI", "ghsa_id": null, "product": "MegaRAC-SPx", "added_date": "2026-06-01T10:34:02.334Z", "cvss_score": 10.0, "epss_score": 0.60747, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99125, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-54085", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bf46e10d-652e-4c0e-b54e-d8f4a100ad60", "vulnerability": {"vulnId": "CVE-2019-6693", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:33:55+02:00"}, "gcve": {"object_uuid": "bf46e10d-652e-4c0e-b54e-d8f4a100ad60", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:33:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:33:55+00:00"}, "scope": {"notes": "Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup... | Affected: Fortinet / FortiGate | CVSS: 6.5 (MEDIUM) | EPSS: 0.05828 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-6693", "url": "https://www.cve.org/CVERecord?id=CVE-2019-6693"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-6693"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup...", "cve_id": "CVE-2019-6693", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiGate", "added_date": "2026-06-01T10:33:55.457Z", "cvss_score": 6.5, "epss_score": 0.05828, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92932, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-6693", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "598056d5-04fc-41d3-b401-377be4ebf3e2", "vulnerability": {"vulnId": "CVE-2023-0386", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:33:20+02:00"}, "gcve": {"object_uuid": "598056d5-04fc-41d3-b401-377be4ebf3e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:33:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:33:20+00:00"}, "scope": {"notes": "A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux... | Affected: Linux / Linux kernel | CVSS: 7.8 (HIGH) | EPSS: 0.0788 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-0386", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0386"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0386"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux...", "cve_id": "CVE-2023-0386", "vendor": "Linux", "ghsa_id": null, "product": "Linux kernel", "added_date": "2026-06-01T10:33:20.672Z", "cvss_score": 7.8, "epss_score": 0.0788, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94535, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0386", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3dbffb28-d32a-46ad-abac-5341966811a6", "vulnerability": {"vulnId": "CVE-2025-43200", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:33:11+02:00"}, "gcve": {"object_uuid": "3dbffb28-d32a-46ad-abac-5341966811a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:33:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:33:11+00:00"}, "scope": {"notes": "This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and... | Affected: Apple / iOS and iPadOS, iPadOS, macOS, visionOS, watchOS | CVSS: 4.2 (MEDIUM) | EPSS: 0.01191 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-43200", "url": "https://www.cve.org/CVERecord?id=CVE-2025-43200"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-43200"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and...", "cve_id": "CVE-2025-43200", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, iPadOS, macOS, visionOS, watchOS", "added_date": "2026-06-01T10:33:11.491Z", "cvss_score": 4.2, "epss_score": 0.01191, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6684, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-43200", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2d158279-5318-4445-b9ea-9b6d2fa3d0db", "vulnerability": {"vulnId": "CVE-2023-33538", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:33:02+02:00"}, "gcve": {"object_uuid": "2d158279-5318-4445-b9ea-9b6d2fa3d0db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:33:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:33:02+00:00"}, "scope": {"notes": "TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component... | Affected: TP-Link / TL-WR940N, TL-WR841N, TL-WR740N | CVSS: 8.8 (HIGH) | EPSS: 0.41606 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33538", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33538"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33538"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component...", "cve_id": "CVE-2023-33538", "vendor": "TP-Link", "ghsa_id": null, "product": "TL-WR940N, TL-WR841N, TL-WR740N", "added_date": "2026-06-01T10:33:02.281Z", "cvss_score": 8.8, "epss_score": 0.41606, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98642, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33538", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18ab3ba3-ed82-4f35-9157-2f8d40930f26", "vulnerability": {"vulnId": "CVE-2025-33053", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:32:38+02:00"}, "gcve": {"object_uuid": "18ab3ba3-ed82-4f35-9157-2f8d40930f26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:32:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:32:38+00:00"}, "scope": {"notes": "Internet Shortcut Files Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.87015 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-33053", "url": "https://www.cve.org/CVERecord?id=CVE-2025-33053"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-33053"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Internet Shortcut Files Remote Code Execution Vulnerability", "cve_id": "CVE-2025-33053", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-06-01T10:32:38.192Z", "cvss_score": 8.8, "epss_score": 0.87015, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99744, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-33053", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8df94b3d-224a-4f1f-8a7c-2c7b6cc049a7", "vulnerability": {"vulnId": "CVE-2025-24016", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:32:30+02:00"}, "gcve": {"object_uuid": "8df94b3d-224a-4f1f-8a7c-2c7b6cc049a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:32:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:32:30+00:00"}, "scope": {"notes": "Remote code execution in Wazuh server | Affected: Wazuh / wazuh | CVSS: 9.9 (CRITICAL) | EPSS: 0.9384 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24016", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24016"}, {"id": "GHSA-HCRC-79HJ-M3QH", "url": "https://github.com/advisories/GHSA-HCRC-79HJ-M3QH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24016"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote code execution in Wazuh server", "cve_id": "CVE-2025-24016", "vendor": "Wazuh", "ghsa_id": "GHSA-HCRC-79HJ-M3QH", "product": "wazuh", "added_date": "2026-06-01T10:32:30.977Z", "cvss_score": 9.9, "epss_score": 0.9384, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99843, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24016", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d385663-3f21-4112-95ca-4fdd66fe1cc3", "vulnerability": {"vulnId": "CVE-2025-32433", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:32:20+02:00"}, "gcve": {"object_uuid": "3d385663-3f21-4112-95ca-4fdd66fe1cc3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:32:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:32:20+00:00"}, "scope": {"notes": "Erlang/OTP SSH Vulnerable to Pre-Authentication RCE | Affected: Erlang / otp | CVSS: 10.0 (CRITICAL) | EPSS: 0.98786 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32433", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32433"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32433"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Erlang/OTP SSH Vulnerable to Pre-Authentication RCE", "cve_id": "CVE-2025-32433", "vendor": "Erlang", "ghsa_id": null, "product": "otp", "added_date": "2026-06-01T10:32:20.432Z", "cvss_score": 10.0, "epss_score": 0.98786, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99925, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32433", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8eb304f4-8e13-4f56-b765-c4ace035bfd9", "vulnerability": {"vulnId": "CVE-2024-42009", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:32:11+02:00"}, "gcve": {"object_uuid": "8eb304f4-8e13-4f56-b765-c4ace035bfd9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:32:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:32:11+00:00"}, "scope": {"notes": "A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a... | Affected: Roundcube / Roundcube Webmail | CVSS: 9.3 (CRITICAL) | EPSS: 0.82882 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-42009", "url": "https://www.cve.org/CVERecord?id=CVE-2024-42009"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-42009"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a...", "cve_id": "CVE-2024-42009", "vendor": "Roundcube", "ghsa_id": null, "product": "Roundcube Webmail", "added_date": "2026-06-01T10:32:11.788Z", "cvss_score": 9.3, "epss_score": 0.82882, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99663, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-42009", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "101deeed-8b7b-4573-abcc-6eaa1debb689", "vulnerability": {"vulnId": "CVE-2025-5419", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:31:54+02:00"}, "gcve": {"object_uuid": "101deeed-8b7b-4573-abcc-6eaa1debb689", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:31:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:31:54+00:00"}, "scope": {"notes": "Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.07821 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-5419", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5419"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5419"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2025-5419", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2026-06-01T10:31:54.550Z", "cvss_score": 8.8, "epss_score": 0.07821, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94495, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5419", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b828c33-6e37-4042-87c3-d55575fc5c5f", "vulnerability": {"vulnId": "CVE-2025-27038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:31:39+02:00"}, "gcve": {"object_uuid": "8b828c33-6e37-4042-87c3-d55575fc5c5f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:31:39+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:31:39+00:00"}, "scope": {"notes": "Use After Free in Graphics | Affected: Qualcomm / Snapdragon | CVSS: 7.5 (HIGH) | EPSS: 0.01016 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-27038", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27038"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use After Free in Graphics", "cve_id": "CVE-2025-27038", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2026-06-01T10:31:39.819Z", "cvss_score": 7.5, "epss_score": 0.01016, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27038", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b95dbd70-3afe-4cf8-8d88-a332e2a1e7eb", "vulnerability": {"vulnId": "CVE-2025-21480", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:31:32+02:00"}, "gcve": {"object_uuid": "b95dbd70-3afe-4cf8-8d88-a332e2a1e7eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:31:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:31:32+00:00"}, "scope": {"notes": "Incorrect Authorization in Graphics Windows | Affected: Qualcomm / Snapdragon | CVSS: 8.6 (HIGH) | EPSS: 0.0046 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21480", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21480"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21480"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect Authorization in Graphics Windows", "cve_id": "CVE-2025-21480", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2026-06-01T10:31:32.721Z", "cvss_score": 8.6, "epss_score": 0.0046, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.37521, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21480", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "77c71f35-0ca5-403f-9d11-7ba5c0bc9a7d", "vulnerability": {"vulnId": "CVE-2025-21479", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:31:25+02:00"}, "gcve": {"object_uuid": "77c71f35-0ca5-403f-9d11-7ba5c0bc9a7d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:31:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:31:25+00:00"}, "scope": {"notes": "Incorrect Authorization in Graphics | Affected: Qualcomm / Snapdragon | CVSS: 8.6 (HIGH) | EPSS: 0.00843 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21479", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21479"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21479"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect Authorization in Graphics", "cve_id": "CVE-2025-21479", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2026-06-01T10:31:25.802Z", "cvss_score": 8.6, "epss_score": 0.00843, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.56421, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21479", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5aeaffb5-6d30-4a69-83e6-b64e8ed6ee52", "vulnerability": {"vulnId": "CVE-2025-3935", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:31:13+02:00"}, "gcve": {"object_uuid": "5aeaffb5-6d30-4a69-83e6-b64e8ed6ee52", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:31:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:31:13+00:00"}, "scope": {"notes": "ScreenConnect Exposure to ASP.NET ViewState Code Injection | Affected: ConnectWise / ScreenConnect | CVSS: 8.1 (HIGH) | EPSS: 0.03507 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-3935", "url": "https://www.cve.org/CVERecord?id=CVE-2025-3935"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-3935"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ScreenConnect Exposure to ASP.NET ViewState Code Injection", "cve_id": "CVE-2025-3935", "vendor": "ConnectWise", "ghsa_id": null, "product": "ScreenConnect", "added_date": "2026-06-01T10:31:13.860Z", "cvss_score": 8.1, "epss_score": 0.03507, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88804, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-3935", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "caf77fd5-825b-4fa4-8a13-31e22d1d65e1", "vulnerability": {"vulnId": "CVE-2025-35939", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:31:06+02:00"}, "gcve": {"object_uuid": "caf77fd5-825b-4fa4-8a13-31e22d1d65e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:31:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:31:06+00:00"}, "scope": {"notes": "Craft CMS stores user-provided content in session files | Affected: Craft / CMS | CVSS: 6.9 (MEDIUM) | EPSS: 0.01317 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-35939", "url": "https://www.cve.org/CVERecord?id=CVE-2025-35939"}, {"id": "GHSA-7VRX-9684-XRF2", "url": "https://github.com/advisories/GHSA-7VRX-9684-XRF2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-35939"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Craft CMS stores user-provided content in session files", "cve_id": "CVE-2025-35939", "vendor": "Craft", "ghsa_id": "GHSA-7VRX-9684-XRF2", "product": "CMS", "added_date": "2026-06-01T10:31:06.978Z", "cvss_score": 6.9, "epss_score": 0.01317, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69748, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-35939", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "74901da5-0d9d-4d2a-811e-c2366c739276", "vulnerability": {"vulnId": "CVE-2024-56145", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:30:59+02:00"}, "gcve": {"object_uuid": "74901da5-0d9d-4d2a-811e-c2366c739276", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:30:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:30:59+00:00"}, "scope": {"notes": "RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms | Affected: Craftcms / cms | CVSS: 9.3 (CRITICAL) | EPSS: 0.97405 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-56145", "url": "https://www.cve.org/CVERecord?id=CVE-2024-56145"}, {"id": "GHSA-2P6P-9RC9-62J9", "url": "https://github.com/advisories/GHSA-2P6P-9RC9-62J9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-56145"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms", "cve_id": "CVE-2024-56145", "vendor": "Craftcms", "ghsa_id": "GHSA-2P6P-9RC9-62J9", "product": "cms", "added_date": "2026-06-01T10:30:59.931Z", "cvss_score": 9.3, "epss_score": 0.97405, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99898, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-56145", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0a829d5e-58a6-401c-a675-3332169b53a4", "vulnerability": {"vulnId": "CVE-2023-39780", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:29:36+02:00"}, "gcve": {"object_uuid": "0a829d5e-58a6-401c-a675-3332169b53a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:29:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:29:36+00:00"}, "scope": {"notes": "On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist... | Affected: ASUS / RT-AX55 | CVSS: 8.8 (HIGH) | EPSS: 0.40189 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-39780", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39780"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39780"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist...", "cve_id": "CVE-2023-39780", "vendor": "ASUS", "ghsa_id": null, "product": "RT-AX55", "added_date": "2026-06-01T10:29:36.477Z", "cvss_score": 8.8, "epss_score": 0.40189, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98596, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39780", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d32d25f8-8b83-4b5c-a1f6-042f57610853", "vulnerability": {"vulnId": "CVE-2026-20182", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T12:28:27+02:00"}, "gcve": {"object_uuid": "d32d25f8-8b83-4b5c-a1f6-042f57610853", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T10:28:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T10:28:27+00:00"}, "scope": {"notes": "Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager | CVSS: 10.0 (CRITICAL) | EPSS: 0.91522 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-20182", "url": "https://www.cve.org/CVERecord?id=CVE-2026-20182"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-20182"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability", "cve_id": "CVE-2026-20182", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager", "added_date": "2026-06-01T10:28:27.362Z", "cvss_score": 10.0, "epss_score": 0.91522, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99811, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-20182", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "782971eb-debc-43cd-863e-a472f834da34", "vulnerability": {"vulnId": "CVE-2025-1302", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "782971eb-debc-43cd-863e-a472f834da34", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker... | Affected: JSONPath-Plus / jsonpath-plus | CVSS: 9.3 (CRITICAL) | EPSS: 0.10395 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-1302", "url": "https://www.cve.org/CVERecord?id=CVE-2025-1302"}, {"id": "GHSA-HW8R-X6GR-5GJP", "url": "https://github.com/advisories/GHSA-HW8R-X6GR-5GJP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-1302"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker...", "cve_id": "CVE-2025-1302", "vendor": "JSONPath-Plus", "ghsa_id": "GHSA-HW8R-X6GR-5GJP", "product": "jsonpath-plus", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.10395, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95597, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-1302", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "63d70163-8189-4bd5-94a9-567a487e7197", "vulnerability": {"vulnId": "CVE-2026-3055", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "63d70163-8189-4bd5-94a9-567a487e7197", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "Insufficient input validation leading to memory overread | Affected: NetScaler / ADC, Gateway | CVSS: 9.3 (CRITICAL) | EPSS: 0.04042 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-3055", "url": "https://www.cve.org/CVERecord?id=CVE-2026-3055"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-3055"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient input validation leading to memory overread", "cve_id": "CVE-2026-3055", "vendor": "NetScaler", "ghsa_id": null, "product": "ADC, Gateway", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.04042, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90303, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-3055", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2390caa7-a97c-442f-8f71-e62f89be6478", "vulnerability": {"vulnId": "CVE-2025-5777", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "2390caa7-a97c-442f-8f71-e62f89be6478", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread | Affected: NetScaler / ADC, Gateway | CVSS: 9.3 (CRITICAL) | EPSS: 0.99972 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-5777", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5777"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5777"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread", "cve_id": "CVE-2025-5777", "vendor": "NetScaler", "ghsa_id": null, "product": "ADC, Gateway", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.99972, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99978, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-5777", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fc27bd33-3be4-481c-9b36-37c3a1a95ba8", "vulnerability": {"vulnId": "CVE-2025-55182", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "fc27bd33-3be4-481c-9b36-37c3a1a95ba8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including... | Affected: Meta / react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel | CVSS: 10.0 (CRITICAL) | EPSS: 0.99802 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-55182", "url": "https://www.cve.org/CVERecord?id=CVE-2025-55182"}, {"id": "GHSA-FV66-9V8Q-G76R", "url": "https://github.com/advisories/GHSA-FV66-9V8Q-G76R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-55182"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including...", "cve_id": "CVE-2025-55182", "vendor": "Meta", "ghsa_id": "GHSA-FV66-9V8Q-G76R", "product": "react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99802, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99957, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-55182", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "814e8202-1288-45d4-b024-bd65710c1270", "vulnerability": {"vulnId": "CVE-2026-34197", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "814e8202-1288-45d4-b024-bd65710c1270", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans | Affected: Apache / Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | CVSS: 8.8 (HIGH) | EPSS: 0.15492 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-34197", "url": "https://www.cve.org/CVERecord?id=CVE-2026-34197"}, {"id": "GHSA-RXPJ-7QVF-XV32", "url": "https://github.com/advisories/GHSA-RXPJ-7QVF-XV32"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-34197"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans", "cve_id": "CVE-2026-34197", "vendor": "Apache", "ghsa_id": "GHSA-RXPJ-7QVF-XV32", "product": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.15492, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96706, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-34197", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3e2e4cad-2057-4dba-adfe-4f44e5d7094e", "vulnerability": {"vulnId": "CVE-2024-12847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "3e2e4cad-2057-4dba-adfe-4f44e5d7094e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "NETGEAR DGN setup.cgi OS Command Injection | Affected: NETGEAR / DGN1000 | CVSS: 9.8 (CRITICAL) | EPSS: 0.29939 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-12847", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NETGEAR DGN setup.cgi OS Command Injection", "cve_id": "CVE-2024-12847", "vendor": "NETGEAR", "ghsa_id": null, "product": "DGN1000", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.29939, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.98157, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12847", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3fb2c5f6-9baa-4ca4-8c3d-433ce1cfbf41", "vulnerability": {"vulnId": "CVE-2026-41940", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "3fb2c5f6-9baa-4ca4-8c3d-433ce1cfbf41", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "WebPros cPanel and WHM Authentication Bypass via Login Flow | Affected: WebPros / cPanel, WP Squared, WHM | CVSS: 9.3 (CRITICAL) | EPSS: 0.98527 | Used in malware: yes | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-41940", "url": "https://www.cve.org/CVERecord?id=CVE-2026-41940"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-41940"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WebPros cPanel and WHM Authentication Bypass via Login Flow", "cve_id": "CVE-2026-41940", "vendor": "WebPros", "ghsa_id": null, "product": "cPanel, WP Squared, WHM", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.98527, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9992, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-41940", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "28bc87fd-258f-4298-ac40-5d3f0471ca6c", "vulnerability": {"vulnId": "CVE-2025-68645", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "28bc87fd-258f-4298-ac40-5d3f0471ca6c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper... | Affected: Zimbra / Zimbra Collaboration (ZCS) | CVSS: 8.8 (HIGH) | EPSS: 0.48873 | Used in malware: unknown | Listed 1 day ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-68645", "url": "https://www.cve.org/CVERecord?id=CVE-2025-68645"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-68645"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper...", "cve_id": "CVE-2025-68645", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration (ZCS)", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.48873, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98843, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-68645", "ahead_of_cisa_kev": {"unit": "day", "count": 1}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac5fc5e0-cfdc-4de5-84bd-a99d0eb6cb51", "vulnerability": {"vulnId": "CVE-2025-55346", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "ac5fc5e0-cfdc-4de5-84bd-a99d0eb6cb51", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-06-01T00:00:00+00:00"}, "scope": {"notes": "Unintended dynamic code execution leads to remote code execution by network attackers | Affected: Flowise / Flowise | CVSS: 9.8 (CRITICAL) | EPSS: 0.21953 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-55346", "url": "https://www.cve.org/CVERecord?id=CVE-2025-55346"}, {"id": "GHSA-HMGH-466J-FX4C", "url": "https://github.com/advisories/GHSA-HMGH-466J-FX4C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-55346"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unintended dynamic code execution leads to remote code execution by network attackers", "cve_id": "CVE-2025-55346", "vendor": "Flowise", "ghsa_id": "GHSA-HMGH-466J-FX4C", "product": "Flowise", "added_date": "2026-06-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.21953, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9759, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-55346", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e8448a4e-b047-421d-8d0d-24d1c2805267", "vulnerability": {"vulnId": "CVE-2026-0257", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-30T09:34:06+02:00"}, "gcve": {"object_uuid": "e8448a4e-b047-421d-8d0d-24d1c2805267", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-30T07:34:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-30T07:34:06+00:00"}, "scope": {"notes": "PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 7.8 (HIGH) | EPSS: 0.96382 | Used in malware: yes | Listed 3 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-0257", "url": "https://www.cve.org/CVERecord?id=CVE-2026-0257"}, {"id": "GHSA-JQXW-84HX-6QJ5", "url": "https://github.com/advisories/GHSA-JQXW-84HX-6QJ5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-0257"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities", "cve_id": "CVE-2026-0257", "vendor": "Palo Alto Networks", "ghsa_id": "GHSA-JQXW-84HX-6QJ5", "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2026-05-30T07:34:06.000Z", "cvss_score": 7.8, "epss_score": 0.96382, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99879, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-0257", "ahead_of_cisa_kev": {"unit": "day", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "69d6d4f7-623c-4a8e-aef0-68ca4b4880de", "vulnerability": {"vulnId": "CVE-2025-58360", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-30T02:00:00+02:00"}, "gcve": {"object_uuid": "69d6d4f7-623c-4a8e-aef0-68ca4b4880de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-30T00:00:00+00:00"}, "scope": {"notes": "GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature | Affected: Geoserver / geoserver | CVSS: 8.2 (HIGH) | EPSS: 0.60522 | Used in malware: unknown | Listed 3 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-58360", "url": "https://www.cve.org/CVERecord?id=CVE-2025-58360"}, {"id": "GHSA-FJF5-XGMQ-5525", "url": "https://github.com/advisories/GHSA-FJF5-XGMQ-5525"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-58360"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature", "cve_id": "CVE-2025-58360", "vendor": "Geoserver", "ghsa_id": "GHSA-FJF5-XGMQ-5525", "product": "geoserver", "added_date": "2026-05-30T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.60522, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99121, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-58360", "ahead_of_cisa_kev": {"unit": "day", "count": 3}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "29a307df-ea0e-423d-a01c-415c98c8df5b", "vulnerability": {"vulnId": "CVE-2025-61882", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-29T02:00:00+02:00"}, "gcve": {"object_uuid": "29a307df-ea0e-423d-a01c-415c98c8df5b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-29T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).  Supported versions... | Affected: Oracle / Oracle Concurrent Processing | CVSS: 9.8 (CRITICAL) | EPSS: 0.99732 | Used in malware: yes | Listed 4 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-61882", "url": "https://www.cve.org/CVERecord?id=CVE-2025-61882"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-61882"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration).  Supported versions...", "cve_id": "CVE-2025-61882", "vendor": "Oracle", "ghsa_id": null, "product": "Oracle Concurrent Processing", "added_date": "2026-05-29T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99732, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99953, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-61882", "ahead_of_cisa_kev": {"unit": "day", "count": 4}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b46b5f5-2193-4c1c-bbdd-4deaf7806ded", "vulnerability": {"vulnId": "CVE-2026-35616", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-28T18:35:05+02:00"}, "gcve": {"object_uuid": "8b46b5f5-2193-4c1c-bbdd-4deaf7806ded", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-28T16:35:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-28T16:35:05+00:00"}, "scope": {"notes": "A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute... | Affected: Fortinet / FortiClientEMS | CVSS: 9.1 (CRITICAL) | EPSS: 0.09098 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-35616", "url": "https://www.cve.org/CVERecord?id=CVE-2026-35616"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-35616"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute...", "cve_id": "CVE-2026-35616", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiClientEMS", "added_date": "2026-05-28T16:35:05.000Z", "cvss_score": 9.1, "epss_score": 0.09098, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95158, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-35616", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b555f0c5-e35c-45af-bd6e-4039cc77878d", "vulnerability": {"vulnId": "CVE-2025-6205", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-28T02:00:00+02:00"}, "gcve": {"object_uuid": "b555f0c5-e35c-45af-bd6e-4039cc77878d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-28T00:00:00+00:00"}, "scope": {"notes": "Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 | Affected: Dassault Syst\u00e8mes / DELMIA Apriso | CVSS: 9.1 (CRITICAL) | EPSS: 0.73308 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-6205", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6205"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6205"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025", "cve_id": "CVE-2025-6205", "vendor": "Dassault Syst\u00e8mes", "ghsa_id": null, "product": "DELMIA Apriso", "added_date": "2026-05-28T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.73308, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99448, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6205", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "255c7e24-8b4f-47b7-ae11-c50e37c73d0f", "vulnerability": {"vulnId": "CVE-2025-34037", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-28T02:00:00+02:00"}, "gcve": {"object_uuid": "255c7e24-8b4f-47b7-ae11-c50e37c73d0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-28T00:00:00+00:00"}, "scope": {"notes": "Linksys Routers E/WAG/WAP/WES/WET/WRT-Series | Affected: Linksys / E4200, E3200, E3000, E2500 v1/v2, E2100L v1, E2000, E1550, E1500 v1, E1200 v1, E1000 v1, E900 v1 | CVSS: 10.0 (CRITICAL) | EPSS: 0.92774 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34037", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34037"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34037"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linksys Routers E/WAG/WAP/WES/WET/WRT-Series", "cve_id": "CVE-2025-34037", "vendor": "Linksys", "ghsa_id": null, "product": "E4200, E3200, E3000, E2500 v1/v2, E2100L v1, E2000, E1550, E1500 v1, E1200 v1, E1000 v1, E900 v1", "added_date": "2026-05-28T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.92774, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99827, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34037", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b3b1d17e-d323-461b-b45f-056fae1e13bb", "vulnerability": {"vulnId": "CVE-2020-7796", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-28T02:00:00+02:00"}, "gcve": {"object_uuid": "b3b1d17e-d323-461b-b45f-056fae1e13bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-28T00:00:00+00:00"}, "scope": {"notes": "Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled. | Affected: Zimbra / Zimbra Collaboration Suite | CVSS: 9.8 (CRITICAL) | EPSS: 0.84418 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-7796", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7796"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-7796"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.", "cve_id": "CVE-2020-7796", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration Suite", "added_date": "2026-05-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84418, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99694, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-7796", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5510bd29-7fbf-47b0-8675-342ef63e96c6", "vulnerability": {"vulnId": "CVE-2026-21643", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-28T02:00:00+02:00"}, "gcve": {"object_uuid": "5510bd29-7fbf-47b0-8675-342ef63e96c6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-28T00:00:00+00:00"}, "scope": {"notes": "An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an... | Affected: Fortinet / FortiClientEMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.93723 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-21643", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21643"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21643"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an...", "cve_id": "CVE-2026-21643", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiClientEMS", "added_date": "2026-05-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93723, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99842, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21643", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "64036e59-4351-4043-b37c-9b143857d5c0", "vulnerability": {"vulnId": "CVE-2025-25257", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-28T02:00:00+02:00"}, "gcve": {"object_uuid": "64036e59-4351-4043-b37c-9b143857d5c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-28T00:00:00+00:00"}, "scope": {"notes": "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb... | Affected: Fortinet / FortiWeb | CVSS: 9.8 (CRITICAL) | EPSS: 0.99775 | Used in malware: unknown | Listed 5 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-25257", "url": "https://www.cve.org/CVERecord?id=CVE-2025-25257"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-25257"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb...", "cve_id": "CVE-2025-25257", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiWeb", "added_date": "2026-05-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99775, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99954, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-25257", "ahead_of_cisa_kev": {"unit": "day", "count": 5}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d076d96-ad8c-4360-a586-6dda4a2112e0", "vulnerability": {"vulnId": "CVE-2026-8398", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-27T20:00:02+02:00"}, "gcve": {"object_uuid": "6d076d96-ad8c-4360-a586-6dda4a2112e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-27T18:00:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-27T18:00:02+00:00"}, "scope": {"notes": "A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434),... | Affected: AVB Disc Soft / DAEMON Tools Lite | CVSS: 9.3 (CRITICAL) | EPSS: 0.00963 | Used in malware: unknown | Listed 6 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-8398", "url": "https://www.cve.org/CVERecord?id=CVE-2026-8398"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-8398"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434),...", "cve_id": "CVE-2026-8398", "vendor": "AVB Disc Soft", "ghsa_id": null, "product": "DAEMON Tools Lite", "added_date": "2026-05-27T18:00:02.449Z", "cvss_score": 9.3, "epss_score": 0.00963, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60255, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-8398", "ahead_of_cisa_kev": {"unit": "day", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e2a548ef-b5cd-480e-9b32-fbe132dcfbd0", "vulnerability": {"vulnId": "CVE-2026-48027", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-27T20:00:02+02:00"}, "gcve": {"object_uuid": "e2a548ef-b5cd-480e-9b32-fbe132dcfbd0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-27T18:00:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-27T18:00:02+00:00"}, "scope": {"notes": "Compromised Nx Console version 18.95.0 | Affected: Nrwl / nx-console | CVSS: 9.3 (CRITICAL) | EPSS: 0.01336 | Used in malware: yes | Listed 6 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-48027", "url": "https://www.cve.org/CVERecord?id=CVE-2026-48027"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-48027"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Compromised Nx Console version 18.95.0", "cve_id": "CVE-2026-48027", "vendor": "Nrwl", "ghsa_id": null, "product": "nx-console", "added_date": "2026-05-27T18:00:02.229Z", "cvss_score": 9.3, "epss_score": 0.01336, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.70179, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-48027", "ahead_of_cisa_kev": {"unit": "day", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "35c232ce-6033-4757-9568-629ac420c641", "vulnerability": {"vulnId": "CVE-2026-45321", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-27T20:00:02+02:00"}, "gcve": {"object_uuid": "35c232ce-6033-4757-9568-629ac420c641", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-27T18:00:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-27T18:00:02+00:00"}, "scope": {"notes": "Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys | Affected: @tanstack / arktype-adapter, eslint-plugin-router, eslint-plugin-start, history, nitro-v2-vite-plugin, react-router, react-router-devtools, react-router-ssr-query, react-start, react-start-client, react-start-rsc, react-start-server, router-cli, router-core, router-devtools, router-devtools-core, router-generator, router-plugin, router-ssr-query-core, router-utils, outer-vite-plugin, solid-router, solid-router-devtools, solid-router-ssr-query, solid-start, solid-start-client, solid-start-server, start-client-core, start-fn-stubs, start-plugin-core, start-server-core, start-static-server-functions, start-storage-context, valibot-adapter, virtual-file-routes, vue-router, vue-router-devtools, vue-router-ssr-query, vue-start, vue-start-client, vue-start-server, zod-adapter | CVSS: 9.6 (CRITICAL) | EPSS: 0.01054 | Used in malware: yes | Listed 6 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2026-45321", "url": "https://www.cve.org/CVERecord?id=CVE-2026-45321"}, {"id": "GHSA-G7CV-RXG3-HMPX", "url": "https://github.com/advisories/GHSA-G7CV-RXG3-HMPX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-45321"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys", "cve_id": "CVE-2026-45321", "vendor": "@tanstack", "ghsa_id": "GHSA-G7CV-RXG3-HMPX", "product": "arktype-adapter, eslint-plugin-router, eslint-plugin-start, history, nitro-v2-vite-plugin, react-router, react-router-devtools, react-router-ssr-query, react-start, react-start-client, react-start-rsc, react-start-server, router-cli, router-core, router-devtools, router-devtools-core, router-generator, router-plugin, router-ssr-query-core, router-utils, outer-vite-plugin, solid-router, solid-router-devtools, solid-router-ssr-query, solid-start, solid-start-client, solid-start-server, start-client-core, start-fn-stubs, start-plugin-core, start-server-core, start-static-server-functions, start-storage-context, valibot-adapter, virtual-file-routes, vue-router, vue-router-devtools, vue-router-ssr-query, vue-start, vue-start-client, vue-start-server, zod-adapter", "added_date": "2026-05-27T18:00:02.338Z", "cvss_score": 9.6, "epss_score": 0.01054, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63111, "used_in_malware": "yes", "vulnerability_id": "CVE-2026-45321", "ahead_of_cisa_kev": {"unit": "day", "count": 6}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0881eca6-29da-4cc6-8b07-99996d5e85a7", "vulnerability": {"vulnId": "CVE-2018-9205", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-27T02:00:00+02:00"}, "gcve": {"object_uuid": "0881eca6-29da-4cc6-8b07-99996d5e85a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-27T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | Affected: Robbin Zhao / avatar_uploader | CVSS: 7.5 (HIGH) | EPSS: 0.55079 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-9205", "url": "https://www.cve.org/CVERecord?id=CVE-2018-9205"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-9205"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.", "cve_id": "CVE-2018-9205", "vendor": "Robbin Zhao", "ghsa_id": null, "product": "avatar_uploader", "added_date": "2026-05-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.55079, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-9205", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7c50f113-dc68-4593-8250-41c8fd858de7", "vulnerability": {"vulnId": "CVE-2022-2414", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-26T02:00:00+02:00"}, "gcve": {"object_uuid": "7c50f113-dc68-4593-8250-41c8fd858de7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-26T00:00:00+00:00"}, "scope": {"notes": "Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to... | Affected: Dogtag PKI / Dogtag Certificate System | CVSS: 7.5 (HIGH) | EPSS: 0.85969 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2414", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2414"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2414"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to...", "cve_id": "CVE-2022-2414", "vendor": "Dogtag PKI", "ghsa_id": null, "product": "Dogtag Certificate System", "added_date": "2026-05-26T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.85969, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99724, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2414", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ea3e6839-22a2-47c3-a247-9e298a6d6730", "vulnerability": {"vulnId": "CVE-2022-0948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-26T02:00:00+02:00"}, "gcve": {"object_uuid": "ea3e6839-22a2-47c3-a247-9e298a6d6730", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-26T00:00:00+00:00"}, "scope": {"notes": "Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi | Affected: WooCommerce / Order Listener for WooCommerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.09879 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0948", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Order Listener for WooCommerce < 3.2.2 - Unauthenticated SQLi", "cve_id": "CVE-2022-0948", "vendor": "WooCommerce", "ghsa_id": null, "product": "Order Listener for WooCommerce", "added_date": "2026-05-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.09879, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95434, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a005ab57-aef9-4d00-ba87-57e3b9580638", "vulnerability": {"vulnId": "CVE-2022-0785", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-26T02:00:00+02:00"}, "gcve": {"object_uuid": "a005ab57-aef9-4d00-ba87-57e3b9580638", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-26T00:00:00+00:00"}, "scope": {"notes": "Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi | Affected: Daily Prayer Time / Daily Prayer Time | CVSS: 9.8 (CRITICAL) | EPSS: 0.09044 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0785", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0785"}, {"id": "GHSA-9QV2-4G99-78C9", "url": "https://github.com/advisories/GHSA-9QV2-4G99-78C9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0785"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi", "cve_id": "CVE-2022-0785", "vendor": "Daily Prayer Time", "ghsa_id": "GHSA-9QV2-4G99-78C9", "product": "Daily Prayer Time", "added_date": "2026-05-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.09044, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95137, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0785", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "be3f3020-6594-435f-a78e-04d633fd3fbd", "vulnerability": {"vulnId": "CVE-2025-34048", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "be3f3020-6594-435f-a78e-04d633fd3fbd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-24T00:00:00+00:00"}, "scope": {"notes": "D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read | Affected: D-Link / DSL-2730U, DSL-2750U, DSL-2750E | CVSS: 8.7 (HIGH) | EPSS: 0.00678 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34048", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34048"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34048"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read", "cve_id": "CVE-2025-34048", "vendor": "D-Link", "ghsa_id": null, "product": "DSL-2730U, DSL-2750U, DSL-2750E", "added_date": "2026-05-24T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.00678, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50526, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34048", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a59f21f-34b2-4c12-815a-756412de01a7", "vulnerability": {"vulnId": "CVE-2023-7311", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-22T02:00:00+02:00"}, "gcve": {"object_uuid": "2a59f21f-34b2-4c12-815a-756412de01a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-22T00:00:00+00:00"}, "scope": {"notes": "BYTEVALUE Intelligent Flow Control Router Command Injection | Affected: BYTEVALUE / Flow Control Router | CVSS: 9.3 (CRITICAL) | EPSS: 0.01858 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7311", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7311"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7311"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BYTEVALUE Intelligent Flow Control Router Command Injection", "cve_id": "CVE-2023-7311", "vendor": "BYTEVALUE", "ghsa_id": null, "product": "Flow Control Router", "added_date": "2026-05-22T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.01858, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78444, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7311", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b7c966d3-b23c-4a55-b3e8-ed0f13a5769c", "vulnerability": {"vulnId": "CVE-2020-11963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-15T02:00:00+02:00"}, "gcve": {"object_uuid": "b7c966d3-b23c-4a55-b3e8-ed0f13a5769c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-15T00:00:00+00:00"}, "scope": {"notes": "IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter... | Affected: Evenroute / IQrouter | CVSS: 9.8 (CRITICAL) | EPSS: 0.03225 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11963", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11963"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter...", "cve_id": "CVE-2020-11963", "vendor": "Evenroute", "ghsa_id": null, "product": "IQrouter", "added_date": "2026-05-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03225, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87803, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11963", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6e69d26b-36d2-475c-af58-3558b8b8b6f9", "vulnerability": {"vulnId": "CVE-2025-7544", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-15T02:00:00+02:00"}, "gcve": {"object_uuid": "6e69d26b-36d2-475c-af58-3558b8b8b6f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-15T00:00:00+00:00"}, "scope": {"notes": "Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow | Affected: Tenda / AC1206 | CVSS: 8.7 (HIGH) | EPSS: 0.01671 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-7544", "url": "https://www.cve.org/CVERecord?id=CVE-2025-7544"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-7544"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow", "cve_id": "CVE-2025-7544", "vendor": "Tenda", "ghsa_id": null, "product": "AC1206", "added_date": "2026-05-15T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.01671, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75951, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-7544", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9aaed923-46b3-48e5-84b8-ae6c0da4f5b5", "vulnerability": {"vulnId": "CVE-2026-41089", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-13T17:21:00+02:00"}, "gcve": {"object_uuid": "9aaed923-46b3-48e5-84b8-ae6c0da4f5b5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-13T15:21:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-13T15:21:00+00:00"}, "scope": {"notes": "Windows Netlogon Remote Code Execution Vulnerability | Affected: Microsoft / Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 9.8 (CRITICAL) | EPSS: 0.00974 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-41089", "url": "https://www.cve.org/CVERecord?id=CVE-2026-41089"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-41089"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Netlogon Remote Code Execution Vulnerability", "cve_id": "CVE-2026-41089", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2026-05-13T15:21:00.000Z", "cvss_score": 9.8, "epss_score": 0.00974, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60692, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-41089", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "485ddf7d-c129-430f-a291-e0e6056a2a91", "vulnerability": {"vulnId": "CVE-2025-34023", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-11T02:00:00+02:00"}, "gcve": {"object_uuid": "485ddf7d-c129-430f-a291-e0e6056a2a91", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-11T00:00:00+00:00"}, "scope": {"notes": "Karel IP Phone IP1211 Path Traversal | Affected: Karel / Karel IP Phone IP1211 | CVSS: 8.5 (HIGH) | EPSS: 0.01572 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34023", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34023"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34023"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Karel IP Phone IP1211 Path Traversal", "cve_id": "CVE-2025-34023", "vendor": "Karel", "ghsa_id": null, "product": "Karel IP Phone IP1211", "added_date": "2026-05-11T00:00:00.000Z", "cvss_score": 8.5, "epss_score": 0.01572, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74495, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34023", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2221c301-c9a4-4064-a4b6-76ab12467737", "vulnerability": {"vulnId": "CVE-2023-42344", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-08T02:00:00+02:00"}, "gcve": {"object_uuid": "2221c301-c9a4-4064-a4b6-76ab12467737", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-08T00:00:00+00:00"}, "scope": {"notes": "Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a... | Affected: Alkacon / OpenCms | CVSS: 7.3 (HIGH) | EPSS: 0.02231 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-42344", "url": "https://www.cve.org/CVERecord?id=CVE-2023-42344"}, {"id": "GHSA-RCC6-6Q2F-M2CW", "url": "https://github.com/advisories/GHSA-RCC6-6Q2F-M2CW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-42344"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a...", "cve_id": "CVE-2023-42344", "vendor": "Alkacon", "ghsa_id": "GHSA-RCC6-6Q2F-M2CW", "product": "OpenCms", "added_date": "2026-05-08T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.02231, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82133, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-42344", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b6e58d23-e0bd-4a6b-b07d-6e022a753003", "vulnerability": {"vulnId": "CVE-2018-11409", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-05-07T02:00:00+02:00"}, "gcve": {"object_uuid": "b6e58d23-e0bd-4a6b-b07d-6e022a753003", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-05-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-05-07T00:00:00+00:00"}, "scope": {"notes": "Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated... | Affected: Splunk / Splunk | CVSS: 5.3 (MEDIUM) | EPSS: 0.98314 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11409", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11409"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11409"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated...", "cve_id": "CVE-2018-11409", "vendor": "Splunk", "ghsa_id": null, "product": "Splunk", "added_date": "2026-05-07T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.98314, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99916, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11409", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e1a81a61-448d-45d0-8e0e-1bfcdec7ec60", "vulnerability": {"vulnId": "CVE-2022-50993", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-30T18:08:46+02:00"}, "gcve": {"object_uuid": "e1a81a61-448d-45d0-8e0e-1bfcdec7ec60", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-30T16:08:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-30T16:08:46+00:00"}, "scope": {"notes": "Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet | Affected: Weaver Network / E-office | CVSS: 9.3 (CRITICAL) | EPSS: 0.00774 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-50993", "url": "https://www.cve.org/CVERecord?id=CVE-2022-50993"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-50993"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-office < 10.0_20221201 Unauthenticated Arbitrary File Read via XmlRpcServlet", "cve_id": "CVE-2022-50993", "vendor": "Weaver Network", "ghsa_id": null, "product": "E-office", "added_date": "2026-04-30T16:08:46.000Z", "cvss_score": 9.3, "epss_score": 0.00774, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.54107, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-50993", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c379ea84-7f2e-45e1-8e8f-64529665ed34", "vulnerability": {"vulnId": "CVE-2025-71284", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-30T18:08:17+02:00"}, "gcve": {"object_uuid": "c379ea84-7f2e-45e1-8e8f-64529665ed34", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-30T16:08:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-30T16:08:17+00:00"}, "scope": {"notes": "Synway SMG Gateway Management Software OS Command Injection via radius_address | Affected: Synway Information Engineering / Synway SMG Gateway Management Software | CVSS: 9.3 (CRITICAL) | EPSS: 0.05727 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-71284", "url": "https://www.cve.org/CVERecord?id=CVE-2025-71284"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-71284"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Synway SMG Gateway Management Software OS Command Injection via radius_address", "cve_id": "CVE-2025-71284", "vendor": "Synway Information Engineering", "ghsa_id": null, "product": "Synway SMG Gateway Management Software", "added_date": "2026-04-30T16:08:17.000Z", "cvss_score": 9.3, "epss_score": 0.05727, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92807, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-71284", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e665f592-fb32-41de-99e1-fa77134cddaa", "vulnerability": {"vulnId": "CVE-2025-34509", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-30T02:00:00+02:00"}, "gcve": {"object_uuid": "e665f592-fb32-41de-99e1-fa77134cddaa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-30T00:00:00+00:00"}, "scope": {"notes": "Sitecore XM and XP Hardcoded Credentials | Affected: Sitecore / Experience Manager, Experience Platform | CVSS: 7.5 (HIGH) | EPSS: 0.55874 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34509", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34509"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34509"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sitecore XM and XP Hardcoded Credentials", "cve_id": "CVE-2025-34509", "vendor": "Sitecore", "ghsa_id": null, "product": "Experience Manager, Experience Platform", "added_date": "2026-04-30T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.55874, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99017, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34509", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "74010f34-3e9b-4ebe-988a-e1a66ba9b8d6", "vulnerability": {"vulnId": "CVE-2024-6893", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-30T02:00:00+02:00"}, "gcve": {"object_uuid": "74010f34-3e9b-4ebe-988a-e1a66ba9b8d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-30T00:00:00+00:00"}, "scope": {"notes": "Journyx Unauthenticated XML External Entities Injection | Affected: Journyx / Journyx (jtime) | CVSS: 7.5 (HIGH) | EPSS: 0.32916 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6893", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6893"}, {"id": "GHSA-9HXQ-VV35-9R5R", "url": "https://github.com/advisories/GHSA-9HXQ-VV35-9R5R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6893"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Journyx Unauthenticated XML External Entities Injection", "cve_id": "CVE-2024-6893", "vendor": "Journyx", "ghsa_id": "GHSA-9HXQ-VV35-9R5R", "product": "Journyx (jtime)", "added_date": "2026-04-30T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.32916, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6893", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6e0ab397-91bf-4137-b002-b2bf65988847", "vulnerability": {"vulnId": "CVE-2023-37999", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-30T02:00:00+02:00"}, "gcve": {"object_uuid": "6e0ab397-91bf-4137-b002-b2bf65988847", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-30T00:00:00+00:00"}, "scope": {"notes": "WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability | Affected: HasThemes / HT Mega | CVSS: 9.8 (CRITICAL) | EPSS: 0.03349 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-37999", "url": "https://www.cve.org/CVERecord?id=CVE-2023-37999"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-37999"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability", "cve_id": "CVE-2023-37999", "vendor": "HasThemes", "ghsa_id": null, "product": "HT Mega", "added_date": "2026-04-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03349, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88281, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-37999", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a40a6b4b-8c76-4af1-87c1-2d76987c82a2", "vulnerability": {"vulnId": "CVE-2025-10353", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "a40a6b4b-8c76-4af1-87c1-2d76987c82a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-28T00:00:00+00:00"}, "scope": {"notes": "Missing Authorization vulnerability in Melis Platform | Affected: Melis Technology / Melis Platform | CVSS: 9.3 (CRITICAL) | EPSS: 0.0266 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-10353", "url": "https://www.cve.org/CVERecord?id=CVE-2025-10353"}, {"id": "GHSA-CHW4-GJVW-3GXC", "url": "https://github.com/advisories/GHSA-CHW4-GJVW-3GXC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-10353"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Missing Authorization vulnerability in Melis Platform", "cve_id": "CVE-2025-10353", "vendor": "Melis Technology", "ghsa_id": "GHSA-CHW4-GJVW-3GXC", "product": "Melis Platform", "added_date": "2026-04-28T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.0266, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85164, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-10353", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f0ef27a2-52de-4e0d-985d-c153f7743863", "vulnerability": {"vulnId": "CVE-2023-0159", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "f0ef27a2-52de-4e0d-985d-c153f7743863", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-28T00:00:00+00:00"}, "scope": {"notes": " Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE | Affected: Extensive VC / Extensive VC Addons for WPBakery page builder | CVSS: 7.5 (HIGH) | EPSS: 0.55459 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-0159", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0159"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0159"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": " Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE", "cve_id": "CVE-2023-0159", "vendor": "Extensive VC", "ghsa_id": null, "product": "Extensive VC Addons for WPBakery page builder", "added_date": "2026-04-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.55459, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99009, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0159", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a1b1be9d-042b-4206-b900-73fb58e6cb76", "vulnerability": {"vulnId": "CVE-2023-25573", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "a1b1be9d-042b-4206-b900-73fb58e6cb76", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-28T00:00:00+00:00"}, "scope": {"notes": "Improper access control to download file in metersphere | Affected: Metersphere / metersphere | CVSS: 8.6 (HIGH) | EPSS: 0.51609 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-25573", "url": "https://www.cve.org/CVERecord?id=CVE-2023-25573"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-25573"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper access control to download file in metersphere", "cve_id": "CVE-2023-25573", "vendor": "Metersphere", "ghsa_id": null, "product": "metersphere", "added_date": "2026-04-28T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.51609, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98913, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-25573", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1145c7a4-c7dd-41d7-b8ee-8a3adaf7126a", "vulnerability": {"vulnId": "CVE-2021-4374", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "1145c7a4-c7dd-41d7-b8ee-8a3adaf7126a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-25T00:00:00+00:00"}, "scope": {"notes": "The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to... | Affected: ValvePress / WordPress Automatic Plugin | CVSS: 9.1 (CRITICAL) | EPSS: 0.16408 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-4374", "url": "https://www.cve.org/CVERecord?id=CVE-2021-4374"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-4374"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to...", "cve_id": "CVE-2021-4374", "vendor": "ValvePress", "ghsa_id": null, "product": "WordPress Automatic Plugin", "added_date": "2026-04-25T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.16408, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96888, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-4374", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3fc35fdd-c0de-4025-bf2e-bd0f3c83295b", "vulnerability": {"vulnId": "CVE-2019-8451", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-23T02:00:00+02:00"}, "gcve": {"object_uuid": "3fc35fdd-c0de-4025-bf2e-bd0f3c83295b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-23T00:00:00+00:00"}, "scope": {"notes": "The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network... | Affected: Atlassian / Jira | CVSS: 6.5 (MEDIUM) | EPSS: 0.94453 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-8451", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8451"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8451"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network...", "cve_id": "CVE-2019-8451", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira", "added_date": "2026-04-23T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.94453, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99851, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8451", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "53feb7fb-1012-453d-a4b1-a2ae175441e5", "vulnerability": {"vulnId": "CVE-2018-6605", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-18T02:00:00+02:00"}, "gcve": {"object_uuid": "53feb7fb-1012-453d-a4b1-a2ae175441e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-18T00:00:00+00:00"}, "scope": {"notes": "SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText,... | Affected: Joomla / Zh BaiduMap | CVSS: 9.8 (CRITICAL) | EPSS: 0.57702 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-6605", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6605"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-6605"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText,...", "cve_id": "CVE-2018-6605", "vendor": "Joomla", "ghsa_id": null, "product": "Zh BaiduMap", "added_date": "2026-04-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.57702, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9906, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-6605", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0a2e85a6-509a-4969-bcdc-7bf6e92e0bd4", "vulnerability": {"vulnId": "CVE-2021-3223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-14T02:00:00+02:00"}, "gcve": {"object_uuid": "0a2e85a6-509a-4969-bcdc-7bf6e92e0bd4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-14T00:00:00+00:00"}, "scope": {"notes": "Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | Affected: Node-RED / Node-RED-Dashboard | CVSS: 7.5 (HIGH) | EPSS: 0.18512 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-3223", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3223"}, {"id": "GHSA-2HW7-MXVJ-M455", "url": "https://github.com/advisories/GHSA-2HW7-MXVJ-M455"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.", "cve_id": "CVE-2021-3223", "vendor": "Node-RED", "ghsa_id": "GHSA-2HW7-MXVJ-M455", "product": "Node-RED-Dashboard", "added_date": "2026-04-14T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.18512, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97169, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3223", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2d273e31-92a2-44d5-beec-3514bc1618bb", "vulnerability": {"vulnId": "CVE-2020-20300", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-14T02:00:00+02:00"}, "gcve": {"object_uuid": "2d273e31-92a2-44d5-beec-3514bc1618bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-14T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in the wp_where function in WeiPHP 5.0. | Affected: WeiPHP / WeiPHP 5.0 | CVSS: 9.8 (CRITICAL) | EPSS: 0.08752 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-20300", "url": "https://www.cve.org/CVERecord?id=CVE-2020-20300"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-20300"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in the wp_where function in WeiPHP 5.0.", "cve_id": "CVE-2020-20300", "vendor": "WeiPHP", "ghsa_id": null, "product": "WeiPHP 5.0", "added_date": "2026-04-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08752, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95008, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-20300", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d7a7f358-5e75-4ca1-9d11-c66bc2161c38", "vulnerability": {"vulnId": "CVE-2026-3965", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-10T02:00:00+02:00"}, "gcve": {"object_uuid": "d7a7f358-5e75-4ca1-9d11-c66bc2161c38", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-10T00:00:00+00:00"}, "scope": {"notes": "whyour qinglong API express.ts protection mechanism | Affected: Whyour / qinglong | CVSS: 5.3 (MEDIUM) | EPSS: 0.00466 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-3965", "url": "https://www.cve.org/CVERecord?id=CVE-2026-3965"}, {"id": "GHSA-XJ37-QJG2-XWV2", "url": "https://github.com/advisories/GHSA-XJ37-QJG2-XWV2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-3965"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "whyour qinglong API express.ts protection mechanism", "cve_id": "CVE-2026-3965", "vendor": "Whyour", "ghsa_id": "GHSA-XJ37-QJG2-XWV2", "product": "qinglong", "added_date": "2026-04-10T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.00466, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.37983, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-3965", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e5de57ea-cedb-48a3-9aeb-1888804e5034", "vulnerability": {"vulnId": "CVE-2026-21891", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-10T02:00:00+02:00"}, "gcve": {"object_uuid": "e5de57ea-cedb-48a3-9aeb-1888804e5034", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-10T00:00:00+00:00"}, "scope": {"notes": "ZimaOS has Authentication Bypass via System-Level Username | Affected: IceWhale Tech / ZimaOS | CVSS: 9.4 (CRITICAL) | EPSS: 0.0235 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-21891", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21891"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21891"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZimaOS has Authentication Bypass via System-Level Username", "cve_id": "CVE-2026-21891", "vendor": "IceWhale Tech", "ghsa_id": null, "product": "ZimaOS", "added_date": "2026-04-10T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.0235, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8307, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21891", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ae6aed72-2da0-4432-9e38-a3c0b31d67fa", "vulnerability": {"vulnId": "CVE-2026-23744", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-03T02:00:00+02:00"}, "gcve": {"object_uuid": "ae6aed72-2da0-4432-9e38-a3c0b31d67fa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-03T00:00:00+00:00"}, "scope": {"notes": "REC in MCPJam inspector due to HTTP Endpoint exposes | Affected: MCPJam / inspector | CVSS: 9.8 (CRITICAL) | EPSS: 0.67516 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-23744", "url": "https://www.cve.org/CVERecord?id=CVE-2026-23744"}, {"id": "GHSA-232V-J27C-5PP6", "url": "https://github.com/advisories/GHSA-232V-J27C-5PP6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-23744"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "REC in MCPJam inspector due to HTTP Endpoint exposes", "cve_id": "CVE-2026-23744", "vendor": "MCPJam", "ghsa_id": "GHSA-232V-J27C-5PP6", "product": "inspector", "added_date": "2026-04-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.67516, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99292, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-23744", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "242c87ec-cba0-4bc4-8f56-b4495408b598", "vulnerability": {"vulnId": "CVE-2024-20404", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-01T02:00:00+02:00"}, "gcve": {"object_uuid": "242c87ec-cba0-4bc4-8f56-b4495408b598", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-01T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on... | Affected: Cisco / Cisco Unified Contact Center Enterprise, Cisco Unified Contact Center Express, Cisco Finesse, Cisco Packaged Contact Center Enterprise | CVSS: 7.2 (HIGH) | EPSS: 0.22644 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-20404", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20404"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20404"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct an SSRF attack on...", "cve_id": "CVE-2024-20404", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Unified Contact Center Enterprise, Cisco Unified Contact Center Express, Cisco Finesse, Cisco Packaged Contact Center Enterprise", "added_date": "2026-04-01T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.22644, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97658, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20404", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a17b2546-892e-4918-a540-931243293a23", "vulnerability": {"vulnId": "CVE-2022-1768", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-04-01T02:00:00+02:00"}, "gcve": {"object_uuid": "a17b2546-892e-4918-a540-931243293a23", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-04-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-04-01T00:00:00+00:00"}, "scope": {"notes": "The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user... | Affected: David F. Carr / RSVPMaker | CVSS: 9.8 (CRITICAL) | EPSS: 0.1286 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1768", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1768"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1768"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user...", "cve_id": "CVE-2022-1768", "vendor": "David F. Carr", "ghsa_id": null, "product": "RSVPMaker", "added_date": "2026-04-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1286, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96186, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1768", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6f74663a-9d9c-4fdd-951a-2aac0eca5159", "vulnerability": {"vulnId": "CVE-2021-46381", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "6f74663a-9d9c-4fdd-951a-2aac0eca5159", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-31T00:00:00+00:00"}, "scope": {"notes": "Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. | Affected: D-Link / DAP-1620 | CVSS: 7.5 (HIGH) | EPSS: 0.58882 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-46381", "url": "https://www.cve.org/CVERecord?id=CVE-2021-46381"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-46381"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].", "cve_id": "CVE-2021-46381", "vendor": "D-Link", "ghsa_id": null, "product": "DAP-1620", "added_date": "2026-03-31T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.58882, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99084, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-46381", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a9c80327-4a93-4e6e-b899-5273ea4e6319", "vulnerability": {"vulnId": "CVE-2018-25114", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "a9c80327-4a93-4e6e-b899-5273ea4e6319", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-30T00:00:00+00:00"}, "scope": {"notes": "osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution | Affected: osCommerce / Online Merchant | CVSS: 9.3 (CRITICAL) | EPSS: 0.04152 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-25114", "url": "https://www.cve.org/CVERecord?id=CVE-2018-25114"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-25114"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution", "cve_id": "CVE-2018-25114", "vendor": "osCommerce", "ghsa_id": null, "product": "Online Merchant", "added_date": "2026-03-30T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.04152, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90543, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-25114", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "66a2ca6e-fe5d-4915-954a-6793508fda61", "vulnerability": {"vulnId": "CVE-2019-5434", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-28T01:00:00+01:00"}, "gcve": {"object_uuid": "66a2ca6e-fe5d-4915-954a-6793508fda61", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-28T00:00:00+00:00"}, "scope": {"notes": "An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the \"what\" parameter... | Affected: Revive Adserver / Revive Adserver | CVSS: 9.8 (CRITICAL) | EPSS: 0.57022 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-5434", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5434"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5434"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the \"what\" parameter...", "cve_id": "CVE-2019-5434", "vendor": "Revive Adserver", "ghsa_id": null, "product": "Revive Adserver", "added_date": "2026-03-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.57022, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99043, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5434", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a79ddd7c-2d25-471c-8115-0e4715487110", "vulnerability": {"vulnId": "CVE-2022-0346", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-26T01:00:00+01:00"}, "gcve": {"object_uuid": "a79ddd7c-2d25-471c-8115-0e4715487110", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-26T00:00:00+00:00"}, "scope": {"notes": "Google XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting | Affected: Google / XML Sitemap Generator | CVSS: 6.1 (MEDIUM) | EPSS: 0.02067 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0346", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0346"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0346"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Google XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting", "cve_id": "CVE-2022-0346", "vendor": "Google", "ghsa_id": null, "product": "XML Sitemap Generator", "added_date": "2026-03-26T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.02067, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80701, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0346", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "885b5a67-a4be-4c54-9861-6ef686f0932d", "vulnerability": {"vulnId": "CVE-2025-15503", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "885b5a67-a4be-4c54-9861-6ef686f0932d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-25T00:00:00+00:00"}, "scope": {"notes": "Sangfor Operation and Maintenance Management System common.jsp unrestricted upload | Affected: Sangfor / Operation and Maintenance Management System | CVSS: 6.9 (MEDIUM) | EPSS: 0.02066 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-15503", "url": "https://www.cve.org/CVERecord?id=CVE-2025-15503"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-15503"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sangfor Operation and Maintenance Management System common.jsp unrestricted upload", "cve_id": "CVE-2025-15503", "vendor": "Sangfor", "ghsa_id": null, "product": "Operation and Maintenance Management System", "added_date": "2026-03-25T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.02066, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80692, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-15503", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7223dfe5-3b33-47ea-b740-158a17de47f4", "vulnerability": {"vulnId": "CVE-2022-40843", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "7223dfe5-3b33-47ea-b740-158a17de47f4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-25T00:00:00+00:00"}, "scope": {"notes": "The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router... | Affected: Tenda / AC1200 V-W15Ev2 | CVSS: 4.9 (MEDIUM) | EPSS: 0.28802 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-40843", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40843"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40843"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router...", "cve_id": "CVE-2022-40843", "vendor": "Tenda", "ghsa_id": null, "product": "AC1200 V-W15Ev2", "added_date": "2026-03-25T00:00:00.000Z", "cvss_score": 4.9, "epss_score": 0.28802, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98097, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40843", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "89ae9b41-f474-466d-aa0a-de3ac70953f4", "vulnerability": {"vulnId": "CVE-2022-2376", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "89ae9b41-f474-466d-aa0a-de3ac70953f4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-25T00:00:00+00:00"}, "scope": {"notes": "Directorist < 7.3.1 - Unauthenticated Email Address Disclosure | Affected: Directorist / Directorist | CVSS: 5.3 (MEDIUM) | EPSS: 0.01836 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2376", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2376"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2376"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directorist < 7.3.1 - Unauthenticated Email Address Disclosure", "cve_id": "CVE-2022-2376", "vendor": "Directorist", "ghsa_id": null, "product": "Directorist", "added_date": "2026-03-25T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.01836, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7816, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2376", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e3141803-3b8c-4f18-a72f-37ed3a78efe2", "vulnerability": {"vulnId": "CVE-2025-25037", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-24T01:00:00+01:00"}, "gcve": {"object_uuid": "e3141803-3b8c-4f18-a72f-37ed3a78efe2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-24T00:00:00+00:00"}, "scope": {"notes": "Aquatronica Controller System Complete Information Disclosure | Affected: Aquatronica / Aquatronica Controller System | CVSS: 9.3 (CRITICAL) | EPSS: 0.01574 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-25037", "url": "https://www.cve.org/CVERecord?id=CVE-2025-25037"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-25037"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Aquatronica Controller System Complete Information Disclosure", "cve_id": "CVE-2025-25037", "vendor": "Aquatronica", "ghsa_id": null, "product": "Aquatronica Controller System", "added_date": "2026-03-24T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.01574, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74522, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-25037", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7d8a7a6d-172f-41b7-ad36-ce89d750fd0f", "vulnerability": {"vulnId": "CVE-2021-47795", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-24T01:00:00+01:00"}, "gcve": {"object_uuid": "7d8a7a6d-172f-41b7-ad36-ce89d750fd0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-24T00:00:00+00:00"}, "scope": {"notes": "GeoVision Geowebserver 5.3.3 - Local FIle Inclusion | Affected: Geovision / GeoVision Geowebserver | CVSS: 8.7 (HIGH) | EPSS: 0.02865 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-47795", "url": "https://www.cve.org/CVERecord?id=CVE-2021-47795"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-47795"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoVision Geowebserver 5.3.3 - Local FIle Inclusion", "cve_id": "CVE-2021-47795", "vendor": "Geovision", "ghsa_id": null, "product": "GeoVision Geowebserver", "added_date": "2026-03-24T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.02865, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86287, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-47795", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0e1ef3ac-cf50-4c58-bd9b-fc8c984ecc2d", "vulnerability": {"vulnId": "CVE-2025-34054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-23T01:00:00+01:00"}, "gcve": {"object_uuid": "0e1ef3ac-cf50-4c58-bd9b-fc8c984ecc2d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-23T00:00:00+00:00"}, "scope": {"notes": "AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection | Affected: AVTECH / IP camera, DVR, and NVR Devices | CVSS: 10.0 (CRITICAL) | EPSS: 0.027 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34054", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection", "cve_id": "CVE-2025-34054", "vendor": "AVTECH", "ghsa_id": null, "product": "IP camera, DVR, and NVR Devices", "added_date": "2026-03-23T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.027, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85407, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c0d5a3a6-8d21-4f32-9891-11eb5d513f33", "vulnerability": {"vulnId": "CVE-2020-10173", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-21T01:00:00+01:00"}, "gcve": {"object_uuid": "c0d5a3a6-8d21-4f32-9891-11eb5d513f33", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-21T00:00:00+00:00"}, "scope": {"notes": "Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and... | Affected: Comtrend / VR-3033 | CVSS: 8.8 (HIGH) | EPSS: 0.77129 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-10173", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10173"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10173"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and...", "cve_id": "CVE-2020-10173", "vendor": "Comtrend", "ghsa_id": null, "product": "VR-3033", "added_date": "2026-03-21T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.77129, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99539, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10173", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7b24c5e3-6660-437c-8c44-84f52c0b4f3c", "vulnerability": {"vulnId": "CVE-2025-34030", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "7b24c5e3-6660-437c-8c44-84f52c0b4f3c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-19T00:00:00+00:00"}, "scope": {"notes": "sar2html OS Command Injection | Affected: sar2html / sar2html | CVSS: 10.0 (CRITICAL) | EPSS: 0.54423 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34030", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34030"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34030"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "sar2html OS Command Injection", "cve_id": "CVE-2025-34030", "vendor": "sar2html", "ghsa_id": null, "product": "sar2html", "added_date": "2026-03-19T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.54423, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98983, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34030", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f103cf4c-35e3-44ff-a386-4b852b90dc3b", "vulnerability": {"vulnId": "CVE-2023-4542", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "f103cf4c-35e3-44ff-a386-4b852b90dc3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-19T00:00:00+00:00"}, "scope": {"notes": "D-Link DAR-8000-10 sys1.php os command injection | Affected: D-Link / DAR-8000-10 | CVSS: 6.3 (MEDIUM) | EPSS: 0.84689 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-4542", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4542"}, {"id": "GHSA-85CP-HM7F-PWXW", "url": "https://github.com/advisories/GHSA-85CP-HM7F-PWXW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4542"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DAR-8000-10 sys1.php os command injection", "cve_id": "CVE-2023-4542", "vendor": "D-Link", "ghsa_id": "GHSA-85CP-HM7F-PWXW", "product": "DAR-8000-10", "added_date": "2026-03-19T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.84689, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.997, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4542", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a5796c9-bfd4-4af5-a008-8fea4a493ed7", "vulnerability": {"vulnId": "CVE-2026-21902", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "2a5796c9-bfd4-4af5-a008-8fea4a493ed7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-19T00:00:00+00:00"}, "scope": {"notes": "Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root | Affected: Juniper Networks / Junos OS Evolved | CVSS: 9.3 (CRITICAL) | EPSS: 0.18003 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-21902", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21902"}, {"id": "GHSA-5W57-GJVC-WHWC", "url": "https://github.com/advisories/GHSA-5W57-GJVC-WHWC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21902"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root", "cve_id": "CVE-2026-21902", "vendor": "Juniper Networks", "ghsa_id": "GHSA-5W57-GJVC-WHWC", "product": "Junos OS Evolved", "added_date": "2026-03-19T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.18003, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97106, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21902", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "41d04e05-c735-44b0-8989-4b2e3ea0d03b", "vulnerability": {"vulnId": "CVE-2020-10546", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-17T01:00:00+01:00"}, "gcve": {"object_uuid": "41d04e05-c735-44b0-8989-4b2e3ea0d03b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-17T00:00:00+00:00"}, "scope": {"notes": "rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored... | Affected: rConfig / rConfig | CVSS: 9.8 (CRITICAL) | EPSS: 0.8733 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-10546", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10546"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10546"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored...", "cve_id": "CVE-2020-10546", "vendor": "rConfig", "ghsa_id": null, "product": "rConfig", "added_date": "2026-03-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.8733, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10546", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f6ad774-6af6-459f-aed9-49cfefa75882", "vulnerability": {"vulnId": "CVE-2021-44868", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-17T01:00:00+01:00"}, "gcve": {"object_uuid": "8f6ad774-6af6-459f-aed9-49cfefa75882", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-17T00:00:00+00:00"}, "scope": {"notes": "A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do | Affected: Mingsoft / MCMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.01412 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-44868", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44868"}, {"id": "GHSA-2PMW-CVC7-FRVH", "url": "https://github.com/advisories/GHSA-2PMW-CVC7-FRVH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44868"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do", "cve_id": "CVE-2021-44868", "vendor": "Mingsoft", "ghsa_id": "GHSA-2PMW-CVC7-FRVH", "product": "MCMS", "added_date": "2026-03-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01412, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71722, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44868", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "292f4791-79c2-432e-9121-aaf87a922709", "vulnerability": {"vulnId": "CVE-2022-38627", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-17T01:00:00+01:00"}, "gcve": {"object_uuid": "292f4791-79c2-432e-9121-aaf87a922709", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-17T00:00:00+00:00"}, "scope": {"notes": "Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection... | Affected: Nortek / Linear eMerge E3-Series | CVSS: 9.8 (CRITICAL) | EPSS: 0.04305 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-38627", "url": "https://www.cve.org/CVERecord?id=CVE-2022-38627"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-38627"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection...", "cve_id": "CVE-2022-38627", "vendor": "Nortek", "ghsa_id": null, "product": "Linear eMerge E3-Series", "added_date": "2026-03-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04305, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90839, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-38627", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bfb0ac3a-bf6c-435d-a0cb-71ab4a593a85", "vulnerability": {"vulnId": "CVE-2020-12124", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-17T01:00:00+01:00"}, "gcve": {"object_uuid": "bfb0ac3a-bf6c-435d-a0cb-71ab4a593a85", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-17T00:00:00+00:00"}, "scope": {"notes": "A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to... | Affected: WAVLINK / WN530H4 | CVSS: 9.8 (CRITICAL) | EPSS: 0.7465 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-12124", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12124"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12124"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to...", "cve_id": "CVE-2020-12124", "vendor": "WAVLINK", "ghsa_id": null, "product": "WN530H4", "added_date": "2026-03-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7465, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99489, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-12124", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c396eaf2-279e-4a60-848e-70f07794895c", "vulnerability": {"vulnId": "CVE-2024-8425", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "c396eaf2-279e-4a60-848e-70f07794895c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-15T00:00:00+00:00"}, "scope": {"notes": "WooCommerce Ultimate Gift Card <= 2.6.0 - Unauthenticated Arbitrary File Upload | Affected: WP Swings / WooCommerce Ultimate Gift Card | CVSS: 9.8 (CRITICAL) | EPSS: 0.04082 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8425", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8425"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8425"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WooCommerce Ultimate Gift Card <= 2.6.0 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2024-8425", "vendor": "WP Swings", "ghsa_id": null, "product": "WooCommerce Ultimate Gift Card", "added_date": "2026-03-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04082, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90392, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8425", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dd3c7e28-a0f0-46f3-9503-f81eecc5cb17", "vulnerability": {"vulnId": "CVE-2023-6329", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-14T01:00:00+01:00"}, "gcve": {"object_uuid": "dd3c7e28-a0f0-46f3-9503-f81eecc5cb17", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-14T00:00:00+00:00"}, "scope": {"notes": "Control iD iDSecure passwordCustom Authentication Bypass | Affected: Control iD / iDSecure | CVSS: 9.8 (CRITICAL) | EPSS: 0.64996 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6329", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6329"}, {"id": "GHSA-9JJV-7CRP-6RR2", "url": "https://github.com/advisories/GHSA-9JJV-7CRP-6RR2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6329"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Control iD iDSecure passwordCustom Authentication Bypass", "cve_id": "CVE-2023-6329", "vendor": "Control iD", "ghsa_id": "GHSA-9JJV-7CRP-6RR2", "product": "iDSecure", "added_date": "2026-03-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.64996, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9923, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6329", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6b916329-6ab7-4537-8ca8-4e76458b25ac", "vulnerability": {"vulnId": "CVE-2021-24915", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-14T01:00:00+01:00"}, "gcve": {"object_uuid": "6b916329-6ab7-4537-8ca8-4e76458b25ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-14T00:00:00+00:00"}, "scope": {"notes": "Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure | Affected: Contest Gallery / Contest Gallery | CVSS: 9.8 (CRITICAL) | EPSS: 0.12004 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24915", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24915"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24915"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Contest Gallery < 13.1.0.6 - Missing Access Controls to Unauthenticated SQL injection / Email Address Disclosure", "cve_id": "CVE-2021-24915", "vendor": "Contest Gallery", "ghsa_id": null, "product": "Contest Gallery", "added_date": "2026-03-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.12004, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96011, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24915", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d9273c31-606d-486e-b8f7-1c102713d666", "vulnerability": {"vulnId": "CVE-2021-24943", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "d9273c31-606d-486e-b8f7-1c102713d666", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-10T00:00:00+00:00"}, "scope": {"notes": "Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection | Affected: Events Calendar / Registrations for the Events Calendar | CVSS: 9.8 (CRITICAL) | EPSS: 0.07303 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24943", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24943"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24943"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Registrations for the Events Calendar < 2.7.6 - Unauthenticated SQL Injection", "cve_id": "CVE-2021-24943", "vendor": "Events Calendar", "ghsa_id": null, "product": "Registrations for the Events Calendar", "added_date": "2026-03-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07303, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94188, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24943", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b2ce00a5-0c3e-4f26-a8e5-dcc4fa3c5a0b", "vulnerability": {"vulnId": "CVE-2022-4063", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "b2ce00a5-0c3e-4f26-a8e5-dcc4fa3c5a0b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-10T00:00:00+00:00"}, "scope": {"notes": "InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE | Affected: InPost / InPost Gallery | CVSS: 9.8 (CRITICAL) | EPSS: 0.09617 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4063", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4063"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4063"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE", "cve_id": "CVE-2022-4063", "vendor": "InPost", "ghsa_id": null, "product": "InPost Gallery", "added_date": "2026-03-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.09617, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95341, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4063", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7921a4b3-fbd8-4a5e-bf02-6154a7b549d1", "vulnerability": {"vulnId": "CVE-2025-47188", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-09T01:00:00+01:00"}, "gcve": {"object_uuid": "7921a4b3-fbd8-4a5e-bf02-6154a7b549d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-09T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit... | Affected: Mitel / 6800 Series, 6900 Series, 6900w Series SIP Phones, 6970 Conference Unit | CVSS: 6.5 (MEDIUM) | EPSS: 0.50237 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-47188", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47188"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47188"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit...", "cve_id": "CVE-2025-47188", "vendor": "Mitel", "ghsa_id": null, "product": "6800 Series, 6900 Series, 6900w Series SIP Phones, 6970 Conference Unit", "added_date": "2026-03-09T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.50237, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98875, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47188", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f0aaa84d-6945-4531-8b8e-e737ef6a33d8", "vulnerability": {"vulnId": "CVE-2023-3606", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "f0aaa84d-6945-4531-8b8e-e737ef6a33d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-07T00:00:00+00:00"}, "scope": {"notes": "TamronOS ping os command injection | Affected: Tamron / TamronOS | CVSS: 6.3 (MEDIUM) | EPSS: 0.07084 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3606", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3606"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3606"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TamronOS ping os command injection", "cve_id": "CVE-2023-3606", "vendor": "Tamron", "ghsa_id": null, "product": "TamronOS", "added_date": "2026-03-07T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.07084, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9403, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3606", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "167a86ae-615a-4915-af8c-bbe41fbc8980", "vulnerability": {"vulnId": "CVE-2024-21620", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "167a86ae-615a-4915-af8c-bbe41fbc8980", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-07T00:00:00+00:00"}, "scope": {"notes": "Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS | Affected: Juniper Networks / Junos OS | CVSS: 8.8 (HIGH) | EPSS: 0.00908 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-21620", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21620"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21620"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: SRX Series and EX Series: J-Web doesn't sufficiently sanitize input to prevent XSS", "cve_id": "CVE-2024-21620", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2026-03-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.00908, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58465, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21620", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dfde00b4-00f6-4a2e-9191-64b54bb99f4e", "vulnerability": {"vulnId": "CVE-2024-13985", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-03-06T01:00:00+01:00"}, "gcve": {"object_uuid": "dfde00b4-00f6-4a2e-9191-64b54bb99f4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-03-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-03-06T00:00:00+00:00"}, "scope": {"notes": "Dahua EIMS capture_handle.action RCE | Affected: Zhejiang Dahua Technology / EIMS | CVSS: 10.0 (CRITICAL) | EPSS: 0.15095 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-13985", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13985"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13985"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dahua EIMS capture_handle.action RCE", "cve_id": "CVE-2024-13985", "vendor": "Zhejiang Dahua Technology", "ghsa_id": null, "product": "EIMS", "added_date": "2026-03-06T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.15095, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96636, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13985", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8ffdbb3c-a273-498e-a02a-a7860ff2d15b", "vulnerability": {"vulnId": "CVE-2021-4462", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-26T01:00:00+01:00"}, "gcve": {"object_uuid": "8ffdbb3c-a273-498e-a02a-a7860ff2d15b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-26T00:00:00+00:00"}, "scope": {"notes": "Employee Records System v1.0 Arbitrary File Upload RCE | Affected: Employee Records System / Employee Records System | CVSS: 9.3 (CRITICAL) | EPSS: 0.0319 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-4462", "url": "https://www.cve.org/CVERecord?id=CVE-2021-4462"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-4462"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Employee Records System v1.0 Arbitrary File Upload RCE", "cve_id": "CVE-2021-4462", "vendor": "Employee Records System", "ghsa_id": null, "product": "Employee Records System", "added_date": "2026-02-26T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.0319, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87648, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-4462", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7b523067-4252-4ac3-8176-dbd205b7a044", "vulnerability": {"vulnId": "CVE-2025-22214", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-19T01:00:00+01:00"}, "gcve": {"object_uuid": "7b523067-4252-4ac3-8176-dbd205b7a044", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-19T00:00:00+00:00"}, "scope": {"notes": "Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection. | Affected: Landray / EIS | CVSS: 4.3 (MEDIUM) | EPSS: 0.01276 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-22214", "url": "https://www.cve.org/CVERecord?id=CVE-2025-22214"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-22214"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Landray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.", "cve_id": "CVE-2025-22214", "vendor": "Landray", "ghsa_id": null, "product": "EIS", "added_date": "2026-02-19T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.01276, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-22214", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f2368979-0e7a-46c1-9fbd-34a7a9452756", "vulnerability": {"vulnId": "CVE-2022-0747", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-18T01:00:00+01:00"}, "gcve": {"object_uuid": "f2368979-0e7a-46c1-9fbd-34a7a9452756", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-18T00:00:00+00:00"}, "scope": {"notes": "Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection | Affected: iList / Infographic Maker | CVSS: 9.8 (CRITICAL) | EPSS: 0.14882 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0747", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0747"}, {"id": "GHSA-G24Q-HMGF-4P5Q", "url": "https://github.com/advisories/GHSA-G24Q-HMGF-4P5Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0747"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection", "cve_id": "CVE-2022-0747", "vendor": "iList", "ghsa_id": "GHSA-G24Q-HMGF-4P5Q", "product": "Infographic Maker", "added_date": "2026-02-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14882, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0747", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a899b6dc-3cb3-4f33-baf8-e9a3a43a86a0", "vulnerability": {"vulnId": "CVE-2024-37393", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-18T01:00:00+01:00"}, "gcve": {"object_uuid": "a899b6dc-3cb3-4f33-baf8-e9a3a43a86a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-18T00:00:00+00:00"}, "scope": {"notes": "Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An... | Affected: SecurEnvoy / MFA | CVSS: 7.5 (HIGH) | EPSS: 0.03304 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-37393", "url": "https://www.cve.org/CVERecord?id=CVE-2024-37393"}, {"id": "GHSA-M2CR-JXG8-PR4V", "url": "https://github.com/advisories/GHSA-M2CR-JXG8-PR4V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-37393"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An...", "cve_id": "CVE-2024-37393", "vendor": "SecurEnvoy", "ghsa_id": "GHSA-M2CR-JXG8-PR4V", "product": "MFA", "added_date": "2026-02-18T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03304, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88126, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-37393", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a24f3c62-fd05-4d1c-82be-c02a12c312de", "vulnerability": {"vulnId": "CVE-2022-0784", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-17T01:00:00+01:00"}, "gcve": {"object_uuid": "a24f3c62-fd05-4d1c-82be-c02a12c312de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-17T00:00:00+00:00"}, "scope": {"notes": "Title Experiments Free < 9.0.1 - Unauthenticated SQLi | Affected: Title Experiments Free / Title Experiments Free | CVSS: 9.8 (CRITICAL) | EPSS: 0.10079 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0784", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0784"}, {"id": "GHSA-7Q7C-RWH6-625C", "url": "https://github.com/advisories/GHSA-7Q7C-RWH6-625C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0784"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Title Experiments Free < 9.0.1 - Unauthenticated SQLi", "cve_id": "CVE-2022-0784", "vendor": "Title Experiments Free", "ghsa_id": "GHSA-7Q7C-RWH6-625C", "product": "Title Experiments Free", "added_date": "2026-02-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.10079, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95499, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0784", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "41f690f0-6a7d-45ce-ac29-3b6ec561db1a", "vulnerability": {"vulnId": "CVE-2024-54763", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "41f690f0-6a7d-45ce-ac29-3b6ec561db1a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-16T00:00:00+00:00"}, "scope": {"notes": "An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without... | Affected: ipTIME / A2004 | CVSS: 6.5 (MEDIUM) | EPSS: 0.00768 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-54763", "url": "https://www.cve.org/CVERecord?id=CVE-2024-54763"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-54763"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without...", "cve_id": "CVE-2024-54763", "vendor": "ipTIME", "ghsa_id": null, "product": "A2004", "added_date": "2026-02-16T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.00768, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.53904, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-54763", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "23099d20-b5db-4fa8-8677-7f0bf19b2a09", "vulnerability": {"vulnId": "CVE-2021-31250", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "23099d20-b5db-4fa8-8677-7f0bf19b2a09", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-16T00:00:00+00:00"}, "scope": {"notes": "Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack... | Affected: CHIYU Technology / BF-430, BF-431, BF-450M TCP/IP Converter | CVSS: 5.4 (MEDIUM) | EPSS: 0.79605 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-31250", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31250"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31250"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack...", "cve_id": "CVE-2021-31250", "vendor": "CHIYU Technology", "ghsa_id": null, "product": "BF-430, BF-431, BF-450M TCP/IP Converter", "added_date": "2026-02-16T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.79605, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99597, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31250", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b83461cd-41b8-490d-b49e-da2a94d712b4", "vulnerability": {"vulnId": "CVE-2025-34041", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "b83461cd-41b8-490d-b49e-da2a94d712b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-16T00:00:00+00:00"}, "scope": {"notes": "Sangfor Endpoint Detection and Response OS Command Injection | Affected: Sangfor / Endpoint Detection and Response Platform | CVSS: 10.0 (CRITICAL) | EPSS: 0.071 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34041", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34041"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34041"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sangfor Endpoint Detection and Response OS Command Injection", "cve_id": "CVE-2025-34041", "vendor": "Sangfor", "ghsa_id": null, "product": "Endpoint Detection and Response Platform", "added_date": "2026-02-16T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.071, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94044, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34041", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9a4f1343-cd7b-4a39-9d02-c972962b2d6d", "vulnerability": {"vulnId": "CVE-2024-36858", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "9a4f1343-cd7b-4a39-9d02-c972962b2d6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-16T00:00:00+00:00"}, "scope": {"notes": "An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via... | Affected: Jan / Jan v0.4.12 | CVSS: 9.8 (CRITICAL) | EPSS: 0.03035 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-36858", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36858"}, {"id": "GHSA-QFJH-MVQ6-C5P8", "url": "https://github.com/advisories/GHSA-QFJH-MVQ6-C5P8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36858"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via...", "cve_id": "CVE-2024-36858", "vendor": "Jan", "ghsa_id": "GHSA-QFJH-MVQ6-C5P8", "product": "Jan v0.4.12", "added_date": "2026-02-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03035, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87038, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36858", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d237ad24-32b2-49b4-8ab0-9a404dc6c1f0", "vulnerability": {"vulnId": "CVE-2024-36857", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "d237ad24-32b2-49b4-8ab0-9a404dc6c1f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-16T00:00:00+00:00"}, "scope": {"notes": "Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface. | Affected: Jan / Jan v0.4.12 | CVSS: 7.5 (HIGH) | EPSS: 0.02054 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-36857", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36857"}, {"id": "GHSA-5JQC-QJ57-4HRC", "url": "https://github.com/advisories/GHSA-5JQC-QJ57-4HRC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36857"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.", "cve_id": "CVE-2024-36857", "vendor": "Jan", "ghsa_id": "GHSA-5JQC-QJ57-4HRC", "product": "Jan v0.4.12", "added_date": "2026-02-16T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02054, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80566, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36857", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f6a8ab08-409e-47cd-bb30-f703524dd1e2", "vulnerability": {"vulnId": "CVE-2025-34068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "f6a8ab08-409e-47cd-bb30-f703524dd1e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-16T00:00:00+00:00"}, "scope": {"notes": "Samsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 Parameters | Affected: Samsung Electronics / WLAN AP WEA453e | CVSS: 9.3 (CRITICAL) | EPSS: 0.00901 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34068", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34068"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Samsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 Parameters", "cve_id": "CVE-2025-34068", "vendor": "Samsung Electronics", "ghsa_id": null, "product": "WLAN AP WEA453e", "added_date": "2026-02-16T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.00901, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58243, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34068", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a7d08e49-da72-4aae-a57b-60e8bbd6215f", "vulnerability": {"vulnId": "CVE-2025-5287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "a7d08e49-da72-4aae-a57b-60e8bbd6215f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-15T00:00:00+00:00"}, "scope": {"notes": "Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection | Affected: Erumfaham / Likes and Dislikes Plugin | CVSS: 7.5 (HIGH) | EPSS: 0.02355 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-5287", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection", "cve_id": "CVE-2025-5287", "vendor": "Erumfaham", "ghsa_id": null, "product": "Likes and Dislikes Plugin", "added_date": "2026-02-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02355, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8311, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6432516a-71cc-48c1-95b6-45b6024cb643", "vulnerability": {"vulnId": "CVE-2025-5605", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "6432516a-71cc-48c1-95b6-45b6024cb643", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-15T00:00:00+00:00"}, "scope": {"notes": "Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure | Affected: WSO2 / WSO2 Identity Server, WSO2 Enterprise Integrator, WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Manager, WSO2 API Control Plane, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, org.wso2.carbon:org.wso2.carbon.ui | CVSS: 4.3 (MEDIUM) | EPSS: 0.0085 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-5605", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5605"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5605"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to Partial Information Disclosure", "cve_id": "CVE-2025-5605", "vendor": "WSO2", "ghsa_id": null, "product": "WSO2 Identity Server, WSO2 Enterprise Integrator, WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Manager, WSO2 API Control Plane, WSO2 Identity Server as Key Manager, WSO2 Open Banking AM, WSO2 Open Banking IAM, org.wso2.carbon:org.wso2.carbon.ui", "added_date": "2026-02-15T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.0085, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.56629, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5605", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a813f5c5-1114-4c36-9f0f-e8a36315b28a", "vulnerability": {"vulnId": "CVE-2020-11854", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "a813f5c5-1114-4c36-9f0f-e8a36315b28a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-15T00:00:00+00:00"}, "scope": {"notes": "Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products. | Affected: Micro Focus / Application Performance Management, Operation Bridge (containerized), Operation Bridge Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.74449 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11854", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11854"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11854"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.", "cve_id": "CVE-2020-11854", "vendor": "Micro Focus", "ghsa_id": null, "product": "Application Performance Management, Operation Bridge (containerized), Operation Bridge Manager", "added_date": "2026-02-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74449, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99481, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11854", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "af3a6b99-2138-4059-b537-2db62bb91bf2", "vulnerability": {"vulnId": "CVE-2024-45388", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "af3a6b99-2138-4059-b537-2db62bb91bf2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-14T00:00:00+00:00"}, "scope": {"notes": "Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`) | Affected: SpectoLabs / hoverfly | CVSS: 7.5 (HIGH) | EPSS: 0.55574 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-45388", "url": "https://www.cve.org/CVERecord?id=CVE-2024-45388"}, {"id": "GHSA-6XX4-X46F-F897", "url": "https://github.com/advisories/GHSA-6XX4-X46F-F897"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-45388"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)", "cve_id": "CVE-2024-45388", "vendor": "SpectoLabs", "ghsa_id": "GHSA-6XX4-X46F-F897", "product": "hoverfly", "added_date": "2026-02-14T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.55574, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99011, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-45388", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "63d6d357-711b-46eb-bbca-766ef09370fb", "vulnerability": {"vulnId": "CVE-2024-34257", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "63d6d357-711b-46eb-bbca-766ef09370fb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-14T00:00:00+00:00"}, "scope": {"notes": "TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary... | Affected: TOTOLINK / EX1800T | CVSS: 9.8 (CRITICAL) | EPSS: 0.03817 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-34257", "url": "https://www.cve.org/CVERecord?id=CVE-2024-34257"}, {"id": "GHSA-VVF7-Q7RC-3M2M", "url": "https://github.com/advisories/GHSA-VVF7-Q7RC-3M2M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-34257"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary...", "cve_id": "CVE-2024-34257", "vendor": "TOTOLINK", "ghsa_id": "GHSA-VVF7-Q7RC-3M2M", "product": "EX1800T", "added_date": "2026-02-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03817, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-34257", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "653d3a97-fe3c-41c1-80cd-e349906ed17b", "vulnerability": {"vulnId": "CVE-2024-50334", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "653d3a97-fe3c-41c1-80cd-e349906ed17b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-14T00:00:00+00:00"}, "scope": {"notes": "Semicolon Path Injection on API /api;/config | Affected: Erudika / scoold | CVSS: 8.7 (HIGH) | EPSS: 0.01035 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-50334", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50334"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50334"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Semicolon Path Injection on API /api;/config", "cve_id": "CVE-2024-50334", "vendor": "Erudika", "ghsa_id": null, "product": "scoold", "added_date": "2026-02-14T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.01035, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62575, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-50334", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ef03f1f6-24b5-47b8-9fea-c42217d2a6d6", "vulnerability": {"vulnId": "CVE-2024-49380", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "ef03f1f6-24b5-47b8-9fea-c42217d2a6d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-14T00:00:00+00:00"}, "scope": {"notes": "Plenti arbitrary file write vulnerability | Affected: Plentico / plenti | CVSS: 8.9 (HIGH) | EPSS: 0.02705 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-49380", "url": "https://www.cve.org/CVERecord?id=CVE-2024-49380"}, {"id": "GHSA-2P96-P7QH-4RGR", "url": "https://github.com/advisories/GHSA-2P96-P7QH-4RGR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-49380"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Plenti arbitrary file write vulnerability", "cve_id": "CVE-2024-49380", "vendor": "Plentico", "ghsa_id": "GHSA-2P96-P7QH-4RGR", "product": "plenti", "added_date": "2026-02-14T00:00:00.000Z", "cvss_score": 8.9, "epss_score": 0.02705, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85434, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-49380", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "77ba680d-37bf-4248-8c07-937439895be3", "vulnerability": {"vulnId": "CVE-2024-4443", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "77ba680d-37bf-4248-8c07-937439895be3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-14T00:00:00+00:00"}, "scope": {"notes": "Business Directory Plugin \u2013 Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter | Affected: Strategy11 Team / Business Directory Plugin \u2013 Easy Listing Directories for WordPress | CVSS: 9.8 (CRITICAL) | EPSS: 0.10355 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-4443", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4443"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4443"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Business Directory Plugin \u2013 Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter", "cve_id": "CVE-2024-4443", "vendor": "Strategy11 Team", "ghsa_id": null, "product": "Business Directory Plugin \u2013 Easy Listing Directories for WordPress", "added_date": "2026-02-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.10355, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95586, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4443", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "11cd4297-6cfe-4727-bb58-717922364899", "vulnerability": {"vulnId": "CVE-2020-22165", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-13T01:00:00+01:00"}, "gcve": {"object_uuid": "11cd4297-6cfe-4727-bb58-717922364899", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-13T00:00:00+00:00"}, "scope": {"notes": "PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \\hms\\user-login.php. Remote unauthenticated users can... | Affected: PHPGurukul / Hospital Management System | CVSS: 7.5 (HIGH) | EPSS: 0.06348 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-22165", "url": "https://www.cve.org/CVERecord?id=CVE-2020-22165"}, {"id": "GHSA-5XFJ-JPRX-5M93", "url": "https://github.com/advisories/GHSA-5XFJ-JPRX-5M93"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-22165"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \\hms\\user-login.php. Remote unauthenticated users can...", "cve_id": "CVE-2020-22165", "vendor": "PHPGurukul", "ghsa_id": "GHSA-5XFJ-JPRX-5M93", "product": "Hospital Management System", "added_date": "2026-02-13T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.06348, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93431, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-22165", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a19da1f2-c483-4f2a-a5da-e14bc17bbb80", "vulnerability": {"vulnId": "CVE-2022-3481", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-12T01:00:00+01:00"}, "gcve": {"object_uuid": "a19da1f2-c483-4f2a-a5da-e14bc17bbb80", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-12T00:00:00+00:00"}, "scope": {"notes": "WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi | Affected: WooCommerce Dropshipping / WooCommerce Dropshipping | CVSS: 9.8 (CRITICAL) | EPSS: 0.03947 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-3481", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3481"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3481"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WooCommerce Dropshipping < 4.4 - Unauthenticated SQLi", "cve_id": "CVE-2022-3481", "vendor": "WooCommerce Dropshipping", "ghsa_id": null, "product": "WooCommerce Dropshipping", "added_date": "2026-02-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03947, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9008, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3481", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "aa1a9974-7b1e-4391-97bb-881d126118af", "vulnerability": {"vulnId": "CVE-2025-0107", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "aa1a9974-7b1e-4391-97bb-881d126118af", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-11T00:00:00+00:00"}, "scope": {"notes": "Expedition: OS Command Injection Vulnerability | Affected: Palo Alto Networks / Cloud NGFW, Expedition, Panorama, PAN-OS, Prisma Access | CVSS: 7.7 (HIGH) | EPSS: 0.78532 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-0107", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0107"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0107"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Expedition: OS Command Injection Vulnerability", "cve_id": "CVE-2025-0107", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, Expedition, Panorama, PAN-OS, Prisma Access", "added_date": "2026-02-11T00:00:00.000Z", "cvss_score": 7.7, "epss_score": 0.78532, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99574, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0107", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5adec36f-32ba-456b-879e-5fd9e29e3787", "vulnerability": {"vulnId": "CVE-2018-14918", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "5adec36f-32ba-456b-879e-5fd9e29e3787", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-11T00:00:00+00:00"}, "scope": {"notes": "LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. | Affected: LOYTEC / LGATE-902 | CVSS: 7.5 (HIGH) | EPSS: 0.18611 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-14918", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14918"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14918"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.", "cve_id": "CVE-2018-14918", "vendor": "LOYTEC", "ghsa_id": null, "product": "LGATE-902", "added_date": "2026-02-11T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.18611, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97179, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14918", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "684b954b-4979-4fa1-8ad8-740491a5494e", "vulnerability": {"vulnId": "CVE-2020-16139", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "684b954b-4979-4fa1-8ad8-740491a5494e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-10T00:00:00+00:00"}, "scope": {"notes": "A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through... | Affected: Cisco / Unified IP Conference Station 7937G | CVSS: 7.5 (HIGH) | EPSS: 0.7977 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-16139", "url": "https://www.cve.org/CVERecord?id=CVE-2020-16139"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-16139"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the device remotely through...", "cve_id": "CVE-2020-16139", "vendor": "Cisco", "ghsa_id": null, "product": "Unified IP Conference Station 7937G", "added_date": "2026-02-10T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.7977, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.996, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-16139", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7b4c0e73-63b3-4fa5-8641-838c77acda0a", "vulnerability": {"vulnId": "CVE-2020-35476", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-08T01:00:00+01:00"}, "gcve": {"object_uuid": "7b4c0e73-63b3-4fa5-8641-838c77acda0a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-08T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written... | Affected: OpenTSDB / OpenTSDB | CVSS: 9.8 (CRITICAL) | EPSS: 0.8533 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35476", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35476"}, {"id": "GHSA-HV53-Q76C-7F8C", "url": "https://github.com/advisories/GHSA-HV53-Q76C-7F8C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35476"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written...", "cve_id": "CVE-2020-35476", "vendor": "OpenTSDB", "ghsa_id": "GHSA-HV53-Q76C-7F8C", "product": "OpenTSDB", "added_date": "2026-02-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.8533, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99712, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35476", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b0085cae-8da1-4227-83cb-89f61179e6f1", "vulnerability": {"vulnId": "CVE-2021-45092", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-08T01:00:00+01:00"}, "gcve": {"object_uuid": "b0085cae-8da1-4227-83cb-89f61179e6f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-08T00:00:00+00:00"}, "scope": {"notes": "Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter. | Affected: Cybele Software / Thinfinity VirtualUI | CVSS: 9.8 (CRITICAL) | EPSS: 0.40584 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-45092", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45092"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45092"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.", "cve_id": "CVE-2021-45092", "vendor": "Cybele Software", "ghsa_id": null, "product": "Thinfinity VirtualUI", "added_date": "2026-02-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.40584, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98609, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-45092", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3a52b0ff-431a-44e0-badd-3315fc185608", "vulnerability": {"vulnId": "CVE-2026-21858", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-07T01:00:00+01:00"}, "gcve": {"object_uuid": "3a52b0ff-431a-44e0-badd-3315fc185608", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-07T00:00:00+00:00"}, "scope": {"notes": "n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling | Affected: n8n-io / n8n | CVSS: 10.0 (CRITICAL) | EPSS: 0.78447 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2026-21858", "url": "https://www.cve.org/CVERecord?id=CVE-2026-21858"}, {"id": "GHSA-V4PR-FM98-W9PG", "url": "https://github.com/advisories/GHSA-V4PR-FM98-W9PG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2026-21858"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling", "cve_id": "CVE-2026-21858", "vendor": "n8n-io", "ghsa_id": "GHSA-V4PR-FM98-W9PG", "product": "n8n", "added_date": "2026-02-07T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.78447, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99573, "used_in_malware": "unknown", "vulnerability_id": "CVE-2026-21858", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6907ea71-c770-48af-abe3-8ac755b19cd9", "vulnerability": {"vulnId": "CVE-2020-26948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "6907ea71-c770-48af-abe3-8ac755b19cd9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-06T00:00:00+00:00"}, "scope": {"notes": "Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. | Affected: Emby / Emby Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.87154 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-26948", "url": "https://www.cve.org/CVERecord?id=CVE-2020-26948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-26948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.", "cve_id": "CVE-2020-26948", "vendor": "Emby", "ghsa_id": null, "product": "Emby Server", "added_date": "2026-02-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.87154, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99747, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-26948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "56858582-b0ea-4306-9118-7f95e48463e7", "vulnerability": {"vulnId": "CVE-2022-22956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-05T01:00:00+01:00"}, "gcve": {"object_uuid": "56858582-b0ea-4306-9118-7f95e48463e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-05T00:00:00+00:00"}, "scope": {"notes": "VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A... | Affected: VMware / Workspace ONE Access | CVSS: 9.8 (CRITICAL) | EPSS: 0.49814 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-22956", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A...", "cve_id": "CVE-2022-22956", "vendor": "VMware", "ghsa_id": null, "product": "Workspace ONE Access", "added_date": "2026-02-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.49814, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98864, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e9bdcaa0-0b18-4b62-8054-a8f4e011f856", "vulnerability": {"vulnId": "CVE-2025-34045", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "e9bdcaa0-0b18-4b62-8054-a8f4e011f856", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-04T00:00:00+00:00"}, "scope": {"notes": "WeiPHP Path Traversal Arbitrary File Read | Affected: Shenzhen Yuanmengyun Technology / WeiPHP | CVSS: 8.7 (HIGH) | EPSS: 0.04197 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34045", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34045"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34045"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WeiPHP Path Traversal Arbitrary File Read", "cve_id": "CVE-2025-34045", "vendor": "Shenzhen Yuanmengyun Technology", "ghsa_id": null, "product": "WeiPHP", "added_date": "2026-02-04T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.04197, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90636, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34045", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "388960c1-1d31-4d85-932b-d936c177f26d", "vulnerability": {"vulnId": "CVE-2025-34047", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "388960c1-1d31-4d85-932b-d936c177f26d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-04T00:00:00+00:00"}, "scope": {"notes": "Leadsec VPN Path Traversal Arbitrary File Read | Affected: Beijing NetGuard Nebula Information Technology / Leadsec SSL VPN | CVSS: 8.7 (HIGH) | EPSS: 0.00548 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34047", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34047"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34047"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Leadsec VPN Path Traversal Arbitrary File Read", "cve_id": "CVE-2025-34047", "vendor": "Beijing NetGuard Nebula Information Technology", "ghsa_id": null, "product": "Leadsec SSL VPN", "added_date": "2026-02-04T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.00548, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.43826, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34047", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3786ee1a-5848-4034-9458-63bb64e40e43", "vulnerability": {"vulnId": "CVE-2023-7335", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "3786ee1a-5848-4034-9458-63bb64e40e43", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-02-04T00:00:00+00:00"}, "scope": {"notes": "EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics | Affected: Hangzhou Kuozhi Network Technology / EduSoho | CVSS: 8.7 (HIGH) | EPSS: 0.00767 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7335", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7335"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7335"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics", "cve_id": "CVE-2023-7335", "vendor": "Hangzhou Kuozhi Network Technology", "ghsa_id": null, "product": "EduSoho", "added_date": "2026-02-04T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.00767, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.53878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7335", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5a23948b-7934-4ce7-83f0-f5b905ced202", "vulnerability": {"vulnId": "CVE-2022-1386", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-30T01:00:00+01:00"}, "gcve": {"object_uuid": "5a23948b-7934-4ce7-83f0-f5b905ced202", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-30T00:00:00+00:00"}, "scope": {"notes": "Fusion Builder < 3.6.2 - Unauthenticated SSRF | Affected: Theme Fusion / Fusion Builder | CVSS: 9.8 (CRITICAL) | EPSS: 0.71427 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1386", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1386"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1386"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fusion Builder < 3.6.2 - Unauthenticated SSRF", "cve_id": "CVE-2022-1386", "vendor": "Theme Fusion", "ghsa_id": null, "product": "Fusion Builder", "added_date": "2026-01-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.71427, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99398, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1386", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "458fd26e-823e-4d91-98cc-319d70166417", "vulnerability": {"vulnId": "CVE-2025-34046", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-30T01:00:00+01:00"}, "gcve": {"object_uuid": "458fd26e-823e-4d91-98cc-319d70166417", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-30T00:00:00+00:00"}, "scope": {"notes": "Fanwei E-Office Unauthenticated File Upload | Affected: Shanghai Fanwei Network Technology / E-Office | CVSS: 10.0 (CRITICAL) | EPSS: 0.00883 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34046", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34046"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34046"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fanwei E-Office Unauthenticated File Upload", "cve_id": "CVE-2025-34046", "vendor": "Shanghai Fanwei Network Technology", "ghsa_id": null, "product": "E-Office", "added_date": "2026-01-30T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.00883, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.57705, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34046", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1428e991-b88a-4060-802e-f99e13d7220f", "vulnerability": {"vulnId": "CVE-2025-34059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-29T01:00:00+01:00"}, "gcve": {"object_uuid": "1428e991-b88a-4060-802e-f99e13d7220f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-29T00:00:00+00:00"}, "scope": {"notes": "Dahua Smart Cloud Gateway Registration Management Platform SQL Injection | Affected: Zhejiang Dahua Technology / Smart Cloud Gateway Registration Management Platform | CVSS: 8.7 (HIGH) | EPSS: 0.0047 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34059", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34059"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dahua Smart Cloud Gateway Registration Management Platform SQL Injection", "cve_id": "CVE-2025-34059", "vendor": "Zhejiang Dahua Technology", "ghsa_id": null, "product": "Smart Cloud Gateway Registration Management Platform", "added_date": "2026-01-29T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.0047, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.38329, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bb248d6b-d17f-4258-9d17-3d7783f2b569", "vulnerability": {"vulnId": "CVE-2025-34038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-29T01:00:00+01:00"}, "gcve": {"object_uuid": "bb248d6b-d17f-4258-9d17-3d7783f2b569", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-29T00:00:00+00:00"}, "scope": {"notes": "Weaver E-cology SQL Injection | Affected: Weaver / E-cology | CVSS: 8.7 (HIGH) | EPSS: 0.02117 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34038", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34038"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-cology SQL Injection", "cve_id": "CVE-2025-34038", "vendor": "Weaver", "ghsa_id": null, "product": "E-cology", "added_date": "2026-01-29T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.02117, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81166, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34038", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "140aeed8-fc3d-40db-9194-52e666aeb77f", "vulnerability": {"vulnId": "CVE-2022-40619", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "140aeed8-fc3d-40db-9194-52e666aeb77f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-28T00:00:00+00:00"}, "scope": {"notes": "FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected... | Affected: NETGEAR / Routers and Orbi WiFi Systems | CVSS: 7.7 (HIGH) | EPSS: 0.02538 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-40619", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40619"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40619"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected...", "cve_id": "CVE-2022-40619", "vendor": "NETGEAR", "ghsa_id": null, "product": "Routers and Orbi WiFi Systems", "added_date": "2026-01-28T00:00:00.000Z", "cvss_score": 7.7, "epss_score": 0.02538, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40619", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "78d2d202-e2a5-475d-9774-d0161248ef17", "vulnerability": {"vulnId": "CVE-2018-11714", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-26T01:00:00+01:00"}, "gcve": {"object_uuid": "78d2d202-e2a5-475d-9774-d0161248ef17", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-26T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0... | Affected: TP-Link / TL-WR840N, TL-WR841N | CVSS: 9.8 (CRITICAL) | EPSS: 0.68053 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11714", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11714"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11714"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0...", "cve_id": "CVE-2018-11714", "vendor": "TP-Link", "ghsa_id": null, "product": "TL-WR840N, TL-WR841N", "added_date": "2026-01-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68053, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99307, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11714", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6be88864-de13-4b48-893e-b9ba378916c7", "vulnerability": {"vulnId": "CVE-2023-40748", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-26T01:00:00+01:00"}, "gcve": {"object_uuid": "6be88864-de13-4b48-893e-b9ba378916c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-26T00:00:00+00:00"}, "scope": {"notes": "PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the \"q\" parameter of index.php. | Affected: PHP Jabbers / Food Delivery Script | CVSS: 9.8 (CRITICAL) | EPSS: 0.03318 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-40748", "url": "https://www.cve.org/CVERecord?id=CVE-2023-40748"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-40748"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the \"q\" parameter of index.php.", "cve_id": "CVE-2023-40748", "vendor": "PHP Jabbers", "ghsa_id": null, "product": "Food Delivery Script", "added_date": "2026-01-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03318, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8818, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-40748", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0f9f6f21-7a35-456f-9993-6e7d619f64b4", "vulnerability": {"vulnId": "CVE-2024-20440", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-25T01:00:00+01:00"}, "gcve": {"object_uuid": "0f9f6f21-7a35-456f-9993-6e7d619f64b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-25T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.\r\n\r\nThis... | Affected: Cisco / Cisco Smart License Utility | CVSS: 7.5 (HIGH) | EPSS: 0.51897 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-20440", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20440"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20440"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.\r\n\r\nThis...", "cve_id": "CVE-2024-20440", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Smart License Utility", "added_date": "2026-01-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.51897, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98919, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20440", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "516848cd-9911-49df-afe4-611a1fae0be4", "vulnerability": {"vulnId": "CVE-2025-10204", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-25T01:00:00+01:00"}, "gcve": {"object_uuid": "516848cd-9911-49df-afe4-611a1fae0be4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-25T00:00:00+00:00"}, "scope": {"notes": "Unauth Admin Reset Password on AC Smart II | Affected: LG Electronics / AC Smart II | CVSS: 7.1 (HIGH) | EPSS: 0.00483 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-10204", "url": "https://www.cve.org/CVERecord?id=CVE-2025-10204"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-10204"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauth Admin Reset Password on AC Smart II", "cve_id": "CVE-2025-10204", "vendor": "LG Electronics", "ghsa_id": null, "product": "AC Smart II", "added_date": "2026-01-25T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.00483, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.39349, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-10204", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c1dd2bbd-ca78-4248-a938-a6011e96ec72", "vulnerability": {"vulnId": "CVE-2025-69200", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-25T01:00:00+01:00"}, "gcve": {"object_uuid": "c1dd2bbd-ca78-4248-a938-a6011e96ec72", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-25T00:00:00+00:00"}, "scope": {"notes": "phpMyFAQ has unauthenticated config backup download via /api/setup/backup | Affected: Thorsten / phpMyFAQ | CVSS: 7.5 (HIGH) | EPSS: 0.02141 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-69200", "url": "https://www.cve.org/CVERecord?id=CVE-2025-69200"}, {"id": "GHSA-9CG9-4H4F-J6FG", "url": "https://github.com/advisories/GHSA-9CG9-4H4F-J6FG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-69200"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "phpMyFAQ has unauthenticated config backup download via /api/setup/backup", "cve_id": "CVE-2025-69200", "vendor": "Thorsten", "ghsa_id": "GHSA-9CG9-4H4F-J6FG", "product": "phpMyFAQ", "added_date": "2026-01-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02141, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81378, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-69200", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6ffce990-9d1b-49e6-bd0c-bf2c4ecd024c", "vulnerability": {"vulnId": "CVE-2022-36923", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-25T01:00:00+01:00"}, "gcve": {"object_uuid": "6ffce990-9d1b-49e6-bd0c-bf2c4ecd024c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-25T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before... | Affected: Zoho / ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, OpUtils | CVSS: 7.5 (HIGH) | EPSS: 0.071 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-36923", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36923"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36923"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before...", "cve_id": "CVE-2022-36923", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, OpUtils", "added_date": "2026-01-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.071, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94044, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36923", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d48b14a4-aea5-42d6-955d-788616df9fa1", "vulnerability": {"vulnId": "CVE-2020-36870", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-24T01:00:00+01:00"}, "gcve": {"object_uuid": "d48b14a4-aea5-42d6-955d-788616df9fa1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-24T00:00:00+00:00"}, "scope": {"notes": "Ruijie Gateway EG & NBR Models v11.1(6)B9P1 - 11.9(4)B12P1 RCE | Affected: Beijing Star-Net Ruijie Network Technology / RG-EG1000C, RG-EG2000F, RG-EG2000K, RG-EG2000L, RG-EG2000CE, RG-EG2000SE, RG-EG2000GE, RG-EG2000XE, RG-EG2000UE, RG-EG3000CE, RG-EG3000SE, RG-EG3000GE, RG-EG3000ME, RG-EG3000UE, RG-EG3000XE, RG-EG2100-P, EG3210, EG3220, EG3230, EG3250, NBR108G-P, NBR1000G-E, NBR1300G-E, NBR1700G-E, NBR2100G-E, NBR2500D-E, NBR3000D-E, NBR6120-E, NBR6135-E, NBR6205-E, NBR6210-E, NBR6215-E, NBR800G, NBR950G, NBR1000G-C, NBR2000G-C, NBR3000G-S | CVSS: 9.2 (CRITICAL) | EPSS: 0.00753 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-36870", "url": "https://www.cve.org/CVERecord?id=CVE-2020-36870"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-36870"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruijie Gateway EG & NBR Models v11.1(6)B9P1 - 11.9(4)B12P1 RCE", "cve_id": "CVE-2020-36870", "vendor": "Beijing Star-Net Ruijie Network Technology", "ghsa_id": null, "product": "RG-EG1000C, RG-EG2000F, RG-EG2000K, RG-EG2000L, RG-EG2000CE, RG-EG2000SE, RG-EG2000GE, RG-EG2000XE, RG-EG2000UE, RG-EG3000CE, RG-EG3000SE, RG-EG3000GE, RG-EG3000ME, RG-EG3000UE, RG-EG3000XE, RG-EG2100-P, EG3210, EG3220, EG3230, EG3250, NBR108G-P, NBR1000G-E, NBR1300G-E, NBR1700G-E, NBR2100G-E, NBR2500D-E, NBR3000D-E, NBR6120-E, NBR6135-E, NBR6205-E, NBR6210-E, NBR6215-E, NBR800G, NBR950G, NBR1000G-C, NBR2000G-C, NBR3000G-S", "added_date": "2026-01-24T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.00753, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.53352, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-36870", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b6ea528b-29f7-4589-9c5f-71f19493177b", "vulnerability": {"vulnId": "CVE-2024-7314", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-24T01:00:00+01:00"}, "gcve": {"object_uuid": "b6ea528b-29f7-4589-9c5f-71f19493177b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-24T00:00:00+00:00"}, "scope": {"notes": "anji-plus AJ-Report Authentication Bypass | Affected: Anji-plus / AJ-Report | CVSS: 9.8 (CRITICAL) | EPSS: 0.5175 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7314", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7314"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7314"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "anji-plus AJ-Report Authentication Bypass", "cve_id": "CVE-2024-7314", "vendor": "Anji-plus", "ghsa_id": null, "product": "AJ-Report", "added_date": "2026-01-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.5175, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98916, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7314", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "817de352-ce61-47c0-ba11-e537ac52a171", "vulnerability": {"vulnId": "CVE-2023-7334", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-24T01:00:00+01:00"}, "gcve": {"object_uuid": "817de352-ce61-47c0-ba11-e537ac52a171", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-24T00:00:00+00:00"}, "scope": {"notes": "Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE | Affected: Changjetong Information Technology / T+ | CVSS: 9.3 (CRITICAL) | EPSS: 0.01115 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7334", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7334"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7334"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE", "cve_id": "CVE-2023-7334", "vendor": "Changjetong Information Technology", "ghsa_id": null, "product": "T+", "added_date": "2026-01-24T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.01115, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64818, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7334", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a3aa68dd-3fcc-4049-8482-8839ddb2876b", "vulnerability": {"vulnId": "CVE-2022-4984", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-24T01:00:00+01:00"}, "gcve": {"object_uuid": "a3aa68dd-3fcc-4049-8482-8839ddb2876b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-24T00:00:00+00:00"}, "scope": {"notes": "ZenTao Biz < 6.5, Max < 3.0, & Open Source Edition 16.5/16.5beta1 SQL Injection via user-login.html | Affected: Qingdao Esoft Tianchuang Network Technology / ZenTao Biz, ZenTao Max, ZenTao Open Source Edition | CVSS: 8.7 (HIGH) | EPSS: 0.0045 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4984", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4984"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4984"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZenTao Biz < 6.5, Max < 3.0, & Open Source Edition 16.5/16.5beta1 SQL Injection via user-login.html", "cve_id": "CVE-2022-4984", "vendor": "Qingdao Esoft Tianchuang Network Technology", "ghsa_id": null, "product": "ZenTao Biz, ZenTao Max, ZenTao Open Source Edition", "added_date": "2026-01-24T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.0045, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.36798, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4984", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "28f35a95-0015-4b30-b4aa-4fe0b0388cbf", "vulnerability": {"vulnId": "CVE-2021-3708", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-16T01:00:00+01:00"}, "gcve": {"object_uuid": "28f35a95-0015-4b30-b4aa-4fe0b0388cbf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-16T00:00:00+00:00"}, "scope": {"notes": "D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local... | Affected: D-Link / DSL-2750U | CVSS: 7.8 (HIGH) | EPSS: 0.24563 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-3708", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3708"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3708"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local...", "cve_id": "CVE-2021-3708", "vendor": "D-Link", "ghsa_id": null, "product": "DSL-2750U", "added_date": "2026-01-16T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.24563, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97818, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3708", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3544112a-23c2-4efd-a439-6f700d4adc62", "vulnerability": {"vulnId": "CVE-2024-7928", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-15T01:00:00+01:00"}, "gcve": {"object_uuid": "3544112a-23c2-4efd-a439-6f700d4adc62", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-15T00:00:00+00:00"}, "scope": {"notes": "FastAdmin lang path traversal | Affected: FastAdmin / FastAdmin | CVSS: 5.3 (MEDIUM) | EPSS: 0.16882 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7928", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7928"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7928"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FastAdmin lang path traversal", "cve_id": "CVE-2024-7928", "vendor": "FastAdmin", "ghsa_id": null, "product": "FastAdmin", "added_date": "2026-01-15T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.16882, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96964, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7928", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e4a1a305-1c52-44b3-9c1a-f26c5abb5281", "vulnerability": {"vulnId": "CVE-2025-34039", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-12T01:00:00+01:00"}, "gcve": {"object_uuid": "e4a1a305-1c52-44b3-9c1a-f26c5abb5281", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-12T00:00:00+00:00"}, "scope": {"notes": "Yonyou NC BeanShell Command Injection | Affected: Yonyou / UFIDA NC | CVSS: 10.0 (CRITICAL) | EPSS: 0.00555 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34039", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34039"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34039"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yonyou NC BeanShell Command Injection", "cve_id": "CVE-2025-34039", "vendor": "Yonyou", "ghsa_id": null, "product": "UFIDA NC", "added_date": "2026-01-12T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.00555, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.44263, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34039", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4afb36f3-2b51-4a61-9849-12436cd2efc1", "vulnerability": {"vulnId": "CVE-2025-34057", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "4afb36f3-2b51-4a61-9849-12436cd2efc1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-10T00:00:00+00:00"}, "scope": {"notes": "Ruijie NBR Router Administrative Credential Disclosure | Affected: Ruijie / NBR Router | CVSS: 8.7 (HIGH) | EPSS: 0.08692 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34057", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34057"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34057"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruijie NBR Router Administrative Credential Disclosure", "cve_id": "CVE-2025-34057", "vendor": "Ruijie", "ghsa_id": null, "product": "NBR Router", "added_date": "2026-01-10T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.08692, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34057", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1cadfa96-b404-49e4-9eb1-7c1f876cd403", "vulnerability": {"vulnId": "CVE-2025-34043", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "1cadfa96-b404-49e4-9eb1-7c1f876cd403", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-10T00:00:00+00:00"}, "scope": {"notes": "Vacron NVR Remote Command Execution | Affected: Vacron / Network Video Recorder (NVR) | CVSS: 10.0 (CRITICAL) | EPSS: 0.07505 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34043", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34043"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34043"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vacron NVR Remote Command Execution", "cve_id": "CVE-2025-34043", "vendor": "Vacron", "ghsa_id": null, "product": "Network Video Recorder (NVR)", "added_date": "2026-01-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.07505, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34043", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0ba6349d-4f43-4048-9b62-f8af8f590d58", "vulnerability": {"vulnId": "CVE-2025-34036", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "0ba6349d-4f43-4048-9b62-f8af8f590d58", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-10T00:00:00+00:00"}, "scope": {"notes": "Shenzhen TVT CCTV-DVR Command Injection | Affected: Shenzhen TVT / CCTV-DVR | CVSS: 10.0 (CRITICAL) | EPSS: 0.30915 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34036", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34036"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34036"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Shenzhen TVT CCTV-DVR Command Injection", "cve_id": "CVE-2025-34036", "vendor": "Shenzhen TVT", "ghsa_id": null, "product": "CCTV-DVR", "added_date": "2026-01-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.30915, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98209, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34036", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bdf3b724-ac42-451b-aaba-a3620d6abb50", "vulnerability": {"vulnId": "CVE-2022-28005", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-09T01:00:00+01:00"}, "gcve": {"object_uuid": "bdf3b724-ac42-451b-aaba-a3620d6abb50", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-09T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse... | Affected: 3CX / 3CX Phone System | CVSS: 9.8 (CRITICAL) | EPSS: 0.06729 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28005", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28005"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28005"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse...", "cve_id": "CVE-2022-28005", "vendor": "3CX", "ghsa_id": null, "product": "3CX Phone System", "added_date": "2026-01-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06729, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28005", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "161ce576-af9b-42bb-ac6e-d97f57c55e30", "vulnerability": {"vulnId": "CVE-2020-36728", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-05T01:00:00+01:00"}, "gcve": {"object_uuid": "161ce576-af9b-42bb-ac6e-d97f57c55e30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-05T00:00:00+00:00"}, "scope": {"notes": "The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows... | Affected: Tunafish / Adning Advertising | CVSS: 6.5 (MEDIUM) | EPSS: 0.03133 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-36728", "url": "https://www.cve.org/CVERecord?id=CVE-2020-36728"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-36728"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and including, 1.5.5. This allows...", "cve_id": "CVE-2020-36728", "vendor": "Tunafish", "ghsa_id": null, "product": "Adning Advertising", "added_date": "2026-01-05T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.03133, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87428, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-36728", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "125cb652-371b-4aa0-a4c3-c11fae3f8e4f", "vulnerability": {"vulnId": "CVE-2020-26879", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-04T01:00:00+01:00"}, "gcve": {"object_uuid": "125cb652-371b-4aa0-a4c3-c11fae3f8e4f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-04T00:00:00+00:00"}, "scope": {"notes": "Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the... | Affected: Ruckus Wireless / vRioT | CVSS: 9.8 (CRITICAL) | EPSS: 0.45083 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-26879", "url": "https://www.cve.org/CVERecord?id=CVE-2020-26879"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-26879"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the...", "cve_id": "CVE-2020-26879", "vendor": "Ruckus Wireless", "ghsa_id": null, "product": "vRioT", "added_date": "2026-01-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.45083, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-26879", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a8fc89f8-30e7-4177-90de-781bd8a8164c", "vulnerability": {"vulnId": "CVE-2021-39312", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-04T01:00:00+01:00"}, "gcve": {"object_uuid": "a8fc89f8-30e7-4177-90de-781bd8a8164c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-04T00:00:00+00:00"}, "scope": {"notes": "True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read | Affected: True Ranker / True Ranker | CVSS: 7.5 (HIGH) | EPSS: 0.77944 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-39312", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39312"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39312"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read", "cve_id": "CVE-2021-39312", "vendor": "True Ranker", "ghsa_id": null, "product": "True Ranker", "added_date": "2026-01-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.77944, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99561, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39312", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ecadce84-47de-4211-a940-9e62ba64ecf0", "vulnerability": {"vulnId": "CVE-2020-28185", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-04T01:00:00+01:00"}, "gcve": {"object_uuid": "ecadce84-47de-4211-a940-9e62ba64ecf0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-04T00:00:00+00:00"}, "scope": {"notes": "User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system... | Affected: TerraMaster / TOS | CVSS: 5.3 (MEDIUM) | EPSS: 0.18253 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-28185", "url": "https://www.cve.org/CVERecord?id=CVE-2020-28185"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-28185"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system...", "cve_id": "CVE-2020-28185", "vendor": "TerraMaster", "ghsa_id": null, "product": "TOS", "added_date": "2026-01-04T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.18253, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97135, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-28185", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "60218540-2072-45bc-ab31-8975c8d4d2e4", "vulnerability": {"vulnId": "CVE-2020-5776", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-04T01:00:00+01:00"}, "gcve": {"object_uuid": "60218540-2072-45bc-ab31-8975c8d4d2e4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-04T00:00:00+00:00"}, "scope": {"notes": "Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a... | Affected: MAGMI / MAGMI | CVSS: 8.8 (HIGH) | EPSS: 0.14725 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-5776", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5776"}, {"id": "GHSA-CV7M-WC7G-7GFP", "url": "https://github.com/advisories/GHSA-CV7M-WC7G-7GFP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5776"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a...", "cve_id": "CVE-2020-5776", "vendor": "MAGMI", "ghsa_id": "GHSA-CV7M-WC7G-7GFP", "product": "MAGMI", "added_date": "2026-01-04T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.14725, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5776", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "575cdab2-3bbc-48fe-8eab-0e0fdfe4362c", "vulnerability": {"vulnId": "CVE-2019-18952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-04T01:00:00+01:00"}, "gcve": {"object_uuid": "575cdab2-3bbc-48fe-8eab-0e0fdfe4362c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-04T00:00:00+00:00"}, "scope": {"notes": "SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code... | Affected: SibSoft / Xfilesharing | CVSS: 9.8 (CRITICAL) | EPSS: 0.45361 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-18952", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code...", "cve_id": "CVE-2019-18952", "vendor": "SibSoft", "ghsa_id": null, "product": "Xfilesharing", "added_date": "2026-01-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.45361, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98753, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18952", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7d5e3347-c552-41f6-97df-a4b394ab464d", "vulnerability": {"vulnId": "CVE-2025-53364", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-04T01:00:00+01:00"}, "gcve": {"object_uuid": "7d5e3347-c552-41f6-97df-a4b394ab464d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-04T00:00:00+00:00"}, "scope": {"notes": "Parse Server exposes the data schema via GraphQL API | Affected: Parse-community / parse-server | CVSS: 5.3 (MEDIUM) | EPSS: 0.00943 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-53364", "url": "https://www.cve.org/CVERecord?id=CVE-2025-53364"}, {"id": "GHSA-48Q3-PRGV-GM4W", "url": "https://github.com/advisories/GHSA-48Q3-PRGV-GM4W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-53364"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Parse Server exposes the data schema via GraphQL API", "cve_id": "CVE-2025-53364", "vendor": "Parse-community", "ghsa_id": "GHSA-48Q3-PRGV-GM4W", "product": "parse-server", "added_date": "2026-01-04T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.00943, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.59618, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-53364", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bfb42f05-f536-4b03-9ee8-a83615093755", "vulnerability": {"vulnId": "CVE-2024-53944", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bfb42f05-f536-4b03-9ee8-a83615093755", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through... | Affected: Tuoshi / LT15D 4G Wi-Fi | CVSS: 9.8 (CRITICAL) | EPSS: 0.39682 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-53944", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53944"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53944"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through...", "cve_id": "CVE-2024-53944", "vendor": "Tuoshi", "ghsa_id": null, "product": "LT15D 4G Wi-Fi", "added_date": "2026-01-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39682, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98578, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-53944", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "19e3d0e3-1016-4e97-86a2-89638da83879", "vulnerability": {"vulnId": "CVE-2023-22897", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-02T01:00:00+01:00"}, "gcve": {"object_uuid": "19e3d0e3-1016-4e97-86a2-89638da83879", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-02T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents... | Affected: SecurePoint / UTM | CVSS: 6.5 (MEDIUM) | EPSS: 0.04074 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-22897", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22897"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22897"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents...", "cve_id": "CVE-2023-22897", "vendor": "SecurePoint", "ghsa_id": null, "product": "UTM", "added_date": "2026-01-02T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.04074, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90372, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-22897", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dbf0a90c-de41-45d4-a4bf-d634cad67eb9", "vulnerability": {"vulnId": "CVE-2025-55190", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-02T01:00:00+01:00"}, "gcve": {"object_uuid": "dbf0a90c-de41-45d4-a4bf-d634cad67eb9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-02T00:00:00+00:00"}, "scope": {"notes": "Argo CD: Project API Token Exposes Repository Credentials | Affected: Argoproj / argo-cd | CVSS: 10.0 (CRITICAL) | EPSS: 0.05463 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-55190", "url": "https://www.cve.org/CVERecord?id=CVE-2025-55190"}, {"id": "GHSA-786Q-9HCG-V9FF", "url": "https://github.com/advisories/GHSA-786Q-9HCG-V9FF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-55190"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Argo CD: Project API Token Exposes Repository Credentials", "cve_id": "CVE-2025-55190", "vendor": "Argoproj", "ghsa_id": "GHSA-786Q-9HCG-V9FF", "product": "argo-cd", "added_date": "2026-01-02T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.05463, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92492, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-55190", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b9ad1706-2940-4ebc-ab27-9e29f1b55914", "vulnerability": {"vulnId": "CVE-2014-9118", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2026-01-01T01:00:00+01:00"}, "gcve": {"object_uuid": "b9ad1706-2940-4ebc-ab27-9e29f1b55914", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2026-01-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2026-01-01T00:00:00+00:00"}, "scope": {"notes": "The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell... | Affected: Zhone / zNID GPON 2426A | CVSS: 8.8 (HIGH) | EPSS: 0.53364 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-9118", "url": "https://www.cve.org/CVERecord?id=CVE-2014-9118"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-9118"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell...", "cve_id": "CVE-2014-9118", "vendor": "Zhone", "ghsa_id": null, "product": "zNID GPON 2426A", "added_date": "2026-01-01T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.53364, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-9118", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dc32265c-8cea-47e9-a759-01e8070e99c5", "vulnerability": {"vulnId": "CVE-2015-10145", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-31T21:48:11+01:00"}, "gcve": {"object_uuid": "dc32265c-8cea-47e9-a759-01e8070e99c5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-31T20:48:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-31T20:48:11+00:00"}, "scope": {"notes": "Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh | Affected: Gargoyle / Gargoyle Router Management Utility | CVSS: 8.7 (HIGH) | EPSS: 0.00733 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-10145", "url": "https://www.cve.org/CVERecord?id=CVE-2015-10145"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-10145"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh", "cve_id": "CVE-2015-10145", "vendor": "Gargoyle", "ghsa_id": null, "product": "Gargoyle Router Management Utility", "added_date": "2025-12-31T20:48:11.000Z", "cvss_score": 8.7, "epss_score": 0.00733, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52679, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-10145", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a13a50e4-8657-4b0e-9e31-670a53e0bf15", "vulnerability": {"vulnId": "CVE-2019-9762", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-30T01:00:00+01:00"}, "gcve": {"object_uuid": "a13a50e4-8657-4b0e-9e31-670a53e0bf15", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-30T00:00:00+00:00"}, "scope": {"notes": "A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any... | Affected: PHPSHE / PHPSHE 1.7 | CVSS: 9.8 (CRITICAL) | EPSS: 0.06041 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-9762", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9762"}, {"id": "GHSA-JPJX-J79X-PV9C", "url": "https://github.com/advisories/GHSA-JPJX-J79X-PV9C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9762"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any...", "cve_id": "CVE-2019-9762", "vendor": "PHPSHE", "ghsa_id": "GHSA-JPJX-J79X-PV9C", "product": "PHPSHE 1.7", "added_date": "2025-12-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06041, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93145, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9762", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b76124bf-1d91-45eb-8211-d9d3e340148b", "vulnerability": {"vulnId": "CVE-2021-22122", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-28T01:00:00+01:00"}, "gcve": {"object_uuid": "b76124bf-1d91-45eb-8211-d9d3e340148b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-28T00:00:00+00:00"}, "scope": {"notes": "An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an... | Affected: Fortinet / Fortinet FortiWeb | CVSS: 6.1 (MEDIUM) | EPSS: 0.1052 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-22122", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22122"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22122"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an...", "cve_id": "CVE-2021-22122", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiWeb", "added_date": "2025-12-28T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.1052, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22122", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a3b456b7-44a0-4d3c-85aa-b94610826df8", "vulnerability": {"vulnId": "CVE-2020-8982", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-27T01:00:00+01:00"}, "gcve": {"object_uuid": "a3b456b7-44a0-4d3c-85aa-b94610826df8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-27T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the... | Affected: Citrix / ShareFile StorageZones Controller | CVSS: 7.5 (HIGH) | EPSS: 0.27149 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8982", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8982"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8982"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the...", "cve_id": "CVE-2020-8982", "vendor": "Citrix", "ghsa_id": null, "product": "ShareFile StorageZones Controller", "added_date": "2025-12-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.27149, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97996, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8982", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0cc8246f-ae47-4d5d-8693-c2fe07a44377", "vulnerability": {"vulnId": "CVE-2023-5914", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-26T01:00:00+01:00"}, "gcve": {"object_uuid": "0cc8246f-ae47-4d5d-8693-c2fe07a44377", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-26T00:00:00+00:00"}, "scope": {"notes": "\u00a0 Cross-site scripting (XSS) | Affected: Cloud Software Group / Citrix StoreFront | CVSS: 5.4 (MEDIUM) | EPSS: 0.73142 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5914", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5914"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5914"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "\u00a0 Cross-site scripting (XSS)", "cve_id": "CVE-2023-5914", "vendor": "Cloud Software Group", "ghsa_id": null, "product": "Citrix StoreFront", "added_date": "2025-12-26T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.73142, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99444, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5914", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "07061274-e14a-400d-b006-30215848cd0c", "vulnerability": {"vulnId": "CVE-2021-29003", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-24T01:00:00+01:00"}, "gcve": {"object_uuid": "07061274-e14a-400d-b006-30215848cd0c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-24T00:00:00+00:00"}, "scope": {"notes": "Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi,... | Affected: Genexis / PLATINUM 4410 | CVSS: 9.8 (CRITICAL) | EPSS: 0.45417 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-29003", "url": "https://www.cve.org/CVERecord?id=CVE-2021-29003"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-29003"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to sys_config_valid.xgi,...", "cve_id": "CVE-2021-29003", "vendor": "Genexis", "ghsa_id": null, "product": "PLATINUM 4410", "added_date": "2025-12-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.45417, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98754, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-29003", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "835b04b2-859d-4644-a399-68eb47bfc034", "vulnerability": {"vulnId": "CVE-2021-30118", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-18T01:00:00+01:00"}, "gcve": {"object_uuid": "835b04b2-859d-4644-a399-68eb47bfc034", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-18T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5 | Affected: Kaseya / VSA | CVSS: 9.8 (CRITICAL) | EPSS: 0.60348 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30118", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30118"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30118"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5", "cve_id": "CVE-2021-30118", "vendor": "Kaseya", "ghsa_id": null, "product": "VSA", "added_date": "2025-12-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.60348, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99117, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30118", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7a566c3c-b21f-4cfb-8192-5e3099ccfe53", "vulnerability": {"vulnId": "CVE-2023-5074", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-17T01:00:00+01:00"}, "gcve": {"object_uuid": "7a566c3c-b21f-4cfb-8192-5e3099ccfe53", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-17T00:00:00+00:00"}, "scope": {"notes": "Authentication Bypass in D-Link D-View 8 | Affected: D-Link / D-View 8 | CVSS: 9.8 (CRITICAL) | EPSS: 0.69555 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5074", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5074"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5074"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass in D-Link D-View 8", "cve_id": "CVE-2023-5074", "vendor": "D-Link", "ghsa_id": null, "product": "D-View 8", "added_date": "2025-12-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.69555, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99346, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5074", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cfff0f14-96ea-4bab-8ddc-890cf7ccb4b3", "vulnerability": {"vulnId": "CVE-2025-29927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-15T15:29:13+01:00"}, "gcve": {"object_uuid": "cfff0f14-96ea-4bab-8ddc-890cf7ccb4b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-15T14:29:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-15T14:29:13+00:00"}, "scope": {"notes": "Authorization Bypass in Next.js Middleware | Affected: Vercel / next.js | CVSS: 9.1 (CRITICAL) | EPSS: 0.99225 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-29927", "url": "https://www.cve.org/CVERecord?id=CVE-2025-29927"}, {"id": "GHSA-F82V-JWR5-MFFW", "url": "https://github.com/advisories/GHSA-F82V-JWR5-MFFW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-29927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authorization Bypass in Next.js Middleware", "cve_id": "CVE-2025-29927", "vendor": "Vercel", "ghsa_id": "GHSA-F82V-JWR5-MFFW", "product": "next.js", "added_date": "2025-12-15T14:29:13.422Z", "cvss_score": 9.1, "epss_score": 0.99225, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-29927", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5eaa4cbb-2d62-4dce-8aaf-025036d41313", "vulnerability": {"vulnId": "CVE-2022-2958", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-09T01:00:00+01:00"}, "gcve": {"object_uuid": "5eaa4cbb-2d62-4dce-8aaf-025036d41313", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-09T00:00:00+00:00"}, "scope": {"notes": "BadgeOS < 3.7.1.3 - Subscriber+ SQLi | Affected: BadgeOS / BadgeOS | CVSS: 8.8 (HIGH) | EPSS: 0.01286 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2958", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2958"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2958"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BadgeOS < 3.7.1.3 - Subscriber+ SQLi", "cve_id": "CVE-2022-2958", "vendor": "BadgeOS", "ghsa_id": null, "product": "BadgeOS", "added_date": "2025-12-09T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.01286, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69089, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2958", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "62778836-ee3b-4fbe-969c-4f78349df9fd", "vulnerability": {"vulnId": "CVE-2021-41649", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-09T01:00:00+01:00"}, "gcve": {"object_uuid": "62778836-ee3b-4fbe-969c-4f78349df9fd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-09T00:00:00+00:00"}, "scope": {"notes": "An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a... | Affected: PuneethReddyHC / online-shopping-system-advanced | CVSS: 9.8 (CRITICAL) | EPSS: 0.5177 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-41649", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41649"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41649"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a...", "cve_id": "CVE-2021-41649", "vendor": "PuneethReddyHC", "ghsa_id": null, "product": "online-shopping-system-advanced", "added_date": "2025-12-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.5177, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98916, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41649", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7aac78e3-b0aa-4f14-9a79-04065fe9a94d", "vulnerability": {"vulnId": "CVE-2018-11511", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-08T01:00:00+01:00"}, "gcve": {"object_uuid": "7aac78e3-b0aa-4f14-9a79-04065fe9a94d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-08T00:00:00+00:00"}, "scope": {"notes": "The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the... | Affected: ASUSTOR / ADM | CVSS: 9.8 (CRITICAL) | EPSS: 0.11266 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11511", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11511"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11511"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the...", "cve_id": "CVE-2018-11511", "vendor": "ASUSTOR", "ghsa_id": null, "product": "ADM", "added_date": "2025-12-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.11266, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95846, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11511", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "968aa8e0-2572-49dc-8997-86dabe04c64b", "vulnerability": {"vulnId": "CVE-2022-31126", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-08T01:00:00+01:00"}, "gcve": {"object_uuid": "968aa8e0-2572-49dc-8997-86dabe04c64b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-08T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Remote Code Execution in Roxy-wi | Affected: Hap-wi / roxy-wi | CVSS: 10.0 (CRITICAL) | EPSS: 0.52649 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31126", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31126"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31126"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Remote Code Execution in Roxy-wi", "cve_id": "CVE-2022-31126", "vendor": "Hap-wi", "ghsa_id": null, "product": "roxy-wi", "added_date": "2025-12-08T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.52649, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31126", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "60b82ed3-2254-406e-81ed-a31a4a6c414c", "vulnerability": {"vulnId": "CVE-2020-17518", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-05T01:00:00+01:00"}, "gcve": {"object_uuid": "60b82ed3-2254-406e-81ed-a31a4a6c414c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-05T00:00:00+00:00"}, "scope": {"notes": "Apache Flink directory traversal attack: remote file writing through the REST API | Affected: Apache / Apache Flink | CVSS: 7.5 (HIGH) | EPSS: 0.51398 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-17518", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17518"}, {"id": "GHSA-7Q5G-GPH2-4RC6", "url": "https://github.com/advisories/GHSA-7Q5G-GPH2-4RC6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17518"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Flink directory traversal attack: remote file writing through the REST API", "cve_id": "CVE-2020-17518", "vendor": "Apache", "ghsa_id": "GHSA-7Q5G-GPH2-4RC6", "product": "Apache Flink", "added_date": "2025-12-05T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.51398, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98909, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17518", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ada2eba8-89ea-43ab-8108-86077b695cc4", "vulnerability": {"vulnId": "CVE-2022-31814", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ada2eba8-89ea-43ab-8108-86077b695cc4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-03T00:00:00+00:00"}, "scope": {"notes": "pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host... | Affected: Netgate / pfSense pfBlockerNG | CVSS: 9.8 (CRITICAL) | EPSS: 0.91881 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31814", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31814"}, {"id": "GHSA-HR8V-98C3-7P3X", "url": "https://github.com/advisories/GHSA-HR8V-98C3-7P3X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31814"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host...", "cve_id": "CVE-2022-31814", "vendor": "Netgate", "ghsa_id": "GHSA-HR8V-98C3-7P3X", "product": "pfSense pfBlockerNG", "added_date": "2025-12-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91881, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99816, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31814", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f2d8314f-398a-466d-b960-e6f602444472", "vulnerability": {"vulnId": "CVE-2022-29081", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "f2d8314f-398a-466d-b960-e6f602444472", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-12-01T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control... | Affected: Zoho / [\"ManageEngine Access Manager Plus\", \"Password Manager Pro\", \"PAM360\"] | CVSS: 9.8 (CRITICAL) | EPSS: 0.83543 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29081", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29081"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29081"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control...", "cve_id": "CVE-2022-29081", "vendor": "Zoho", "ghsa_id": null, "product": "[\"ManageEngine Access Manager Plus\", \"Password Manager Pro\", \"PAM360\"]", "added_date": "2025-12-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83543, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99679, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29081", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5f48d215-7a4d-4a59-a608-59ee9927865f", "vulnerability": {"vulnId": "CVE-2021-24212", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-30T01:00:00+01:00"}, "gcve": {"object_uuid": "5f48d215-7a4d-4a59-a608-59ee9927865f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-30T00:00:00+00:00"}, "scope": {"notes": "WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE | Affected: WooCommerce / WooCommerce Help Scout | CVSS: 9.8 (CRITICAL) | EPSS: 0.07908 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24212", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24212"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24212"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCE", "cve_id": "CVE-2021-24212", "vendor": "WooCommerce", "ghsa_id": null, "product": "WooCommerce Help Scout", "added_date": "2025-11-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07908, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94548, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24212", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f63a6ad3-0675-4fe6-913d-9407c40859c2", "vulnerability": {"vulnId": "CVE-2022-1574", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-30T01:00:00+01:00"}, "gcve": {"object_uuid": "f63a6ad3-0675-4fe6-913d-9407c40859c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-30T00:00:00+00:00"}, "scope": {"notes": "HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload | Affected: HTML2WP / HTML2WP | CVSS: 9.8 (CRITICAL) | EPSS: 0.12194 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1574", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1574"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1574"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2022-1574", "vendor": "HTML2WP", "ghsa_id": null, "product": "HTML2WP", "added_date": "2025-11-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.12194, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96045, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1574", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "837a8ab4-ecbb-4b22-bc7c-043487c8f992", "vulnerability": {"vulnId": "CVE-2023-7304", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-29T01:00:00+01:00"}, "gcve": {"object_uuid": "837a8ab4-ecbb-4b22-bc7c-043487c8f992", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-29T00:00:00+00:00"}, "scope": {"notes": "Ruijie RG-UAC nmc_sync.php Command Injection | Affected: Ruijie / RG-UAC | CVSS: 9.3 (CRITICAL) | EPSS: 0.03556 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7304", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7304"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7304"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruijie RG-UAC nmc_sync.php Command Injection", "cve_id": "CVE-2023-7304", "vendor": "Ruijie", "ghsa_id": null, "product": "RG-UAC", "added_date": "2025-11-29T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.03556, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88938, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7304", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6525c1af-3b90-4cc6-a611-9f6aad150b98", "vulnerability": {"vulnId": "CVE-2019-19825", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-27T01:00:00+01:00"}, "gcve": {"object_uuid": "6525c1af-3b90-4cc6-a611-9f6aad150b98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-27T00:00:00+00:00"}, "scope": {"notes": "On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {\"topicurl\":\"setting/getSanvas\"} POST to the... | Affected: TOTOLINK / Realtek SDK based routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.29557 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-19825", "url": "https://www.cve.org/CVERecord?id=CVE-2019-19825"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-19825"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {\"topicurl\":\"setting/getSanvas\"} POST to the...", "cve_id": "CVE-2019-19825", "vendor": "TOTOLINK", "ghsa_id": null, "product": "Realtek SDK based routers", "added_date": "2025-11-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.29557, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98138, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-19825", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cf55c28f-8854-4072-b185-c5f9bb2b86ab", "vulnerability": {"vulnId": "CVE-2023-4169", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-26T01:00:00+01:00"}, "gcve": {"object_uuid": "cf55c28f-8854-4072-b185-c5f9bb2b86ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-26T00:00:00+00:00"}, "scope": {"notes": "Ruijie RG-EW1200G Administrator Password set_passwd access control | Affected: Ruijie / RG-EW1200G | CVSS: 6.3 (MEDIUM) | EPSS: 0.4923 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-4169", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4169"}, {"id": "GHSA-4MVQ-G24W-Q4W9", "url": "https://github.com/advisories/GHSA-4MVQ-G24W-Q4W9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4169"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruijie RG-EW1200G Administrator Password set_passwd access control", "cve_id": "CVE-2023-4169", "vendor": "Ruijie", "ghsa_id": "GHSA-4MVQ-G24W-Q4W9", "product": "RG-EW1200G", "added_date": "2025-11-26T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.4923, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98853, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4169", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d37ddaeb-16f0-46d5-9a84-d65f4fa4b938", "vulnerability": {"vulnId": "CVE-2023-50968", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-25T01:00:00+01:00"}, "gcve": {"object_uuid": "d37ddaeb-16f0-46d5-9a84-d65f4fa4b938", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-25T00:00:00+00:00"}, "scope": {"notes": "Apache OFBiz: Arbitrary file properties reading and SSRF attack | Affected: Apache / Apache OFBiz | CVSS: 7.5 (HIGH) | EPSS: 0.63373 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-50968", "url": "https://www.cve.org/CVERecord?id=CVE-2023-50968"}, {"id": "GHSA-GM45-8HGV-XG5F", "url": "https://github.com/advisories/GHSA-GM45-8HGV-XG5F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-50968"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache OFBiz: Arbitrary file properties reading and SSRF attack", "cve_id": "CVE-2023-50968", "vendor": "Apache", "ghsa_id": "GHSA-GM45-8HGV-XG5F", "product": "Apache OFBiz", "added_date": "2025-11-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.63373, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99187, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-50968", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "48479784-7831-42c8-8e3c-707b80534f3b", "vulnerability": {"vulnId": "CVE-2022-0656", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-25T01:00:00+01:00"}, "gcve": {"object_uuid": "48479784-7831-42c8-8e3c-707b80534f3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-25T00:00:00+00:00"}, "scope": {"notes": "uDraw < 3.3.3 - Unauthenticated Arbitrary File Access | Affected: uDraw / uDraw | CVSS: 7.5 (HIGH) | EPSS: 0.07879 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0656", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0656"}, {"id": "GHSA-452J-V697-RP7M", "url": "https://github.com/advisories/GHSA-452J-V697-RP7M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0656"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "uDraw < 3.3.3 - Unauthenticated Arbitrary File Access", "cve_id": "CVE-2022-0656", "vendor": "uDraw", "ghsa_id": "GHSA-452J-V697-RP7M", "product": "uDraw", "added_date": "2025-11-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.07879, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94534, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0656", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "73e923ff-2696-4ef5-8baa-6d665fb5f719", "vulnerability": {"vulnId": "CVE-2018-25126", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-24T21:30:45+01:00"}, "gcve": {"object_uuid": "73e923ff-2696-4ef5-8baa-6d665fb5f719", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-24T20:30:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-24T20:30:45+00:00"}, "scope": {"notes": "TVT NVMS-9000 Hard-coded API Credentials & Command Injection | Affected: Shenzhen TVT Digital Technology / NVMS-9000 | CVSS: 9.3 (CRITICAL) | EPSS: 0.04071 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-25126", "url": "https://www.cve.org/CVERecord?id=CVE-2018-25126"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-25126"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TVT NVMS-9000 Hard-coded API Credentials & Command Injection", "cve_id": "CVE-2018-25126", "vendor": "Shenzhen TVT Digital Technology", "ghsa_id": null, "product": "NVMS-9000", "added_date": "2025-11-24T20:30:45.000Z", "cvss_score": 9.3, "epss_score": 0.04071, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90365, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-25126", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "afb947d8-b8c1-4c8f-a143-db350a9e5e96", "vulnerability": {"vulnId": "CVE-2013-2678", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-23T01:00:00+01:00"}, "gcve": {"object_uuid": "afb947d8-b8c1-4c8f-a143-db350a9e5e96", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-23T00:00:00+00:00"}, "scope": {"notes": "Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive... | Affected: Cisco / Linksys E4200 | CVSS: 8.1 (HIGH) | EPSS: 0.16873 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-2678", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2678"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2678"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive...", "cve_id": "CVE-2013-2678", "vendor": "Cisco", "ghsa_id": null, "product": "Linksys E4200", "added_date": "2025-11-23T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.16873, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96964, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2678", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9306cf1e-432a-4910-ab97-b9a8d4729369", "vulnerability": {"vulnId": "CVE-2023-48022", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-20T18:26:09+01:00"}, "gcve": {"object_uuid": "9306cf1e-432a-4910-ab97-b9a8d4729369", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-20T17:26:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-20T17:26:09+00:00"}, "scope": {"notes": "Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that... | Affected: Anyscale / Ray | CVSS: 9.8 (CRITICAL) | EPSS: 0.83942 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-48022", "url": "https://www.cve.org/CVERecord?id=CVE-2023-48022"}, {"id": "GHSA-6WGJ-66M2-XXP2", "url": "https://github.com/advisories/GHSA-6WGJ-66M2-XXP2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-48022"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that...", "cve_id": "CVE-2023-48022", "vendor": "Anyscale", "ghsa_id": "GHSA-6WGJ-66M2-XXP2", "product": "Ray", "added_date": "2025-11-20T17:26:09.000Z", "cvss_score": 9.8, "epss_score": 0.83942, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-48022", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fa4e36a1-d15e-4d1f-8322-db459702bde3", "vulnerability": {"vulnId": "CVE-2025-27505", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-20T01:00:00+01:00"}, "gcve": {"object_uuid": "fa4e36a1-d15e-4d1f-8322-db459702bde3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-20T00:00:00+00:00"}, "scope": {"notes": "GeoServer Missing Authorization on REST API Index | Affected: Geoserver / geoserver | CVSS: 5.3 (MEDIUM) | EPSS: 0.01152 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-27505", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27505"}, {"id": "GHSA-H86G-X8MM-78M5", "url": "https://github.com/advisories/GHSA-H86G-X8MM-78M5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27505"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoServer Missing Authorization on REST API Index", "cve_id": "CVE-2025-27505", "vendor": "Geoserver", "ghsa_id": "GHSA-H86G-X8MM-78M5", "product": "geoserver", "added_date": "2025-11-20T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.01152, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.65771, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27505", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "96c2858e-c1a8-4860-853f-aa0e48abea76", "vulnerability": {"vulnId": "CVE-2022-38130", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "96c2858e-c1a8-4860-853f-aa0e48abea76", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-13T00:00:00+00:00"}, "scope": {"notes": "The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the... | Affected: Keysight / Tentacle | CVSS: 9.8 (CRITICAL) | EPSS: 0.54072 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-38130", "url": "https://www.cve.org/CVERecord?id=CVE-2022-38130"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-38130"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the...", "cve_id": "CVE-2022-38130", "vendor": "Keysight", "ghsa_id": null, "product": "Tentacle", "added_date": "2025-11-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.54072, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98976, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-38130", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d5bf656d-bf86-4752-9078-2bc208148232", "vulnerability": {"vulnId": "CVE-2023-5815", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "d5bf656d-bf86-4752-9078-2bc208148232", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-12T00:00:00+00:00"}, "scope": {"notes": "The News & Blog Designer Pack \u2013 WordPress Blog Plugin \u2014 (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post... | Affected: Infornweb / News & Blog Designer Pack \u2013 WordPress Blog Plugin \u2014 (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) | CVSS: 8.1 (HIGH) | EPSS: 0.04262 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5815", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5815"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5815"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The News & Blog Designer Pack \u2013 WordPress Blog Plugin \u2014 (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post...", "cve_id": "CVE-2023-5815", "vendor": "Infornweb", "ghsa_id": null, "product": "News & Blog Designer Pack \u2013 WordPress Blog Plugin \u2014 (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry)", "added_date": "2025-11-12T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.04262, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90759, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5815", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "33f6dc3a-e5c0-4ca1-9f35-e4ddb6fae343", "vulnerability": {"vulnId": "CVE-2022-1006", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "33f6dc3a-e5c0-4ca1-9f35-e4ddb6fae343", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-12T00:00:00+00:00"}, "scope": {"notes": "Advanced Booking Calendar < 1.7.1 - Admin+ SQLi | Affected: Advanced Booking Calendar / Advanced Booking Calendar | CVSS: 7.2 (HIGH) | EPSS: 0.01484 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1006", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1006"}, {"id": "GHSA-WR35-3F65-J6MC", "url": "https://github.com/advisories/GHSA-WR35-3F65-J6MC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1006"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Advanced Booking Calendar < 1.7.1 - Admin+ SQLi", "cve_id": "CVE-2022-1006", "vendor": "Advanced Booking Calendar", "ghsa_id": "GHSA-WR35-3F65-J6MC", "product": "Advanced Booking Calendar", "added_date": "2025-11-12T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.01484, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.73052, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1006", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "42ac5380-1a95-4abe-8159-8dedcfefa9b6", "vulnerability": {"vulnId": "CVE-2017-8961", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "42ac5380-1a95-4abe-8159-8dedcfefa9b6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-12T00:00:00+00:00"}, "scope": {"notes": "A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution. | Affected: Hewlett Packard Enterprise / Intelligent Management Center | CVSS: 8.8 (HIGH) | EPSS: 0.19056 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-8961", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8961"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8961"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.", "cve_id": "CVE-2017-8961", "vendor": "Hewlett Packard Enterprise", "ghsa_id": null, "product": "Intelligent Management Center", "added_date": "2025-11-12T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.19056, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97232, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8961", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "891770e9-c1e8-4b20-a2d8-758a6b9b4c98", "vulnerability": {"vulnId": "CVE-2021-34187", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "891770e9-c1e8-4b20-a2d8-758a6b9b4c98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-12T00:00:00+00:00"}, "scope": {"notes": "main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | Affected: Chamilo / Chamilo LMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.16181 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-34187", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34187"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34187"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.", "cve_id": "CVE-2021-34187", "vendor": "Chamilo", "ghsa_id": null, "product": "Chamilo LMS", "added_date": "2025-11-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.16181, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96842, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34187", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "98caa970-a8ca-4d8b-afe8-9e437f249390", "vulnerability": {"vulnId": "CVE-2025-0674", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "98caa970-a8ca-4d8b-afe8-9e437f249390", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "Elber Communications Equipment Authentication Bypass Using an Alternate Path or Channel | Affected: Elber / Signum DVB-S/S2 IRD, Cleber/3 Broadcast Multi-Purpose Platform, Reble610 M/ODU XPIC IP-ASI-SDH, ESE DVB-S/S2 Satellite Receiver, Wayber Analog/Digital Audio STL | CVSS: 9.3 (CRITICAL) | EPSS: 0.03654 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-0674", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0674"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0674"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Elber Communications Equipment Authentication Bypass Using an Alternate Path or Channel", "cve_id": "CVE-2025-0674", "vendor": "Elber", "ghsa_id": null, "product": "Signum DVB-S/S2 IRD, Cleber/3 Broadcast Multi-Purpose Platform, Reble610 M/ODU XPIC IP-ASI-SDH, ESE DVB-S/S2 Satellite Receiver, Wayber Analog/Digital Audio STL", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.03654, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89249, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0674", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d114d920-1c18-44ab-869a-6cbecaafffc7", "vulnerability": {"vulnId": "CVE-2025-4009", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "d114d920-1c18-44ab-869a-6cbecaafffc7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Arbitrary Command Injection in Evertz SDVN | Affected: Evertz / 3080ipx-10G, MViP-II, cVIP, 7890IXG, CC Access Server, 5782XPS-APP-4E | CVSS: 9.3 (CRITICAL) | EPSS: 0.7144 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4009", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4009"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4009"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Arbitrary Command Injection in Evertz SDVN", "cve_id": "CVE-2025-4009", "vendor": "Evertz", "ghsa_id": null, "product": "3080ipx-10G, MViP-II, cVIP, 7890IXG, CC Access Server, 5782XPS-APP-4E", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.7144, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99398, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4009", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bc89d50e-80c5-4b6e-abac-727f6d2b05b3", "vulnerability": {"vulnId": "CVE-2024-6235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "bc89d50e-80c5-4b6e-abac-727f6d2b05b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "Sensitive information disclosure | Affected: NetScaler / NetScaler Console | CVSS: 9.4 (CRITICAL) | EPSS: 0.21168 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6235", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6235"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sensitive information disclosure", "cve_id": "CVE-2024-6235", "vendor": "NetScaler", "ghsa_id": null, "product": "NetScaler Console", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.21168, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97519, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3ac058c8-c393-479a-99e3-cd1c302c4c04", "vulnerability": {"vulnId": "CVE-2025-34143", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "3ac058c8-c393-479a-99e3-cd1c302c4c04", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "ETQ Reliance CG Authentication Bypass via Trailing Space RCE | Affected: ETQ / Reliance CG (legacy) | CVSS: 9.3 (CRITICAL) | EPSS: 0.32678 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34143", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34143"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34143"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ETQ Reliance CG Authentication Bypass via Trailing Space RCE", "cve_id": "CVE-2025-34143", "vendor": "ETQ", "ghsa_id": null, "product": "Reliance CG (legacy)", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.32678, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98296, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34143", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ec58ecb9-59c3-4ac9-8bfa-9e24b75e0243", "vulnerability": {"vulnId": "CVE-2025-47539", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "ec58ecb9-59c3-4ac9-8bfa-9e24b75e0243", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability | Affected: Arraytics / Eventin | CVSS: 9.8 (CRITICAL) | EPSS: 0.27878 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-47539", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47539"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47539"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability", "cve_id": "CVE-2025-47539", "vendor": "Arraytics", "ghsa_id": null, "product": "Eventin", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.27878, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98044, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47539", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "048847d1-8d03-40b0-9abf-efd8456aa027", "vulnerability": {"vulnId": "CVE-2025-54123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "048847d1-8d03-40b0-9abf-efd8456aa027", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation | Affected: SpectoLabs / hoverfly | CVSS: 9.8 (CRITICAL) | EPSS: 0.10543 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-54123", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54123"}, {"id": "GHSA-R4H8-HFP2-GGMF", "url": "https://github.com/advisories/GHSA-R4H8-HFP2-GGMF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation", "cve_id": "CVE-2025-54123", "vendor": "SpectoLabs", "ghsa_id": "GHSA-R4H8-HFP2-GGMF", "product": "hoverfly", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.10543, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95641, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "855f0bc4-1ccb-453f-b8f9-6d16ce695b64", "vulnerability": {"vulnId": "CVE-2024-9193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "855f0bc4-1ccb-453f-b8f9-6d16ce695b64", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update | Affected: Creativeon / WHMpress - WHMCS WordPress Integration Plugin | CVSS: 9.8 (CRITICAL) | EPSS: 0.03292 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9193", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update", "cve_id": "CVE-2024-9193", "vendor": "Creativeon", "ghsa_id": null, "product": "WHMpress - WHMCS WordPress Integration Plugin", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03292, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e26a9382-1422-4d15-856b-fa4d2dcefc16", "vulnerability": {"vulnId": "CVE-2025-53118", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "e26a9382-1422-4d15-856b-fa4d2dcefc16", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "Securden Unified PAM Authentication Bypass | Affected: Securden / Unified PAM | CVSS: 9.8 (CRITICAL) | EPSS: 0.30525 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-53118", "url": "https://www.cve.org/CVERecord?id=CVE-2025-53118"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-53118"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Securden Unified PAM Authentication Bypass", "cve_id": "CVE-2025-53118", "vendor": "Securden", "ghsa_id": null, "product": "Unified PAM", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.30525, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9819, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-53118", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b3da397e-a580-45a0-8db7-369e5c732119", "vulnerability": {"vulnId": "CVE-2023-7309", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "b3da397e-a580-45a0-8db7-369e5c732119", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "Dahua Smart Park Integrated Management Platform Front-End Arbitrary File Upload | Affected: Zhejiang Dahua Technology / Smart Park Integrated Management Platform | CVSS: 10.0 (CRITICAL) | EPSS: 0.00813 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7309", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7309"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7309"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dahua Smart Park Integrated Management Platform Front-End Arbitrary File Upload", "cve_id": "CVE-2023-7309", "vendor": "Zhejiang Dahua Technology", "ghsa_id": null, "product": "Smart Park Integrated Management Platform", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.00813, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55432, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7309", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "85ced2e4-2393-483d-9fb1-c267abc450f0", "vulnerability": {"vulnId": "CVE-2025-25034", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-11T01:00:00+01:00"}, "gcve": {"object_uuid": "85ced2e4-2393-483d-9fb1-c267abc450f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-11T00:00:00+00:00"}, "scope": {"notes": "SugarCRM PHP Deserialization RCE | Affected: SugarCRM / SugarCRM | CVSS: 9.3 (CRITICAL) | EPSS: 0.04963 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-25034", "url": "https://www.cve.org/CVERecord?id=CVE-2025-25034"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-25034"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SugarCRM PHP Deserialization RCE", "cve_id": "CVE-2025-25034", "vendor": "SugarCRM", "ghsa_id": null, "product": "SugarCRM", "added_date": "2025-11-11T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.04963, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9192, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-25034", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "be80daf9-96fd-4eaa-9a89-c044d0c78df8", "vulnerability": {"vulnId": "CVE-2018-25124", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-10T23:32:03+01:00"}, "gcve": {"object_uuid": "be80daf9-96fd-4eaa-9a89-c044d0c78df8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-10T22:32:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-10T22:32:03+00:00"}, "scope": {"notes": "PacsOne Server 6.6.2 DICOM Web Viewer Directory Traversal LFI | Affected: RainbowFish Software / PacsOne Server | CVSS: 8.7 (HIGH) | EPSS: 0.00924 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-25124", "url": "https://www.cve.org/CVERecord?id=CVE-2018-25124"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-25124"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PacsOne Server 6.6.2 DICOM Web Viewer Directory Traversal LFI", "cve_id": "CVE-2018-25124", "vendor": "RainbowFish Software", "ghsa_id": null, "product": "PacsOne Server", "added_date": "2025-11-10T22:32:03.000Z", "cvss_score": 8.7, "epss_score": 0.00924, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58973, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-25124", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "264378f9-ccf6-4611-a299-2ec8dd441a51", "vulnerability": {"vulnId": "CVE-2023-26258", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-09T01:00:00+01:00"}, "gcve": {"object_uuid": "264378f9-ccf6-4611-a299-2ec8dd441a51", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-09T00:00:00+00:00"}, "scope": {"notes": "Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the... | Affected: Arcserve / Arcserve UDP | CVSS: 9.8 (CRITICAL) | EPSS: 0.39773 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26258", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26258"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26258"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the...", "cve_id": "CVE-2023-26258", "vendor": "Arcserve", "ghsa_id": null, "product": "Arcserve UDP", "added_date": "2025-11-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39773, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98581, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26258", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "114462cf-8e67-41b3-8dc6-00d37fce02c2", "vulnerability": {"vulnId": "CVE-2022-3980", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-09T01:00:00+01:00"}, "gcve": {"object_uuid": "114462cf-8e67-41b3-8dc6-00d37fce02c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-09T00:00:00+00:00"}, "scope": {"notes": "An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed... | Affected: Sophos / Sophos Mobile managed on-premises | CVSS: 9.8 (CRITICAL) | EPSS: 0.08906 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-3980", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3980"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3980"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed...", "cve_id": "CVE-2022-3980", "vendor": "Sophos", "ghsa_id": null, "product": "Sophos Mobile managed on-premises", "added_date": "2025-11-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08906, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95083, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3980", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "362f34e2-c39d-49ba-baf5-f6c0a34ed7e7", "vulnerability": {"vulnId": "CVE-2022-4328", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-09T01:00:00+01:00"}, "gcve": {"object_uuid": "362f34e2-c39d-49ba-baf5-f6c0a34ed7e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-09T00:00:00+00:00"}, "scope": {"notes": "WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload | Affected: WooCommerce / Checkout Field Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.04427 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4328", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4328"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4328"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2022-4328", "vendor": "WooCommerce", "ghsa_id": null, "product": "Checkout Field Manager", "added_date": "2025-11-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04427, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91061, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4328", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "064ced41-4bd7-4391-8518-c9c20ebf00cf", "vulnerability": {"vulnId": "CVE-2023-20073", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-09T01:00:00+01:00"}, "gcve": {"object_uuid": "064ced41-4bd7-4391-8518-c9c20ebf00cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-09T00:00:00+00:00"}, "scope": {"notes": "Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 5.3 (MEDIUM) | EPSS: 0.90106 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-20073", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20073"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20073"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Arbitrary File Upload Vulnerability", "cve_id": "CVE-2023-20073", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2025-11-09T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.90106, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99794, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20073", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b26dd339-c843-4f8c-a6d2-6bef0143120d", "vulnerability": {"vulnId": "CVE-2023-49785", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-09T01:00:00+01:00"}, "gcve": {"object_uuid": "b26dd339-c843-4f8c-a6d2-6bef0143120d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-09T00:00:00+00:00"}, "scope": {"notes": "NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting | Affected: ChatGPTNextWeb / NextChat | CVSS: 9.1 (CRITICAL) | EPSS: 0.83163 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-49785", "url": "https://www.cve.org/CVERecord?id=CVE-2023-49785"}, {"id": "GHSA-QF3Q-9F3H-CJP9", "url": "https://github.com/advisories/GHSA-QF3Q-9F3H-CJP9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-49785"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting", "cve_id": "CVE-2023-49785", "vendor": "ChatGPTNextWeb", "ghsa_id": "GHSA-QF3Q-9F3H-CJP9", "product": "NextChat", "added_date": "2025-11-09T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.83163, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99669, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-49785", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "35edc5f6-2496-49d8-8020-45d16f720eac", "vulnerability": {"vulnId": "CVE-2023-5830", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-09T01:00:00+01:00"}, "gcve": {"object_uuid": "35edc5f6-2496-49d8-8020-45d16f720eac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-09T00:00:00+00:00"}, "scope": {"notes": "ColumbiaSoft Document Locator WebTools login improper authentication | Affected: ColumbiaSoft / Document Locator | CVSS: 7.3 (HIGH) | EPSS: 0.60782 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5830", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5830"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5830"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ColumbiaSoft Document Locator WebTools login improper authentication", "cve_id": "CVE-2023-5830", "vendor": "ColumbiaSoft", "ghsa_id": null, "product": "Document Locator", "added_date": "2025-11-09T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.60782, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99126, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5830", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "59d01405-62eb-45e9-aea0-b492fd83bd43", "vulnerability": {"vulnId": "CVE-2021-37580", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "59d01405-62eb-45e9-aea0-b492fd83bd43", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "Apache ShenYu Admin bypass JWT authentication | Affected: Apache / Apache ShenYu Admin | CVSS: 9.8 (CRITICAL) | EPSS: 0.41851 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-37580", "url": "https://www.cve.org/CVERecord?id=CVE-2021-37580"}, {"id": "GHSA-VPFP-5GWQ-G533", "url": "https://github.com/advisories/GHSA-VPFP-5GWQ-G533"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-37580"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache ShenYu Admin bypass JWT authentication", "cve_id": "CVE-2021-37580", "vendor": "Apache", "ghsa_id": "GHSA-VPFP-5GWQ-G533", "product": "Apache ShenYu Admin", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.41851, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98649, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-37580", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ea3b7726-dcfc-4166-83d4-26419e3c9226", "vulnerability": {"vulnId": "CVE-2022-0826", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "ea3b7726-dcfc-4166-83d4-26419e3c9226", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "WP Video Gallery <= 1.7.1 - Unauthenticated SQLi | Affected: WP Video Gallery / WP Video Gallery | CVSS: 9.8 (CRITICAL) | EPSS: 0.09127 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0826", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0826"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0826"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WP Video Gallery <= 1.7.1 - Unauthenticated SQLi", "cve_id": "CVE-2022-0826", "vendor": "WP Video Gallery", "ghsa_id": null, "product": "WP Video Gallery", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.09127, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95169, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0826", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "104926d5-cff6-4b67-8099-e8f872b4a225", "vulnerability": {"vulnId": "CVE-2022-31137", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "104926d5-cff6-4b67-8099-e8f872b4a225", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Remote Code Execution in Roxy-WI | Affected: Hap-wi / roxy-wi | CVSS: 10.0 (CRITICAL) | EPSS: 0.90577 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31137", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31137"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31137"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Remote Code Execution in Roxy-WI", "cve_id": "CVE-2022-31137", "vendor": "Hap-wi", "ghsa_id": null, "product": "roxy-wi", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.90577, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31137", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "02fb5148-4092-4eb5-8602-d3e9fdd99a4d", "vulnerability": {"vulnId": "CVE-2022-1020", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "02fb5148-4092-4eb5-8602-d3e9fdd99a4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call | Affected: WP Desk / Woo Product Table | CVSS: 9.8 (CRITICAL) | EPSS: 0.25937 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1020", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1020"}, {"id": "GHSA-FVGR-6H35-229M", "url": "https://github.com/advisories/GHSA-FVGR-6H35-229M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1020"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call", "cve_id": "CVE-2022-1020", "vendor": "WP Desk", "ghsa_id": "GHSA-FVGR-6H35-229M", "product": "Woo Product Table", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.25937, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97924, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1020", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8c995347-3b09-4576-994c-c2000e7e4d54", "vulnerability": {"vulnId": "CVE-2021-44427", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "8c995347-3b09-4576-994c-c2000e7e4d54", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to... | Affected: Rosario Student Information System / rosariosis | CVSS: 9.8 (CRITICAL) | EPSS: 0.50641 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-44427", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44427"}, {"id": "GHSA-WF5P-F5XR-C4JJ", "url": "https://github.com/advisories/GHSA-WF5P-F5XR-C4JJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44427"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to...", "cve_id": "CVE-2021-44427", "vendor": "Rosario Student Information System", "ghsa_id": "GHSA-WF5P-F5XR-C4JJ", "product": "rosariosis", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.50641, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44427", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "23bce350-3569-4d3d-ba07-74a78e3ec853", "vulnerability": {"vulnId": "CVE-2022-0827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "23bce350-3569-4d3d-ba07-74a78e3ec853", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "Bestbooks <= 2.6.3 - Unauthenticated SQLi | Affected: Bestbooks / Bestbooks | CVSS: 9.8 (CRITICAL) | EPSS: 0.09127 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0827", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Bestbooks <= 2.6.3 - Unauthenticated SQLi", "cve_id": "CVE-2022-0827", "vendor": "Bestbooks", "ghsa_id": null, "product": "Bestbooks", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.09127, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95168, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1cba7d43-6483-4745-b3ea-636010ea396a", "vulnerability": {"vulnId": "CVE-2022-29007", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "1cba7d43-6483-4745-b3ea-636010ea396a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows... | Affected: Dairy Farm / Shop Management System | CVSS: 9.8 (CRITICAL) | EPSS: 0.19253 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29007", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29007"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29007"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows...", "cve_id": "CVE-2022-29007", "vendor": "Dairy Farm", "ghsa_id": null, "product": "Shop Management System", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.19253, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29007", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5529ff55-8b1e-4a9d-82af-5543ee396acb", "vulnerability": {"vulnId": "CVE-2021-27931", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "5529ff55-8b1e-4a9d-82af-5543ee396acb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a... | Affected: Lumis / LumisXP | CVSS: 9.1 (CRITICAL) | EPSS: 0.18132 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27931", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27931"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27931"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a...", "cve_id": "CVE-2021-27931", "vendor": "Lumis", "ghsa_id": null, "product": "LumisXP", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.18132, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97118, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27931", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a4cb6d8b-a6c8-4dbc-81bd-553c3f3607ab", "vulnerability": {"vulnId": "CVE-2022-0592", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "a4cb6d8b-a6c8-4dbc-81bd-553c3f3607ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-08T00:00:00+00:00"}, "scope": {"notes": "MapSVG < 6.2.20 - Unauthenticated SQLi | Affected: MapSVG / MapSVG | CVSS: 9.8 (CRITICAL) | EPSS: 0.10172 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0592", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0592"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0592"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MapSVG < 6.2.20 - Unauthenticated SQLi", "cve_id": "CVE-2022-0592", "vendor": "MapSVG", "ghsa_id": null, "product": "MapSVG", "added_date": "2025-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.10172, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95527, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0592", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5edc31a9-8526-474c-807a-89fec19e2fe3", "vulnerability": {"vulnId": "CVE-2018-17173", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-06T01:00:00+01:00"}, "gcve": {"object_uuid": "5edc31a9-8526-474c-807a-89fec19e2fe3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-06T00:00:00+00:00"}, "scope": {"notes": "LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | Affected: LG / SuperSign CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.56237 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-17173", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17173"}, {"id": "GHSA-QGG8-99P6-V8V8", "url": "https://github.com/advisories/GHSA-QGG8-99P6-V8V8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17173"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.", "cve_id": "CVE-2018-17173", "vendor": "LG", "ghsa_id": "GHSA-QGG8-99P6-V8V8", "product": "SuperSign CMS", "added_date": "2025-11-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.56237, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99025, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17173", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7693d0da-76eb-44d5-964b-704bbbbf0034", "vulnerability": {"vulnId": "CVE-2024-12856", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7693d0da-76eb-44d5-964b-704bbbbf0034", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-11-03T00:00:00+00:00"}, "scope": {"notes": "Four-Faith Industrial Router adjust_sys_time OS Command Injection | Affected: Four-Faith / F3x24, F3x36 | CVSS: 7.2 (HIGH) | EPSS: 0.8422 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-12856", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12856"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12856"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Four-Faith Industrial Router adjust_sys_time OS Command Injection", "cve_id": "CVE-2024-12856", "vendor": "Four-Faith", "ghsa_id": null, "product": "F3x24, F3x36", "added_date": "2025-11-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.8422, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99691, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12856", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "41857e27-824e-4c88-b7a1-d312e53927a8", "vulnerability": {"vulnId": "CVE-2018-17532", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-31T01:00:00+01:00"}, "gcve": {"object_uuid": "41857e27-824e-4c88-b7a1-d312e53927a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-31T00:00:00+00:00"}, "scope": {"notes": "Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi... | Affected: Teltonika / RUT9XX routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.70659 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-17532", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17532"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17532"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi...", "cve_id": "CVE-2018-17532", "vendor": "Teltonika", "ghsa_id": null, "product": "RUT9XX routers", "added_date": "2025-10-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.70659, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99378, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17532", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a4a1fbf5-1f50-495f-b8d3-bb67c74b0022", "vulnerability": {"vulnId": "CVE-2018-25120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-29T19:39:03+01:00"}, "gcve": {"object_uuid": "a4a1fbf5-1f50-495f-b8d3-bb67c74b0022", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-29T18:39:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-29T18:39:03+00:00"}, "scope": {"notes": "D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test | Affected: D-Link / DNS-343 ShareCenter | CVSS: 9.3 (CRITICAL) | EPSS: 0.09806 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-25120", "url": "https://www.cve.org/CVERecord?id=CVE-2018-25120"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-25120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test", "cve_id": "CVE-2018-25120", "vendor": "D-Link", "ghsa_id": null, "product": "DNS-343 ShareCenter", "added_date": "2025-10-29T18:39:03.000Z", "cvss_score": 9.3, "epss_score": 0.09806, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95409, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-25120", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "608e75ab-c1ef-4de4-a681-9e1569dd7107", "vulnerability": {"vulnId": "CVE-2020-8958", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-29T01:00:00+01:00"}, "gcve": {"object_uuid": "608e75ab-c1ef-4de4-a681-9e1569dd7107", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-29T00:00:00+00:00"}, "scope": {"notes": "Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to... | Affected: Guangzhou / 1GE ONU V2801RW and V2804RGW | CVSS: 7.2 (HIGH) | EPSS: 0.46642 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8958", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8958"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8958"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to...", "cve_id": "CVE-2020-8958", "vendor": "Guangzhou", "ghsa_id": null, "product": "1GE ONU V2801RW and V2804RGW", "added_date": "2025-10-29T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.46642, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98788, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8958", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1403a7bc-de22-4d36-aec4-eb25b7e1e793", "vulnerability": {"vulnId": "CVE-2025-64095", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-28T22:46:11+01:00"}, "gcve": {"object_uuid": "1403a7bc-de22-4d36-aec4-eb25b7e1e793", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-28T21:46:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-28T21:46:11+00:00"}, "scope": {"notes": "DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite | Affected: DNN Software / Dnn.Platform | CVSS: 10.0 (CRITICAL) | EPSS: 0.4697 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-64095", "url": "https://www.cve.org/CVERecord?id=CVE-2025-64095"}, {"id": "GHSA-3M8R-W7XG-JQVW", "url": "https://github.com/advisories/GHSA-3M8R-W7XG-JQVW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-64095"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite", "cve_id": "CVE-2025-64095", "vendor": "DNN Software", "ghsa_id": "GHSA-3M8R-W7XG-JQVW", "product": "Dnn.Platform", "added_date": "2025-10-28T21:46:11.000Z", "cvss_score": 10.0, "epss_score": 0.4697, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98796, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-64095", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ce053370-d1d1-4c5c-941c-ca4d5ed6f1bf", "vulnerability": {"vulnId": "CVE-2025-8868", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-27T15:10:46+01:00"}, "gcve": {"object_uuid": "ce053370-d1d1-4c5c-941c-ca4d5ed6f1bf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-27T14:10:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-27T14:10:46+00:00"}, "scope": {"notes": "Chef Automate compliance service SQL Injection Vulnerability | Affected: Progress Software / Chef Automate | CVSS: 9.8 (CRITICAL) | EPSS: 0.24317 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-8868", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8868"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8868"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Chef Automate compliance service SQL Injection Vulnerability", "cve_id": "CVE-2025-8868", "vendor": "Progress Software", "ghsa_id": null, "product": "Chef Automate", "added_date": "2025-10-27T14:10:46.518Z", "cvss_score": 9.8, "epss_score": 0.24317, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.978, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8868", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4a33e88a-1c54-47a5-9a53-a28552919d8c", "vulnerability": {"vulnId": "CVE-2025-59474", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-26T20:42:31+01:00"}, "gcve": {"object_uuid": "4a33e88a-1c54-47a5-9a53-a28552919d8c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-26T19:42:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-26T19:42:31+00:00"}, "scope": {"notes": "Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users... | Affected: Jenkins Project / Jenkins | CVSS: 5.3 (MEDIUM) | EPSS: 0.04908 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-59474", "url": "https://www.cve.org/CVERecord?id=CVE-2025-59474"}, {"id": "GHSA-67V4-38H7-9JJP", "url": "https://github.com/advisories/GHSA-67V4-38H7-9JJP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-59474"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users...", "cve_id": "CVE-2025-59474", "vendor": "Jenkins Project", "ghsa_id": "GHSA-67V4-38H7-9JJP", "product": "Jenkins", "added_date": "2025-10-26T19:42:31.435Z", "cvss_score": 5.3, "epss_score": 0.04908, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91832, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-59474", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "98a6fc21-fa27-4370-861f-9ff0dbcf44f9", "vulnerability": {"vulnId": "CVE-2023-50358", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-26T02:00:00+02:00"}, "gcve": {"object_uuid": "98a6fc21-fa27-4370-861f-9ff0dbcf44f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-26T00:00:00+00:00"}, "scope": {"notes": "QTS, QuTS hero, QuTScloud | Affected: QNAP / QTS, QuTS hero, QuTScloud | CVSS: 5.8 (MEDIUM) | EPSS: 0.13523 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-50358", "url": "https://www.cve.org/CVERecord?id=CVE-2023-50358"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-50358"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "QTS, QuTS hero, QuTScloud", "cve_id": "CVE-2023-50358", "vendor": "QNAP", "ghsa_id": null, "product": "QTS, QuTS hero, QuTScloud", "added_date": "2025-10-26T00:00:00.000Z", "cvss_score": 5.8, "epss_score": 0.13523, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96338, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-50358", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cb9f3054-bf5a-4b73-a22f-7e956d35d4d4", "vulnerability": {"vulnId": "CVE-2024-9707", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-24T09:29:14+02:00"}, "gcve": {"object_uuid": "cb9f3054-bf5a-4b73-a22f-7e956d35d4d4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-24T07:29:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-24T07:29:14+00:00"}, "scope": {"notes": "Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation | Affected: Themehunk / Hunk Companion | CVSS: 9.8 (CRITICAL) | EPSS: 0.09078 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9707", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9707"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9707"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation", "cve_id": "CVE-2024-9707", "vendor": "Themehunk", "ghsa_id": null, "product": "Hunk Companion", "added_date": "2025-10-24T07:29:14.921Z", "cvss_score": 9.8, "epss_score": 0.09078, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95148, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9707", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "85659308-8654-4465-ac55-75f0b7591d9e", "vulnerability": {"vulnId": "CVE-2025-34033", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-22T18:58:31+02:00"}, "gcve": {"object_uuid": "85659308-8654-4465-ac55-75f0b7591d9e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-22T16:58:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-22T16:58:31+00:00"}, "scope": {"notes": "5VTechnologies Blue Angel Software Suite OS Command Injection | Affected: 5VTechnologies / Blue Angel Software Suite | CVSS: 7.7 (HIGH) | EPSS: 0.11206 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34033", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34033"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34033"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "5VTechnologies Blue Angel Software Suite OS Command Injection", "cve_id": "CVE-2025-34033", "vendor": "5VTechnologies", "ghsa_id": null, "product": "Blue Angel Software Suite", "added_date": "2025-10-22T16:58:31.546Z", "cvss_score": 7.7, "epss_score": 0.11206, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95834, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34033", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7a575314-daad-4451-a9cd-7389aabfad27", "vulnerability": {"vulnId": "CVE-2025-49533", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-22T00:26:08+02:00"}, "gcve": {"object_uuid": "7a575314-daad-4451-a9cd-7389aabfad27", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-21T22:26:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-21T22:26:08+00:00"}, "scope": {"notes": "Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502) | Affected: Adobe / Adobe Experience Manager (MS) | CVSS: 9.8 (CRITICAL) | EPSS: 0.56053 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-49533", "url": "https://www.cve.org/CVERecord?id=CVE-2025-49533"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-49533"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)", "cve_id": "CVE-2025-49533", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Experience Manager (MS)", "added_date": "2025-10-21T22:26:08.112Z", "cvss_score": 9.8, "epss_score": 0.56053, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99021, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-49533", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "25c470e9-4d6d-4187-b762-eddd399f46fa", "vulnerability": {"vulnId": "CVE-2018-25118", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-20T23:14:41+02:00"}, "gcve": {"object_uuid": "25c470e9-4d6d-4187-b762-eddd399f46fa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-20T21:14:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-20T21:14:41+00:00"}, "scope": {"notes": "GeoVision Command Injection RCE via /PictureCatch.cgi | Affected: GeoVision / GV-BX1500, GV-MFD1501, GeoVision embedded IP devices | CVSS: 10.0 (CRITICAL) | EPSS: 0.01267 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-25118", "url": "https://www.cve.org/CVERecord?id=CVE-2018-25118"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-25118"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoVision Command Injection RCE via /PictureCatch.cgi", "cve_id": "CVE-2018-25118", "vendor": "GeoVision", "ghsa_id": null, "product": "GV-BX1500, GV-MFD1501, GeoVision embedded IP devices", "added_date": "2025-10-20T21:14:41.000Z", "cvss_score": 10.0, "epss_score": 0.01267, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68705, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-25118", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "061ed336-8e44-4a28-98e8-114a5079b5ef", "vulnerability": {"vulnId": "CVE-2021-27855", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-14T02:00:00+02:00"}, "gcve": {"object_uuid": "061ed336-8e44-4a28-98e8-114a5079b5ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-14T00:00:00+00:00"}, "scope": {"notes": "FatPipe software allows privilege escalation | Affected: FatPipe / WARP, IPVPN, MPVPN | CVSS: 8.8 (HIGH) | EPSS: 0.01604 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27855", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27855"}, {"id": "GHSA-53HG-58MG-7J38", "url": "https://github.com/advisories/GHSA-53HG-58MG-7J38"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27855"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FatPipe software allows privilege escalation", "cve_id": "CVE-2021-27855", "vendor": "FatPipe", "ghsa_id": "GHSA-53HG-58MG-7J38", "product": "WARP, IPVPN, MPVPN", "added_date": "2025-10-14T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.01604, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27855", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "41773501-aa17-47d7-99b8-568401346bbc", "vulnerability": {"vulnId": "CVE-2025-28367", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-09T02:00:00+02:00"}, "gcve": {"object_uuid": "41773501-aa17-47d7-99b8-568401346bbc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-09T00:00:00+00:00"}, "scope": {"notes": "mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this... | Affected: mojoPortal / mojoPortal | CVSS: 6.5 (MEDIUM) | EPSS: 0.01937 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-28367", "url": "https://www.cve.org/CVERecord?id=CVE-2025-28367"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-28367"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this...", "cve_id": "CVE-2025-28367", "vendor": "mojoPortal", "ghsa_id": null, "product": "mojoPortal", "added_date": "2025-10-09T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.01937, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79353, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-28367", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "48e23086-c034-4d14-947d-ff4553da925f", "vulnerability": {"vulnId": "CVE-2025-55161", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-08T02:00:00+02:00"}, "gcve": {"object_uuid": "48e23086-c034-4d14-947d-ff4553da925f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-08T00:00:00+00:00"}, "scope": {"notes": "Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf | Affected: Stirling-Tools / Stirling-PDF | CVSS: 8.6 (HIGH) | EPSS: 0.01999 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-55161", "url": "https://www.cve.org/CVERecord?id=CVE-2025-55161"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-55161"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf", "cve_id": "CVE-2025-55161", "vendor": "Stirling-Tools", "ghsa_id": null, "product": "Stirling-PDF", "added_date": "2025-10-08T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.01999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-55161", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "be7a050e-db15-4572-96c2-e2bcbf51b8ef", "vulnerability": {"vulnId": "CVE-2023-5222", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "be7a050e-db15-4572-96c2-e2bcbf51b8ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-05T00:00:00+00:00"}, "scope": {"notes": "Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password | Affected: Viessmann / Vitogate 300 | CVSS: 6.3 (MEDIUM) | EPSS: 0.80402 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5222", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5222"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5222"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password", "cve_id": "CVE-2023-5222", "vendor": "Viessmann", "ghsa_id": null, "product": "Vitogate 300", "added_date": "2025-10-05T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.80402, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99613, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5222", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7ee09fc2-ef83-4e20-bc08-d9e917fd5a08", "vulnerability": {"vulnId": "CVE-2024-25852", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "7ee09fc2-ef83-4e20-bc08-d9e917fd5a08", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-05T00:00:00+00:00"}, "scope": {"notes": "Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the \"AccessControlList\" parameter of the access control... | Affected: Linksys / RE7000 | CVSS: 8.8 (HIGH) | EPSS: 0.16519 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-25852", "url": "https://www.cve.org/CVERecord?id=CVE-2024-25852"}, {"id": "GHSA-P5Q9-4VG3-6X89", "url": "https://github.com/advisories/GHSA-P5Q9-4VG3-6X89"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-25852"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the \"AccessControlList\" parameter of the access control...", "cve_id": "CVE-2024-25852", "vendor": "Linksys", "ghsa_id": "GHSA-P5Q9-4VG3-6X89", "product": "RE7000", "added_date": "2025-10-05T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.16519, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-25852", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "53119d18-3eb7-4aa3-814a-202c22e8e82a", "vulnerability": {"vulnId": "CVE-2024-1561", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "53119d18-3eb7-4aa3-814a-202c22e8e82a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-05T00:00:00+00:00"}, "scope": {"notes": "Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio | Affected: Gradio-app / gradio-app/gradio | CVSS: 7.5 (HIGH) | EPSS: 0.09314 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-1561", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1561"}, {"id": "GHSA-G9CJ-CFPP-4G2X", "url": "https://github.com/advisories/GHSA-G9CJ-CFPP-4G2X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1561"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio", "cve_id": "CVE-2024-1561", "vendor": "Gradio-app", "ghsa_id": "GHSA-G9CJ-CFPP-4G2X", "product": "gradio-app/gradio", "added_date": "2025-10-05T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.09314, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95233, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-1561", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4355aca8-1bb5-48a3-90bd-251df96f8a23", "vulnerability": {"vulnId": "CVE-2024-4325", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "4355aca8-1bb5-48a3-90bd-251df96f8a23", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-05T00:00:00+00:00"}, "scope": {"notes": "Server-Side Request Forgery (SSRF) in gradio-app/gradio | Affected: Gradio-app / gradio-app/gradio | CVSS: 8.6 (HIGH) | EPSS: 0.37366 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-4325", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4325"}, {"id": "GHSA-973G-55HP-3FRW", "url": "https://github.com/advisories/GHSA-973G-55HP-3FRW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4325"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Server-Side Request Forgery (SSRF) in gradio-app/gradio", "cve_id": "CVE-2024-4325", "vendor": "Gradio-app", "ghsa_id": "GHSA-973G-55HP-3FRW", "product": "gradio-app/gradio", "added_date": "2025-10-05T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.37366, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98485, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4325", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d4e61451-18ac-4598-a836-0ba24955e127", "vulnerability": {"vulnId": "CVE-2024-35219", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "d4e61451-18ac-4598-a836-0ba24955e127", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-05T00:00:00+00:00"}, "scope": {"notes": "OpenAPI Generator Online - Arbitrary File Read/Delete | Affected: OpenAPITools / openapi-generator | CVSS: 8.3 (HIGH) | EPSS: 0.03592 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-35219", "url": "https://www.cve.org/CVERecord?id=CVE-2024-35219"}, {"id": "GHSA-G3HR-P86P-593H", "url": "https://github.com/advisories/GHSA-G3HR-P86P-593H"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-35219"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenAPI Generator Online - Arbitrary File Read/Delete", "cve_id": "CVE-2024-35219", "vendor": "OpenAPITools", "ghsa_id": "GHSA-G3HR-P86P-593H", "product": "openapi-generator", "added_date": "2025-10-05T00:00:00.000Z", "cvss_score": 8.3, "epss_score": 0.03592, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89067, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-35219", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c0baa789-8faa-4c1f-a75a-b675b7146238", "vulnerability": {"vulnId": "CVE-2020-12832", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "c0baa789-8faa-4c1f-a75a-b675b7146238", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-05T00:00:00+00:00"}, "scope": {"notes": "WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails... | Affected: Simple File List / Simple File List | CVSS: 9.8 (CRITICAL) | EPSS: 0.07073 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-12832", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12832"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12832"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails...", "cve_id": "CVE-2020-12832", "vendor": "Simple File List", "ghsa_id": null, "product": "Simple File List", "added_date": "2025-10-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07073, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94022, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-12832", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5932ad0e-c999-4fda-87af-f6b08ff46131", "vulnerability": {"vulnId": "CVE-2021-28151", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-04T02:00:00+02:00"}, "gcve": {"object_uuid": "5932ad0e-c999-4fda-87af-f6b08ff46131", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-04T00:00:00+00:00"}, "scope": {"notes": "Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping... | Affected: Hongdian / H8922 | CVSS: 8.8 (HIGH) | EPSS: 0.27912 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-28151", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28151"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28151"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping...", "cve_id": "CVE-2021-28151", "vendor": "Hongdian", "ghsa_id": null, "product": "H8922", "added_date": "2025-10-04T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.27912, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98046, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28151", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "040f0df7-6b25-4967-9eaa-5278cb6f6a03", "vulnerability": {"vulnId": "CVE-2021-20092", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-03T02:00:00+02:00"}, "gcve": {"object_uuid": "040f0df7-6b25-4967-9eaa-5278cb6f6a03", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-03T00:00:00+00:00"}, "scope": {"notes": "The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict... | Affected: Buffalo / WSR-2533DHPL2, WSR-2533DHP3 | CVSS: 7.5 (HIGH) | EPSS: 0.0817 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-20092", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20092"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20092"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict...", "cve_id": "CVE-2021-20092", "vendor": "Buffalo", "ghsa_id": null, "product": "WSR-2533DHPL2, WSR-2533DHP3", "added_date": "2025-10-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0817, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94694, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20092", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d7c00495-460b-4ce3-b411-069ff420d087", "vulnerability": {"vulnId": "CVE-2021-22911", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-03T02:00:00+02:00"}, "gcve": {"object_uuid": "d7c00495-460b-4ce3-b411-069ff420d087", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-03T00:00:00+00:00"}, "scope": {"notes": "A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection,... | Affected: Rocket.Chat / Rocket.Chat server | CVSS: 9.8 (CRITICAL) | EPSS: 0.95242 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-22911", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22911"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22911"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection,...", "cve_id": "CVE-2021-22911", "vendor": "Rocket.Chat", "ghsa_id": null, "product": "Rocket.Chat server", "added_date": "2025-10-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95242, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99865, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22911", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "087e2a9b-f567-4524-b711-00917083aaa8", "vulnerability": {"vulnId": "CVE-2020-24581", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-01T02:00:00+02:00"}, "gcve": {"object_uuid": "087e2a9b-f567-4524-b711-00917083aaa8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-01T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not... | Affected: D-Link / DSL-2888A | CVSS: 8.0 (HIGH) | EPSS: 0.13727 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-24581", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24581"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24581"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not...", "cve_id": "CVE-2020-24581", "vendor": "D-Link", "ghsa_id": null, "product": "DSL-2888A", "added_date": "2025-10-01T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.13727, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96394, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24581", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "30c70b50-2b54-461d-99a8-35e18faa468d", "vulnerability": {"vulnId": "CVE-2020-24914", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-01T02:00:00+02:00"}, "gcve": {"object_uuid": "30c70b50-2b54-461d-99a8-35e18faa468d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-01T00:00:00+00:00"}, "scope": {"notes": "A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable... | Affected: Qcubed / qcubed | CVSS: 9.8 (CRITICAL) | EPSS: 0.04978 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-24914", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24914"}, {"id": "GHSA-7W3C-JGH7-CWJW", "url": "https://github.com/advisories/GHSA-7W3C-JGH7-CWJW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24914"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A PHP object injection bug in profile.php in qcubed (all versions including 3.1.1) unserializes the untrusted data of the POST-variable...", "cve_id": "CVE-2020-24914", "vendor": "Qcubed", "ghsa_id": "GHSA-7W3C-JGH7-CWJW", "product": "qcubed", "added_date": "2025-10-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04978, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24914", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c4a9d58e-84ed-45d7-b771-6bd2b4552893", "vulnerability": {"vulnId": "CVE-2021-34993", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-01T02:00:00+02:00"}, "gcve": {"object_uuid": "c4a9d58e-84ed-45d7-b771-6bd2b4552893", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-01T00:00:00+00:00"}, "scope": {"notes": "This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not... | Affected: Commvault / CommCell | CVSS: 9.8 (CRITICAL) | EPSS: 0.05424 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-34993", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34993"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34993"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not...", "cve_id": "CVE-2021-34993", "vendor": "Commvault", "ghsa_id": null, "product": "CommCell", "added_date": "2025-10-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.05424, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92456, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34993", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d7510f98-ec5b-42af-8b50-464914da242b", "vulnerability": {"vulnId": "CVE-2020-17505", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-10-01T02:00:00+02:00"}, "gcve": {"object_uuid": "d7510f98-ec5b-42af-8b50-464914da242b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-10-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-10-01T00:00:00+00:00"}, "scope": {"notes": "Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands... | Affected: Artica / Artica Web Proxy | CVSS: 8.8 (HIGH) | EPSS: 0.82165 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-17505", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17505"}, {"id": "GHSA-M3F9-9CW6-5CCJ", "url": "https://github.com/advisories/GHSA-M3F9-9CW6-5CCJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17505"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands...", "cve_id": "CVE-2020-17505", "vendor": "Artica", "ghsa_id": "GHSA-M3F9-9CW6-5CCJ", "product": "Artica Web Proxy", "added_date": "2025-10-01T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.82165, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99647, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17505", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fccc3fbe-4395-4ddf-8388-eb4aa170def3", "vulnerability": {"vulnId": "CVE-2019-13372", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-28T02:00:00+02:00"}, "gcve": {"object_uuid": "fccc3fbe-4395-4ddf-8388-eb4aa170def3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-28T00:00:00+00:00"}, "scope": {"notes": "/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary... | Affected: D-Link / Central WiFi Manager CWM(100) | CVSS: 9.8 (CRITICAL) | EPSS: 0.8249 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-13372", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13372"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13372"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary...", "cve_id": "CVE-2019-13372", "vendor": "D-Link", "ghsa_id": null, "product": "Central WiFi Manager CWM(100)", "added_date": "2025-09-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.8249, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99656, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-13372", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7a88f269-66d6-4428-9987-acda5b5daa80", "vulnerability": {"vulnId": "CVE-2018-16059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-27T02:00:00+02:00"}, "gcve": {"object_uuid": "7a88f269-66d6-4428-9987-acda5b5daa80", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-27T00:00:00+00:00"}, "scope": {"notes": "Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. | Affected: Endress+Hauser / WirelessHART Fieldgate SWG70 | CVSS: 5.3 (MEDIUM) | EPSS: 0.29816 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-16059", "url": "https://www.cve.org/CVERecord?id=CVE-2018-16059"}, {"id": "GHSA-F7V2-J977-J9V3", "url": "https://github.com/advisories/GHSA-F7V2-J977-J9V3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-16059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.", "cve_id": "CVE-2018-16059", "vendor": "Endress+Hauser", "ghsa_id": "GHSA-F7V2-J977-J9V3", "product": "WirelessHART Fieldgate SWG70", "added_date": "2025-09-27T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.29816, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98152, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-16059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1f11a5e9-2243-42d2-be90-77b30a07aef1", "vulnerability": {"vulnId": "CVE-2022-40881", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-19T02:00:00+02:00"}, "gcve": {"object_uuid": "1f11a5e9-2243-42d2-be90-77b30a07aef1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-19T00:00:00+00:00"}, "scope": {"notes": "SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | Affected: SolarView / SolarView Compact | CVSS: 9.8 (CRITICAL) | EPSS: 0.30111 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-40881", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40881"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40881"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php", "cve_id": "CVE-2022-40881", "vendor": "SolarView", "ghsa_id": null, "product": "SolarView Compact", "added_date": "2025-09-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.30111, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98167, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40881", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f3113328-bc48-4917-bd72-3d990e665510", "vulnerability": {"vulnId": "CVE-2022-4447", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-19T02:00:00+02:00"}, "gcve": {"object_uuid": "f3113328-bc48-4917-bd72-3d990e665510", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-19T00:00:00+00:00"}, "scope": {"notes": "Fontsy <= 1.8.6 - Multiple Unauthenticated SQLi | Affected: Fontsy / Fontsy | CVSS: 9.8 (CRITICAL) | EPSS: 0.04756 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4447", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4447"}, {"id": "GHSA-XJG5-J24F-8P55", "url": "https://github.com/advisories/GHSA-XJG5-J24F-8P55"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4447"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fontsy <= 1.8.6 - Multiple Unauthenticated SQLi", "cve_id": "CVE-2022-4447", "vendor": "Fontsy", "ghsa_id": "GHSA-XJG5-J24F-8P55", "product": "Fontsy", "added_date": "2025-09-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04756, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91604, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4447", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fa83b4df-4ab5-4654-b012-8b0de25f7ef4", "vulnerability": {"vulnId": "CVE-2022-39986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-19T02:00:00+02:00"}, "gcve": {"object_uuid": "fa83b4df-4ab5-4654-b012-8b0de25f7ef4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-19T00:00:00+00:00"}, "scope": {"notes": "A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id... | Affected: RaspAP / RaspAP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99058 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-39986", "url": "https://www.cve.org/CVERecord?id=CVE-2022-39986"}, {"id": "GHSA-7C28-WG7R-PG6F", "url": "https://github.com/advisories/GHSA-7C28-WG7R-PG6F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-39986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id...", "cve_id": "CVE-2022-39986", "vendor": "RaspAP", "ghsa_id": "GHSA-7C28-WG7R-PG6F", "product": "RaspAP", "added_date": "2025-09-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99058, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99931, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-39986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "879c9b25-7e03-4863-b08a-73a0e3bd7c46", "vulnerability": {"vulnId": "CVE-2022-4117", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-19T02:00:00+02:00"}, "gcve": {"object_uuid": "879c9b25-7e03-4863-b08a-73a0e3bd7c46", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-19T00:00:00+00:00"}, "scope": {"notes": "IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi | Affected: IWS / Geo Form Fields | CVSS: 9.8 (CRITICAL) | EPSS: 0.04955 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4117", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4117"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4117"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi", "cve_id": "CVE-2022-4117", "vendor": "IWS", "ghsa_id": null, "product": "Geo Form Fields", "added_date": "2025-09-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04955, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4117", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9f8f662d-baee-413a-a1e9-9c021cb8210e", "vulnerability": {"vulnId": "CVE-2022-31161", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "9f8f662d-baee-413a-a1e9-9c021cb8210e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-18T00:00:00+00:00"}, "scope": {"notes": "Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload | Affected: Hap-wi / roxy-wi | CVSS: 10.0 (CRITICAL) | EPSS: 0.28411 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31161", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31161"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31161"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload", "cve_id": "CVE-2022-31161", "vendor": "Hap-wi", "ghsa_id": null, "product": "roxy-wi", "added_date": "2025-09-18T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.28411, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98073, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31161", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "21215607-930b-48e4-b637-474d60f9b46d", "vulnerability": {"vulnId": "CVE-2021-41653", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "21215607-930b-48e4-b637-474d60f9b46d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-18T00:00:00+00:00"}, "scope": {"notes": "The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a... | Affected: TP-Link / TL-WR840N EU v5 router | CVSS: 9.8 (CRITICAL) | EPSS: 0.76045 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-41653", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41653"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41653"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a...", "cve_id": "CVE-2021-41653", "vendor": "TP-Link", "ghsa_id": null, "product": "TL-WR840N EU v5 router", "added_date": "2025-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.76045, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99517, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41653", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0f1a8942-d9dc-4a56-9ea1-177bb22c2a13", "vulnerability": {"vulnId": "CVE-2022-2486", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "0f1a8942-d9dc-4a56-9ea1-177bb22c2a13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-18T00:00:00+00:00"}, "scope": {"notes": "WAVLINK WN535K2/WN535K3 os command injection | Affected: WAVLINK / WN535K2, WN535K3 | CVSS: 8.0 (HIGH) | EPSS: 0.30522 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2486", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2486"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2486"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WAVLINK WN535K2/WN535K3 os command injection", "cve_id": "CVE-2022-2486", "vendor": "WAVLINK", "ghsa_id": null, "product": "WN535K2, WN535K3", "added_date": "2025-09-18T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.30522, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98189, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2486", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "24e4af08-002f-431c-8662-b454598e3653", "vulnerability": {"vulnId": "CVE-2022-0679", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "24e4af08-002f-431c-8662-b454598e3653", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-18T00:00:00+00:00"}, "scope": {"notes": "Narnoo Distributor <= 2.5.1 - Unauthenticated LFI to Arbitrary File Read / RCE | Affected: Narnoo / Narnoo Distributor | CVSS: 9.8 (CRITICAL) | EPSS: 0.4783 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0679", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0679"}, {"id": "GHSA-VR55-FV2W-8FHH", "url": "https://github.com/advisories/GHSA-VR55-FV2W-8FHH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0679"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Narnoo Distributor <= 2.5.1 - Unauthenticated LFI to Arbitrary File Read / RCE", "cve_id": "CVE-2022-0679", "vendor": "Narnoo", "ghsa_id": "GHSA-VR55-FV2W-8FHH", "product": "Narnoo Distributor", "added_date": "2025-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.4783, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98817, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0679", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "07adbec9-b081-430a-8edf-d2b6790af455", "vulnerability": {"vulnId": "CVE-2022-2314", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "07adbec9-b081-430a-8edf-d2b6790af455", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-18T00:00:00+00:00"}, "scope": {"notes": "VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call | Affected: VR Calendar / VR Calendar | CVSS: 9.8 (CRITICAL) | EPSS: 0.1652 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2314", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2314"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2314"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call", "cve_id": "CVE-2022-2314", "vendor": "VR Calendar", "ghsa_id": null, "product": "VR Calendar", "added_date": "2025-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1652, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96908, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2314", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0d1f386f-e890-402d-a812-8a16cf47ce49", "vulnerability": {"vulnId": "CVE-2025-54782", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "0d1f386f-e890-402d-a812-8a16cf47ce49", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-18T00:00:00+00:00"}, "scope": {"notes": "@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers | Affected: Nest.js / nest | CVSS: 9.4 (CRITICAL) | EPSS: 0.51324 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-54782", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54782"}, {"id": "GHSA-85CG-CMQ5-QJM7", "url": "https://github.com/advisories/GHSA-85CG-CMQ5-QJM7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54782"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers", "cve_id": "CVE-2025-54782", "vendor": "Nest.js", "ghsa_id": "GHSA-85CG-CMQ5-QJM7", "product": "nest", "added_date": "2025-09-18T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.51324, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54782", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0feb259d-5dd3-415d-a8a3-0d6f8c0e88c2", "vulnerability": {"vulnId": "CVE-2022-23178", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "0feb259d-5dd3-415d-a8a3-0d6f8c0e88c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-16T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed... | Affected: Crestron / HD-MD4X2-4K-E | CVSS: 9.8 (CRITICAL) | EPSS: 0.75159 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-23178", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23178"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23178"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed...", "cve_id": "CVE-2022-23178", "vendor": "Crestron", "ghsa_id": null, "product": "HD-MD4X2-4K-E", "added_date": "2025-09-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.75159, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99497, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23178", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8b1d0095-b0ff-4ca7-ab2d-d3d7f4cf9f18", "vulnerability": {"vulnId": "CVE-2021-3297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "8b1d0095-b0ff-4ca7-ab2d-d3d7f4cf9f18", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-16T00:00:00+00:00"}, "scope": {"notes": "On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. | Affected: Zyxel / NBG2105 | CVSS: 7.8 (HIGH) | EPSS: 0.20514 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-3297", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.", "cve_id": "CVE-2021-3297", "vendor": "Zyxel", "ghsa_id": null, "product": "NBG2105", "added_date": "2025-09-16T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.20514, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97444, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a63b95c-e6aa-4d6a-adf3-a7fa3a540e9d", "vulnerability": {"vulnId": "CVE-2019-13101", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "2a63b95c-e6aa-4d6a-adf3-a7fa3a540e9d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-16T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can... | Affected: D-Link / DIR-600M | CVSS: 9.8 (CRITICAL) | EPSS: 0.67091 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-13101", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13101"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13101"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can...", "cve_id": "CVE-2019-13101", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-600M", "added_date": "2025-09-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.67091, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99281, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-13101", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cde09681-8587-40f3-9680-7898af3798c0", "vulnerability": {"vulnId": "CVE-2021-40875", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "cde09681-8587-40f3-9680-7898af3798c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-16T00:00:00+00:00"}, "scope": {"notes": "Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the... | Affected: Gurock / TestRail | CVSS: 7.5 (HIGH) | EPSS: 0.47486 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-40875", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40875"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40875"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the...", "cve_id": "CVE-2021-40875", "vendor": "Gurock", "ghsa_id": null, "product": "TestRail", "added_date": "2025-09-16T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.47486, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98805, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40875", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "03ef2da4-1ca3-4dc8-86dd-0a990dff84a7", "vulnerability": {"vulnId": "CVE-2025-52488", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-12T02:00:00+02:00"}, "gcve": {"object_uuid": "03ef2da4-1ca3-4dc8-86dd-0a990dff84a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-12T00:00:00+00:00"}, "scope": {"notes": "DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input | Affected: DNN Software / Dnn.Platform | CVSS: 8.6 (HIGH) | EPSS: 0.35761 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-52488", "url": "https://www.cve.org/CVERecord?id=CVE-2025-52488"}, {"id": "GHSA-MGFV-2362-JQ96", "url": "https://github.com/advisories/GHSA-MGFV-2362-JQ96"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-52488"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input", "cve_id": "CVE-2025-52488", "vendor": "DNN Software", "ghsa_id": "GHSA-MGFV-2362-JQ96", "product": "Dnn.Platform", "added_date": "2025-09-12T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.35761, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98421, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-52488", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0a53453c-72d5-4e77-93b2-c741a9159990", "vulnerability": {"vulnId": "CVE-2024-52875", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-12T02:00:00+02:00"}, "gcve": {"object_uuid": "0a53453c-72d5-4e77-93b2-c741a9159990", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-12T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and... | Affected: GFI / Kerio Control | CVSS: 8.8 (HIGH) | EPSS: 0.29344 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-52875", "url": "https://www.cve.org/CVERecord?id=CVE-2024-52875"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-52875"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and...", "cve_id": "CVE-2024-52875", "vendor": "GFI", "ghsa_id": null, "product": "Kerio Control", "added_date": "2025-09-12T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.29344, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98127, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-52875", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c4147cff-b759-42ba-afda-47e94fbca5c0", "vulnerability": {"vulnId": "CVE-2025-10211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-10T22:02:05+02:00"}, "gcve": {"object_uuid": "c4147cff-b759-42ba-afda-47e94fbca5c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-10T20:02:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-10T20:02:05+00:00"}, "scope": {"notes": "yanyutao0402 ChanCMS getArticle CollectController server-side request forgery | Affected: yanyutao0402 / ChanCMS | CVSS: 5.3 (MEDIUM) | EPSS: 0.00721 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-10211", "url": "https://www.cve.org/CVERecord?id=CVE-2025-10211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-10211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "yanyutao0402 ChanCMS getArticle CollectController server-side request forgery", "cve_id": "CVE-2025-10211", "vendor": "yanyutao0402", "ghsa_id": null, "product": "ChanCMS", "added_date": "2025-09-10T20:02:05.000Z", "cvss_score": 5.3, "epss_score": 0.00721, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52232, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-10211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d29d7109-1e32-4b33-b9e0-4bb4d7050ab0", "vulnerability": {"vulnId": "CVE-2025-54236", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-09T15:20:17+02:00"}, "gcve": {"object_uuid": "d29d7109-1e32-4b33-b9e0-4bb4d7050ab0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-09T13:20:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-09T13:20:17+00:00"}, "scope": {"notes": "Adobe Commerce | Improper Input Validation (CWE-20) | Affected: Adobe / Adobe Commerce | CVSS: 9.1 (CRITICAL) | EPSS: 0.94532 | Used in malware: unknown | Listed 266 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-54236", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54236"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54236"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Commerce | Improper Input Validation (CWE-20)", "cve_id": "CVE-2025-54236", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Commerce", "added_date": "2025-09-09T13:20:17.939Z", "cvss_score": 9.1, "epss_score": 0.94532, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99852, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54236", "ahead_of_cisa_kev": {"unit": "day", "count": 266}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4767b833-f263-4801-93e8-312214974657", "vulnerability": {"vulnId": "CVE-2024-38653", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-09-05T02:00:00+02:00"}, "gcve": {"object_uuid": "4767b833-f263-4801-93e8-312214974657", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-09-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-09-05T00:00:00+00:00"}, "scope": {"notes": "XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. | Affected: Ivanti / Avalanche | CVSS: 8.2 (HIGH) | EPSS: 0.91984 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-38653", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38653"}, {"id": "GHSA-6JJX-98R4-VCM4", "url": "https://github.com/advisories/GHSA-6JJX-98R4-VCM4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38653"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.", "cve_id": "CVE-2024-38653", "vendor": "Ivanti", "ghsa_id": "GHSA-6JJX-98R4-VCM4", "product": "Avalanche", "added_date": "2025-09-05T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.91984, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99818, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38653", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9dc364b7-14a2-4d61-954d-9dcc908bb3fe", "vulnerability": {"vulnId": "CVE-2020-4463", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-31T02:00:00+02:00"}, "gcve": {"object_uuid": "9dc364b7-14a2-4d61-954d-9dcc908bb3fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-31T00:00:00+00:00"}, "scope": {"notes": "IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote... | Affected: IBM / Maximo Asset Management | CVSS: 8.2 (HIGH) | EPSS: 0.3159 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-4463", "url": "https://www.cve.org/CVERecord?id=CVE-2020-4463"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-4463"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote...", "cve_id": "CVE-2020-4463", "vendor": "IBM", "ghsa_id": null, "product": "Maximo Asset Management", "added_date": "2025-08-31T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.3159, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9824, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-4463", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a15d929d-53a4-4d8a-a9ee-27b0a7ca62f0", "vulnerability": {"vulnId": "CVE-2020-7136", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-31T02:00:00+02:00"}, "gcve": {"object_uuid": "a15d929d-53a4-4d8a-a9ee-27b0a7ca62f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-31T00:00:00+00:00"}, "scope": {"notes": "A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard... | Affected: Hewlett Packard Enterprise / Smart Update Manager (SUM) | CVSS: 9.8 (CRITICAL) | EPSS: 0.79522 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-7136", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7136"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-7136"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard...", "cve_id": "CVE-2020-7136", "vendor": "Hewlett Packard Enterprise", "ghsa_id": null, "product": "Smart Update Manager (SUM)", "added_date": "2025-08-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.79522, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-7136", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1bbfdbb4-31b0-4c64-b7d0-d02c75e04810", "vulnerability": {"vulnId": "CVE-2019-8446", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-30T02:00:00+02:00"}, "gcve": {"object_uuid": "1bbfdbb4-31b0-4c64-b7d0-d02c75e04810", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-30T00:00:00+00:00"}, "scope": {"notes": "The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation... | Affected: Atlassian / Jira | CVSS: 5.3 (MEDIUM) | EPSS: 0.1755 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-8446", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8446"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8446"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation...", "cve_id": "CVE-2019-8446", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira", "added_date": "2025-08-30T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.1755, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97052, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8446", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f0809a48-ec73-438a-a140-e32c1b37ed8d", "vulnerability": {"vulnId": "CVE-2023-43177", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-28T02:00:00+02:00"}, "gcve": {"object_uuid": "f0809a48-ec73-438a-a140-e32c1b37ed8d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-28T00:00:00+00:00"}, "scope": {"notes": "CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes. | Affected: CrushFTP / CrushFTP | CVSS: 9.8 (CRITICAL) | EPSS: 0.81801 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-43177", "url": "https://www.cve.org/CVERecord?id=CVE-2023-43177"}, {"id": "GHSA-6WMG-7VXW-42FX", "url": "https://github.com/advisories/GHSA-6WMG-7VXW-42FX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-43177"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.", "cve_id": "CVE-2023-43177", "vendor": "CrushFTP", "ghsa_id": "GHSA-6WMG-7VXW-42FX", "product": "CrushFTP", "added_date": "2025-08-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.81801, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99638, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-43177", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f5f109e7-2920-47b7-a574-f971cde01199", "vulnerability": {"vulnId": "CVE-2020-7209", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-28T02:00:00+02:00"}, "gcve": {"object_uuid": "f5f109e7-2920-47b7-a574-f971cde01199", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-28T00:00:00+00:00"}, "scope": {"notes": "LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Affected: Hewlett Packard / LinuxKI | CVSS: 9.8 (CRITICAL) | EPSS: 0.98751 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-7209", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7209"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-7209"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.", "cve_id": "CVE-2020-7209", "vendor": "Hewlett Packard", "ghsa_id": null, "product": "LinuxKI", "added_date": "2025-08-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98751, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99925, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-7209", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3f5c363e-5bcc-40c0-bde6-2c806c9ae339", "vulnerability": {"vulnId": "CVE-2024-13982", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-27T23:26:56+02:00"}, "gcve": {"object_uuid": "3f5c363e-5bcc-40c0-bde6-2c806c9ae339", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-27T21:26:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-27T21:26:56+00:00"}, "scope": {"notes": "SPON IP Network Intercom System rj_get_token.php Arbitrary File Read | Affected: Changsha SPON Communication Technology / SPON IP Network Broadcast System | CVSS: 8.7 (HIGH) | EPSS: 0.01056 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-13982", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13982"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13982"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SPON IP Network Intercom System rj_get_token.php Arbitrary File Read", "cve_id": "CVE-2024-13982", "vendor": "Changsha SPON Communication Technology", "ghsa_id": null, "product": "SPON IP Network Broadcast System", "added_date": "2025-08-27T21:26:56.000Z", "cvss_score": 8.7, "epss_score": 0.01056, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63162, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13982", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3984ef79-fa15-4568-b789-304019c66e4f", "vulnerability": {"vulnId": "CVE-2023-7308", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-27T23:26:35+02:00"}, "gcve": {"object_uuid": "3984ef79-fa15-4568-b789-304019c66e4f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-27T21:26:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-27T21:26:35+00:00"}, "scope": {"notes": "SecGate3600 Firewall Information Disclosure via authManageSet.cgi | Affected: NSFOCUS / SecGate3600 Firewall | CVSS: 8.7 (HIGH) | EPSS: 0.07476 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7308", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7308"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7308"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SecGate3600 Firewall Information Disclosure via authManageSet.cgi", "cve_id": "CVE-2023-7308", "vendor": "NSFOCUS", "ghsa_id": null, "product": "SecGate3600 Firewall", "added_date": "2025-08-27T21:26:35.000Z", "cvss_score": 8.7, "epss_score": 0.07476, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94288, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7308", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c58a4a19-83ab-49ee-8503-06f6646bd366", "vulnerability": {"vulnId": "CVE-2023-7307", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-27T23:26:14+02:00"}, "gcve": {"object_uuid": "c58a4a19-83ab-49ee-8503-06f6646bd366", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-27T21:26:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-27T21:26:14+00:00"}, "scope": {"notes": "Sangfor Behavior Management System XML External Entity Injection | Affected: Sangfor / Sangfor Behavior Management System (DC Management System) | CVSS: 8.7 (HIGH) | EPSS: 0.00517 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-7307", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7307"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7307"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sangfor Behavior Management System XML External Entity Injection", "cve_id": "CVE-2023-7307", "vendor": "Sangfor", "ghsa_id": null, "product": "Sangfor Behavior Management System (DC Management System)", "added_date": "2025-08-27T21:26:14.000Z", "cvss_score": 8.7, "epss_score": 0.00517, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.41811, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7307", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b0fa7b0a-c010-4266-ba87-96b6a0d6e6a7", "vulnerability": {"vulnId": "CVE-2024-13984", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-27T23:25:52+02:00"}, "gcve": {"object_uuid": "b0fa7b0a-c010-4266-ba87-96b6a0d6e6a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-27T21:25:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-27T21:25:52+00:00"}, "scope": {"notes": "Qi'anxin TianQing Management Center rptsvr Arbitrary File Upload | Affected: Qi'anxin / TianQing Management Center | CVSS: 10.0 (CRITICAL) | EPSS: 0.0082 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-13984", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13984"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13984"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Qi'anxin TianQing Management Center rptsvr Arbitrary File Upload", "cve_id": "CVE-2024-13984", "vendor": "Qi'anxin", "ghsa_id": null, "product": "TianQing Management Center", "added_date": "2025-08-27T21:25:52.000Z", "cvss_score": 10.0, "epss_score": 0.0082, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5567, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13984", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "52d6bb52-6749-402c-abbd-72901e8336a4", "vulnerability": {"vulnId": "CVE-2024-13981", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-27T23:25:29+02:00"}, "gcve": {"object_uuid": "52d6bb52-6749-402c-abbd-72901e8336a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-27T21:25:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-27T21:25:29+00:00"}, "scope": {"notes": "LiveBos UploadFile.do Arbitrary File Upload | Affected: Fujian Apex Software / LiveBOS | CVSS: 10.0 (CRITICAL) | EPSS: 0.00904 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-13981", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13981"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13981"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LiveBos UploadFile.do Arbitrary File Upload", "cve_id": "CVE-2024-13981", "vendor": "Fujian Apex Software", "ghsa_id": null, "product": "LiveBOS", "added_date": "2025-08-27T21:25:29.000Z", "cvss_score": 10.0, "epss_score": 0.00904, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58351, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13981", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b4ab8bb2-1457-42eb-903f-a4868e9fdf4f", "vulnerability": {"vulnId": "CVE-2022-40022", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "b4ab8bb2-1457-42eb-903f-a4868e9fdf4f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-22T00:00:00+00:00"}, "scope": {"notes": "Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. | Affected: Microchip / SyncServer S650 | CVSS: 9.8 (CRITICAL) | EPSS: 0.92472 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-40022", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40022"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40022"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.", "cve_id": "CVE-2022-40022", "vendor": "Microchip", "ghsa_id": null, "product": "SyncServer S650", "added_date": "2025-08-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.92472, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99823, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40022", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e4f98873-38ba-4df3-bdc0-f4e593268d40", "vulnerability": {"vulnId": "CVE-2023-45038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "e4f98873-38ba-4df3-bdc0-f4e593268d40", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-21T00:00:00+00:00"}, "scope": {"notes": "Music Station | Affected: QNAP / Music Station | CVSS: 4.3 (MEDIUM) | EPSS: 0.01243 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-45038", "url": "https://www.cve.org/CVERecord?id=CVE-2023-45038"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-45038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Music Station", "cve_id": "CVE-2023-45038", "vendor": "QNAP", "ghsa_id": null, "product": "Music Station", "added_date": "2025-08-21T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.01243, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6814, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-45038", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d0fd7c93-b307-46b2-8fa4-ae420bbc1c8a", "vulnerability": {"vulnId": "CVE-2021-22053", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "d0fd7c93-b307-46b2-8fa4-ae420bbc1c8a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-21T00:00:00+00:00"}, "scope": {"notes": "Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within... | Affected: VMware / Spring Cloud Netflix Hystrix Dashboard | CVSS: 8.8 (HIGH) | EPSS: 0.13235 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-22053", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22053"}, {"id": "GHSA-GX3F-HQ7P-8FXV", "url": "https://github.com/advisories/GHSA-GX3F-HQ7P-8FXV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22053"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within...", "cve_id": "CVE-2021-22053", "vendor": "VMware", "ghsa_id": "GHSA-GX3F-HQ7P-8FXV", "product": "Spring Cloud Netflix Hystrix Dashboard", "added_date": "2025-08-21T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.13235, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96268, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22053", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b709f3e1-3732-483b-9806-d5333a209e3c", "vulnerability": {"vulnId": "CVE-2014-2321", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-20T02:00:00+02:00"}, "gcve": {"object_uuid": "b709f3e1-3732-483b-9806-d5333a209e3c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-20T00:00:00+00:00"}, "scope": {"notes": "web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated... | Affected: ZTE / F460 and F660 cable modems | CVSS: 10.0 (HIGH) | EPSS: 0.59259 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-2321", "url": "https://www.cve.org/CVERecord?id=CVE-2014-2321"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-2321"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated...", "cve_id": "CVE-2014-2321", "vendor": "ZTE", "ghsa_id": null, "product": "F460 and F660 cable modems", "added_date": "2025-08-20T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.59259, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99092, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-2321", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "36449ae7-6410-4c13-ac73-27927b70348c", "vulnerability": {"vulnId": "CVE-2024-7029", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-20T02:00:00+02:00"}, "gcve": {"object_uuid": "36449ae7-6410-4c13-ac73-27927b70348c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-20T00:00:00+00:00"}, "scope": {"notes": "Command Injection in AVTech AVM1203 (IP Camera) | Affected: AVTech / AVM1203 (IP Camera) | CVSS: 8.7 (HIGH) | EPSS: 0.38998 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7029", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7029"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7029"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection in AVTech AVM1203 (IP Camera)", "cve_id": "CVE-2024-7029", "vendor": "AVTech", "ghsa_id": null, "product": "AVM1203 (IP Camera)", "added_date": "2025-08-20T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.38998, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9855, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7029", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e9e64d8b-1e07-4804-a67a-ff126977a03f", "vulnerability": {"vulnId": "CVE-2019-12593", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-20T02:00:00+02:00"}, "gcve": {"object_uuid": "e9e64d8b-1e07-4804-a67a-ff126977a03f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-20T00:00:00+00:00"}, "scope": {"notes": "IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory... | Affected: IceWarp / IceWarp Mail Server | CVSS: 7.5 (HIGH) | EPSS: 0.40965 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12593", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12593"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12593"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory...", "cve_id": "CVE-2019-12593", "vendor": "IceWarp", "ghsa_id": null, "product": "IceWarp Mail Server", "added_date": "2025-08-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.40965, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98619, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12593", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "945f508c-53d0-422c-94dc-e8ac561b1398", "vulnerability": {"vulnId": "CVE-2020-2507", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-16T02:00:00+02:00"}, "gcve": {"object_uuid": "945f508c-53d0-422c-94dc-e8ac561b1398", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-16T00:00:00+00:00"}, "scope": {"notes": "command injection vulnerability in Helpdesk | Affected: QNAP / Helpdesk | CVSS: 9.8 (CRITICAL) | EPSS: 0.03042 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-2507", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2507"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2507"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "command injection vulnerability in Helpdesk", "cve_id": "CVE-2020-2507", "vendor": "QNAP", "ghsa_id": null, "product": "Helpdesk", "added_date": "2025-08-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03042, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87061, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-2507", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8ef2ac9a-be1e-4093-abcd-01732913c05b", "vulnerability": {"vulnId": "CVE-2024-7339", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-15T02:00:00+02:00"}, "gcve": {"object_uuid": "8ef2ac9a-be1e-4093-abcd-01732913c05b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-15T00:00:00+00:00"}, "scope": {"notes": "TVT DVR TD-2104TS-CL queryDevInfo information disclosure | Affected: TVT / DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM), AVISION DVR AV108T | CVSS: 6.9 (MEDIUM) | EPSS: 0.32028 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7339", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7339"}, {"id": "GHSA-VCQX-95XM-6XH4", "url": "https://github.com/advisories/GHSA-VCQX-95XM-6XH4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7339"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TVT DVR TD-2104TS-CL queryDevInfo information disclosure", "cve_id": "CVE-2024-7339", "vendor": "TVT", "ghsa_id": "GHSA-VCQX-95XM-6XH4", "product": "DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM), AVISION DVR AV108T", "added_date": "2025-08-15T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.32028, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98262, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7339", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "13e41e1c-622b-4e89-957a-a84f3f34b18b", "vulnerability": {"vulnId": "CVE-2025-25231", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-11T20:12:49+02:00"}, "gcve": {"object_uuid": "13e41e1c-622b-4e89-957a-a84f3f34b18b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-11T18:12:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-11T18:12:49+00:00"}, "scope": {"notes": "Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability.\u00a0A malicious actor may be able to gain access to sensitive... | Affected: Omnissa / Omnissa Workspace ONE UEM | CVSS: 7.5 (HIGH) | EPSS: 0.22294 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-25231", "url": "https://www.cve.org/CVERecord?id=CVE-2025-25231"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-25231"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability.\u00a0A malicious actor may be able to gain access to sensitive...", "cve_id": "CVE-2025-25231", "vendor": "Omnissa", "ghsa_id": null, "product": "Omnissa Workspace ONE UEM", "added_date": "2025-08-11T18:12:49.000Z", "cvss_score": 7.5, "epss_score": 0.22294, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97619, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-25231", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d7eefa01-af23-4038-a85a-6dff36263b1b", "vulnerability": {"vulnId": "CVE-2025-8829", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-11T06:02:05+02:00"}, "gcve": {"object_uuid": "d7eefa01-af23-4038-a85a-6dff36263b1b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-11T04:02:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-11T04:02:05+00:00"}, "scope": {"notes": "Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection | Affected: Linksys / RE6250, RE6300, RE6350, RE6500, RE7000, RE9000 | CVSS: 5.3 (MEDIUM) | EPSS: 0.06814 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-8829", "url": "https://www.cve.org/CVERecord?id=CVE-2025-8829"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-8829"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_setBasicAuto um_red os command injection", "cve_id": "CVE-2025-8829", "vendor": "Linksys", "ghsa_id": null, "product": "RE6250, RE6300, RE6350, RE6500, RE7000, RE9000", "added_date": "2025-08-11T04:02:05.000Z", "cvss_score": 5.3, "epss_score": 0.06814, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93815, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-8829", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "989c6b45-dbdd-41b3-ab94-c207f4382738", "vulnerability": {"vulnId": "CVE-2018-1217", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-09T02:00:00+02:00"}, "gcve": {"object_uuid": "989c6b45-dbdd-41b3-ab94-c207f4382738", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-09T00:00:00+00:00"}, "scope": {"notes": "Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is... | Affected: Dell EMC / Avamar, Integrated Data Protection Appliance | CVSS: 9.8 (CRITICAL) | EPSS: 0.50874 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-1217", "url": "https://www.cve.org/CVERecord?id=CVE-2018-1217"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-1217"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is...", "cve_id": "CVE-2018-1217", "vendor": "Dell EMC", "ghsa_id": null, "product": "Avamar, Integrated Data Protection Appliance", "added_date": "2025-08-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.50874, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98895, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-1217", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8349f69e-324f-46cb-b3a2-524f9a246567", "vulnerability": {"vulnId": "CVE-2025-34152", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-07T18:44:59+02:00"}, "gcve": {"object_uuid": "8349f69e-324f-46cb-b3a2-524f9a246567", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-07T16:44:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-07T16:44:59+00:00"}, "scope": {"notes": "Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter | Affected: Shenzhen Aitemi E Commerce / M300 Wi-Fi Repeater | CVSS: 9.4 (CRITICAL) | EPSS: 0.86839 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34152", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34152"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34152"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter", "cve_id": "CVE-2025-34152", "vendor": "Shenzhen Aitemi E Commerce", "ghsa_id": null, "product": "M300 Wi-Fi Repeater", "added_date": "2025-08-07T16:44:59.000Z", "cvss_score": 9.4, "epss_score": 0.86839, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99741, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34152", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "37229ecf-1c33-4450-80b3-351d2540252c", "vulnerability": {"vulnId": "CVE-2019-8442", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-07T02:00:00+02:00"}, "gcve": {"object_uuid": "37229ecf-1c33-4450-80b3-351d2540252c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-07T00:00:00+00:00"}, "scope": {"notes": "The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0... | Affected: Atlassian / Jira | CVSS: 7.5 (HIGH) | EPSS: 0.59832 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-8442", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8442"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8442"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0...", "cve_id": "CVE-2019-8442", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira", "added_date": "2025-08-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.59832, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99106, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8442", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bd3c2f24-2d09-4a26-9e5f-a32a23f6a4bb", "vulnerability": {"vulnId": "CVE-2017-1000028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-07T02:00:00+02:00"}, "gcve": {"object_uuid": "bd3c2f24-2d09-4a26-9e5f-a32a23f6a4bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-07T00:00:00+00:00"}, "scope": {"notes": "Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that... | Affected: Oracle / GlassFish Server Open Source Edition | CVSS: 7.5 (HIGH) | EPSS: 0.99479 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-1000028", "url": "https://www.cve.org/CVERecord?id=CVE-2017-1000028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-1000028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that...", "cve_id": "CVE-2017-1000028", "vendor": "Oracle", "ghsa_id": null, "product": "GlassFish Server Open Source Edition", "added_date": "2025-08-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99479, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99944, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-1000028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c861b789-9cec-4820-972e-01a74c7054a3", "vulnerability": {"vulnId": "CVE-2025-54254", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-05T18:53:39+02:00"}, "gcve": {"object_uuid": "c861b789-9cec-4820-972e-01a74c7054a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-05T16:53:39+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-05T16:53:39+00:00"}, "scope": {"notes": "Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) | Affected: Adobe / Adobe Experience Manager | CVSS: 8.6 (HIGH) | EPSS: 0.77463 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-54254", "url": "https://www.cve.org/CVERecord?id=CVE-2025-54254"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-54254"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)", "cve_id": "CVE-2025-54254", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Experience Manager", "added_date": "2025-08-05T16:53:39.000Z", "cvss_score": 8.6, "epss_score": 0.77463, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99547, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-54254", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "205a94b8-876e-4f6e-b907-aeff42a33945", "vulnerability": {"vulnId": "CVE-2022-28219", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-04T02:00:00+02:00"}, "gcve": {"object_uuid": "205a94b8-876e-4f6e-b907-aeff42a33945", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-04T00:00:00+00:00"}, "scope": {"notes": "Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | Affected: Zoho / ManageEngine ADAudit Plus | CVSS: 9.8 (CRITICAL) | EPSS: 0.97193 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28219", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28219"}, {"id": "GHSA-CGV8-9R56-PQQH", "url": "https://github.com/advisories/GHSA-CGV8-9R56-PQQH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28219"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.", "cve_id": "CVE-2022-28219", "vendor": "Zoho", "ghsa_id": "GHSA-CGV8-9R56-PQQH", "product": "ManageEngine ADAudit Plus", "added_date": "2025-08-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97193, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99894, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28219", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "94ffdf1a-05b6-43ba-92ca-607ac47a3d86", "vulnerability": {"vulnId": "CVE-2020-17506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-02T02:00:00+02:00"}, "gcve": {"object_uuid": "94ffdf1a-05b6-43ba-92ca-607ac47a3d86", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-02T00:00:00+00:00"}, "scope": {"notes": "Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL... | Affected: Artica / Web Proxy | CVSS: 9.8 (CRITICAL) | EPSS: 0.93967 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-17506", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL...", "cve_id": "CVE-2020-17506", "vendor": "Artica", "ghsa_id": null, "product": "Web Proxy", "added_date": "2025-08-02T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93967, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99844, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7269042f-25cd-459d-912d-5c646ba4eda2", "vulnerability": {"vulnId": "CVE-2025-30220", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-02T02:00:00+02:00"}, "gcve": {"object_uuid": "7269042f-25cd-459d-912d-5c646ba4eda2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-02T00:00:00+00:00"}, "scope": {"notes": "GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling | Affected: Geoserver / geoserver | CVSS: 9.9 (CRITICAL) | EPSS: 0.42285 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-30220", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30220"}, {"id": "GHSA-JJ54-8F66-C5PC", "url": "https://github.com/advisories/GHSA-JJ54-8F66-C5PC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30220"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling", "cve_id": "CVE-2025-30220", "vendor": "Geoserver", "ghsa_id": "GHSA-JJ54-8F66-C5PC", "product": "geoserver", "added_date": "2025-08-02T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.42285, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98659, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30220", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "11936a93-d50a-4e0e-b027-9ae7bcc71bd7", "vulnerability": {"vulnId": "CVE-2022-26833", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "11936a93-d50a-4e0e-b027-9ae7bcc71bd7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A... | Affected: Open Automation Software / OAS Platform | CVSS: 9.4 (CRITICAL) | EPSS: 0.37639 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-26833", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26833"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26833"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A...", "cve_id": "CVE-2022-26833", "vendor": "Open Automation Software", "ghsa_id": null, "product": "OAS Platform", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.37639, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98496, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26833", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0e7f853b-d718-403b-90c6-788cd6a0127f", "vulnerability": {"vulnId": "CVE-2025-34027", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "0e7f853b-d718-403b-90c6-788cd6a0127f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "Versa Concerto Authentication Bypass File Write Remote Code Execution | Affected: Versa / Concerto | CVSS: 10.0 (CRITICAL) | EPSS: 0.4522 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34027", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34027"}, {"id": "GHSA-96GF-3RQF-C8M9", "url": "https://github.com/advisories/GHSA-96GF-3RQF-C8M9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34027"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Versa Concerto Authentication Bypass File Write Remote Code Execution", "cve_id": "CVE-2025-34027", "vendor": "Versa", "ghsa_id": "GHSA-96GF-3RQF-C8M9", "product": "Concerto", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.4522, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98749, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34027", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "208be6f6-5e08-4750-9de0-c719af4b241e", "vulnerability": {"vulnId": "CVE-2024-48455", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "208be6f6-5e08-4750-9de0-c719af4b241e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327... | Affected: Netis / Wifi6 Router NX10, Wifi 11AC Router NC65, Wifi 11AC Router NC63, Wifi 11AC Router NC21, Wifi Router MW5360 | CVSS: 2.7 (LOW) | EPSS: 0.06427 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-48455", "url": "https://www.cve.org/CVERecord?id=CVE-2024-48455"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-48455"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327...", "cve_id": "CVE-2024-48455", "vendor": "Netis", "ghsa_id": null, "product": "Wifi6 Router NX10, Wifi 11AC Router NC65, Wifi 11AC Router NC63, Wifi 11AC Router NC21, Wifi Router MW5360", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 2.7, "epss_score": 0.06427, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93495, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-48455", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0db7a9b8-21f2-4b86-9068-5245925bc00f", "vulnerability": {"vulnId": "CVE-2023-6023", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "0db7a9b8-21f2-4b86-9068-5245925bc00f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "ModelDB Local File Include | Affected: Vertaai / vertaai/modeldb | CVSS: 8.6 (HIGH) | EPSS: 0.02975 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6023", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6023"}, {"id": "GHSA-QR8V-2MXV-XRJ9", "url": "https://github.com/advisories/GHSA-QR8V-2MXV-XRJ9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6023"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ModelDB Local File Include", "cve_id": "CVE-2023-6023", "vendor": "Vertaai", "ghsa_id": "GHSA-QR8V-2MXV-XRJ9", "product": "vertaai/modeldb", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.02975, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86782, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6023", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "155e29a5-91ab-495a-bd84-ac0b4f1b95a2", "vulnerability": {"vulnId": "CVE-2018-12296", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "155e29a5-91ab-495a-bd84-ac0b4f1b95a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information... | Affected: Seagate / NAS OS | CVSS: 7.5 (HIGH) | EPSS: 0.11337 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-12296", "url": "https://www.cve.org/CVERecord?id=CVE-2018-12296"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-12296"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information...", "cve_id": "CVE-2018-12296", "vendor": "Seagate", "ghsa_id": null, "product": "NAS OS", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.11337, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9586, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-12296", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3e8cb95a-dc5d-43a3-be81-d52b385a6ff4", "vulnerability": {"vulnId": "CVE-2019-20074", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "3e8cb95a-dc5d-43a3-be81-d52b385a6ff4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. | Affected: Netis / DL4323 | CVSS: 8.8 (HIGH) | EPSS: 0.01399 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-20074", "url": "https://www.cve.org/CVERecord?id=CVE-2019-20074"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-20074"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.", "cve_id": "CVE-2019-20074", "vendor": "Netis", "ghsa_id": null, "product": "DL4323", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.01399, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71482, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-20074", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a287f53f-4cd3-47b2-88e7-be603570f47e", "vulnerability": {"vulnId": "CVE-2024-50967", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-08-01T02:00:00+02:00"}, "gcve": {"object_uuid": "a287f53f-4cd3-47b2-88e7-be603570f47e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-08-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-08-01T00:00:00+00:00"}, "scope": {"notes": "The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely... | Affected: Becon / DATAGerry | CVSS: 6.5 (MEDIUM) | EPSS: 0.01677 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-50967", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50967"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50967"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely...", "cve_id": "CVE-2024-50967", "vendor": "Becon", "ghsa_id": null, "product": "DATAGerry", "added_date": "2025-08-01T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.01677, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76035, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-50967", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a991b333-d3fc-406f-9031-d6f73657472d", "vulnerability": {"vulnId": "CVE-2025-5394", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-31T10:05:53+02:00"}, "gcve": {"object_uuid": "a991b333-d3fc-406f-9031-d6f73657472d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-31T08:05:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-31T08:05:53+00:00"}, "scope": {"notes": "Alone \u2013 Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation | Affected: Bearsthemes / Alone \u2013 Charity Multipurpose Non-profit WordPress Theme | CVSS: 9.8 (CRITICAL) | EPSS: 0.52758 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-5394", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5394"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5394"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Alone \u2013 Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation", "cve_id": "CVE-2025-5394", "vendor": "Bearsthemes", "ghsa_id": null, "product": "Alone \u2013 Charity Multipurpose Non-profit WordPress Theme", "added_date": "2025-07-31T08:05:53.000Z", "cvss_score": 9.8, "epss_score": 0.52758, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5394", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "330bca7c-c492-4414-94a1-9941b3a68913", "vulnerability": {"vulnId": "CVE-2022-47075", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-31T02:00:00+02:00"}, "gcve": {"object_uuid": "330bca7c-c492-4414-94a1-9941b3a68913", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-31T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to... | Affected: Smart Office / Smart Office Web | CVSS: 7.5 (HIGH) | EPSS: 0.59407 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-47075", "url": "https://www.cve.org/CVERecord?id=CVE-2022-47075"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-47075"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to...", "cve_id": "CVE-2022-47075", "vendor": "Smart Office", "ghsa_id": null, "product": "Smart Office Web", "added_date": "2025-07-31T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.59407, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99096, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-47075", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "69aa2b51-fa31-4296-85d5-7db896d48d5b", "vulnerability": {"vulnId": "CVE-2022-1026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-31T02:00:00+02:00"}, "gcve": {"object_uuid": "69aa2b51-fa31-4296-85d5-7db896d48d5b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-31T00:00:00+00:00"}, "scope": {"notes": "Kyocera Net View Address Book Exposure | Affected: Kyocera / Multifunction Printer Net Viewer | CVSS: 8.6 (HIGH) | EPSS: 0.14733 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1026", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1026"}, {"id": "GHSA-4CGP-8JR7-7X94", "url": "https://github.com/advisories/GHSA-4CGP-8JR7-7X94"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kyocera Net View Address Book Exposure", "cve_id": "CVE-2022-1026", "vendor": "Kyocera", "ghsa_id": "GHSA-4CGP-8JR7-7X94", "product": "Multifunction Printer Net Viewer", "added_date": "2025-07-31T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.14733, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96578, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "91fb63f0-f9e8-4832-b7a4-edd954c6e737", "vulnerability": {"vulnId": "CVE-2022-31656", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-31T02:00:00+02:00"}, "gcve": {"object_uuid": "91fb63f0-f9e8-4832-b7a4-edd954c6e737", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-31T00:00:00+00:00"}, "scope": {"notes": "VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.... | Affected: VMware / Workspace ONE Access, Identity Manager, vRealize Automation | CVSS: 9.8 (CRITICAL) | EPSS: 0.24338 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31656", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31656"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31656"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users....", "cve_id": "CVE-2022-31656", "vendor": "VMware", "ghsa_id": null, "product": "Workspace ONE Access, Identity Manager, vRealize Automation", "added_date": "2025-07-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.24338, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97801, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31656", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "84b0561f-3608-4ecd-ab98-875f105a8b52", "vulnerability": {"vulnId": "CVE-2022-45933", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-31T02:00:00+02:00"}, "gcve": {"object_uuid": "84b0561f-3608-4ecd-ab98-875f105a8b52", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-31T00:00:00+00:00"}, "scope": {"notes": "KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication,... | Affected: KubeView / KubeView | CVSS: 9.8 (CRITICAL) | EPSS: 0.51696 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-45933", "url": "https://www.cve.org/CVERecord?id=CVE-2022-45933"}, {"id": "GHSA-22VC-5PGW-644Q", "url": "https://github.com/advisories/GHSA-22VC-5PGW-644Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-45933"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication,...", "cve_id": "CVE-2022-45933", "vendor": "KubeView", "ghsa_id": "GHSA-22VC-5PGW-644Q", "product": "KubeView", "added_date": "2025-07-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.51696, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-45933", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2c1c55b3-2d3f-4fd8-b056-9ef560780b32", "vulnerability": {"vulnId": "CVE-2023-36144", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-31T02:00:00+02:00"}, "gcve": {"object_uuid": "2c1c55b3-2d3f-4fd8-b056-9ef560780b32", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-31T00:00:00+00:00"}, "scope": {"notes": "An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the... | Affected: Intelbras / Switch SG 2404 MR | CVSS: 7.5 (HIGH) | EPSS: 0.36507 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-36144", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36144"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36144"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the...", "cve_id": "CVE-2023-36144", "vendor": "Intelbras", "ghsa_id": null, "product": "Switch SG 2404 MR", "added_date": "2025-07-31T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.36507, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98448, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36144", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b95a7e41-e7f9-4ba2-ac1a-b527a87433b8", "vulnerability": {"vulnId": "CVE-2022-23961", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-30T02:00:00+02:00"}, "gcve": {"object_uuid": "b95a7e41-e7f9-4ba2-ac1a-b527a87433b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-30T00:00:00+00:00"}, "scope": {"notes": "In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by... | Affected: Thruk / Thruk Monitoring | CVSS: 6.1 (MEDIUM) | EPSS: 0.00201 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-23961", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23961"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23961"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by...", "cve_id": "CVE-2022-23961", "vendor": "Thruk", "ghsa_id": null, "product": "Thruk Monitoring", "added_date": "2025-07-30T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.00201, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.08951, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23961", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "797d8856-1c86-44cf-bfd3-7c2313790dd0", "vulnerability": {"vulnId": "CVE-2024-8181", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-30T02:00:00+02:00"}, "gcve": {"object_uuid": "797d8856-1c86-44cf-bfd3-7c2313790dd0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-30T00:00:00+00:00"}, "scope": {"notes": "Flowise Authentication Bypass | Affected: FlowiseAI / Flowise | CVSS: 9.8 (CRITICAL) | EPSS: 0.4505 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8181", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8181"}, {"id": "GHSA-2Q4W-X8H2-2FVH", "url": "https://github.com/advisories/GHSA-2Q4W-X8H2-2FVH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8181"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowise Authentication Bypass", "cve_id": "CVE-2024-8181", "vendor": "FlowiseAI", "ghsa_id": "GHSA-2Q4W-X8H2-2FVH", "product": "Flowise", "added_date": "2025-07-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.4505, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98745, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8181", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7ce1e1cf-11ce-43c8-bba2-a54f227d8ff7", "vulnerability": {"vulnId": "CVE-2025-41646", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-30T02:00:00+02:00"}, "gcve": {"object_uuid": "7ce1e1cf-11ce-43c8-bba2-a54f227d8ff7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-30T00:00:00+00:00"}, "scope": {"notes": "RevPi Webstatus application is vulnerable to an authentication bypass | Affected: Kunbus / Revolution Pi webstatus | CVSS: 9.8 (CRITICAL) | EPSS: 0.51267 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-41646", "url": "https://www.cve.org/CVERecord?id=CVE-2025-41646"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-41646"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "RevPi Webstatus application is vulnerable to an authentication bypass", "cve_id": "CVE-2025-41646", "vendor": "Kunbus", "ghsa_id": null, "product": "Revolution Pi webstatus", "added_date": "2025-07-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.51267, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-41646", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "10d344ae-4a68-4094-934c-6ba81aa593e0", "vulnerability": {"vulnId": "CVE-2020-11991", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "10d344ae-4a68-4094-934c-6ba81aa593e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-29T00:00:00+00:00"}, "scope": {"notes": "When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to... | Affected: Apache / Cocoon | CVSS: 7.5 (HIGH) | EPSS: 0.72456 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11991", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11991"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11991"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to...", "cve_id": "CVE-2020-11991", "vendor": "Apache", "ghsa_id": null, "product": "Cocoon", "added_date": "2025-07-29T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.72456, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99426, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11991", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dd621e38-6c2e-471a-bca1-6c577e9bad98", "vulnerability": {"vulnId": "CVE-2023-45852", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "dd621e38-6c2e-471a-bca1-6c577e9bad98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-29T00:00:00+00:00"}, "scope": {"notes": "In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell... | Affected: Viessmann / Vitogate 300 | CVSS: 9.8 (CRITICAL) | EPSS: 0.14003 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-45852", "url": "https://www.cve.org/CVERecord?id=CVE-2023-45852"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-45852"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell...", "cve_id": "CVE-2023-45852", "vendor": "Viessmann", "ghsa_id": null, "product": "Vitogate 300", "added_date": "2025-07-29T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14003, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96446, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-45852", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d9e415b8-d15e-4172-a513-b9b9f6a9a811", "vulnerability": {"vulnId": "CVE-2023-30258", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "d9e415b8-d15e-4172-a513-b9b9f6a9a811", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-29T00:00:00+00:00"}, "scope": {"notes": "Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated... | Affected: MagnusSolution / magnusbilling | CVSS: 9.8 (CRITICAL) | EPSS: 0.9425 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-30258", "url": "https://www.cve.org/CVERecord?id=CVE-2023-30258"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-30258"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated...", "cve_id": "CVE-2023-30258", "vendor": "MagnusSolution", "ghsa_id": null, "product": "magnusbilling", "added_date": "2025-07-29T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9425, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99849, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-30258", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "73a269e0-c7aa-4d65-b891-16c47c707139", "vulnerability": {"vulnId": "CVE-2023-34993", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "73a269e0-c7aa-4d65-b891-16c47c707139", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-29T00:00:00+00:00"}, "scope": {"notes": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and... | Affected: Fortinet / FortiWLM | CVSS: 9.6 (CRITICAL) | EPSS: 0.18148 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34993", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34993"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34993"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and...", "cve_id": "CVE-2023-34993", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiWLM", "added_date": "2025-07-29T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.18148, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97119, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34993", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e04fdfa4-0fc5-4eee-a28a-116d317f1a55", "vulnerability": {"vulnId": "CVE-2023-35844", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-27T02:00:00+02:00"}, "gcve": {"object_uuid": "e04fdfa4-0fc5-4eee-a28a-116d317f1a55", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-27T00:00:00+00:00"}, "scope": {"notes": "packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure... | Affected: Lightdash / Lightdash | CVSS: 7.5 (HIGH) | EPSS: 0.06344 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-35844", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35844"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35844"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure...", "cve_id": "CVE-2023-35844", "vendor": "Lightdash", "ghsa_id": null, "product": "Lightdash", "added_date": "2025-07-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.06344, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93427, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35844", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "99657af1-7a4e-47eb-a829-872dc197d36f", "vulnerability": {"vulnId": "CVE-2021-21479", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-27T02:00:00+02:00"}, "gcve": {"object_uuid": "99657af1-7a4e-47eb-a829-872dc197d36f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-27T00:00:00+00:00"}, "scope": {"notes": "In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the... | Affected: SAP SE / SCIMono | CVSS: 9.1 (CRITICAL) | EPSS: 0.10116 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21479", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21479"}, {"id": "GHSA-29Q4-GXJQ-RX5C", "url": "https://github.com/advisories/GHSA-29Q4-GXJQ-RX5C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21479"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the...", "cve_id": "CVE-2021-21479", "vendor": "SAP SE", "ghsa_id": "GHSA-29Q4-GXJQ-RX5C", "product": "SCIMono", "added_date": "2025-07-27T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.10116, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9551, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21479", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b8bcce2c-b893-4013-8431-61f58c8eb659", "vulnerability": {"vulnId": "CVE-2019-18393", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-27T02:00:00+02:00"}, "gcve": {"object_uuid": "b8bcce2c-b893-4013-8431-61f58c8eb659", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-27T00:00:00+00:00"}, "scope": {"notes": "PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory,... | Affected: Ignite Realtime / Openfire | CVSS: 5.3 (MEDIUM) | EPSS: 0.13945 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-18393", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18393"}, {"id": "GHSA-59H8-H34R-Q9CV", "url": "https://github.com/advisories/GHSA-59H8-H34R-Q9CV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18393"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory,...", "cve_id": "CVE-2019-18393", "vendor": "Ignite Realtime", "ghsa_id": "GHSA-59H8-H34R-Q9CV", "product": "Openfire", "added_date": "2025-07-27T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.13945, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96434, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18393", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "adcd58f0-735d-49d3-8e56-68e367f86ffb", "vulnerability": {"vulnId": "CVE-2021-21087", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-26T02:00:00+02:00"}, "gcve": {"object_uuid": "adcd58f0-735d-49d3-8e56-68e367f86ffb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-26T00:00:00+00:00"}, "scope": {"notes": "ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser | Affected: Adobe / ColdFusion | CVSS: 5.4 (MEDIUM) | EPSS: 0.37095 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21087", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21087"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21087"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ColdFusion Improper neutralization of web input during page generation could lead to arbitrary JavaScript execution in the browser", "cve_id": "CVE-2021-21087", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2025-07-26T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.37095, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98475, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21087", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ca69f55f-137d-41df-8284-8eb2d396155d", "vulnerability": {"vulnId": "CVE-2022-21500", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-26T02:00:00+02:00"}, "gcve": {"object_uuid": "ca69f55f-137d-41df-8284-8eb2d396155d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-26T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable... | Affected: Oracle / User Management | CVSS: 7.5 (HIGH) | EPSS: 0.71703 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-21500", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21500"}, {"id": "GHSA-VF87-8CH9-X7HF", "url": "https://github.com/advisories/GHSA-VF87-8CH9-X7HF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21500"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable...", "cve_id": "CVE-2022-21500", "vendor": "Oracle", "ghsa_id": "GHSA-VF87-8CH9-X7HF", "product": "User Management", "added_date": "2025-07-26T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.71703, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99406, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21500", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ed87d0c8-d96a-492b-83b9-f11b1e0ec199", "vulnerability": {"vulnId": "CVE-2016-0457", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-26T02:00:00+02:00"}, "gcve": {"object_uuid": "ed87d0c8-d96a-492b-83b9-f11b1e0ec199", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-26T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote... | Affected: Oracle / E-Business Suite | CVSS: 5.0 (MEDIUM) | EPSS: 0.03814 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-0457", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0457"}, {"id": "GHSA-HX29-457G-G6VV", "url": "https://github.com/advisories/GHSA-HX29-457G-G6VV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0457"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote...", "cve_id": "CVE-2016-0457", "vendor": "Oracle", "ghsa_id": "GHSA-HX29-457G-G6VV", "product": "E-Business Suite", "added_date": "2025-07-26T00:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.03814, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89715, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0457", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "65445778-c801-4893-b602-8caf4231a832", "vulnerability": {"vulnId": "CVE-2021-43287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-26T02:00:00+02:00"}, "gcve": {"object_uuid": "65445778-c801-4893-b602-8caf4231a832", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-26T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to... | Affected: ThoughtWorks / GoCD | CVSS: 7.5 (HIGH) | EPSS: 0.2736 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-43287", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43287"}, {"id": "GHSA-4X25-WQ2V-85F9", "url": "https://github.com/advisories/GHSA-4X25-WQ2V-85F9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to...", "cve_id": "CVE-2021-43287", "vendor": "ThoughtWorks", "ghsa_id": "GHSA-4X25-WQ2V-85F9", "product": "GoCD", "added_date": "2025-07-26T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.2736, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98005, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-43287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "45d8a35e-1b34-4a1f-9be9-c2c0c9928458", "vulnerability": {"vulnId": "CVE-2019-18371", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-25T02:00:00+02:00"}, "gcve": {"object_uuid": "45d8a35e-1b34-4a1f-9be9-c2c0c9928458", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-25T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files... | Affected: Xiaomi / Mi WiFi R3G | CVSS: 7.5 (HIGH) | EPSS: 0.55872 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-18371", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18371"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18371"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerability to read arbitrary files...", "cve_id": "CVE-2019-18371", "vendor": "Xiaomi", "ghsa_id": null, "product": "Mi WiFi R3G", "added_date": "2025-07-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.55872, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99017, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18371", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "70345409-a2af-4f62-b49c-95ef51c859ec", "vulnerability": {"vulnId": "CVE-2020-26073", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-24T02:00:00+02:00"}, "gcve": {"object_uuid": "70345409-a2af-4f62-b49c-95ef51c859ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-24T00:00:00+00:00"}, "scope": {"notes": "Cisco SD-WAN vManage Directory Traversal Vulnerability | Affected: Cisco / Cisco Catalyst SD-WAN Manager | CVSS: 7.5 (HIGH) | EPSS: 0.12583 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-26073", "url": "https://www.cve.org/CVERecord?id=CVE-2020-26073"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-26073"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco SD-WAN vManage Directory Traversal Vulnerability", "cve_id": "CVE-2020-26073", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Catalyst SD-WAN Manager", "added_date": "2025-07-24T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.12583, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9612, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-26073", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1aa68efd-2f90-48af-ab96-67f02587b01b", "vulnerability": {"vulnId": "CVE-2024-10586", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-24T02:00:00+02:00"}, "gcve": {"object_uuid": "1aa68efd-2f90-48af-ab96-67f02587b01b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-24T00:00:00+00:00"}, "scope": {"notes": "Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation | Affected: Eugen Bobrowski / Debug Tool | CVSS: 9.8 (CRITICAL) | EPSS: 0.02145 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-10586", "url": "https://www.cve.org/CVERecord?id=CVE-2024-10586"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-10586"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation", "cve_id": "CVE-2024-10586", "vendor": "Eugen Bobrowski", "ghsa_id": null, "product": "Debug Tool", "added_date": "2025-07-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.02145, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8141, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-10586", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5a761713-a844-48bc-8155-ee1783a685a9", "vulnerability": {"vulnId": "CVE-2024-46938", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-24T02:00:00+02:00"}, "gcve": {"object_uuid": "5a761713-a844-48bc-8155-ee1783a685a9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-24T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through... | Affected: Sitecore / Experience Platform, Experience Manager, Experience Commerce | CVSS: 7.5 (HIGH) | EPSS: 0.46767 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-46938", "url": "https://www.cve.org/CVERecord?id=CVE-2024-46938"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-46938"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through...", "cve_id": "CVE-2024-46938", "vendor": "Sitecore", "ghsa_id": null, "product": "Experience Platform, Experience Manager, Experience Commerce", "added_date": "2025-07-24T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.46767, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9879, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-46938", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b8dbd3b1-e8e5-42a9-8524-b50d13812d0d", "vulnerability": {"vulnId": "CVE-2022-23347", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-23T02:00:00+02:00"}, "gcve": {"object_uuid": "b8dbd3b1-e8e5-42a9-8524-b50d13812d0d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-23T00:00:00+00:00"}, "scope": {"notes": "BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. | Affected: BigAnt Software / BigAnt Server | CVSS: 7.5 (HIGH) | EPSS: 0.13483 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-23347", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23347"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23347"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.", "cve_id": "CVE-2022-23347", "vendor": "BigAnt Software", "ghsa_id": null, "product": "BigAnt Server", "added_date": "2025-07-23T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.13483, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96328, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23347", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "24d234cc-e6c8-47c1-9f8b-d2f205205ee2", "vulnerability": {"vulnId": "CVE-2020-27986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-23T02:00:00+02:00"}, "gcve": {"object_uuid": "24d234cc-e6c8-47c1-9f8b-d2f205205ee2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-23T00:00:00+00:00"}, "scope": {"notes": "SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE:... | Affected: SonarSource / SonarQube | CVSS: 7.5 (HIGH) | EPSS: 0.15966 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-27986", "url": "https://www.cve.org/CVERecord?id=CVE-2020-27986"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-27986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE:...", "cve_id": "CVE-2020-27986", "vendor": "SonarSource", "ghsa_id": null, "product": "SonarQube", "added_date": "2025-07-23T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.15966, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96803, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-27986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1bf9c07d-1d98-4777-9ffe-8acc4732beb7", "vulnerability": {"vulnId": "CVE-2021-21402", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-23T02:00:00+02:00"}, "gcve": {"object_uuid": "1bf9c07d-1d98-4777-9ffe-8acc4732beb7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-23T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Arbitrary File Access in Jellyfin | Affected: Jellyfin / jellyfin | CVSS: 7.7 (HIGH) | EPSS: 0.79313 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21402", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21402"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21402"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Arbitrary File Access in Jellyfin", "cve_id": "CVE-2021-21402", "vendor": "Jellyfin", "ghsa_id": null, "product": "jellyfin", "added_date": "2025-07-23T00:00:00.000Z", "cvss_score": 7.7, "epss_score": 0.79313, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99592, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21402", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "31aa5051-2f8d-4c4c-afb6-5551e427cd2c", "vulnerability": {"vulnId": "CVE-2025-51482", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-22T02:00:00+02:00"}, "gcve": {"object_uuid": "31aa5051-2f8d-4c4c-afb6-5551e427cd2c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-22T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute... | Affected: Letta-ai / Letta | CVSS: 8.8 (HIGH) | EPSS: 0.01876 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-51482", "url": "https://www.cve.org/CVERecord?id=CVE-2025-51482"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-51482"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute...", "cve_id": "CVE-2025-51482", "vendor": "Letta-ai", "ghsa_id": null, "product": "Letta", "added_date": "2025-07-22T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.01876, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78648, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-51482", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "970ef532-8954-494e-b190-876432837280", "vulnerability": {"vulnId": "CVE-2022-22242", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-21T02:00:00+02:00"}, "gcve": {"object_uuid": "970ef532-8954-494e-b190-876432837280", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-21T00:00:00+00:00"}, "scope": {"notes": "Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web | Affected: Juniper Networks / Junos OS | CVSS: 6.1 (MEDIUM) | EPSS: 0.02785 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-22242", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22242"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22242"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web", "cve_id": "CVE-2022-22242", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2025-07-21T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.02785, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22242", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3aebab2d-0933-4e8e-8081-01b4614c7893", "vulnerability": {"vulnId": "CVE-2022-29014", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-21T02:00:00+02:00"}, "gcve": {"object_uuid": "3aebab2d-0933-4e8e-8081-01b4614c7893", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-21T00:00:00+00:00"}, "scope": {"notes": "A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files. | Affected: Razer / Sila Gaming Router | CVSS: 7.5 (HIGH) | EPSS: 0.11816 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29014", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29014"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29014"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.", "cve_id": "CVE-2022-29014", "vendor": "Razer", "ghsa_id": null, "product": "Sila Gaming Router", "added_date": "2025-07-21T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.11816, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95967, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29014", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "50aebb2e-5e0d-4018-9aae-7e8d2b5b97c4", "vulnerability": {"vulnId": "CVE-2023-45878", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-21T02:00:00+02:00"}, "gcve": {"object_uuid": "50aebb2e-5e0d-4018-9aae-7e8d2b5b97c4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-21T00:00:00+00:00"}, "scope": {"notes": "GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The... | Affected: GibbonEdu / Gibbon | CVSS: 9.8 (CRITICAL) | EPSS: 0.63113 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-45878", "url": "https://www.cve.org/CVERecord?id=CVE-2023-45878"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-45878"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The...", "cve_id": "CVE-2023-45878", "vendor": "GibbonEdu", "ghsa_id": null, "product": "Gibbon", "added_date": "2025-07-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.63113, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99182, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-45878", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2438292e-9397-4dc3-8fa7-26ad0f6467ad", "vulnerability": {"vulnId": "CVE-2022-0952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-21T02:00:00+02:00"}, "gcve": {"object_uuid": "2438292e-9397-4dc3-8fa7-26ad0f6467ad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-21T00:00:00+00:00"}, "scope": {"notes": "Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update | Affected: click5 / Sitemap | CVSS: 8.8 (HIGH) | EPSS: 0.11419 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0952", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update", "cve_id": "CVE-2022-0952", "vendor": "click5", "ghsa_id": null, "product": "Sitemap", "added_date": "2025-07-21T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.11419, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9588, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0952", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dbd0b3f5-350b-443a-b8bb-c5210ed4fb1b", "vulnerability": {"vulnId": "CVE-2025-3415", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-17T12:13:14+02:00"}, "gcve": {"object_uuid": "dbd0b3f5-350b-443a-b8bb-c5210ed4fb1b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-17T10:13:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-17T10:13:14+00:00"}, "scope": {"notes": "Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could... | Affected: Grafana / Grafana | CVSS: 4.3 (MEDIUM) | EPSS: 0.00983 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-3415", "url": "https://www.cve.org/CVERecord?id=CVE-2025-3415"}, {"id": "GHSA-46M5-8HPJ-P5P5", "url": "https://github.com/advisories/GHSA-46M5-8HPJ-P5P5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-3415"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could...", "cve_id": "CVE-2025-3415", "vendor": "Grafana", "ghsa_id": "GHSA-46M5-8HPJ-P5P5", "product": "Grafana", "added_date": "2025-07-17T10:13:14.000Z", "cvss_score": 4.3, "epss_score": 0.00983, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6094, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-3415", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "47dc76d3-c7a4-4029-9abd-e54d0c06aaea", "vulnerability": {"vulnId": "CVE-2021-30497", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-16T02:00:00+02:00"}, "gcve": {"object_uuid": "47dc76d3-c7a4-4029-9abd-e54d0c06aaea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-16T00:00:00+00:00"}, "scope": {"notes": "Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath... | Affected: Ivanti / Avalanche | CVSS: 7.5 (HIGH) | EPSS: 0.9658 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30497", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30497"}, {"id": "GHSA-5PF7-7GPX-8VJV", "url": "https://github.com/advisories/GHSA-5PF7-7GPX-8VJV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30497"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath...", "cve_id": "CVE-2021-30497", "vendor": "Ivanti", "ghsa_id": "GHSA-5PF7-7GPX-8VJV", "product": "Avalanche", "added_date": "2025-07-16T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.9658, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99882, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30497", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "387ebba0-dfc5-41d4-9e6f-a6feee1e616f", "vulnerability": {"vulnId": "CVE-2023-6114", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-16T02:00:00+02:00"}, "gcve": {"object_uuid": "387ebba0-dfc5-41d4-9e6f-a6feee1e616f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-16T00:00:00+00:00"}, "scope": {"notes": "Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure | Affected: Snap Creek / Duplicator | CVSS: 7.5 (HIGH) | EPSS: 0.30894 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6114", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6114"}, {"id": "GHSA-769Q-5WW3-V8WW", "url": "https://github.com/advisories/GHSA-769Q-5WW3-V8WW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6114"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Duplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure", "cve_id": "CVE-2023-6114", "vendor": "Snap Creek", "ghsa_id": "GHSA-769Q-5WW3-V8WW", "product": "Duplicator", "added_date": "2025-07-16T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.30894, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98207, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6114", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6cc10442-03a7-48dd-aa67-f4c067c518a3", "vulnerability": {"vulnId": "CVE-2019-2768", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-15T02:00:00+02:00"}, "gcve": {"object_uuid": "6cc10442-03a7-48dd-aa67-f4c067c518a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-15T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The... | Affected: Oracle / BI Publisher (formerly XML Publisher) | CVSS: 7.5 (HIGH) | EPSS: 0.01711 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-2768", "url": "https://www.cve.org/CVERecord?id=CVE-2019-2768"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-2768"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The...", "cve_id": "CVE-2019-2768", "vendor": "Oracle", "ghsa_id": null, "product": "BI Publisher (formerly XML Publisher)", "added_date": "2025-07-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01711, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76514, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-2768", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4050c16f-648f-4fc2-943f-4b33a9245cea", "vulnerability": {"vulnId": "CVE-2020-35580", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-14T02:00:00+02:00"}, "gcve": {"object_uuid": "4050c16f-648f-4fc2-943f-4b33a9245cea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-14T00:00:00+00:00"}, "scope": {"notes": "A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files... | Affected: SearchBlox / SearchBlox | CVSS: 7.5 (HIGH) | EPSS: 0.13975 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35580", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35580"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35580"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files...", "cve_id": "CVE-2020-35580", "vendor": "SearchBlox", "ghsa_id": null, "product": "SearchBlox", "added_date": "2025-07-14T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.13975, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9644, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35580", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3dd24f77-0c1a-4285-a6e3-81413efa959f", "vulnerability": {"vulnId": "CVE-2023-32235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-14T02:00:00+02:00"}, "gcve": {"object_uuid": "3dd24f77-0c1a-4285-a6e3-81413efa959f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-14T00:00:00+00:00"}, "scope": {"notes": "Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory... | Affected: Ghost / Ghost | CVSS: 7.5 (HIGH) | EPSS: 0.39078 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-32235", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32235"}, {"id": "GHSA-WF7X-FH6W-34R6", "url": "https://github.com/advisories/GHSA-WF7X-FH6W-34R6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory...", "cve_id": "CVE-2023-32235", "vendor": "Ghost", "ghsa_id": "GHSA-WF7X-FH6W-34R6", "product": "Ghost", "added_date": "2025-07-14T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.39078, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98552, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dd3b11e5-6ae9-46fe-8a41-4e1177bc12c4", "vulnerability": {"vulnId": "CVE-2022-46381", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-14T02:00:00+02:00"}, "gcve": {"object_uuid": "dd3b11e5-6ae9-46fe-8a41-4e1177bc12c4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-14T00:00:00+00:00"}, "scope": {"notes": "Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This... | Affected: Linear / eMerge E3-Series | CVSS: 6.1 (MEDIUM) | EPSS: 0.01757 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-46381", "url": "https://www.cve.org/CVERecord?id=CVE-2022-46381"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-46381"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This...", "cve_id": "CVE-2022-46381", "vendor": "Linear", "ghsa_id": null, "product": "eMerge E3-Series", "added_date": "2025-07-14T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01757, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77131, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-46381", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f050b864-71f3-4dcb-b392-52b8ebac24f1", "vulnerability": {"vulnId": "CVE-2021-45420", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-14T02:00:00+02:00"}, "gcve": {"object_uuid": "f050b864-71f3-4dcb-b392-52b8ebac24f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-14T00:00:00+00:00"}, "scope": {"notes": "Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and... | Affected: Emerson / Dixell XWEB-500 | CVSS: 9.8 (CRITICAL) | EPSS: 0.1755 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-45420", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45420"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45420"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and...", "cve_id": "CVE-2021-45420", "vendor": "Emerson", "ghsa_id": null, "product": "Dixell XWEB-500", "added_date": "2025-07-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1755, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97052, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-45420", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "623353ff-261f-4c59-a275-21c03e51ac0d", "vulnerability": {"vulnId": "CVE-2021-33690", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "623353ff-261f-4c59-a275-21c03e51ac0d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-11T00:00:00+00:00"}, "scope": {"notes": "Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions... | Affected: SAP SE / SAP NetWeaver Development Infrastructure (Component Build Service) | CVSS: 9.9 (CRITICAL) | EPSS: 0.69075 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-33690", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33690"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33690"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service versions...", "cve_id": "CVE-2021-33690", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP NetWeaver Development Infrastructure (Component Build Service)", "added_date": "2025-07-11T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.69075, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99336, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33690", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "77295112-5f14-43c2-8b51-f55b90f95cc8", "vulnerability": {"vulnId": "CVE-2020-15227", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "77295112-5f14-43c2-8b51-f55b90f95cc8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-11T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution vulnerability | Affected: Nette / application | CVSS: 8.7 (HIGH) | EPSS: 0.34424 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-15227", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15227"}, {"id": "GHSA-8GV3-3J7F-WG94", "url": "https://github.com/advisories/GHSA-8GV3-3J7F-WG94"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15227"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution vulnerability", "cve_id": "CVE-2020-15227", "vendor": "Nette", "ghsa_id": "GHSA-8GV3-3J7F-WG94", "product": "application", "added_date": "2025-07-11T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.34424, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15227", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0ea2b4da-3518-4738-8cb4-f820910d305e", "vulnerability": {"vulnId": "CVE-2025-7414", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-10T22:32:07+02:00"}, "gcve": {"object_uuid": "0ea2b4da-3518-4738-8cb4-f820910d305e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-10T20:32:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-10T20:32:07+00:00"}, "scope": {"notes": "Tenda O3V2 httpd setPingInfo fromNetToolGet os command injection | Affected: Tenda / O3V2 | CVSS: 5.3 (MEDIUM) | EPSS: 0.12841 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-7414", "url": "https://www.cve.org/CVERecord?id=CVE-2025-7414"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-7414"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tenda O3V2 httpd setPingInfo fromNetToolGet os command injection", "cve_id": "CVE-2025-7414", "vendor": "Tenda", "ghsa_id": null, "product": "O3V2", "added_date": "2025-07-10T20:32:07.000Z", "cvss_score": 5.3, "epss_score": 0.12841, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9618, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-7414", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "96571390-aa48-44f7-8dfb-a81700705741", "vulnerability": {"vulnId": "CVE-2025-7407", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-10T15:32:05+02:00"}, "gcve": {"object_uuid": "96571390-aa48-44f7-8dfb-a81700705741", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-10T13:32:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-10T13:32:05+00:00"}, "scope": {"notes": "Netgear D6400 diag.cgi os command injection | Affected: Netgear / D6400 | CVSS: 5.3 (MEDIUM) | EPSS: 0.10446 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-7407", "url": "https://www.cve.org/CVERecord?id=CVE-2025-7407"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-7407"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Netgear D6400 diag.cgi os command injection", "cve_id": "CVE-2025-7407", "vendor": "Netgear", "ghsa_id": null, "product": "D6400", "added_date": "2025-07-10T13:32:05.000Z", "cvss_score": 5.3, "epss_score": 0.10446, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-7407", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "25e068dd-0e1d-486a-98c0-307095cb6e6b", "vulnerability": {"vulnId": "CVE-2020-28188", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-09T02:00:00+02:00"}, "gcve": {"object_uuid": "25e068dd-0e1d-486a-98c0-307095cb6e6b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-09T00:00:00+00:00"}, "scope": {"notes": "Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via... | Affected: TerraMaster / TOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.96598 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-28188", "url": "https://www.cve.org/CVERecord?id=CVE-2020-28188"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-28188"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via...", "cve_id": "CVE-2020-28188", "vendor": "TerraMaster", "ghsa_id": null, "product": "TOS", "added_date": "2025-07-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96598, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99883, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-28188", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "424ca34f-05d5-4efd-b660-2dff4495720e", "vulnerability": {"vulnId": "CVE-2025-44177", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-09T02:00:00+02:00"}, "gcve": {"object_uuid": "424ca34f-05d5-4efd-b660-2dff4495720e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-09T00:00:00+00:00"}, "scope": {"notes": "A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint.... | Affected: White Star Software / Protop | CVSS: 8.2 (HIGH) | EPSS: 0.04361 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-44177", "url": "https://www.cve.org/CVERecord?id=CVE-2025-44177"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-44177"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ endpoint....", "cve_id": "CVE-2025-44177", "vendor": "White Star Software", "ghsa_id": null, "product": "Protop", "added_date": "2025-07-09T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.04361, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-44177", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fd70b376-413d-450b-977d-681e1d32ebeb", "vulnerability": {"vulnId": "CVE-2023-35885", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-08T02:00:00+02:00"}, "gcve": {"object_uuid": "fd70b376-413d-450b-977d-681e1d32ebeb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-08T00:00:00+00:00"}, "scope": {"notes": "CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication. | Affected: CloudPanel / CloudPanel 2 | CVSS: 9.8 (CRITICAL) | EPSS: 0.74888 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-35885", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35885"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35885"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.", "cve_id": "CVE-2023-35885", "vendor": "CloudPanel", "ghsa_id": null, "product": "CloudPanel 2", "added_date": "2025-07-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74888, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99493, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35885", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "23929e37-911b-43f6-831e-47a190dabf2e", "vulnerability": {"vulnId": "CVE-2023-23489", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "23929e37-911b-43f6-831e-47a190dabf2e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's'... | Affected: Easy Digital Downloads / WordPress Plugin | CVSS: 9.8 (CRITICAL) | EPSS: 0.11172 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-23489", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23489"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23489"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's'...", "cve_id": "CVE-2023-23489", "vendor": "Easy Digital Downloads", "ghsa_id": null, "product": "WordPress Plugin", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.11172, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95827, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23489", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "55e7e7fe-a83d-4dda-844f-6a2e123a49d8", "vulnerability": {"vulnId": "CVE-2023-31446", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "55e7e7fe-a83d-4dda-844f-6a2e123a49d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This... | Affected: Cassia Networks / Cassia Gateway | CVSS: 9.8 (CRITICAL) | EPSS: 0.61081 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-31446", "url": "https://www.cve.org/CVERecord?id=CVE-2023-31446"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-31446"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This...", "cve_id": "CVE-2023-31446", "vendor": "Cassia Networks", "ghsa_id": null, "product": "Cassia Gateway", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.61081, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99135, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-31446", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "11c29bb3-f400-444f-9d5f-86b657473054", "vulnerability": {"vulnId": "CVE-2023-52028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "11c29bb3-f400-444f-9d5f-86b657473054", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function. | Affected: TOTOlink / A3700R | CVSS: 9.8 (CRITICAL) | EPSS: 0.01668 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-52028", "url": "https://www.cve.org/CVERecord?id=CVE-2023-52028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-52028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.", "cve_id": "CVE-2023-52028", "vendor": "TOTOlink", "ghsa_id": null, "product": "A3700R", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01668, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75908, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-52028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dacf52cf-1e29-4cc4-971c-a2f071b429ec", "vulnerability": {"vulnId": "CVE-2023-29919", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "dacf52cf-1e29-4cc4-971c-a2f071b429ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not... | Affected: SolarView / SolarView Compact | CVSS: 9.1 (CRITICAL) | EPSS: 0.60221 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-29919", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29919"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29919"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not...", "cve_id": "CVE-2023-29919", "vendor": "SolarView", "ghsa_id": null, "product": "SolarView Compact", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.60221, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99113, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29919", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1d10b317-e055-41cb-aa09-57f25fa65170", "vulnerability": {"vulnId": "CVE-2023-34960", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "1d10b317-e055-41cb-aa09-57f25fa65170", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands... | Affected: Chamilo / Chamilo | CVSS: 9.8 (CRITICAL) | EPSS: 0.99325 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34960", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34960"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34960"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands...", "cve_id": "CVE-2023-34960", "vendor": "Chamilo", "ghsa_id": null, "product": "Chamilo", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99325, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34960", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ef7929f9-26a1-429b-a2a7-02a22c6cc451", "vulnerability": {"vulnId": "CVE-2023-31478", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "ef7929f9-26a1-429b-a2a7-02a22c6cc451", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and... | Affected: GL.iNet / GL.iNet devices | CVSS: 7.5 (HIGH) | EPSS: 0.29699 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-31478", "url": "https://www.cve.org/CVERecord?id=CVE-2023-31478"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-31478"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and...", "cve_id": "CVE-2023-31478", "vendor": "GL.iNet", "ghsa_id": null, "product": "GL.iNet devices", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.29699, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98145, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-31478", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "730a257c-de71-47a0-9fe4-ef1a4916b7c0", "vulnerability": {"vulnId": "CVE-2023-3836", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "730a257c-de71-47a0-9fe4-ef1a4916b7c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "Dahua Smart Park Management unrestricted upload | Affected: Dahua / Smart Park Management | CVSS: 6.3 (MEDIUM) | EPSS: 0.7367 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3836", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3836"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3836"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dahua Smart Park Management unrestricted upload", "cve_id": "CVE-2023-3836", "vendor": "Dahua", "ghsa_id": null, "product": "Smart Park Management", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.7367, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3836", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4e2a0221-aeb3-4a50-b465-ef4ba499c920", "vulnerability": {"vulnId": "CVE-2022-36509", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "4e2a0221-aeb3-4a50-b465-ef4ba499c920", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList. | Affected: H3C / GR3200 MiniGR1B0V100R014 | CVSS: 7.8 (HIGH) | EPSS: 0.11183 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-36509", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36509"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36509"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "H3C GR3200 MiniGR1B0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.", "cve_id": "CVE-2022-36509", "vendor": "H3C", "ghsa_id": null, "product": "GR3200 MiniGR1B0V100R014", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.11183, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36509", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6331dc86-193c-4d79-915b-056952ef6d11", "vulnerability": {"vulnId": "CVE-2023-33831", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "6331dc86-193c-4d79-915b-056952ef6d11", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a... | Affected: FUXA / FUXA | CVSS: 9.8 (CRITICAL) | EPSS: 0.25951 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-33831", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33831"}, {"id": "GHSA-R87Q-FQ37-PVR6", "url": "https://github.com/advisories/GHSA-R87Q-FQ37-PVR6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33831"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a...", "cve_id": "CVE-2023-33831", "vendor": "FUXA", "ghsa_id": "GHSA-R87Q-FQ37-PVR6", "product": "FUXA", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.25951, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97925, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33831", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3acc6956-3a6c-43c5-a2af-e1a73422cd0f", "vulnerability": {"vulnId": "CVE-2023-26802", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "3acc6956-3a6c-43c5-a2af-e1a73422cd0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass... | Affected: Digital China Networks / DCBI-Netlog-LAB | CVSS: 9.8 (CRITICAL) | EPSS: 0.4871 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26802", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26802"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26802"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass...", "cve_id": "CVE-2023-26802", "vendor": "Digital China Networks", "ghsa_id": null, "product": "DCBI-Netlog-LAB", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.4871, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26802", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "34a95afb-4c81-4c27-94b0-29b57ef2b0be", "vulnerability": {"vulnId": "CVE-2023-49070", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "34a95afb-4c81-4c27-94b0-29b57ef2b0be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present | Affected: Apache / Apache OFBiz | CVSS: 9.8 (CRITICAL) | EPSS: 0.95368 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-49070", "url": "https://www.cve.org/CVERecord?id=CVE-2023-49070"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-49070"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present", "cve_id": "CVE-2023-49070", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95368, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99867, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-49070", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ac0a2f6d-99cd-44c4-bbd7-e841196552eb", "vulnerability": {"vulnId": "CVE-2023-46574", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "ac0a2f6d-99cd-44c4-bbd7-e841196552eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the... | Affected: TOTOLINK / A3700R | CVSS: 9.8 (CRITICAL) | EPSS: 0.65412 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-46574", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46574"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46574"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the...", "cve_id": "CVE-2023-46574", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A3700R", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.65412, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9924, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-46574", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "75a945c5-be82-4b90-aea6-ff75fb8cc337", "vulnerability": {"vulnId": "CVE-2023-46347", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "75a945c5-be82-4b90-aea6-ff75fb8cc337", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "In the module \"Step by Step products Pack\" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL... | Affected: NDK Design / Step by Step products Pack | CVSS: 9.8 (CRITICAL) | EPSS: 0.49885 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-46347", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46347"}, {"id": "GHSA-8V8R-33P8-HH47", "url": "https://github.com/advisories/GHSA-8V8R-33P8-HH47"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46347"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In the module \"Step by Step products Pack\" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL...", "cve_id": "CVE-2023-46347", "vendor": "NDK Design", "ghsa_id": "GHSA-8V8R-33P8-HH47", "product": "Step by Step products Pack", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.49885, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98866, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-46347", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0bd0da1f-38dd-4f79-8f50-7674ae94f149", "vulnerability": {"vulnId": "CVE-2023-1454", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "0bd0da1f-38dd-4f79-8f50-7674ae94f149", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "jeecg-boot qurestSql sql injection | Affected: Jeecg / jeecg-boot | CVSS: 6.3 (MEDIUM) | EPSS: 0.35825 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-1454", "url": "https://www.cve.org/CVERecord?id=CVE-2023-1454"}, {"id": "GHSA-J72F-4HGP-3MWC", "url": "https://github.com/advisories/GHSA-J72F-4HGP-3MWC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-1454"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "jeecg-boot qurestSql sql injection", "cve_id": "CVE-2023-1454", "vendor": "Jeecg", "ghsa_id": "GHSA-J72F-4HGP-3MWC", "product": "jeecg-boot", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.35825, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98424, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-1454", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "02e6e3af-b463-47c8-af0a-f95f82580e54", "vulnerability": {"vulnId": "CVE-2023-34659", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "02e6e3af-b463-47c8-af0a-f95f82580e54", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | Affected: Jeecg / jeecg-boot | CVSS: 9.8 (CRITICAL) | EPSS: 0.1248 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34659", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34659"}, {"id": "GHSA-934G-FVCC-4833", "url": "https://github.com/advisories/GHSA-934G-FVCC-4833"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34659"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.", "cve_id": "CVE-2023-34659", "vendor": "Jeecg", "ghsa_id": "GHSA-934G-FVCC-4833", "product": "jeecg-boot", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1248, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96101, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34659", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "60b756ca-a6c6-4f21-bb33-c1ff6ab71624", "vulnerability": {"vulnId": "CVE-2023-25135", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "60b756ca-a6c6-4f21-bb33-c1ff6ab71624", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers... | Affected: vBulletin / vBulletin | CVSS: 9.8 (CRITICAL) | EPSS: 0.23926 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-25135", "url": "https://www.cve.org/CVERecord?id=CVE-2023-25135"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-25135"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers...", "cve_id": "CVE-2023-25135", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.23926, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97769, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-25135", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b5093ced-275d-4332-a62d-237755f8a375", "vulnerability": {"vulnId": "CVE-2023-4450", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "b5093ced-275d-4332-a62d-237755f8a375", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "jeecgboot JimuReport Template injection | Affected: Jeecgboot / JimuReport | CVSS: 6.3 (MEDIUM) | EPSS: 0.11595 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-4450", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4450"}, {"id": "GHSA-J8H5-8RRR-M6J9", "url": "https://github.com/advisories/GHSA-J8H5-8RRR-M6J9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4450"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "jeecgboot JimuReport Template injection", "cve_id": "CVE-2023-4450", "vendor": "Jeecgboot", "ghsa_id": "GHSA-J8H5-8RRR-M6J9", "product": "JimuReport", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.11595, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95917, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4450", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3d6b0e09-48c7-42fe-8229-5ccc17799b6f", "vulnerability": {"vulnId": "CVE-2024-36111", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "3d6b0e09-48c7-42fe-8229-5ccc17799b6f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "KubePi's JWT token validation has a defect | Affected: 1Panel-dev / KubePi | CVSS: 6.3 (MEDIUM) | EPSS: 0.08388 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-36111", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36111"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36111"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "KubePi's JWT token validation has a defect", "cve_id": "CVE-2024-36111", "vendor": "1Panel-dev", "ghsa_id": null, "product": "KubePi", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.08388, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94816, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36111", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3ec86e3e-2a36-4464-b3a8-72b21883dc78", "vulnerability": {"vulnId": "CVE-2023-1177", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "3ec86e3e-2a36-4464-b3a8-72b21883dc78", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "Path Traversal: '\\..\\filename' in mlflow/mlflow | Affected: Mlflow / mlflow/mlflow | CVSS: 9.3 (CRITICAL) | EPSS: 0.6968 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-1177", "url": "https://www.cve.org/CVERecord?id=CVE-2023-1177"}, {"id": "GHSA-XG73-94FP-G449", "url": "https://github.com/advisories/GHSA-XG73-94FP-G449"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-1177"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path Traversal: '\\..\\filename' in mlflow/mlflow", "cve_id": "CVE-2023-1177", "vendor": "Mlflow", "ghsa_id": "GHSA-XG73-94FP-G449", "product": "mlflow/mlflow", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.6968, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9935, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-1177", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cad51494-3743-45cf-9602-a796e739fcad", "vulnerability": {"vulnId": "CVE-2023-22478", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "cad51494-3743-45cf-9602-a796e739fcad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "KubePi is vulnerable to missing authorization | Affected: KubeOperator / KubePi | CVSS: 7.3 (HIGH) | EPSS: 0.03573 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-22478", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22478"}, {"id": "GHSA-GQX8-HXMV-C4V4", "url": "https://github.com/advisories/GHSA-GQX8-HXMV-C4V4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22478"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "KubePi is vulnerable to missing authorization", "cve_id": "CVE-2023-22478", "vendor": "KubeOperator", "ghsa_id": "GHSA-GQX8-HXMV-C4V4", "product": "KubePi", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.03573, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-22478", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8594bd05-ef01-4e98-a6c3-54f1d8ca3125", "vulnerability": {"vulnId": "CVE-2023-23333", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "8594bd05-ef01-4e98-a6c3-54f1d8ca3125", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions... | Affected: SolarView / SolarView Compact | CVSS: 9.8 (CRITICAL) | EPSS: 0.99291 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-23333", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23333"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23333"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions...", "cve_id": "CVE-2023-23333", "vendor": "SolarView", "ghsa_id": null, "product": "SolarView Compact", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99291, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99937, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23333", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f5684a4-9b67-4a01-943b-cdf4e52eb7c7", "vulnerability": {"vulnId": "CVE-2023-30625", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "8f5684a4-9b67-4a01-943b-cdf4e52eb7c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "rudder-server vulnerable to SQL Injection | Affected: Rudderlabs / rudder-server | CVSS: 8.8 (HIGH) | EPSS: 0.85825 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-30625", "url": "https://www.cve.org/CVERecord?id=CVE-2023-30625"}, {"id": "GHSA-3JMM-F6JJ-RCC3", "url": "https://github.com/advisories/GHSA-3JMM-F6JJ-RCC3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-30625"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "rudder-server vulnerable to SQL Injection", "cve_id": "CVE-2023-30625", "vendor": "Rudderlabs", "ghsa_id": "GHSA-3JMM-F6JJ-RCC3", "product": "rudder-server", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.85825, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-30625", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "805d9e1b-4134-4370-8981-52a6f492e9c9", "vulnerability": {"vulnId": "CVE-2023-1698", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "805d9e1b-4134-4370-8981-52a6f492e9c9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "WAGO: WBM Command Injection in multiple products | Affected: WAGO / Compact Controller CC100, Edge Controller, PFC100, PFC200, Touch Panel 600 Advanced Line, Touch Panel 600 Marine Line, Touch Panel 600 Standard Line | CVSS: 9.8 (CRITICAL) | EPSS: 0.82037 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-1698", "url": "https://www.cve.org/CVERecord?id=CVE-2023-1698"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-1698"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WAGO: WBM Command Injection in multiple products", "cve_id": "CVE-2023-1698", "vendor": "WAGO", "ghsa_id": null, "product": "Compact Controller CC100, Edge Controller, PFC100, PFC200, Touch Panel 600 Advanced Line, Touch Panel 600 Marine Line, Touch Panel 600 Standard Line", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82037, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99644, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-1698", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e1b2ba8f-75d1-4368-8e00-eab3f0a49340", "vulnerability": {"vulnId": "CVE-2023-34133", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "e1b2ba8f-75d1-4368-8e00-eab3f0a49340", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an... | Affected: SonicWall / GMS, Analytics | CVSS: 7.5 (HIGH) | EPSS: 0.72579 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34133", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34133"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34133"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an...", "cve_id": "CVE-2023-34133", "vendor": "SonicWall", "ghsa_id": null, "product": "GMS, Analytics", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.72579, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99428, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34133", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fc68293c-3bee-4bf3-b9ce-6fed7252dc39", "vulnerability": {"vulnId": "CVE-2023-3710", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "fc68293c-3bee-4bf3-b9ce-6fed7252dc39", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "Printer web page invalid command execution | Affected: Honeywell / PM23/43, PC23/43, PD43, PM42, PX4ie/6ie, PX45/65, PD45, PX240, PX940, PM45, RP2f/RP4f | CVSS: 9.9 (CRITICAL) | EPSS: 0.4904 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3710", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3710"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3710"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Printer web page invalid command execution", "cve_id": "CVE-2023-3710", "vendor": "Honeywell", "ghsa_id": null, "product": "PM23/43, PC23/43, PD43, PM42, PX4ie/6ie, PX45/65, PD45, PX240, PX940, PM45, RP2f/RP4f", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.4904, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98849, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3710", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e1f9ba69-983d-4563-b9ee-27b5f8caa2ef", "vulnerability": {"vulnId": "CVE-2023-4634", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "e1f9ba69-983d-4563-b9ee-27b5f8caa2ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including,... | Affected: Dglingren / Media Library Assistant | CVSS: 9.8 (CRITICAL) | EPSS: 0.85595 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-4634", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4634"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4634"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including,...", "cve_id": "CVE-2023-4634", "vendor": "Dglingren", "ghsa_id": null, "product": "Media Library Assistant", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.85595, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99719, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4634", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "04aca0c5-e3db-4105-9f50-57dfd2e7f342", "vulnerability": {"vulnId": "CVE-2023-28343", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "04aca0c5-e3db-4105-9f50-57dfd2e7f342", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone... | Affected: Altenergy / Power Control Software | CVSS: 9.8 (CRITICAL) | EPSS: 0.84752 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-28343", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28343"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28343"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone...", "cve_id": "CVE-2023-28343", "vendor": "Altenergy", "ghsa_id": null, "product": "Power Control Software", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84752, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99702, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28343", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "28c72ec0-0585-4f0c-aeb1-66d1f96054c7", "vulnerability": {"vulnId": "CVE-2023-31465", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "28c72ec0-0585-4f0c-aeb1-66d1f96054c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-07T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to... | Affected: FSMLabs / TimeKeeper | CVSS: 9.8 (CRITICAL) | EPSS: 0.46304 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-31465", "url": "https://www.cve.org/CVERecord?id=CVE-2023-31465"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-31465"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to...", "cve_id": "CVE-2023-31465", "vendor": "FSMLabs", "ghsa_id": null, "product": "TimeKeeper", "added_date": "2025-07-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.46304, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-31465", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "10aaa87e-16c1-4100-9946-7b1c95826f53", "vulnerability": {"vulnId": "CVE-2025-7081", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T15:32:04+02:00"}, "gcve": {"object_uuid": "10aaa87e-16c1-4100-9946-7b1c95826f53", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T13:32:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T13:32:04+00:00"}, "scope": {"notes": "Belkin F9K1122 webs formSetWanStatic os command injection | Affected: Belkin / F9K1122 | CVSS: 5.3 (MEDIUM) | EPSS: 0.17253 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-7081", "url": "https://www.cve.org/CVERecord?id=CVE-2025-7081"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-7081"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Belkin F9K1122 webs formSetWanStatic os command injection", "cve_id": "CVE-2025-7081", "vendor": "Belkin", "ghsa_id": null, "product": "F9K1122", "added_date": "2025-07-06T13:32:04.000Z", "cvss_score": 5.3, "epss_score": 0.17253, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97014, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-7081", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8fee2d35-94a3-4b95-ae90-fedbab6d1306", "vulnerability": {"vulnId": "CVE-2022-0781", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "8fee2d35-94a3-4b95-ae90-fedbab6d1306", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "Nirweb support < 2.8.2 - Unauthenticated SQLi | Affected: Nirweb / Nirweb support | CVSS: 9.8 (CRITICAL) | EPSS: 0.1305 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0781", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0781"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0781"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nirweb support < 2.8.2 - Unauthenticated SQLi", "cve_id": "CVE-2022-0781", "vendor": "Nirweb", "ghsa_id": null, "product": "Nirweb support", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1305, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96234, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0781", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d88b3482-d67e-4c0d-9402-f2cd80df08fe", "vulnerability": {"vulnId": "CVE-2020-35235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "d88b3482-d67e-4c0d-9402-f2cd80df08fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access... | Affected: Elfinder / secure-file-manager | CVSS: 8.8 (HIGH) | EPSS: 0.18284 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35235", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35235"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access...", "cve_id": "CVE-2020-35235", "vendor": "Elfinder", "ghsa_id": null, "product": "secure-file-manager", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.18284, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97139, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f55cc410-db15-4f7e-974c-4f17939d80d1", "vulnerability": {"vulnId": "CVE-2021-41266", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "f55cc410-db15-4f7e-974c-4f17939d80d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "Authentication bypass issue in the Operator Console | Affected: Minio / console | CVSS: 8.6 (HIGH) | EPSS: 0.48414 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-41266", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41266"}, {"id": "GHSA-4999-659W-MQ36", "url": "https://github.com/advisories/GHSA-4999-659W-MQ36"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41266"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication bypass issue in the Operator Console", "cve_id": "CVE-2021-41266", "vendor": "Minio", "ghsa_id": "GHSA-4999-659W-MQ36", "product": "console", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.48414, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9883, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41266", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8b1b7b0d-186f-4e0f-b5e7-c7265e71b118", "vulnerability": {"vulnId": "CVE-2022-22897", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "8b1b7b0d-186f-4e0f-b5e7-c7265e71b118", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for... | Affected: PrestaShop / ApolloTheme AP PageBuilder | CVSS: 9.8 (CRITICAL) | EPSS: 0.1439 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-22897", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22897"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22897"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for...", "cve_id": "CVE-2022-22897", "vendor": "PrestaShop", "ghsa_id": null, "product": "ApolloTheme AP PageBuilder", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1439, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96518, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22897", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a717d43-bd15-4e39-848e-6d14a98265fc", "vulnerability": {"vulnId": "CVE-2021-24442", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "2a717d43-bd15-4e39-848e-6d14a98265fc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection | Affected: Wpdevart / Poll, Survey, Questionnaire and Voting system | CVSS: 9.8 (CRITICAL) | EPSS: 0.45996 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24442", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24442"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24442"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Poll, Survey, Questionnaire and Voting system < 1.5.3 - Unauthenticated Blind SQL Injection", "cve_id": "CVE-2021-24442", "vendor": "Wpdevart", "ghsa_id": null, "product": "Poll, Survey, Questionnaire and Voting system", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.45996, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9877, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24442", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e19f0c0a-e410-4f96-955c-28239aca7f06", "vulnerability": {"vulnId": "CVE-2022-2488", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "e19f0c0a-e410-4f96-955c-28239aca7f06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection | Affected: WAVLINK / WN535K2, WN535K3 | CVSS: 8.0 (HIGH) | EPSS: 0.33764 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2488", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2488"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2488"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection", "cve_id": "CVE-2022-2488", "vendor": "WAVLINK", "ghsa_id": null, "product": "WN535K2, WN535K3", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.33764, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98345, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2488", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2adb622b-0779-41e5-99ea-16aecfa9f460", "vulnerability": {"vulnId": "CVE-2022-25487", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "2adb622b-0779-41e5-99ea-16aecfa9f460", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. | Affected: Atom CMS / Atom CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.53839 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25487", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25487"}, {"id": "GHSA-R8JC-FQM2-4629", "url": "https://github.com/advisories/GHSA-R8JC-FQM2-4629"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25487"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.", "cve_id": "CVE-2022-25487", "vendor": "Atom CMS", "ghsa_id": "GHSA-R8JC-FQM2-4629", "product": "Atom CMS", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.53839, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25487", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bced3ea0-6398-4c21-b431-4bc109eb272c", "vulnerability": {"vulnId": "CVE-2022-1952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-06T02:00:00+02:00"}, "gcve": {"object_uuid": "bced3ea0-6398-4c21-b431-4bc109eb272c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-06T00:00:00+00:00"}, "scope": {"notes": "eaSYNC < 1.1.16 - Unauthenticated Arbitrary File Upload | Affected: Free Booking Plugin / Free Booking Plugin for Hotels, Restaurant and Car Rental | CVSS: 9.8 (CRITICAL) | EPSS: 0.24635 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1952", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "eaSYNC < 1.1.16 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2022-1952", "vendor": "Free Booking Plugin", "ghsa_id": null, "product": "Free Booking Plugin for Hotels, Restaurant and Car Rental", "added_date": "2025-07-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.24635, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97825, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1952", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4a9ad8ac-1ddd-4a56-806c-24527fc0778e", "vulnerability": {"vulnId": "CVE-2017-6090", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "4a9ad8ac-1ddd-4a56-806c-24527fc0778e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute... | Affected: PhpCollab / PhpCollab | CVSS: 8.8 (HIGH) | EPSS: 0.96385 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-6090", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6090"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6090"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute...", "cve_id": "CVE-2017-6090", "vendor": "PhpCollab", "ghsa_id": null, "product": "PhpCollab", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.96385, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6090", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ea70c0d3-2ec9-4d49-8746-59d794e632f2", "vulnerability": {"vulnId": "CVE-2019-15642", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "ea70c0d3-2ec9-4d49-8746-59d794e632f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval... | Affected: Webmin / Webmin | CVSS: 8.8 (HIGH) | EPSS: 0.34798 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-15642", "url": "https://www.cve.org/CVERecord?id=CVE-2019-15642"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-15642"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval...", "cve_id": "CVE-2019-15642", "vendor": "Webmin", "ghsa_id": null, "product": "Webmin", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.34798, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98384, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-15642", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "10c159cf-7b7e-4bba-b072-8d7cccc197cf", "vulnerability": {"vulnId": "CVE-2018-1000130", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "10c159cf-7b7e-4bba-b072-8d7cccc197cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on... | Affected: Jolokia / Jolokia agent | CVSS: 8.1 (HIGH) | EPSS: 0.73976 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-1000130", "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000130"}, {"id": "GHSA-RHQJ-4PP8-VVGF", "url": "https://github.com/advisories/GHSA-RHQJ-4PP8-VVGF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-1000130"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on...", "cve_id": "CVE-2018-1000130", "vendor": "Jolokia", "ghsa_id": "GHSA-RHQJ-4PP8-VVGF", "product": "Jolokia agent", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.73976, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99469, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-1000130", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8bbf9ba9-621b-4b98-8fe5-12a03c267fbf", "vulnerability": {"vulnId": "CVE-2016-10108", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "8bbf9ba9-621b-4b98-8fe5-12a03c267fbf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified... | Affected: Western Digital / MyCloud NAS | CVSS: 9.8 (CRITICAL) | EPSS: 0.9782 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-10108", "url": "https://www.cve.org/CVERecord?id=CVE-2016-10108"}, {"id": "GHSA-GX5G-W3R2-CXJ2", "url": "https://github.com/advisories/GHSA-GX5G-W3R2-CXJ2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-10108"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified...", "cve_id": "CVE-2016-10108", "vendor": "Western Digital", "ghsa_id": "GHSA-GX5G-W3R2-CXJ2", "product": "MyCloud NAS", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9782, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-10108", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8a908573-91f6-4e4f-87b6-405735a61538", "vulnerability": {"vulnId": "CVE-2018-1335", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "8a908573-91f6-4e4f-87b6-405735a61538", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the... | Affected: Apache / Apache Tika | CVSS: 8.1 (HIGH) | EPSS: 0.93758 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-1335", "url": "https://www.cve.org/CVERecord?id=CVE-2018-1335"}, {"id": "GHSA-9R24-GP44-H3PM", "url": "https://github.com/advisories/GHSA-9R24-GP44-H3PM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-1335"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the...", "cve_id": "CVE-2018-1335", "vendor": "Apache", "ghsa_id": "GHSA-9R24-GP44-H3PM", "product": "Apache Tika", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.93758, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99843, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-1335", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "52060876-ec15-466b-a1c5-5d7f1fc424ac", "vulnerability": {"vulnId": "CVE-2011-3600", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "52060876-ec15-466b-a1c5-5d7f1fc424ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with... | Affected: OFBiz / OFBiz | CVSS: 7.5 (HIGH) | EPSS: 0.1591 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-3600", "url": "https://www.cve.org/CVERecord?id=CVE-2011-3600"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-3600"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with...", "cve_id": "CVE-2011-3600", "vendor": "OFBiz", "ghsa_id": null, "product": "OFBiz", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.1591, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96794, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-3600", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "525a725d-6eab-4144-9912-8082eca4fe62", "vulnerability": {"vulnId": "CVE-2018-16159", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-05T02:00:00+02:00"}, "gcve": {"object_uuid": "525a725d-6eab-4144-9912-8082eca4fe62", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-05T00:00:00+00:00"}, "scope": {"notes": "The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php... | Affected: Gift Vouchers / Gift Vouchers | CVSS: 9.8 (CRITICAL) | EPSS: 0.49918 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-16159", "url": "https://www.cve.org/CVERecord?id=CVE-2018-16159"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-16159"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php...", "cve_id": "CVE-2018-16159", "vendor": "Gift Vouchers", "ghsa_id": null, "product": "Gift Vouchers", "added_date": "2025-07-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.49918, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98867, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-16159", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1a4e19f9-4ca8-4141-bb93-6608ca5b6d31", "vulnerability": {"vulnId": "CVE-2018-11686", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-03T02:00:00+02:00"}, "gcve": {"object_uuid": "1a4e19f9-4ca8-4141-bb93-6608ca5b6d31", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-03T00:00:00+00:00"}, "scope": {"notes": "The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php. | Affected: FlowPaper / FlexPaper | CVSS: 9.8 (CRITICAL) | EPSS: 0.52542 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11686", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11686"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11686"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.", "cve_id": "CVE-2018-11686", "vendor": "FlowPaper", "ghsa_id": null, "product": "FlexPaper", "added_date": "2025-07-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.52542, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98933, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11686", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b5001ba9-4055-4638-a557-bf8d362d77f7", "vulnerability": {"vulnId": "CVE-2025-34067", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-02T15:44:21+02:00"}, "gcve": {"object_uuid": "b5001ba9-4055-4638-a557-bf8d362d77f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-02T13:44:21+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-02T13:44:21+00:00"}, "scope": {"notes": "Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson | Affected: Hikvision / Integrated Security Management Platform | CVSS: 10.0 (CRITICAL) | EPSS: 0.18727 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34067", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34067"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34067"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson", "cve_id": "CVE-2025-34067", "vendor": "Hikvision", "ghsa_id": null, "product": "Integrated Security Management Platform", "added_date": "2025-07-02T13:44:21.000Z", "cvss_score": 10.0, "epss_score": 0.18727, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97193, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34067", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "09d63b58-3539-4d97-80b7-82b350049b16", "vulnerability": {"vulnId": "CVE-2025-34058", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T16:48:40+02:00"}, "gcve": {"object_uuid": "09d63b58-3539-4d97-80b7-82b350049b16", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T14:48:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T14:48:40+00:00"}, "scope": {"notes": "Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read | Affected: Hangzhou Hikvision System Technology / Streaming Media Management Server | CVSS: 8.7 (HIGH) | EPSS: 0.00852 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34058", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34058"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34058"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read", "cve_id": "CVE-2025-34058", "vendor": "Hangzhou Hikvision System Technology", "ghsa_id": null, "product": "Streaming Media Management Server", "added_date": "2025-07-01T14:48:40.000Z", "cvss_score": 8.7, "epss_score": 0.00852, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.56704, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34058", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fb670b5e-1c63-4dcf-95f1-0a441c2e77d2", "vulnerability": {"vulnId": "CVE-2019-20933", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "fb670b5e-1c63-4dcf-95f1-0a441c2e77d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T00:00:00+00:00"}, "scope": {"notes": "InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may... | Affected: InfluxData / InfluxDB | CVSS: 9.8 (CRITICAL) | EPSS: 0.30921 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-20933", "url": "https://www.cve.org/CVERecord?id=CVE-2019-20933"}, {"id": "GHSA-2RMP-FW5R-J5QV", "url": "https://github.com/advisories/GHSA-2RMP-FW5R-J5QV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-20933"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may...", "cve_id": "CVE-2019-20933", "vendor": "InfluxData", "ghsa_id": "GHSA-2RMP-FW5R-J5QV", "product": "InfluxDB", "added_date": "2025-07-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.30921, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-20933", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3acc1649-713f-4f8f-8f87-4518cbb5906b", "vulnerability": {"vulnId": "CVE-2021-31602", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "3acc1649-713f-4f8f-8f87-4518cbb5906b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has... | Affected: Hitachi Vantara / Pentaho | CVSS: 5.3 (MEDIUM) | EPSS: 0.51653 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-31602", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31602"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31602"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has...", "cve_id": "CVE-2021-31602", "vendor": "Hitachi Vantara", "ghsa_id": null, "product": "Pentaho", "added_date": "2025-07-01T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.51653, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98914, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31602", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dcbaea92-1e7d-45e1-ab48-0a008e3fc744", "vulnerability": {"vulnId": "CVE-2022-25237", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "dcbaea92-1e7d-45e1-ab48-0a008e3fc744", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T00:00:00+00:00"}, "scope": {"notes": "Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the... | Affected: Bonitasoft / Bonita Web | CVSS: 9.8 (CRITICAL) | EPSS: 0.56449 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25237", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25237"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25237"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the...", "cve_id": "CVE-2022-25237", "vendor": "Bonitasoft", "ghsa_id": null, "product": "Bonita Web", "added_date": "2025-07-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.56449, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99032, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25237", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "92c9478b-212a-405a-aaaa-c62a99812ea9", "vulnerability": {"vulnId": "CVE-2021-33564", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "92c9478b-212a-405a-aaaa-c62a99812ea9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T00:00:00+00:00"}, "scope": {"notes": "An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a... | Affected: Markevans / Dragonfly | CVSS: 9.8 (CRITICAL) | EPSS: 0.72143 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-33564", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33564"}, {"id": "GHSA-J858-XP5V-F8XX", "url": "https://github.com/advisories/GHSA-J858-XP5V-F8XX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33564"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a...", "cve_id": "CVE-2021-33564", "vendor": "Markevans", "ghsa_id": "GHSA-J858-XP5V-F8XX", "product": "Dragonfly", "added_date": "2025-07-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.72143, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99417, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33564", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a9cacb61-5123-4791-9bb4-58108ed8a52e", "vulnerability": {"vulnId": "CVE-2023-35813", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "a9cacb61-5123-4791-9bb4-58108ed8a52e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T00:00:00+00:00"}, "scope": {"notes": "Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3. | Affected: Sitecore / Experience Manager, Experience Platform, Experience Commerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.86685 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-35813", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35813"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35813"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.", "cve_id": "CVE-2023-35813", "vendor": "Sitecore", "ghsa_id": null, "product": "Experience Manager, Experience Platform, Experience Commerce", "added_date": "2025-07-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86685, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99737, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35813", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "80cbbf0d-d3a7-4322-849a-181ef9dd5f0a", "vulnerability": {"vulnId": "CVE-2019-12276", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "80cbbf0d-d3a7-4322-849a-181ef9dd5f0a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-07-01T00:00:00+00:00"}, "scope": {"notes": "A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated... | Affected: GrandNode / GrandNode | CVSS: 7.5 (HIGH) | EPSS: 0.57099 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12276", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12276"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12276"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated...", "cve_id": "CVE-2019-12276", "vendor": "GrandNode", "ghsa_id": null, "product": "GrandNode", "added_date": "2025-07-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.57099, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99045, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12276", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9fb6a580-0923-4ee1-8bd7-e5562b47e5d5", "vulnerability": {"vulnId": "CVE-2023-51467", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-30T02:00:00+02:00"}, "gcve": {"object_uuid": "9fb6a580-0923-4ee1-8bd7-e5562b47e5d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-30T00:00:00+00:00"}, "scope": {"notes": "Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability | Affected: Apache / Apache OFBiz | CVSS: 9.8 (CRITICAL) | EPSS: 0.96001 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-51467", "url": "https://www.cve.org/CVERecord?id=CVE-2023-51467"}, {"id": "GHSA-9699-FMX5-WVPF", "url": "https://github.com/advisories/GHSA-9699-FMX5-WVPF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-51467"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability", "cve_id": "CVE-2023-51467", "vendor": "Apache", "ghsa_id": "GHSA-9699-FMX5-WVPF", "product": "Apache OFBiz", "added_date": "2025-06-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96001, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99875, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-51467", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0f5e4b1f-f749-4a10-a0e7-c408eb5a9630", "vulnerability": {"vulnId": "CVE-2020-21650", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-30T02:00:00+02:00"}, "gcve": {"object_uuid": "0f5e4b1f-f749-4a10-a0e7-c408eb5a9630", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-30T00:00:00+00:00"}, "scope": {"notes": "Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \\controller\\Config.php, which can be exploited via the add()... | Affected: Myucms / Myucms v2.2.1 | CVSS: 8.8 (HIGH) | EPSS: 0.03225 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-21650", "url": "https://www.cve.org/CVERecord?id=CVE-2020-21650"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-21650"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \\controller\\Config.php, which can be exploited via the add()...", "cve_id": "CVE-2020-21650", "vendor": "Myucms", "ghsa_id": null, "product": "Myucms v2.2.1", "added_date": "2025-06-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03225, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87802, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-21650", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "57e4aa59-6581-4a90-ba04-9cf29f75a73f", "vulnerability": {"vulnId": "CVE-2025-49493", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-30T02:00:00+02:00"}, "gcve": {"object_uuid": "57e4aa59-6581-4a90-ba04-9cf29f75a73f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-30T00:00:00+00:00"}, "scope": {"notes": "Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. | Affected: Akamai / CloudTest | CVSS: 5.8 (MEDIUM) | EPSS: 0.02377 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-49493", "url": "https://www.cve.org/CVERecord?id=CVE-2025-49493"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-49493"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.", "cve_id": "CVE-2025-49493", "vendor": "Akamai", "ghsa_id": null, "product": "CloudTest", "added_date": "2025-06-30T00:00:00.000Z", "cvss_score": 5.8, "epss_score": 0.02377, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83251, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-49493", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fb27157e-bc82-4c58-9f22-21861e219fa8", "vulnerability": {"vulnId": "CVE-2021-21389", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-30T02:00:00+02:00"}, "gcve": {"object_uuid": "fb27157e-bc82-4c58-9f22-21861e219fa8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-30T00:00:00+00:00"}, "scope": {"notes": "BuddyPress privilege escalation via REST API | Affected: Buddypress / BuddyPress | CVSS: 8.1 (HIGH) | EPSS: 0.13521 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21389", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21389"}, {"id": "GHSA-M6J4-8R7P-WPP3", "url": "https://github.com/advisories/GHSA-M6J4-8R7P-WPP3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21389"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BuddyPress privilege escalation via REST API", "cve_id": "CVE-2021-21389", "vendor": "Buddypress", "ghsa_id": "GHSA-M6J4-8R7P-WPP3", "product": "BuddyPress", "added_date": "2025-06-30T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.13521, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96337, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21389", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e9653b1d-4ab1-4440-bddd-2f47172754ed", "vulnerability": {"vulnId": "CVE-2021-29441", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-28T02:00:00+02:00"}, "gcve": {"object_uuid": "e9653b1d-4ab1-4440-bddd-2f47172754ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-28T00:00:00+00:00"}, "scope": {"notes": "Authentication bypass | Affected: Alibaba / nacos | CVSS: 8.6 (HIGH) | EPSS: 0.83483 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-29441", "url": "https://www.cve.org/CVERecord?id=CVE-2021-29441"}, {"id": "GHSA-36HP-JR8H-556F", "url": "https://github.com/advisories/GHSA-36HP-JR8H-556F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-29441"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication bypass", "cve_id": "CVE-2021-29441", "vendor": "Alibaba", "ghsa_id": "GHSA-36HP-JR8H-556F", "product": "nacos", "added_date": "2025-06-28T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.83483, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99677, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-29441", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c644eaab-aae2-4166-92ce-281f62d19e36", "vulnerability": {"vulnId": "CVE-2019-9733", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-28T02:00:00+02:00"}, "gcve": {"object_uuid": "c644eaab-aae2-4166-92ce-281f62d19e36", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-28T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case... | Affected: JFrog / Artifactory | CVSS: 9.8 (CRITICAL) | EPSS: 0.53879 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-9733", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9733"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9733"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case...", "cve_id": "CVE-2019-9733", "vendor": "JFrog", "ghsa_id": null, "product": "Artifactory", "added_date": "2025-06-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.53879, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9733", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "283cf6c8-8e81-4898-bef2-cd45d27f3999", "vulnerability": {"vulnId": "CVE-2023-36934", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-27T11:50:50+02:00"}, "gcve": {"object_uuid": "283cf6c8-8e81-4898-bef2-cd45d27f3999", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-27T09:50:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-27T09:50:50+00:00"}, "scope": {"notes": "In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4... | Affected: Progress Software / MOVEit Transfer | CVSS: 9.1 (CRITICAL) | EPSS: 0.95184 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-36934", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36934"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36934"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4...", "cve_id": "CVE-2023-36934", "vendor": "Progress Software", "ghsa_id": null, "product": "MOVEit Transfer", "added_date": "2025-06-27T09:50:50.000Z", "cvss_score": 9.1, "epss_score": 0.95184, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99864, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36934", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bb6ed3f8-fab3-4d74-bd2e-dbb59e53caee", "vulnerability": {"vulnId": "CVE-2020-29597", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "bb6ed3f8-fab3-4d74-bd2e-dbb59e53caee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-27T00:00:00+00:00"}, "scope": {"notes": "IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to... | Affected: IncomCMS / IncomCMS 2.0 | CVSS: 9.8 (CRITICAL) | EPSS: 0.71006 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-29597", "url": "https://www.cve.org/CVERecord?id=CVE-2020-29597"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-29597"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to...", "cve_id": "CVE-2020-29597", "vendor": "IncomCMS", "ghsa_id": null, "product": "IncomCMS 2.0", "added_date": "2025-06-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.71006, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99389, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-29597", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ccaf4d5f-c9f6-4d44-9e30-bf45fddff4b5", "vulnerability": {"vulnId": "CVE-2020-35713", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "ccaf4d5f-c9f6-4d44-9e30-bf45fddff4b5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-27T00:00:00+00:00"}, "scope": {"notes": "Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell... | Affected: Belkin / LINKSYS RE6500 | CVSS: 9.8 (CRITICAL) | EPSS: 0.32936 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35713", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35713"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35713"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new password via shell...", "cve_id": "CVE-2020-35713", "vendor": "Belkin", "ghsa_id": null, "product": "LINKSYS RE6500", "added_date": "2025-06-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.32936, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98311, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35713", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "26ef1b58-33af-4cdc-af88-9b039cb73a44", "vulnerability": {"vulnId": "CVE-2025-34049", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T17:52:12+02:00"}, "gcve": {"object_uuid": "26ef1b58-33af-4cdc-af88-9b039cb73a44", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T15:52:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T15:52:12+00:00"}, "scope": {"notes": "OptiLink ONT1GEW GPON Remote Code Execution | Affected: OptiLink / ONT1GEW GPON | CVSS: 9.4 (CRITICAL) | EPSS: 0.02431 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34049", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34049"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34049"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OptiLink ONT1GEW GPON Remote Code Execution", "cve_id": "CVE-2025-34049", "vendor": "OptiLink", "ghsa_id": null, "product": "ONT1GEW GPON", "added_date": "2025-06-26T15:52:12.000Z", "cvss_score": 9.4, "epss_score": 0.02431, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83664, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34049", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "da792c2e-a096-48c1-88fd-c966c1553858", "vulnerability": {"vulnId": "CVE-2025-34044", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T17:51:30+02:00"}, "gcve": {"object_uuid": "da792c2e-a096-48c1-88fd-c966c1553858", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T15:51:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T15:51:30+00:00"}, "scope": {"notes": "WIFISKY 7-Layer Flow Control Router Remote Command Execution | Affected: Shenzhen Lingkong Technology / WIFISKY 7-layer flow control router | CVSS: 9.4 (CRITICAL) | EPSS: 0.03855 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34044", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34044"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34044"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WIFISKY 7-Layer Flow Control Router Remote Command Execution", "cve_id": "CVE-2025-34044", "vendor": "Shenzhen Lingkong Technology", "ghsa_id": null, "product": "WIFISKY 7-layer flow control router", "added_date": "2025-06-26T15:51:30.000Z", "cvss_score": 9.4, "epss_score": 0.03855, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34044", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "103b2ba4-9476-4423-a5b4-c6bbbbda9610", "vulnerability": {"vulnId": "CVE-2025-34042", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T17:51:13+02:00"}, "gcve": {"object_uuid": "103b2ba4-9476-4423-a5b4-c6bbbbda9610", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T15:51:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T15:51:13+00:00"}, "scope": {"notes": "Beward N100 IP Camera Remote Command Execution | Affected: Beward / N100 IP Camera | CVSS: 9.4 (CRITICAL) | EPSS: 0.0174 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34042", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34042"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34042"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Beward N100 IP Camera Remote Command Execution", "cve_id": "CVE-2025-34042", "vendor": "Beward", "ghsa_id": null, "product": "N100 IP Camera", "added_date": "2025-06-26T15:51:13.000Z", "cvss_score": 9.4, "epss_score": 0.0174, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76889, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34042", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f4e0e076-7e25-49da-a936-7dce64126e01", "vulnerability": {"vulnId": "CVE-2024-10081", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "f4e0e076-7e25-49da-a936-7dce64126e01", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. \nAuthentication bypass... | Affected: Ericsson / CodeChecker | CVSS: 10.0 (CRITICAL) | EPSS: 0.3992 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-10081", "url": "https://www.cve.org/CVERecord?id=CVE-2024-10081"}, {"id": "GHSA-F3F8-VX3W-HP5Q", "url": "https://github.com/advisories/GHSA-F3F8-VX3W-HP5Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-10081"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. \nAuthentication bypass...", "cve_id": "CVE-2024-10081", "vendor": "Ericsson", "ghsa_id": "GHSA-F3F8-VX3W-HP5Q", "product": "CodeChecker", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.3992, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98585, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-10081", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1283ae47-6193-4d14-8e1d-99b0935cf655", "vulnerability": {"vulnId": "CVE-2024-2389", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "1283ae47-6193-4d14-8e1d-99b0935cf655", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Flowmon Unauthenticated Command Injection Vulnerability | Affected: Progress Software / Flowmon | CVSS: 10.0 (CRITICAL) | EPSS: 0.93037 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-2389", "url": "https://www.cve.org/CVERecord?id=CVE-2024-2389"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-2389"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flowmon Unauthenticated Command Injection Vulnerability", "cve_id": "CVE-2024-2389", "vendor": "Progress Software", "ghsa_id": null, "product": "Flowmon", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.93037, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-2389", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "efae7ac7-a7af-4d90-bd07-72940c0d99e9", "vulnerability": {"vulnId": "CVE-2024-8856", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "efae7ac7-a7af-4d90-bd07-72940c0d99e9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload | Affected: Revmakx / Backup and Staging by WP Time Capsule | CVSS: 9.8 (CRITICAL) | EPSS: 0.94135 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8856", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8856"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8856"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2024-8856", "vendor": "Revmakx", "ghsa_id": null, "product": "Backup and Staging by WP Time Capsule", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94135, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99847, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8856", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d1bc65b6-b79f-40fb-9fff-b68fc02fcf3f", "vulnerability": {"vulnId": "CVE-2024-44849", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "d1bc65b6-b79f-40fb-9fff-b68fc02fcf3f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. | Affected: Qualitor / Qualitor | CVSS: 9.8 (CRITICAL) | EPSS: 0.46287 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-44849", "url": "https://www.cve.org/CVERecord?id=CVE-2024-44849"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-44849"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.", "cve_id": "CVE-2024-44849", "vendor": "Qualitor", "ghsa_id": null, "product": "Qualitor", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.46287, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98779, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-44849", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ebe4e2cf-7f80-405b-8ea3-e49e23e999c4", "vulnerability": {"vulnId": "CVE-2024-45507", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "ebe4e2cf-7f80-405b-8ea3-e49e23e999c4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE | Affected: Apache / Apache OFBiz | CVSS: 9.8 (CRITICAL) | EPSS: 0.93229 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-45507", "url": "https://www.cve.org/CVERecord?id=CVE-2024-45507"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-45507"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE", "cve_id": "CVE-2024-45507", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93229, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99834, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-45507", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "05683c6f-068a-49f9-8ceb-d5951a96dca3", "vulnerability": {"vulnId": "CVE-2024-1698", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "05683c6f-068a-49f9-8ceb-d5951a96dca3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "The NotificationX \u2013 Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is... | Affected: Wpdevteam / NotificationX \u2013 Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor | CVSS: 9.8 (CRITICAL) | EPSS: 0.77585 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-1698", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1698"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1698"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The NotificationX \u2013 Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is...", "cve_id": "CVE-2024-1698", "vendor": "Wpdevteam", "ghsa_id": null, "product": "NotificationX \u2013 Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.77585, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9955, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-1698", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4180a8a5-7cf3-4251-a12b-bc0afcfbf9e6", "vulnerability": {"vulnId": "CVE-2024-9047", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "4180a8a5-7cf3-4251-a12b-bc0afcfbf9e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php | Affected: Nickboss / WordPress File Upload | CVSS: 9.8 (CRITICAL) | EPSS: 0.93339 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9047", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9047"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9047"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php", "cve_id": "CVE-2024-9047", "vendor": "Nickboss", "ghsa_id": null, "product": "WordPress File Upload", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93339, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99836, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9047", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "aa862480-df73-46d1-a4b6-cdc17396385c", "vulnerability": {"vulnId": "CVE-2024-1061", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "aa862480-df73-46d1-a4b6-cdc17396385c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in... | Affected: WebVenture / HTML5 Video Player | CVSS: 8.6 (HIGH) | EPSS: 0.11215 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-1061", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1061"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1061"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in...", "cve_id": "CVE-2024-1061", "vendor": "WebVenture", "ghsa_id": null, "product": "HTML5 Video Player", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.11215, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-1061", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "997644e2-6000-455e-9bdf-fdef9d5ce424", "vulnerability": {"vulnId": "CVE-2024-43360", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "997644e2-6000-455e-9bdf-fdef9d5ce424", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "ZoneMinder Time-based SQL Injection | Affected: ZoneMinder / zoneminder | CVSS: 9.8 (CRITICAL) | EPSS: 0.06222 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-43360", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43360"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43360"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZoneMinder Time-based SQL Injection", "cve_id": "CVE-2024-43360", "vendor": "ZoneMinder", "ghsa_id": null, "product": "zoneminder", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06222, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9332, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43360", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2f8fdfa0-ba84-4f6e-91ad-74b74754b6cb", "vulnerability": {"vulnId": "CVE-2024-42640", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "2f8fdfa0-ba84-4f6e-91ad-74b74754b6cb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability... | Affected: Adonespitogo / angular-base64-upload | CVSS: 9.8 (CRITICAL) | EPSS: 0.45097 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-42640", "url": "https://www.cve.org/CVERecord?id=CVE-2024-42640"}, {"id": "GHSA-VGXQ-6RCF-QWRW", "url": "https://github.com/advisories/GHSA-VGXQ-6RCF-QWRW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-42640"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability...", "cve_id": "CVE-2024-42640", "vendor": "Adonespitogo", "ghsa_id": "GHSA-VGXQ-6RCF-QWRW", "product": "angular-base64-upload", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.45097, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98747, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-42640", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "04e50b77-afcb-4a59-9959-cca0d48dd47a", "vulnerability": {"vulnId": "CVE-2024-29895", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "04e50b77-afcb-4a59-9959-cca0d48dd47a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Cacti command injection in cmd_realtime.php | Affected: Cacti / cacti | CVSS: 10.0 (CRITICAL) | EPSS: 0.98455 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-29895", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29895"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29895"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cacti command injection in cmd_realtime.php", "cve_id": "CVE-2024-29895", "vendor": "Cacti", "ghsa_id": null, "product": "cacti", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.98455, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99918, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29895", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7028a7b7-aac1-4494-87ae-d8d7bb90a252", "vulnerability": {"vulnId": "CVE-2024-6396", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "7028a7b7-aac1-4494-87ae-d8d7bb90a252", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim | Affected: Aimhubio / aimhubio/aim | CVSS: 9.8 (CRITICAL) | EPSS: 0.53113 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6396", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6396"}, {"id": "GHSA-W9PM-MP9P-GPGC", "url": "https://github.com/advisories/GHSA-W9PM-MP9P-GPGC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6396"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim", "cve_id": "CVE-2024-6396", "vendor": "Aimhubio", "ghsa_id": "GHSA-W9PM-MP9P-GPGC", "product": "aimhubio/aim", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.53113, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6396", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ecf1691f-69e5-4f66-b499-f4c980075cb5", "vulnerability": {"vulnId": "CVE-2024-6205", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "ecf1691f-69e5-4f66-b499-f4c980075cb5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi | Affected: PayPlus / PayPlus Payment Gateway | CVSS: 9.8 (CRITICAL) | EPSS: 0.04134 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6205", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6205"}, {"id": "GHSA-H8W3-XWP6-M9V8", "url": "https://github.com/advisories/GHSA-H8W3-XWP6-M9V8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6205"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi", "cve_id": "CVE-2024-6205", "vendor": "PayPlus", "ghsa_id": "GHSA-H8W3-XWP6-M9V8", "product": "PayPlus Payment Gateway", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04134, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90509, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6205", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "667d9357-c91d-40d5-8041-609b843a6c87", "vulnerability": {"vulnId": "CVE-2024-29973", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "667d9357-c91d-40d5-8041-609b843a6c87", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "** UNSUPPORTED WHEN ASSIGNED **\nThe command injection vulnerability in the \u201csetCookie\u201d parameter in Zyxel NAS326 firmware versions before... | Affected: Zyxel / NAS326 firmware, NAS542 firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.86089 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-29973", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29973"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29973"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "** UNSUPPORTED WHEN ASSIGNED **\nThe command injection vulnerability in the \u201csetCookie\u201d parameter in Zyxel NAS326 firmware versions before...", "cve_id": "CVE-2024-29973", "vendor": "Zyxel", "ghsa_id": null, "product": "NAS326 firmware, NAS542 firmware", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86089, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29973", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5b40b6a4-2ec6-4e0b-b4ea-215e4f94b156", "vulnerability": {"vulnId": "CVE-2024-8877", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "5b40b6a4-2ec6-4e0b-b4ea-215e4f94b156", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "SQL Injection | Affected: Riello / Netman 204 | CVSS: 6.9 (MEDIUM) | EPSS: 0.77265 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8877", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8877"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8877"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL Injection", "cve_id": "CVE-2024-8877", "vendor": "Riello", "ghsa_id": null, "product": "Netman 204", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.77265, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99543, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8877", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fddb8175-c3a7-4dcc-87a6-03aba7721d69", "vulnerability": {"vulnId": "CVE-2023-5148", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "fddb8175-c3a7-4dcc-87a6-03aba7721d69", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload | Affected: D-Link / DAR-7000, DAR-8000 | CVSS: 6.3 (MEDIUM) | EPSS: 0.30512 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5148", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5148"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5148"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload", "cve_id": "CVE-2023-5148", "vendor": "D-Link", "ghsa_id": null, "product": "DAR-7000, DAR-8000", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.30512, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98188, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5148", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0402a288-6c93-4f6b-9838-5b0cfdb2e8c3", "vulnerability": {"vulnId": "CVE-2024-39914", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "0402a288-6c93-4f6b-9838-5b0cfdb2e8c3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": " FOG has a command injection in /fog/management/export.php?filename= | Affected: FOGProject / fogproject | CVSS: 9.8 (CRITICAL) | EPSS: 0.23237 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-39914", "url": "https://www.cve.org/CVERecord?id=CVE-2024-39914"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-39914"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": " FOG has a command injection in /fog/management/export.php?filename=", "cve_id": "CVE-2024-39914", "vendor": "FOGProject", "ghsa_id": null, "product": "fogproject", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.23237, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97711, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-39914", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5df175ca-231d-484f-bd02-8b265082bee7", "vulnerability": {"vulnId": "CVE-2024-22319", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "5df175ca-231d-484f-bd02-8b265082bee7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "IBM Operational Decision Manager JDNI injection | Affected: IBM / Operational Decision Manager | CVSS: 8.1 (HIGH) | EPSS: 0.764 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-22319", "url": "https://www.cve.org/CVERecord?id=CVE-2024-22319"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-22319"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Operational Decision Manager JDNI injection", "cve_id": "CVE-2024-22319", "vendor": "IBM", "ghsa_id": null, "product": "Operational Decision Manager", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.764, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99525, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-22319", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5c63e297-bf3b-46a8-b43f-36f821f34513", "vulnerability": {"vulnId": "CVE-2024-37032", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "5c63e297-bf3b-46a8-b43f-36f821f34513", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the... | Affected: Ollama / Ollama | CVSS: 8.8 (HIGH) | EPSS: 0.89633 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-37032", "url": "https://www.cve.org/CVERecord?id=CVE-2024-37032"}, {"id": "GHSA-8HQG-WHRW-PV92", "url": "https://github.com/advisories/GHSA-8HQG-WHRW-PV92"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-37032"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the...", "cve_id": "CVE-2024-37032", "vendor": "Ollama", "ghsa_id": "GHSA-8HQG-WHRW-PV92", "product": "Ollama", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.89633, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99785, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-37032", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "84b8d281-23be-43d3-9ffd-7d7f2dddfba2", "vulnerability": {"vulnId": "CVE-2024-27956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "84b8d281-23be-43d3-9ffd-7d7f2dddfba2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability | Affected: ValvePress / Automatic | CVSS: 9.9 (CRITICAL) | EPSS: 0.94057 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-27956", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability", "cve_id": "CVE-2024-27956", "vendor": "ValvePress", "ghsa_id": null, "product": "Automatic", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.94057, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8b202c74-fa95-415d-8eef-c037cb18be30", "vulnerability": {"vulnId": "CVE-2024-28255", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "8b202c74-fa95-415d-8eef-c037cb18be30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Authentication Bypass in OpenMetadata | Affected: Open-metadata / OpenMetadata | CVSS: 9.8 (CRITICAL) | EPSS: 0.73255 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-28255", "url": "https://www.cve.org/CVERecord?id=CVE-2024-28255"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-28255"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass in OpenMetadata", "cve_id": "CVE-2024-28255", "vendor": "Open-metadata", "ghsa_id": null, "product": "OpenMetadata", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.73255, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99446, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-28255", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ec35a123-ce4b-49ca-b67d-5e128a2b6da8", "vulnerability": {"vulnId": "CVE-2024-38289", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "ec35a123-ce4b-49ca-b67d-5e128a2b6da8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote... | Affected: R-HUB / TurboMeeting | CVSS: 9.8 (CRITICAL) | EPSS: 0.40609 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-38289", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38289"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38289"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote...", "cve_id": "CVE-2024-38289", "vendor": "R-HUB", "ghsa_id": null, "product": "TurboMeeting", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.40609, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9861, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38289", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e08b480a-60c6-4bdf-9fd7-1b2bc4556888", "vulnerability": {"vulnId": "CVE-2024-7954", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "e08b480a-60c6-4bdf-9fd7-1b2bc4556888", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "SPIP porte_plume Plugin Arbitrary PHP Execution | Affected: SPIP / SPIP | CVSS: 9.8 (CRITICAL) | EPSS: 0.90053 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7954", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7954"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7954"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SPIP porte_plume Plugin Arbitrary PHP Execution", "cve_id": "CVE-2024-7954", "vendor": "SPIP", "ghsa_id": null, "product": "SPIP", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90053, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99793, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7954", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0dc5c48f-ca6e-4ef9-9d90-4aadd22b54b3", "vulnerability": {"vulnId": "CVE-2024-48307", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "0dc5c48f-ca6e-4ef9-9d90-4aadd22b54b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | Affected: JeecgBoot / JeecgBoot | CVSS: 9.8 (CRITICAL) | EPSS: 0.44335 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-48307", "url": "https://www.cve.org/CVERecord?id=CVE-2024-48307"}, {"id": "GHSA-MCW3-H5XG-R95M", "url": "https://github.com/advisories/GHSA-MCW3-H5XG-R95M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-48307"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.", "cve_id": "CVE-2024-48307", "vendor": "JeecgBoot", "ghsa_id": "GHSA-MCW3-H5XG-R95M", "product": "JeecgBoot", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.44335, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-48307", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "53ac557a-4ef7-42ae-b6e5-1379ed960e54", "vulnerability": {"vulnId": "CVE-2024-50498", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "53ac557a-4ef7-42ae-b6e5-1379ed960e54", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability | Affected: Ajit Bohra / WP Query Console | CVSS: 10.0 (CRITICAL) | EPSS: 0.52905 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-50498", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50498"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50498"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability", "cve_id": "CVE-2024-50498", "vendor": "Ajit Bohra", "ghsa_id": null, "product": "WP Query Console", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.52905, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98943, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-50498", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9be38d05-abf4-4991-bf24-1b63e4defaa3", "vulnerability": {"vulnId": "CVE-2024-32640", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "9be38d05-abf4-4991-bf24-1b63e4defaa3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "MasaCMS SQL Injection vulnerability | Affected: MasaCMS / MasaCMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.76558 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-32640", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32640"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32640"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MasaCMS SQL Injection vulnerability", "cve_id": "CVE-2024-32640", "vendor": "MasaCMS", "ghsa_id": null, "product": "MasaCMS", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.76558, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99528, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32640", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0f740b1d-0b0e-4dbb-9174-08a17d69eb0b", "vulnerability": {"vulnId": "CVE-2024-5827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "0f740b1d-0b0e-4dbb-9174-08a17d69eb0b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-26T00:00:00+00:00"}, "scope": {"notes": "Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna | Affected: Vanna-ai / vanna-ai/vanna | CVSS: 9.8 (CRITICAL) | EPSS: 0.03424 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-5827", "url": "https://www.cve.org/CVERecord?id=CVE-2024-5827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-5827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna", "cve_id": "CVE-2024-5827", "vendor": "Vanna-ai", "ghsa_id": null, "product": "vanna-ai/vanna", "added_date": "2025-06-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03424, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88517, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-5827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ae8d17ff-00dd-48b4-ac28-393c16e5c516", "vulnerability": {"vulnId": "CVE-2020-13167", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "ae8d17ff-00dd-48b4-ac28-393c16e5c516", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-25T00:00:00+00:00"}, "scope": {"notes": "Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches... | Affected: Netsweeper / Netsweeper | CVSS: 9.8 (CRITICAL) | EPSS: 0.94971 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-13167", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13167"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13167"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches...", "cve_id": "CVE-2020-13167", "vendor": "Netsweeper", "ghsa_id": null, "product": "Netsweeper", "added_date": "2025-06-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94971, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9986, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13167", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3836d185-177e-431a-93a9-4d8aa2f79765", "vulnerability": {"vulnId": "CVE-2020-12800", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "3836d185-177e-431a-93a9-4d8aa2f79765", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-25T00:00:00+00:00"}, "scope": {"notes": "The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution... | Affected: drag-and-drop-multiple-file-upload-contact-form-7 / drag-and-drop-multiple-file-upload-contact-form-7 | CVSS: 9.8 (CRITICAL) | EPSS: 0.78608 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-12800", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12800"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12800"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution...", "cve_id": "CVE-2020-12800", "vendor": "drag-and-drop-multiple-file-upload-contact-form-7", "ghsa_id": null, "product": "drag-and-drop-multiple-file-upload-contact-form-7", "added_date": "2025-06-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.78608, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-12800", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ad05a971-4b87-48ae-8170-86747b9d4349", "vulnerability": {"vulnId": "CVE-2023-26775", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "ad05a971-4b87-48ae-8170-86747b9d4349", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-25T00:00:00+00:00"}, "scope": {"notes": "File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the... | Affected: Monitorr / Monitorr | CVSS: 7.8 (HIGH) | EPSS: 0.49367 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26775", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26775"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26775"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the...", "cve_id": "CVE-2023-26775", "vendor": "Monitorr", "ghsa_id": null, "product": "Monitorr", "added_date": "2025-06-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.49367, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98857, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26775", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "49d4aaf1-6876-410f-bab0-c262d98efea1", "vulnerability": {"vulnId": "CVE-2020-24589", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "49d4aaf1-6876-410f-bab0-c262d98efea1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-25T00:00:00+00:00"}, "scope": {"notes": "The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks. | Affected: WSO2 / API Manager | CVSS: 9.1 (CRITICAL) | EPSS: 0.26282 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-24589", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24589"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24589"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.", "cve_id": "CVE-2020-24589", "vendor": "WSO2", "ghsa_id": null, "product": "API Manager", "added_date": "2025-06-25T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.26282, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97944, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24589", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ba8720b8-acf5-43d1-9a56-f67d75c42fef", "vulnerability": {"vulnId": "CVE-2020-17456", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "ba8720b8-acf5-43d1-9a56-f67d75c42fef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-25T00:00:00+00:00"}, "scope": {"notes": "SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page. | Affected: Seowonintech / SLC-130 and SLR-120S | CVSS: 9.8 (CRITICAL) | EPSS: 0.73635 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-17456", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17456"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17456"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.", "cve_id": "CVE-2020-17456", "vendor": "Seowonintech", "ghsa_id": null, "product": "SLC-130 and SLR-120S", "added_date": "2025-06-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.73635, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99459, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17456", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1ae8a02a-8dc2-4bba-9527-88f63ed89b5b", "vulnerability": {"vulnId": "CVE-2020-12720", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-25T02:00:00+02:00"}, "gcve": {"object_uuid": "1ae8a02a-8dc2-4bba-9527-88f63ed89b5b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-25T00:00:00+00:00"}, "scope": {"notes": "vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control. | Affected: vBulletin / vBulletin | CVSS: 9.8 (CRITICAL) | EPSS: 0.88948 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-12720", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12720"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12720"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.", "cve_id": "CVE-2020-12720", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2025-06-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88948, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99776, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-12720", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cd04b4c0-b3a7-4e08-b3ff-0d15a8a558dc", "vulnerability": {"vulnId": "CVE-2025-34040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T03:12:22+02:00"}, "gcve": {"object_uuid": "cd04b4c0-b3a7-4e08-b3ff-0d15a8a558dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T01:12:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T01:12:22+00:00"}, "scope": {"notes": "Seeyon Zhiyuan OA System Path Traversal File Upload | Affected: Seeyon (Beijing Zhiyuan Internet Software Co.) / Zhiyuan OA Web Application System | CVSS: 10.0 (CRITICAL) | EPSS: 0.15401 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34040", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Seeyon Zhiyuan OA System Path Traversal File Upload", "cve_id": "CVE-2025-34040", "vendor": "Seeyon (Beijing Zhiyuan Internet Software Co.)", "ghsa_id": null, "product": "Zhiyuan OA Web Application System", "added_date": "2025-06-24T01:12:22.000Z", "cvss_score": 10.0, "epss_score": 0.15401, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c70485f6-a7fb-4832-bdd9-009546dba3cb", "vulnerability": {"vulnId": "CVE-2025-34031", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:58:57+02:00"}, "gcve": {"object_uuid": "c70485f6-a7fb-4832-bdd9-009546dba3cb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:58:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:58:57+00:00"}, "scope": {"notes": "Moodle LMS Jmol Plugin Path Traversal | Affected: Moodle / Jmol Plugin | CVSS: 8.7 (HIGH) | EPSS: 0.03057 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34031", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34031"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34031"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Moodle LMS Jmol Plugin Path Traversal", "cve_id": "CVE-2025-34031", "vendor": "Moodle", "ghsa_id": null, "product": "Jmol Plugin", "added_date": "2025-06-24T00:58:57.000Z", "cvss_score": 8.7, "epss_score": 0.03057, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87131, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34031", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "37ff4848-da74-47f4-81ce-fd74e2071f4d", "vulnerability": {"vulnId": "CVE-2025-2777", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:00:00+02:00"}, "gcve": {"object_uuid": "37ff4848-da74-47f4-81ce-fd74e2071f4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:00:00+00:00"}, "scope": {"notes": "SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection | Affected: SysAid / SysAid On-Prem | CVSS: 9.3 (CRITICAL) | EPSS: 0.72202 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-2777", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2777"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2777"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection", "cve_id": "CVE-2025-2777", "vendor": "SysAid", "ghsa_id": null, "product": "SysAid On-Prem", "added_date": "2025-06-24T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.72202, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2777", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d1b790e7-99e3-449d-9893-7ea55cca667e", "vulnerability": {"vulnId": "CVE-2025-24799", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:00:00+02:00"}, "gcve": {"object_uuid": "d1b790e7-99e3-449d-9893-7ea55cca667e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:00:00+00:00"}, "scope": {"notes": "GLPI allows unauthenticated SQL injection through the inventory endpoint | Affected: Glpi-project / glpi | CVSS: 7.5 (HIGH) | EPSS: 0.86692 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-24799", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24799"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24799"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GLPI allows unauthenticated SQL injection through the inventory endpoint", "cve_id": "CVE-2025-24799", "vendor": "Glpi-project", "ghsa_id": null, "product": "glpi", "added_date": "2025-06-24T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.86692, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99738, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24799", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "59966bc3-25d4-45b2-9c54-3bd83024ff86", "vulnerability": {"vulnId": "CVE-2025-26319", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:00:00+02:00"}, "gcve": {"object_uuid": "59966bc3-25d4-45b2-9c54-3bd83024ff86", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:00:00+00:00"}, "scope": {"notes": "FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. | Affected: FlowiseAI / Flowise | CVSS: 9.8 (CRITICAL) | EPSS: 0.55869 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-26319", "url": "https://www.cve.org/CVERecord?id=CVE-2025-26319"}, {"id": "GHSA-69JQ-QR7W-J7QH", "url": "https://github.com/advisories/GHSA-69JQ-QR7W-J7QH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-26319"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.", "cve_id": "CVE-2025-26319", "vendor": "FlowiseAI", "ghsa_id": "GHSA-69JQ-QR7W-J7QH", "product": "Flowise", "added_date": "2025-06-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.55869, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99016, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-26319", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6d62a698-65ed-4c08-997c-13d283189ea9", "vulnerability": {"vulnId": "CVE-2025-27112", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:00:00+02:00"}, "gcve": {"object_uuid": "6d62a698-65ed-4c08-997c-13d283189ea9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:00:00+00:00"}, "scope": {"notes": "Navidrome has authentication bypass in Subsonic API with non-existent username | Affected: Navidrome / navidrome | CVSS: 6.9 (MEDIUM) | EPSS: 0.00982 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-27112", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27112"}, {"id": "GHSA-C3P4-VM8F-386P", "url": "https://github.com/advisories/GHSA-C3P4-VM8F-386P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27112"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Navidrome has authentication bypass in Subsonic API with non-existent username", "cve_id": "CVE-2025-27112", "vendor": "Navidrome", "ghsa_id": "GHSA-C3P4-VM8F-386P", "product": "navidrome", "added_date": "2025-06-24T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.00982, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60919, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27112", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "638fcf76-5708-4e29-bc2b-73c2575dca8f", "vulnerability": {"vulnId": "CVE-2025-26793", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:00:00+02:00"}, "gcve": {"object_uuid": "638fcf76-5708-4e29-bc2b-73c2575dca8f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:00:00+00:00"}, "scope": {"notes": "The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username... | Affected: Hirsch / Enterphone MESH | CVSS: 10.0 (CRITICAL) | EPSS: 0.02396 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-26793", "url": "https://www.cve.org/CVERecord?id=CVE-2025-26793"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-26793"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username...", "cve_id": "CVE-2025-26793", "vendor": "Hirsch", "ghsa_id": null, "product": "Enterphone MESH", "added_date": "2025-06-24T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.02396, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83398, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-26793", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "af36cd7b-d733-4b82-98dd-9daa1064841a", "vulnerability": {"vulnId": "CVE-2025-2294", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-24T02:00:00+02:00"}, "gcve": {"object_uuid": "af36cd7b-d733-4b82-98dd-9daa1064841a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-24T00:00:00+00:00"}, "scope": {"notes": "Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion | Affected: Extend Themes / Kubio AI Page Builder | CVSS: 9.8 (CRITICAL) | EPSS: 0.7836 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-2294", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2294"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2294"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion", "cve_id": "CVE-2025-2294", "vendor": "Extend Themes", "ghsa_id": null, "product": "Kubio AI Page Builder", "added_date": "2025-06-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7836, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9957, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2294", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7120b8fa-a792-46a4-9e1d-cf3992c7ff03", "vulnerability": {"vulnId": "CVE-2021-24285", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "7120b8fa-a792-46a4-9e1d-cf3992c7ff03", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-23T00:00:00+00:00"}, "scope": {"notes": "Car Seller - Auto Classifieds Script <= 2.1.0 - Unauthenticated SQL Injection | Affected: Car Seller / Auto Classifieds Script | CVSS: 9.8 (CRITICAL) | EPSS: 0.14697 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24285", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24285"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24285"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Car Seller - Auto Classifieds Script <= 2.1.0 - Unauthenticated SQL Injection", "cve_id": "CVE-2021-24285", "vendor": "Car Seller", "ghsa_id": null, "product": "Auto Classifieds Script", "added_date": "2025-06-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14697, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96571, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24285", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "217d0e4a-6bca-4e00-a66f-6e6998e110ec", "vulnerability": {"vulnId": "CVE-2025-6485", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-22T19:00:16+02:00"}, "gcve": {"object_uuid": "217d0e4a-6bca-4e00-a66f-6e6998e110ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-22T17:00:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-22T17:00:16+00:00"}, "scope": {"notes": "TOTOLINK A3002R formWlSiteSurvey os command injection | Affected: TOTOLINK / A3002R | CVSS: 5.3 (MEDIUM) | EPSS: 0.09122 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-6485", "url": "https://www.cve.org/CVERecord?id=CVE-2025-6485"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-6485"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK A3002R formWlSiteSurvey os command injection", "cve_id": "CVE-2025-6485", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A3002R", "added_date": "2025-06-22T17:00:16.000Z", "cvss_score": 5.3, "epss_score": 0.09122, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95167, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-6485", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "017603e2-25ad-46d2-b1dd-aeded67e1e85", "vulnerability": {"vulnId": "CVE-2025-0868", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "017603e2-25ad-46d2-b1dd-aeded67e1e85", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution in DocsGPT | Affected: Arc53 / DocsGPT | CVSS: 9.3 (CRITICAL) | EPSS: 0.17087 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-0868", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0868"}, {"id": "GHSA-9GFF-5V8W-X922", "url": "https://github.com/advisories/GHSA-9GFF-5V8W-X922"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0868"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution in DocsGPT", "cve_id": "CVE-2025-0868", "vendor": "Arc53", "ghsa_id": "GHSA-9GFF-5V8W-X922", "product": "DocsGPT", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.17087, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0868", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dfde07f3-ad40-47ac-b83a-a7724755270f", "vulnerability": {"vulnId": "CVE-2018-19276", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "dfde07f3-ad40-47ac-b83a-a7724755270f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary... | Affected: OpenMRS / OpenMRS | CVSS: 9.8 (CRITICAL) | EPSS: 0.98714 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-19276", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19276"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19276"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary...", "cve_id": "CVE-2018-19276", "vendor": "OpenMRS", "ghsa_id": null, "product": "OpenMRS", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98714, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99924, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-19276", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e3516712-1d47-4526-8e51-f3ab7075ef99", "vulnerability": {"vulnId": "CVE-2001-0537", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "e3516712-1d47-4526-8e51-f3ab7075ef99", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being... | Affected: Cisco / IOS | CVSS: 9.3 (HIGH) | EPSS: 0.6845 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2001-0537", "url": "https://www.cve.org/CVERecord?id=CVE-2001-0537"}, {"id": "previdian", "url": "https://previdian.com/CVE-2001-0537"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being...", "cve_id": "CVE-2001-0537", "vendor": "Cisco", "ghsa_id": null, "product": "IOS", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.6845, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99316, "used_in_malware": "unknown", "vulnerability_id": "CVE-2001-0537", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8ad2b697-7320-40bc-bf28-af07ebac4d2c", "vulnerability": {"vulnId": "CVE-2020-13117", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "8ad2b697-7320-40bc-bf28-af07ebac4d2c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a... | Affected: Wavlink / WN575A4, WN579X3, WN530G3A | CVSS: 9.8 (CRITICAL) | EPSS: 0.68576 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-13117", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13117"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13117"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a...", "cve_id": "CVE-2020-13117", "vendor": "Wavlink", "ghsa_id": null, "product": "WN575A4, WN579X3, WN530G3A", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68576, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9932, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13117", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bacaeedd-bb94-4b65-b33a-ff5fdea7eab5", "vulnerability": {"vulnId": "CVE-2021-22707", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "bacaeedd-bb94-4b65-b33a-ff5fdea7eab5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink... | Affected: Schneider Electric / EVlink City, EVlink Parking, EVlink Smart Wallbox | CVSS: 9.8 (CRITICAL) | EPSS: 0.64612 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-22707", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22707"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22707"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink...", "cve_id": "CVE-2021-22707", "vendor": "Schneider Electric", "ghsa_id": null, "product": "EVlink City, EVlink Parking, EVlink Smart Wallbox", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.64612, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99219, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22707", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "689a2754-4e8d-4356-95d0-24f0e877ffb9", "vulnerability": {"vulnId": "CVE-2022-47945", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "689a2754-4e8d-4356-95d0-24f0e877ffb9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled... | Affected: ThinkPHP / ThinkPHP Framework | CVSS: 9.8 (CRITICAL) | EPSS: 0.28254 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-47945", "url": "https://www.cve.org/CVERecord?id=CVE-2022-47945"}, {"id": "GHSA-P4QR-VQ2G-22WP", "url": "https://github.com/advisories/GHSA-P4QR-VQ2G-22WP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-47945"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled...", "cve_id": "CVE-2022-47945", "vendor": "ThinkPHP", "ghsa_id": "GHSA-P4QR-VQ2G-22WP", "product": "ThinkPHP Framework", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.28254, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.98064, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-47945", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1a2bd63f-3d8b-49fa-b8f6-98d1ec0a86f7", "vulnerability": {"vulnId": "CVE-2018-0127", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-21T02:00:00+02:00"}, "gcve": {"object_uuid": "1a2bd63f-3d8b-49fa-b8f6-98d1ec0a86f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-21T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an... | Affected: Cisco / RV132W ADSL2+ Wireless-N VPN Router, RV134W VDSL2 Wireless-AC VPN Router | CVSS: 9.8 (CRITICAL) | EPSS: 0.77484 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-0127", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0127"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0127"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an...", "cve_id": "CVE-2018-0127", "vendor": "Cisco", "ghsa_id": null, "product": "RV132W ADSL2+ Wireless-N VPN Router, RV134W VDSL2 Wireless-AC VPN Router", "added_date": "2025-06-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.77484, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99548, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0127", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1f6dae17-4d53-4e6b-9552-aed1b3a75e6d", "vulnerability": {"vulnId": "CVE-2025-34022", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T20:37:23+02:00"}, "gcve": {"object_uuid": "1f6dae17-4d53-4e6b-9552-aed1b3a75e6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T18:37:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T18:37:23+00:00"}, "scope": {"notes": "Selea Targa IP OCR-ANPR Camera Path Traversal | Affected: Selea / Targa IP OCR-ANPR Camera | CVSS: 9.3 (CRITICAL) | EPSS: 0.00794 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34022", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34022"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34022"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Selea Targa IP OCR-ANPR Camera Path Traversal", "cve_id": "CVE-2025-34022", "vendor": "Selea", "ghsa_id": null, "product": "Targa IP OCR-ANPR Camera", "added_date": "2025-06-20T18:37:23.000Z", "cvss_score": 9.3, "epss_score": 0.00794, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.54797, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34022", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2938b5b9-1582-4ce8-8712-69c11d6a0960", "vulnerability": {"vulnId": "CVE-2025-34021", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T20:37:00+02:00"}, "gcve": {"object_uuid": "2938b5b9-1582-4ce8-8712-69c11d6a0960", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T18:37:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T18:37:00+00:00"}, "scope": {"notes": "Selea Targa IP OCR-ANPR Camera Server-Side Request Forgery | Affected: Selea / Targa IP OCR-ANPR Camera | CVSS: 7.8 (HIGH) | EPSS: 0.00604 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-34021", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34021"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34021"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Selea Targa IP OCR-ANPR Camera Server-Side Request Forgery", "cve_id": "CVE-2025-34021", "vendor": "Selea", "ghsa_id": null, "product": "Targa IP OCR-ANPR Camera", "added_date": "2025-06-20T18:37:00.000Z", "cvss_score": 7.8, "epss_score": 0.00604, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.46984, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34021", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "468f17b5-078a-4821-9cc7-459b5f01be7b", "vulnerability": {"vulnId": "CVE-2017-1000170", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T02:00:00+02:00"}, "gcve": {"object_uuid": "468f17b5-078a-4821-9cc7-459b5f01be7b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T00:00:00+00:00"}, "scope": {"notes": "jqueryFileTree 2.1.5 and older Directory Traversal | Affected: jqueryFileTree / jqueryFileTree | CVSS: 7.5 (HIGH) | EPSS: 0.59063 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-1000170", "url": "https://www.cve.org/CVERecord?id=CVE-2017-1000170"}, {"id": "GHSA-P739-9479-5WR2", "url": "https://github.com/advisories/GHSA-P739-9479-5WR2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-1000170"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "jqueryFileTree 2.1.5 and older Directory Traversal", "cve_id": "CVE-2017-1000170", "vendor": "jqueryFileTree", "ghsa_id": "GHSA-P739-9479-5WR2", "product": "jqueryFileTree", "added_date": "2025-06-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.59063, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99088, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-1000170", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4a9a99e2-ab7e-4270-b215-25bcd11860f1", "vulnerability": {"vulnId": "CVE-2018-11222", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T02:00:00+02:00"}, "gcve": {"object_uuid": "4a9a99e2-ab7e-4270-b215-25bcd11860f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T00:00:00+00:00"}, "scope": {"notes": "Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php... | Affected: Artica / Pandora FMS | CVSS: 7.5 (HIGH) | EPSS: 0.06534 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11222", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11222"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11222"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php...", "cve_id": "CVE-2018-11222", "vendor": "Artica", "ghsa_id": null, "product": "Pandora FMS", "added_date": "2025-06-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.06534, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93589, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11222", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "100401cc-0e71-4f1f-ab80-d18bea26cca9", "vulnerability": {"vulnId": "CVE-2017-8226", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T02:00:00+02:00"}, "gcve": {"object_uuid": "100401cc-0e71-4f1f-ab80-d18bea26cca9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T00:00:00+00:00"}, "scope": {"notes": "Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who... | Affected: Amcrest / IPM-721S | CVSS: 9.8 (CRITICAL) | EPSS: 0.03799 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-8226", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8226"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8226"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who...", "cve_id": "CVE-2017-8226", "vendor": "Amcrest", "ghsa_id": null, "product": "IPM-721S", "added_date": "2025-06-20T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03799, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89666, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8226", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f2bfdf1b-b4ec-42fe-bbe8-7c6312ecf9ea", "vulnerability": {"vulnId": "CVE-2021-41293", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T02:00:00+02:00"}, "gcve": {"object_uuid": "f2bfdf1b-b4ec-42fe-bbe8-7c6312ecf9ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T00:00:00+00:00"}, "scope": {"notes": "ECOA BAS controller - Path Traversal-3 | Affected: ECOA / ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB 3.0.0, RiskBuster System TRANE 1.0, Graphic Control Software, SmartHome II E9246, RiskTerminator | CVSS: 7.5 (HIGH) | EPSS: 0.19867 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-41293", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41293"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41293"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ECOA BAS controller - Path Traversal-3", "cve_id": "CVE-2021-41293", "vendor": "ECOA", "ghsa_id": null, "product": "ECS Router Controller ECS (FLASH), RiskBuster Terminator E6L45, RiskBuster System RB 3.0.0, RiskBuster System TRANE 1.0, Graphic Control Software, SmartHome II E9246, RiskTerminator", "added_date": "2025-06-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.19867, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97349, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41293", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "da7e454f-b579-4f15-b6a9-8695812a5835", "vulnerability": {"vulnId": "CVE-2020-11455", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T02:00:00+02:00"}, "gcve": {"object_uuid": "da7e454f-b579-4f15-b6a9-8695812a5835", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T00:00:00+00:00"}, "scope": {"notes": "LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php. | Affected: LimeSurvey / LimeSurvey | CVSS: 9.8 (CRITICAL) | EPSS: 0.97179 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11455", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11455"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11455"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.", "cve_id": "CVE-2020-11455", "vendor": "LimeSurvey", "ghsa_id": null, "product": "LimeSurvey", "added_date": "2025-06-20T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97179, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99894, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11455", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3ba0bee4-1a8a-40ca-ba7b-d3d1c9156ecc", "vulnerability": {"vulnId": "CVE-2018-14912", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-20T02:00:00+02:00"}, "gcve": {"object_uuid": "3ba0bee4-1a8a-40ca-ba7b-d3d1c9156ecc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-20T00:00:00+00:00"}, "scope": {"notes": "cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a... | Affected: Zx2c4 / CGit | CVSS: 7.5 (HIGH) | EPSS: 0.92033 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-14912", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14912"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14912"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a...", "cve_id": "CVE-2018-14912", "vendor": "Zx2c4", "ghsa_id": null, "product": "CGit", "added_date": "2025-06-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.92033, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99819, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14912", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "57542889-a518-44c2-b214-f295adbea99e", "vulnerability": {"vulnId": "CVE-2024-7120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-19T02:00:00+02:00"}, "gcve": {"object_uuid": "57542889-a518-44c2-b214-f295adbea99e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-19T00:00:00+00:00"}, "scope": {"notes": "Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection | Affected: Raisecom / MSG1200, MSG2100E, MSG2200, MSG2300 | CVSS: 5.3 (MEDIUM) | EPSS: 0.934 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7120", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7120"}, {"id": "GHSA-9254-9WVC-GMQR", "url": "https://github.com/advisories/GHSA-9254-9WVC-GMQR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection", "cve_id": "CVE-2024-7120", "vendor": "Raisecom", "ghsa_id": "GHSA-9254-9WVC-GMQR", "product": "MSG1200, MSG2100E, MSG2200, MSG2300", "added_date": "2025-06-19T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.934, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99838, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7120", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "13ed417c-3161-4eec-bf48-45b277b0426d", "vulnerability": {"vulnId": "CVE-2024-9644", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-18T02:00:00+02:00"}, "gcve": {"object_uuid": "13ed417c-3161-4eec-bf48-45b277b0426d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-18T00:00:00+00:00"}, "scope": {"notes": "Four-Faith F3x36 bapply.cgi Auth Bypass | Affected: Four-Faith / F3x36 | CVSS: 9.8 (CRITICAL) | EPSS: 0.00673 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9644", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9644"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9644"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Four-Faith F3x36 bapply.cgi Auth Bypass", "cve_id": "CVE-2024-9644", "vendor": "Four-Faith", "ghsa_id": null, "product": "F3x36", "added_date": "2025-06-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.00673, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50329, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9644", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "635728bf-a6fd-4799-930b-27c2d4745b72", "vulnerability": {"vulnId": "CVE-2021-29442", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-18T02:00:00+02:00"}, "gcve": {"object_uuid": "635728bf-a6fd-4799-930b-27c2d4745b72", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-18T00:00:00+00:00"}, "scope": {"notes": "Authentication bypass | Affected: Alibaba / nacos | CVSS: 8.6 (HIGH) | EPSS: 0.65717 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-29442", "url": "https://www.cve.org/CVERecord?id=CVE-2021-29442"}, {"id": "GHSA-XV5H-V7JH-P2QH", "url": "https://github.com/advisories/GHSA-XV5H-V7JH-P2QH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-29442"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication bypass", "cve_id": "CVE-2021-29442", "vendor": "Alibaba", "ghsa_id": "GHSA-XV5H-V7JH-P2QH", "product": "nacos", "added_date": "2025-06-18T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.65717, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99246, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-29442", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "95a4365a-8c37-4e95-be0e-31fd17461592", "vulnerability": {"vulnId": "CVE-2025-4123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-17T17:00:06+02:00"}, "gcve": {"object_uuid": "95a4365a-8c37-4e95-be0e-31fd17461592", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-17T15:00:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-17T15:00:06+00:00"}, "scope": {"notes": "A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers... | Affected: Grafana / Grafana | CVSS: 7.6 (HIGH) | EPSS: 0.97007 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4123", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4123"}, {"id": "GHSA-Q53Q-GXQ9-MGRJ", "url": "https://github.com/advisories/GHSA-Q53Q-GXQ9-MGRJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers...", "cve_id": "CVE-2025-4123", "vendor": "Grafana", "ghsa_id": "GHSA-Q53Q-GXQ9-MGRJ", "product": "Grafana", "added_date": "2025-06-17T15:00:06.000Z", "cvss_score": 7.6, "epss_score": 0.97007, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1edb8587-11f7-4f8e-af98-2d05f2784e81", "vulnerability": {"vulnId": "CVE-2022-48164", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-17T02:00:00+02:00"}, "gcve": {"object_uuid": "1edb8587-11f7-4f8e-af98-2d05f2784e81", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-17T00:00:00+00:00"}, "scope": {"notes": "An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to... | Affected: Wavlink / WL-WN533A8 | CVSS: 7.5 (HIGH) | EPSS: 0.03096 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-48164", "url": "https://www.cve.org/CVERecord?id=CVE-2022-48164"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-48164"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to...", "cve_id": "CVE-2022-48164", "vendor": "Wavlink", "ghsa_id": null, "product": "WL-WN533A8", "added_date": "2025-06-17T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03096, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87284, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-48164", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "201d8e78-e6f5-4ca7-a64e-3b2b4008647a", "vulnerability": {"vulnId": "CVE-2022-0540", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-17T02:00:00+02:00"}, "gcve": {"object_uuid": "201d8e78-e6f5-4ca7-a64e-3b2b4008647a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-17T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This... | Affected: Atlassian / Jira Core Server, Jira Software Server, Jira Software Data Center, Jira Service Management Server, Jira Service Management Data Center | CVSS: 9.8 (CRITICAL) | EPSS: 0.88057 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0540", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0540"}, {"id": "GHSA-H5CM-VC68-69H9", "url": "https://github.com/advisories/GHSA-H5CM-VC68-69H9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0540"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This...", "cve_id": "CVE-2022-0540", "vendor": "Atlassian", "ghsa_id": "GHSA-H5CM-VC68-69H9", "product": "Jira Core Server, Jira Software Server, Jira Software Data Center, Jira Service Management Server, Jira Service Management Data Center", "added_date": "2025-06-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88057, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99763, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0540", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ed60a20d-dc5f-4583-843f-a3109adc332b", "vulnerability": {"vulnId": "CVE-2022-39960", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-17T02:00:00+02:00"}, "gcve": {"object_uuid": "ed60a20d-dc5f-4583-843f-a3109adc332b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-17T00:00:00+00:00"}, "scope": {"notes": "The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to... | Affected: Atlassian / Jira | CVSS: 5.3 (MEDIUM) | EPSS: 0.2568 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-39960", "url": "https://www.cve.org/CVERecord?id=CVE-2022-39960"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-39960"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to...", "cve_id": "CVE-2022-39960", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira", "added_date": "2025-06-17T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.2568, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-39960", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b56aec57-6702-4df8-84d1-055201d58f6d", "vulnerability": {"vulnId": "CVE-2022-31847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-17T02:00:00+02:00"}, "gcve": {"object_uuid": "b56aec57-6702-4df8-84d1-055201d58f6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-17T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via... | Affected: WAVLINK / WN579 X3 | CVSS: 7.5 (HIGH) | EPSS: 0.06555 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31847", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via...", "cve_id": "CVE-2022-31847", "vendor": "WAVLINK", "ghsa_id": null, "product": "WN579 X3", "added_date": "2025-06-17T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.06555, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93605, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31847", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7e0721e3-38c4-410c-b3fe-f08a503babda", "vulnerability": {"vulnId": "CVE-2020-8209", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-14T02:00:00+02:00"}, "gcve": {"object_uuid": "7e0721e3-38c4-410c-b3fe-f08a503babda", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-14T00:00:00+00:00"}, "scope": {"notes": "Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before... | Affected: Citrix / XenMobile Server | CVSS: 7.5 (HIGH) | EPSS: 0.48656 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8209", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8209"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8209"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before...", "cve_id": "CVE-2020-8209", "vendor": "Citrix", "ghsa_id": null, "product": "XenMobile Server", "added_date": "2025-06-14T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.48656, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98836, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8209", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9e3f6986-bd7e-4f0a-8b2b-61f7bb5a6298", "vulnerability": {"vulnId": "CVE-2020-8191", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-14T02:00:00+02:00"}, "gcve": {"object_uuid": "9e3f6986-bd7e-4f0a-8b2b-61f7bb5a6298", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-14T00:00:00+00:00"}, "scope": {"notes": "Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... | Affected: Citrix / Citrix ADC and Citrix Gateway | CVSS: 6.1 (MEDIUM) | EPSS: 0.26136 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8191", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8191"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8191"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...", "cve_id": "CVE-2020-8191", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ADC and Citrix Gateway", "added_date": "2025-06-14T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.26136, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97935, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8191", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "82b8b0ea-a951-4ae6-9180-55977404bfe2", "vulnerability": {"vulnId": "CVE-2019-12990", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "82b8b0ea-a951-4ae6-9180-55977404bfe2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-13T00:00:00+00:00"}, "scope": {"notes": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. | Affected: Citrix / SD-WAN | CVSS: 9.8 (CRITICAL) | EPSS: 0.39335 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12990", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12990"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12990"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.", "cve_id": "CVE-2019-12990", "vendor": "Citrix", "ghsa_id": null, "product": "SD-WAN", "added_date": "2025-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39335, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98563, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12990", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "836c0d5b-e2d2-4756-ab91-4f9b1ca09b7b", "vulnerability": {"vulnId": "CVE-2019-12986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "836c0d5b-e2d2-4756-ab91-4f9b1ca09b7b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-13T00:00:00+00:00"}, "scope": {"notes": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). | Affected: Citrix / SD-WAN | CVSS: 9.8 (CRITICAL) | EPSS: 0.39544 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12986", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12986"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).", "cve_id": "CVE-2019-12986", "vendor": "Citrix", "ghsa_id": null, "product": "SD-WAN", "added_date": "2025-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39544, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98571, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "82dfaa4e-469a-45eb-aeea-ab9cc6c5f048", "vulnerability": {"vulnId": "CVE-2019-12987", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "82dfaa4e-469a-45eb-aeea-ab9cc6c5f048", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-13T00:00:00+00:00"}, "scope": {"notes": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). | Affected: Citrix / SD-WAN | CVSS: 9.8 (CRITICAL) | EPSS: 0.42551 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12987", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12987"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12987"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).", "cve_id": "CVE-2019-12987", "vendor": "Citrix", "ghsa_id": null, "product": "SD-WAN", "added_date": "2025-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.42551, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98669, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12987", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b4677418-a0bd-4b68-820b-bf6a696aaa09", "vulnerability": {"vulnId": "CVE-2025-45988", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "b4677418-a0bd-4b68-820b-bf6a696aaa09", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-13T00:00:00+00:00"}, "scope": {"notes": "Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4... | Affected: Blink / Blink routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.10883 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-45988", "url": "https://www.cve.org/CVERecord?id=CVE-2025-45988"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-45988"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4...", "cve_id": "CVE-2025-45988", "vendor": "Blink", "ghsa_id": null, "product": "Blink routers", "added_date": "2025-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.10883, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95736, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-45988", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0948eb2c-73a1-42fc-8d10-02e968b7b3bd", "vulnerability": {"vulnId": "CVE-2021-20837", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "0948eb2c-73a1-42fc-8d10-02e968b7b3bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-13T00:00:00+00:00"}, "scope": {"notes": "Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002... | Affected: Six Apart / Movable Type | CVSS: 9.8 (CRITICAL) | EPSS: 0.88144 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-20837", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20837"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20837"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002...", "cve_id": "CVE-2021-20837", "vendor": "Six Apart", "ghsa_id": null, "product": "Movable Type", "added_date": "2025-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88144, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99765, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20837", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c074425f-0ae5-42cb-b2eb-9492562dace4", "vulnerability": {"vulnId": "CVE-2019-12985", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "c074425f-0ae5-42cb-b2eb-9492562dace4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-13T00:00:00+00:00"}, "scope": {"notes": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). | Affected: Citrix / SD-WAN | CVSS: 9.8 (CRITICAL) | EPSS: 0.39544 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12985", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12985"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12985"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).", "cve_id": "CVE-2019-12985", "vendor": "Citrix", "ghsa_id": null, "product": "SD-WAN", "added_date": "2025-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39544, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98571, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12985", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f2a8af6-a296-4457-92b2-1b19e8360e5a", "vulnerability": {"vulnId": "CVE-2021-34624", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-12T02:00:00+02:00"}, "gcve": {"object_uuid": "8f2a8af6-a296-4457-92b2-1b19e8360e5a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-12T00:00:00+00:00"}, "scope": {"notes": "ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component | Affected: ProfilePress / ProfilePress | CVSS: 9.8 (CRITICAL) | EPSS: 0.06744 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-34624", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34624"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34624"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component", "cve_id": "CVE-2021-34624", "vendor": "ProfilePress", "ghsa_id": null, "product": "ProfilePress", "added_date": "2025-06-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06744, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93762, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34624", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8d33085f-98e0-40bc-9254-932e354e3f0f", "vulnerability": {"vulnId": "CVE-2023-1020", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-12T02:00:00+02:00"}, "gcve": {"object_uuid": "8d33085f-98e0-40bc-9254-932e354e3f0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-12T00:00:00+00:00"}, "scope": {"notes": "Steveas WP Live Chat Shoutbox <= 1.4.2 - Unauthenticated SQLi | Affected: Steveas / WP Live Chat Shoutbox | CVSS: 9.8 (CRITICAL) | EPSS: 0.04949 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-1020", "url": "https://www.cve.org/CVERecord?id=CVE-2023-1020"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-1020"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Steveas WP Live Chat Shoutbox <= 1.4.2 - Unauthenticated SQLi", "cve_id": "CVE-2023-1020", "vendor": "Steveas", "ghsa_id": null, "product": "WP Live Chat Shoutbox", "added_date": "2025-06-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04949, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91894, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-1020", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "90eaf52a-fefd-4e3e-94a2-8f945e7aec14", "vulnerability": {"vulnId": "CVE-2021-24499", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-11T02:00:00+02:00"}, "gcve": {"object_uuid": "90eaf52a-fefd-4e3e-94a2-8f945e7aec14", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-11T00:00:00+00:00"}, "scope": {"notes": "Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution | Affected: Workreap / Workreap | CVSS: 9.8 (CRITICAL) | EPSS: 0.60113 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24499", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24499"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24499"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution", "cve_id": "CVE-2021-24499", "vendor": "Workreap", "ghsa_id": null, "product": "Workreap", "added_date": "2025-06-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.60113, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9911, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24499", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7e1cc910-7400-4a85-9839-f8a3cfcdfbdb", "vulnerability": {"vulnId": "CVE-2021-36356", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-11T02:00:00+02:00"}, "gcve": {"object_uuid": "7e1cc910-7400-4a85-9839-f8a3cfcdfbdb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-11T00:00:00+00:00"}, "scope": {"notes": "KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts... | Affected: KRAMER / VIAware | CVSS: 9.8 (CRITICAL) | EPSS: 0.54393 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-36356", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36356"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36356"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts...", "cve_id": "CVE-2021-36356", "vendor": "KRAMER", "ghsa_id": null, "product": "VIAware", "added_date": "2025-06-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.54393, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36356", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e565b832-f0f3-4869-bdfb-741b1078ff3b", "vulnerability": {"vulnId": "CVE-2021-24762", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-11T02:00:00+02:00"}, "gcve": {"object_uuid": "e565b832-f0f3-4869-bdfb-741b1078ff3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-11T00:00:00+00:00"}, "scope": {"notes": "Perfect Survey < 1.5.2 - Unauthenticated SQL Injection | Affected: Perfect Survey / Perfect Survey | CVSS: 9.8 (CRITICAL) | EPSS: 0.86782 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24762", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24762"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24762"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Perfect Survey < 1.5.2 - Unauthenticated SQL Injection", "cve_id": "CVE-2021-24762", "vendor": "Perfect Survey", "ghsa_id": null, "product": "Perfect Survey", "added_date": "2025-06-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86782, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9974, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24762", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ff81564d-ad3c-44e9-927f-5d696c5c560b", "vulnerability": {"vulnId": "CVE-2021-29203", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-11T02:00:00+02:00"}, "gcve": {"object_uuid": "ff81564d-ad3c-44e9-927f-5d696c5c560b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-11T00:00:00+00:00"}, "scope": {"notes": "A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management... | Affected: Hewlett Packard Enterprise / HPE Edgeline Infrastructure Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.68293 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-29203", "url": "https://www.cve.org/CVERecord?id=CVE-2021-29203"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-29203"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management...", "cve_id": "CVE-2021-29203", "vendor": "Hewlett Packard Enterprise", "ghsa_id": null, "product": "HPE Edgeline Infrastructure Manager", "added_date": "2025-06-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68293, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99312, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-29203", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "29229d1c-f9e6-404e-a3cc-60d5b78a67d5", "vulnerability": {"vulnId": "CVE-2009-0545", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-10T02:00:00+02:00"}, "gcve": {"object_uuid": "29229d1c-f9e6-404e-a3cc-60d5b78a67d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-10T00:00:00+00:00"}, "scope": {"notes": "cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type... | Affected: ZeroShell / ZeroShell | CVSS: 10.0 (HIGH) | EPSS: 0.90386 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-0545", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0545"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0545"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type...", "cve_id": "CVE-2009-0545", "vendor": "ZeroShell", "ghsa_id": null, "product": "ZeroShell", "added_date": "2025-06-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.90386, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99798, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0545", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9804d061-84fa-47af-978c-335c77de64d3", "vulnerability": {"vulnId": "CVE-2024-32735", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-10T02:00:00+02:00"}, "gcve": {"object_uuid": "9804d061-84fa-47af-978c-335c77de64d3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-10T00:00:00+00:00"}, "scope": {"notes": "CyberPower PowerPanel Enterprise Missing Authentication | Affected: CyberPower / CyberPower PowerPanel Enterprise | CVSS: 9.8 (CRITICAL) | EPSS: 0.06765 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-32735", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32735"}, {"id": "GHSA-67P4-W92F-QX68", "url": "https://github.com/advisories/GHSA-67P4-W92F-QX68"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32735"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CyberPower PowerPanel Enterprise Missing Authentication", "cve_id": "CVE-2024-32735", "vendor": "CyberPower", "ghsa_id": "GHSA-67P4-W92F-QX68", "product": "CyberPower PowerPanel Enterprise", "added_date": "2025-06-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06765, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93777, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32735", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d9ba08b2-cf5e-420b-872a-4fe3a109c824", "vulnerability": {"vulnId": "CVE-2021-21234", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-10T02:00:00+02:00"}, "gcve": {"object_uuid": "d9ba08b2-cf5e-420b-872a-4fe3a109c824", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-10T00:00:00+00:00"}, "scope": {"notes": "Directory Traversal | Affected: Lukashinsch / spring-boot-actuator-logview | CVSS: 7.7 (HIGH) | EPSS: 0.21011 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21234", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21234"}, {"id": "GHSA-P4Q6-QXJX-8JGP", "url": "https://github.com/advisories/GHSA-P4Q6-QXJX-8JGP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21234"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory Traversal", "cve_id": "CVE-2021-21234", "vendor": "Lukashinsch", "ghsa_id": "GHSA-P4Q6-QXJX-8JGP", "product": "spring-boot-actuator-logview", "added_date": "2025-06-10T00:00:00.000Z", "cvss_score": 7.7, "epss_score": 0.21011, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97503, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21234", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "568b5efb-c1d5-4a05-b991-472b9216e084", "vulnerability": {"vulnId": "CVE-2020-13942", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-09T02:00:00+02:00"}, "gcve": {"object_uuid": "568b5efb-c1d5-4a05-b991-472b9216e084", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-09T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution in Apache Unomi | Affected: Apache / Apache Unomi | CVSS: 9.8 (CRITICAL) | EPSS: 0.68296 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-13942", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13942"}, {"id": "GHSA-XP5J-WJ4H-2JQ9", "url": "https://github.com/advisories/GHSA-XP5J-WJ4H-2JQ9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13942"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution in Apache Unomi", "cve_id": "CVE-2020-13942", "vendor": "Apache", "ghsa_id": "GHSA-XP5J-WJ4H-2JQ9", "product": "Apache Unomi", "added_date": "2025-06-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68296, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99313, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13942", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "21d0c2e1-b6da-4a3a-97a8-3466c49ccb39", "vulnerability": {"vulnId": "CVE-2023-47248", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-09T02:00:00+02:00"}, "gcve": {"object_uuid": "21d0c2e1-b6da-4a3a-97a8-3466c49ccb39", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-09T00:00:00+00:00"}, "scope": {"notes": "PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file | Affected: Apache / PyArrow | CVSS: 9.8 (CRITICAL) | EPSS: 0.14528 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-47248", "url": "https://www.cve.org/CVERecord?id=CVE-2023-47248"}, {"id": "GHSA-5WVP-7F3H-6WMM", "url": "https://github.com/advisories/GHSA-5WVP-7F3H-6WMM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-47248"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PyArrow, PyArrow: Arbitrary code execution when loading a malicious data file", "cve_id": "CVE-2023-47248", "vendor": "Apache", "ghsa_id": "GHSA-5WVP-7F3H-6WMM", "product": "PyArrow", "added_date": "2025-06-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14528, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96539, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-47248", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1f99809b-a021-4aeb-988b-70063ac97c37", "vulnerability": {"vulnId": "CVE-2019-18818", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "1f99809b-a021-4aeb-988b-70063ac97c37", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-08T00:00:00+00:00"}, "scope": {"notes": "strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and... | Affected: Strapi / strapi | CVSS: 9.8 (CRITICAL) | EPSS: 0.97639 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-18818", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18818"}, {"id": "GHSA-6XC2-MJ39-Q599", "url": "https://github.com/advisories/GHSA-6XC2-MJ39-Q599"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18818"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and...", "cve_id": "CVE-2019-18818", "vendor": "Strapi", "ghsa_id": "GHSA-6XC2-MJ39-Q599", "product": "strapi", "added_date": "2025-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97639, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18818", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3a121382-5820-4572-b847-220fb2c9a511", "vulnerability": {"vulnId": "CVE-2019-1821", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "3a121382-5820-4572-b847-220fb2c9a511", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-08T00:00:00+00:00"}, "scope": {"notes": "Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities | Affected: Cisco / Cisco Prime Infrastructure | CVSS: 8.8 (HIGH) | EPSS: 0.98051 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-1821", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1821"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1821"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities", "cve_id": "CVE-2019-1821", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Prime Infrastructure", "added_date": "2025-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.98051, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9991, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1821", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ed824f61-114f-4e5e-975f-452e6f481cb1", "vulnerability": {"vulnId": "CVE-2020-11546", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "ed824f61-114f-4e5e-975f-452e6f481cb1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-08T00:00:00+00:00"}, "scope": {"notes": "SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An... | Affected: SuperWebMailer / SuperWebMailer | CVSS: 9.8 (CRITICAL) | EPSS: 0.32841 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11546", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11546"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11546"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An...", "cve_id": "CVE-2020-11546", "vendor": "SuperWebMailer", "ghsa_id": null, "product": "SuperWebMailer", "added_date": "2025-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.32841, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98307, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11546", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ee6c6a10-0c54-4e0a-8a51-0c40b7131baf", "vulnerability": {"vulnId": "CVE-2020-36112", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "ee6c6a10-0c54-4e0a-8a51-0c40b7131baf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-07T00:00:00+00:00"}, "scope": {"notes": "CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in... | Affected: CSE / Bookstore | CVSS: 9.8 (CRITICAL) | EPSS: 0.18052 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-36112", "url": "https://www.cve.org/CVERecord?id=CVE-2020-36112"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-36112"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in...", "cve_id": "CVE-2020-36112", "vendor": "CSE", "ghsa_id": null, "product": "Bookstore", "added_date": "2025-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.18052, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9711, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-36112", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4b0d0504-6a05-41dd-99de-ec90a5fd667d", "vulnerability": {"vulnId": "CVE-2022-0867", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "4b0d0504-6a05-41dd-99de-ec90a5fd667d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-07T00:00:00+00:00"}, "scope": {"notes": "ARPrice Lite < 3.6.1 - Unauthenticated SQLi | Affected: ARPrice / ARPrice Lite | CVSS: 9.8 (CRITICAL) | EPSS: 0.1345 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0867", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0867"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0867"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ARPrice Lite < 3.6.1 - Unauthenticated SQLi", "cve_id": "CVE-2022-0867", "vendor": "ARPrice", "ghsa_id": null, "product": "ARPrice Lite", "added_date": "2025-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1345, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0867", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "01858887-b8a7-4f02-814b-0333c2d234b7", "vulnerability": {"vulnId": "CVE-2018-2894", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "01858887-b8a7-4f02-814b-0333c2d234b7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-07T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.50224 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-2894", "url": "https://www.cve.org/CVERecord?id=CVE-2018-2894"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-2894"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are...", "cve_id": "CVE-2018-2894", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2025-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.50224, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98874, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-2894", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "00b7e5dc-8786-4910-8e58-1c7b1a3a1620", "vulnerability": {"vulnId": "CVE-2018-10942", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "00b7e5dc-8786-4910-8e58-1c7b1a3a1620", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-07T00:00:00+00:00"}, "scope": {"notes": "modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to... | Affected: PrestaShop / Attribute Wizard addon | CVSS: 9.8 (CRITICAL) | EPSS: 0.12555 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10942", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10942"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10942"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to...", "cve_id": "CVE-2018-10942", "vendor": "PrestaShop", "ghsa_id": null, "product": "Attribute Wizard addon", "added_date": "2025-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.12555, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96116, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10942", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fe722a10-e7b9-45b5-9caf-952b00318ba8", "vulnerability": {"vulnId": "CVE-2018-3810", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "fe722a10-e7b9-45b5-9caf-952b00318ba8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-07T00:00:00+00:00"}, "scope": {"notes": "Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to... | Affected: Oturia / Smart Google Code Inserter | CVSS: 9.8 (CRITICAL) | EPSS: 0.91141 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-3810", "url": "https://www.cve.org/CVERecord?id=CVE-2018-3810"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-3810"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to...", "cve_id": "CVE-2018-3810", "vendor": "Oturia", "ghsa_id": null, "product": "Smart Google Code Inserter", "added_date": "2025-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91141, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99807, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-3810", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "df215d45-8c7d-4a20-8b15-b89456d7d048", "vulnerability": {"vulnId": "CVE-2014-3206", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "df215d45-8c7d-4a20-8b15-b89456d7d048", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-07T00:00:00+00:00"}, "scope": {"notes": "Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the... | Affected: Seagate / BlackArmor NAS | CVSS: 9.8 (CRITICAL) | EPSS: 0.51014 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-3206", "url": "https://www.cve.org/CVERecord?id=CVE-2014-3206"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-3206"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the...", "cve_id": "CVE-2014-3206", "vendor": "Seagate", "ghsa_id": null, "product": "BlackArmor NAS", "added_date": "2025-06-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.51014, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98898, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-3206", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "587985be-41be-4948-ad79-671ecc3bcee7", "vulnerability": {"vulnId": "CVE-2022-0786", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "587985be-41be-4948-ad79-671ecc3bcee7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "KiviCare < 2.3.9 - Unauthenticated SQLi | Affected: KiviCare / KiviCare | CVSS: 9.8 (CRITICAL) | EPSS: 0.13271 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0786", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0786"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0786"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "KiviCare < 2.3.9 - Unauthenticated SQLi", "cve_id": "CVE-2022-0786", "vendor": "KiviCare", "ghsa_id": null, "product": "KiviCare", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.13271, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96275, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0786", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e8044253-8660-46bb-8ea3-f7c8f6146398", "vulnerability": {"vulnId": "CVE-2020-10548", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "e8044253-8660-46bb-8ea3-f7c8f6146398", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in... | Affected: rConfig / rConfig | CVSS: 9.8 (CRITICAL) | EPSS: 0.36513 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-10548", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10548"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10548"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in...", "cve_id": "CVE-2020-10548", "vendor": "rConfig", "ghsa_id": null, "product": "rConfig", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.36513, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98449, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10548", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f093c0da-3ccd-4534-ae9a-f69fd7ffde0c", "vulnerability": {"vulnId": "CVE-2022-25369", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "f093c0da-3ccd-4534-ae9a-f69fd7ffde0c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a... | Affected: Dynamicweb / Dynamicweb | CVSS: 9.8 (CRITICAL) | EPSS: 0.40014 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25369", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25369"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25369"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a...", "cve_id": "CVE-2022-25369", "vendor": "Dynamicweb", "ghsa_id": null, "product": "Dynamicweb", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.40014, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98589, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25369", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1b8a504e-3006-45da-b770-6eeff782b615", "vulnerability": {"vulnId": "CVE-2018-16763", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "1b8a504e-3006-45da-b770-6eeff782b615", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote... | Affected: Daylight Studio / FUEL CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.82937 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-16763", "url": "https://www.cve.org/CVERecord?id=CVE-2018-16763"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-16763"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote...", "cve_id": "CVE-2018-16763", "vendor": "Daylight Studio", "ghsa_id": null, "product": "FUEL CMS", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82937, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99664, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-16763", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d6cf04a6-9407-47fa-9a1a-2749bb5b19da", "vulnerability": {"vulnId": "CVE-2022-24260", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "d6cf04a6-9407-47fa-9a1a-2749bb5b19da", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. | Affected: Voipmonitor / Voipmonitor GUI | CVSS: 9.8 (CRITICAL) | EPSS: 0.49992 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-24260", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24260"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24260"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.", "cve_id": "CVE-2022-24260", "vendor": "Voipmonitor", "ghsa_id": null, "product": "Voipmonitor GUI", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.49992, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98869, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24260", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "94af0cd4-49ec-49bc-9b28-c7943e2e58a4", "vulnerability": {"vulnId": "CVE-2021-30168", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "94af0cd4-49ec-49bc-9b28-c7943e2e58a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "MERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-1 | Affected: MERIT LILIN ENT / P2/Z2/P3/Z3 IP camera firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.02075 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30168", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30168"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30168"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-1", "cve_id": "CVE-2021-30168", "vendor": "MERIT LILIN ENT", "ghsa_id": null, "product": "P2/Z2/P3/Z3 IP camera firmware", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.02075, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80771, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30168", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fdc452ff-8808-40bc-ac4c-331403a8e33a", "vulnerability": {"vulnId": "CVE-2022-41840", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-06T02:00:00+02:00"}, "gcve": {"object_uuid": "fdc452ff-8808-40bc-ac4c-331403a8e33a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-06T00:00:00+00:00"}, "scope": {"notes": "WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability | Affected: Collne / Welcart e-Commerce (WordPress plugin) | CVSS: 7.5 (HIGH) | EPSS: 0.05521 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-41840", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41840"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41840"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability", "cve_id": "CVE-2022-41840", "vendor": "Collne", "ghsa_id": null, "product": "Welcart e-Commerce (WordPress plugin)", "added_date": "2025-06-06T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.05521, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92557, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41840", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ffae912c-9c62-4cf2-ae3d-d49e4bfe51f4", "vulnerability": {"vulnId": "CVE-2023-2648", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:08:41+02:00"}, "gcve": {"object_uuid": "ffae912c-9c62-4cf2-ae3d-d49e4bfe51f4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:08:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:08:41+00:00"}, "scope": {"notes": "Weaver E-Office uploadify.php unrestricted upload | Affected: Weaver / E-Office | CVSS: 6.3 (MEDIUM) | EPSS: 0.28478 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-2648", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2648"}, {"id": "GHSA-P87M-68PC-HG94", "url": "https://github.com/advisories/GHSA-P87M-68PC-HG94"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2648"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-Office uploadify.php unrestricted upload", "cve_id": "CVE-2023-2648", "vendor": "Weaver", "ghsa_id": "GHSA-P87M-68PC-HG94", "product": "E-Office", "added_date": "2025-06-05T09:08:41.357Z", "cvss_score": 6.3, "epss_score": 0.28478, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98076, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2648", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "075a1ace-dbb0-4c9c-90f7-68a516e085f3", "vulnerability": {"vulnId": "CVE-2024-11238", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:08:33+02:00"}, "gcve": {"object_uuid": "075a1ace-dbb0-4c9c-90f7-68a516e085f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:08:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:08:33+00:00"}, "scope": {"notes": "Landray EKP sysUiComponent.do delPreviewFile path traversal | Affected: Landray / EKP | CVSS: 6.9 (MEDIUM) | EPSS: 0.05747 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-11238", "url": "https://www.cve.org/CVERecord?id=CVE-2024-11238"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-11238"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Landray EKP sysUiComponent.do delPreviewFile path traversal", "cve_id": "CVE-2024-11238", "vendor": "Landray", "ghsa_id": null, "product": "EKP", "added_date": "2025-06-05T09:08:33.869Z", "cvss_score": 6.9, "epss_score": 0.05747, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9283, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-11238", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0888cf80-1b1c-4f30-971c-a12cb0c83e29", "vulnerability": {"vulnId": "CVE-2023-47218", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:08:26+02:00"}, "gcve": {"object_uuid": "0888cf80-1b1c-4f30-971c-a12cb0c83e29", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:08:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:08:26+00:00"}, "scope": {"notes": "QTS, QuTS hero, QuTScloud | Affected: QNAP / QTS, QuTS hero, QuTScloud | CVSS: 5.8 (MEDIUM) | EPSS: 0.8992 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-47218", "url": "https://www.cve.org/CVERecord?id=CVE-2023-47218"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-47218"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "QTS, QuTS hero, QuTScloud", "cve_id": "CVE-2023-47218", "vendor": "QNAP", "ghsa_id": null, "product": "QTS, QuTS hero, QuTScloud", "added_date": "2025-06-05T09:08:26.504Z", "cvss_score": 5.8, "epss_score": 0.8992, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-47218", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5553775a-bc40-4c38-ad70-ce47c3454b19", "vulnerability": {"vulnId": "CVE-2022-2487", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:08:19+02:00"}, "gcve": {"object_uuid": "5553775a-bc40-4c38-ad70-ce47c3454b19", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:08:19+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:08:19+00:00"}, "scope": {"notes": "WAVLINK WN535K2/WN535K3 nightled.cgi os command injection | Affected: WAVLINK / WN535K2, WN535K3 | CVSS: 8.0 (HIGH) | EPSS: 0.79513 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-2487", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2487"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2487"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WAVLINK WN535K2/WN535K3 nightled.cgi os command injection", "cve_id": "CVE-2022-2487", "vendor": "WAVLINK", "ghsa_id": null, "product": "WN535K2, WN535K3", "added_date": "2025-06-05T09:08:19.477Z", "cvss_score": 8.0, "epss_score": 0.79513, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2487", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f3206b82-07c4-4eab-b02f-9aaebe5ee949", "vulnerability": {"vulnId": "CVE-2020-7980", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:08:12+02:00"}, "gcve": {"object_uuid": "f3206b82-07c4-4eab-b02f-9aaebe5ee949", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:08:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:08:12+00:00"}, "scope": {"notes": "Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI.... | Affected: Intellian / Aptus Web | CVSS: 9.8 (CRITICAL) | EPSS: 0.82544 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-7980", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7980"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-7980"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI....", "cve_id": "CVE-2020-7980", "vendor": "Intellian", "ghsa_id": null, "product": "Aptus Web", "added_date": "2025-06-05T09:08:12.401Z", "cvss_score": 9.8, "epss_score": 0.82544, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99657, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-7980", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ede84818-6599-4dd6-9e03-12fe30a69527", "vulnerability": {"vulnId": "CVE-2023-32563", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:08:04+02:00"}, "gcve": {"object_uuid": "ede84818-6599-4dd6-9e03-12fe30a69527", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:08:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:08:04+00:00"}, "scope": {"notes": "An unauthenticated attacker could achieve the code execution through a RemoteControl server. | Affected: Ivanti / Avalanche | CVSS: 9.8 (CRITICAL) | EPSS: 0.89099 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-32563", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32563"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32563"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated attacker could achieve the code execution through a RemoteControl server.", "cve_id": "CVE-2023-32563", "vendor": "Ivanti", "ghsa_id": null, "product": "Avalanche", "added_date": "2025-06-05T09:08:04.933Z", "cvss_score": 9.8, "epss_score": 0.89099, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99778, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32563", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "13141c60-c9ad-44e7-8743-49245569111c", "vulnerability": {"vulnId": "CVE-2013-7091", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:07:57+02:00"}, "gcve": {"object_uuid": "13141c60-c9ad-44e7-8743-49245569111c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:07:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:07:57+00:00"}, "scope": {"notes": "Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows... | Affected: Zimbra / Zimbra Collaboration Suite | CVSS: 5.0 (MEDIUM) | EPSS: 0.86311 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-7091", "url": "https://www.cve.org/CVERecord?id=CVE-2013-7091"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-7091"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows...", "cve_id": "CVE-2013-7091", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration Suite", "added_date": "2025-06-05T09:07:57.969Z", "cvss_score": 5.0, "epss_score": 0.86311, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99729, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-7091", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "aa0c1231-e824-448a-a360-e31bd85e35c9", "vulnerability": {"vulnId": "CVE-2020-15568", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:07:50+02:00"}, "gcve": {"object_uuid": "aa0c1231-e824-448a-a360-e31bd85e35c9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:07:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:07:50+00:00"}, "scope": {"notes": "TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation... | Affected: TerraMaster / TOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.28984 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-15568", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15568"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15568"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation...", "cve_id": "CVE-2020-15568", "vendor": "TerraMaster", "ghsa_id": null, "product": "TOS", "added_date": "2025-06-05T09:07:50.716Z", "cvss_score": 9.8, "epss_score": 0.28984, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9811, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15568", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bcc265ed-3878-43fd-be83-65dbe38833c4", "vulnerability": {"vulnId": "CVE-2022-0760", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:07:43+02:00"}, "gcve": {"object_uuid": "bcc265ed-3878-43fd-be83-65dbe38833c4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:07:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:07:43+00:00"}, "scope": {"notes": "Simple Link Directory < 7.7.2 - Unauthenticated SQL injection | Affected: Simple Link Directory / Simple Link Directory | CVSS: 9.8 (CRITICAL) | EPSS: 0.10825 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0760", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0760"}, {"id": "GHSA-R29C-P472-3P96", "url": "https://github.com/advisories/GHSA-R29C-P472-3P96"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0760"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Simple Link Directory < 7.7.2 - Unauthenticated SQL injection", "cve_id": "CVE-2022-0760", "vendor": "Simple Link Directory", "ghsa_id": "GHSA-R29C-P472-3P96", "product": "Simple Link Directory", "added_date": "2025-06-05T09:07:43.354Z", "cvss_score": 9.8, "epss_score": 0.10825, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95724, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0760", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e3206a3a-2d7a-4516-a232-539a557d32a0", "vulnerability": {"vulnId": "CVE-2021-43711", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T11:07:36+02:00"}, "gcve": {"object_uuid": "e3206a3a-2d7a-4516-a232-539a557d32a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T09:07:36+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T09:07:36+00:00"}, "scope": {"notes": "The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The... | Affected: TOTOLINK / EX200 | CVSS: 9.8 (CRITICAL) | EPSS: 0.37835 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-43711", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43711"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43711"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The...", "cve_id": "CVE-2021-43711", "vendor": "TOTOLINK", "ghsa_id": null, "product": "EX200", "added_date": "2025-06-05T09:07:36.025Z", "cvss_score": 9.8, "epss_score": 0.37835, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98504, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-43711", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "acdd9e0e-10fd-4d7c-844d-ab0ae4a602ef", "vulnerability": {"vulnId": "CVE-2022-35413", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "acdd9e0e-10fd-4d7c-844d-ab0ae4a602ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential... | Affected: Penta Security Systems / WAPPLES | CVSS: 9.8 (CRITICAL) | EPSS: 0.17979 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-35413", "url": "https://www.cve.org/CVERecord?id=CVE-2022-35413"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-35413"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential...", "cve_id": "CVE-2022-35413", "vendor": "Penta Security Systems", "ghsa_id": null, "product": "WAPPLES", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.17979, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97104, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-35413", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d6d29f2b-3c90-4f6d-867e-0b266d37043f", "vulnerability": {"vulnId": "CVE-2022-25322", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "d6d29f2b-3c90-4f6d-867e-0b266d37043f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. | Affected: ZEROF / Web Server 2.0 | CVSS: 9.8 (CRITICAL) | EPSS: 0.08346 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25322", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25322"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25322"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.", "cve_id": "CVE-2022-25322", "vendor": "ZEROF", "ghsa_id": null, "product": "Web Server 2.0", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08346, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94792, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25322", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "58173c89-3100-46f3-a424-66e8299ee729", "vulnerability": {"vulnId": "CVE-2022-4050", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "58173c89-3100-46f3-a424-66e8299ee729", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "JoomSport < 5.2.8 - Unauthenticated SQLi | Affected: JoomSport / JoomSport | CVSS: 9.8 (CRITICAL) | EPSS: 0.04805 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4050", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4050"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4050"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "JoomSport < 5.2.8 - Unauthenticated SQLi", "cve_id": "CVE-2022-4050", "vendor": "JoomSport", "ghsa_id": null, "product": "JoomSport", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04805, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91674, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4050", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5d9cc608-cba0-44d7-9fa5-57edd397c07f", "vulnerability": {"vulnId": "CVE-2023-41109", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "5d9cc608-cba0-44d7-9fa5-57edd397c07f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection. | Affected: SmartNode / SN200 | CVSS: 9.8 (CRITICAL) | EPSS: 0.6451 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-41109", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41109"}, {"id": "GHSA-CG7V-JCG7-3J87", "url": "https://github.com/advisories/GHSA-CG7V-JCG7-3J87"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41109"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.", "cve_id": "CVE-2023-41109", "vendor": "SmartNode", "ghsa_id": "GHSA-CG7V-JCG7-3J87", "product": "SN200", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.6451, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99216, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41109", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "955aa0c3-6277-4a05-9559-905e9edba426", "vulnerability": {"vulnId": "CVE-2022-0846", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "955aa0c3-6277-4a05-9559-905e9edba426", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi | Affected: SpeakOut! / Email Petitions | CVSS: 9.8 (CRITICAL) | EPSS: 0.08785 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0846", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0846"}, {"id": "GHSA-V734-49QC-6VHM", "url": "https://github.com/advisories/GHSA-V734-49QC-6VHM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0846"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLi", "cve_id": "CVE-2022-0846", "vendor": "SpeakOut!", "ghsa_id": "GHSA-V734-49QC-6VHM", "product": "Email Petitions", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08785, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95023, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0846", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fc1bd62c-ce75-4a6d-b7f7-2ea2e10a2678", "vulnerability": {"vulnId": "CVE-2021-27964", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "fc1bd62c-ce75-4a6d-b7f7-2ea2e10a2678", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to... | Affected: SonLogger / SonLogger | CVSS: 9.8 (CRITICAL) | EPSS: 0.47519 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27964", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27964"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27964"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to...", "cve_id": "CVE-2021-27964", "vendor": "SonLogger", "ghsa_id": null, "product": "SonLogger", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.47519, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98809, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27964", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6d16ddfa-fbc4-464f-a566-431d06ba6175", "vulnerability": {"vulnId": "CVE-2020-35131", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "6d16ddfa-fbc4-464f-a566-431d06ba6175", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in... | Affected: Agentejo / Cockpit | CVSS: 9.8 (CRITICAL) | EPSS: 0.51299 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35131", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35131"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35131"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in...", "cve_id": "CVE-2020-35131", "vendor": "Agentejo", "ghsa_id": null, "product": "Cockpit", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.51299, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98906, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35131", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1deee341-8409-4930-bd21-1d85644f16f6", "vulnerability": {"vulnId": "CVE-2018-12031", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "1deee341-8409-4930-bd21-1d85644f16f6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory... | Affected: Eaton / Intelligent Power Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.19762 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-12031", "url": "https://www.cve.org/CVERecord?id=CVE-2018-12031"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-12031"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory...", "cve_id": "CVE-2018-12031", "vendor": "Eaton", "ghsa_id": null, "product": "Intelligent Power Manager", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.19762, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97332, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-12031", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "667f06c4-a210-49fe-a3ea-f9b2d6825362", "vulnerability": {"vulnId": "CVE-2023-27482", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "667f06c4-a210-49fe-a3ea-f9b2d6825362", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor... | Affected: Home-assistant / core, supervisor | CVSS: 10.0 (CRITICAL) | EPSS: 0.72167 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27482", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27482"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27482"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor...", "cve_id": "CVE-2023-27482", "vendor": "Home-assistant", "ghsa_id": null, "product": "core, supervisor", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.72167, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99418, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27482", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "64c5174b-b45a-4881-b5cd-0f3b4b7ed99c", "vulnerability": {"vulnId": "CVE-2022-0769", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "64c5174b-b45a-4881-b5cd-0f3b4b7ed99c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "Users Ultra <= 3.1.0 - Unauthenticated SQL Injection | Affected: Users Ultra / Users Ultra | CVSS: 9.8 (CRITICAL) | EPSS: 0.08326 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0769", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0769"}, {"id": "GHSA-6GQF-MGMR-77R9", "url": "https://github.com/advisories/GHSA-6GQF-MGMR-77R9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0769"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Users Ultra <= 3.1.0 - Unauthenticated SQL Injection", "cve_id": "CVE-2022-0769", "vendor": "Users Ultra", "ghsa_id": "GHSA-6GQF-MGMR-77R9", "product": "Users Ultra", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08326, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94784, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0769", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d38ffb11-41df-4c06-a975-4fcfb316adcd", "vulnerability": {"vulnId": "CVE-2021-24931", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "d38ffb11-41df-4c06-a975-4fcfb316adcd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-05T00:00:00+00:00"}, "scope": {"notes": "Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection | Affected: Secure Copy / Secure Copy Content Protection and Content Locking | CVSS: 9.8 (CRITICAL) | EPSS: 0.78812 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24931", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24931"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24931"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection", "cve_id": "CVE-2021-24931", "vendor": "Secure Copy", "ghsa_id": null, "product": "Secure Copy Content Protection and Content Locking", "added_date": "2025-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.78812, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99582, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24931", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fa73395a-3610-4835-b3b1-5126226bbffd", "vulnerability": {"vulnId": "CVE-2025-5571", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-04T07:31:53+02:00"}, "gcve": {"object_uuid": "fa73395a-3610-4835-b3b1-5126226bbffd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-04T05:31:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-04T05:31:53+00:00"}, "scope": {"notes": "D-Link DCS-932L setSystemAdmin os command injection | Affected: D-Link / DCS-932L | CVSS: 5.3 (MEDIUM) | EPSS: 0.13619 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-5571", "url": "https://www.cve.org/CVERecord?id=CVE-2025-5571"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-5571"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DCS-932L setSystemAdmin os command injection", "cve_id": "CVE-2025-5571", "vendor": "D-Link", "ghsa_id": null, "product": "DCS-932L", "added_date": "2025-06-04T05:31:53.000Z", "cvss_score": 5.3, "epss_score": 0.13619, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96362, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-5571", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "57568196-04ee-44fb-8200-97db5fd8a5eb", "vulnerability": {"vulnId": "CVE-2019-17270", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "57568196-04ee-44fb-8200-97db5fd8a5eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-04T00:00:00+00:00"}, "scope": {"notes": "Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the... | Affected: Yachtcontrol / Yachtcontrol | CVSS: 9.8 (CRITICAL) | EPSS: 0.58879 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-17270", "url": "https://www.cve.org/CVERecord?id=CVE-2019-17270"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-17270"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the...", "cve_id": "CVE-2019-17270", "vendor": "Yachtcontrol", "ghsa_id": null, "product": "Yachtcontrol", "added_date": "2025-06-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.58879, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99084, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-17270", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ef07c0d5-ef64-4b1f-911f-046d112723d5", "vulnerability": {"vulnId": "CVE-2017-18378", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "ef07c0d5-ef64-4b1f-911f-046d112723d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-04T00:00:00+00:00"}, "scope": {"notes": "In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through... | Affected: NETGEAR / ReadyNAS Surveillance | CVSS: 8.4 (HIGH) | EPSS: 0.0817 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-18378", "url": "https://www.cve.org/CVERecord?id=CVE-2017-18378"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-18378"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through...", "cve_id": "CVE-2017-18378", "vendor": "NETGEAR", "ghsa_id": null, "product": "ReadyNAS Surveillance", "added_date": "2025-06-04T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.0817, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94694, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-18378", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b7d53213-941a-4546-81ea-d2b7f899efdf", "vulnerability": {"vulnId": "CVE-2017-14135", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-04T02:00:00+02:00"}, "gcve": {"object_uuid": "b7d53213-941a-4546-81ea-d2b7f899efdf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-04T00:00:00+00:00"}, "scope": {"notes": "enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute... | Affected: OpenDreambox / OpenDreambox 2.0.0 | CVSS: 9.8 (CRITICAL) | EPSS: 0.21842 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-14135", "url": "https://www.cve.org/CVERecord?id=CVE-2017-14135"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-14135"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute...", "cve_id": "CVE-2017-14135", "vendor": "OpenDreambox", "ghsa_id": null, "product": "OpenDreambox 2.0.0", "added_date": "2025-06-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.21842, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97578, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-14135", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "225073ac-4204-46ab-adc6-3d50b6764710", "vulnerability": {"vulnId": "CVE-2021-37291", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-02T02:00:00+02:00"}, "gcve": {"object_uuid": "225073ac-4204-46ab-adc6-3d50b6764710", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-02T00:00:00+00:00"}, "scope": {"notes": "An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | Affected: KevinLAB / Building Energy Management System 4ST BEMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.06535 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-37291", "url": "https://www.cve.org/CVERecord?id=CVE-2021-37291"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-37291"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.", "cve_id": "CVE-2021-37291", "vendor": "KevinLAB", "ghsa_id": null, "product": "Building Energy Management System 4ST BEMS", "added_date": "2025-06-02T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06535, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9359, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-37291", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a14c7844-3f79-4eb3-b2e2-2d5191103a73", "vulnerability": {"vulnId": "CVE-2020-13638", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "a14c7844-3f79-4eb3-b2e2-2d5191103a73", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-01T00:00:00+00:00"}, "scope": {"notes": "lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been... | Affected: rConfig / rConfig | CVSS: 9.8 (CRITICAL) | EPSS: 0.76601 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-13638", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13638"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13638"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been...", "cve_id": "CVE-2020-13638", "vendor": "rConfig", "ghsa_id": null, "product": "rConfig", "added_date": "2025-06-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.76601, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99529, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13638", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3b480ecb-bf66-46f9-87d3-557dd23b7090", "vulnerability": {"vulnId": "CVE-2023-26255", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "3b480ecb-bf66-46f9-87d3-557dd23b7090", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-01T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated path traversal vulnerability affects the \"STAGIL Navigation for Jira - Menu & Themes\" plugin before 2.0.52 for Jira. By... | Affected: Atlassian / Jira | CVSS: 7.5 (HIGH) | EPSS: 0.47199 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26255", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26255"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26255"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated path traversal vulnerability affects the \"STAGIL Navigation for Jira - Menu & Themes\" plugin before 2.0.52 for Jira. By...", "cve_id": "CVE-2023-26255", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira", "added_date": "2025-06-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.47199, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98802, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26255", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4e9883b5-627c-4e2e-a1c6-6911e645ee85", "vulnerability": {"vulnId": "CVE-2023-26256", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "4e9883b5-627c-4e2e-a1c6-6911e645ee85", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-06-01T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated path traversal vulnerability affects the \"STAGIL Navigation for Jira - Menu & Themes\" plugin before 2.0.52 for Jira. By... | Affected: Atlassian / Jira | CVSS: 7.5 (HIGH) | EPSS: 0.11615 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26256", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26256"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26256"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated path traversal vulnerability affects the \"STAGIL Navigation for Jira - Menu & Themes\" plugin before 2.0.52 for Jira. By...", "cve_id": "CVE-2023-26256", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira", "added_date": "2025-06-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.11615, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95922, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26256", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "30d1f20a-6dcb-4e16-9f4b-8dc32cd8cbb1", "vulnerability": {"vulnId": "CVE-2024-7097", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-30T17:04:09+02:00"}, "gcve": {"object_uuid": "30d1f20a-6dcb-4e16-9f4b-8dc32cd8cbb1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-30T15:04:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-30T15:04:09+00:00"}, "scope": {"notes": "Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup | Affected: WSO2 / WSO2 Open Banking AM, WSO2 Open Banking KM, WSO2 Identity Server as Key Manager, WSO2 API Manager, WSO2 Identity Server, WSO2 Open Banking IAM, WSO2 Enterprise Mobility Manager | CVSS: 4.3 (MEDIUM) | EPSS: 0.00665 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-7097", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7097"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7097"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup", "cve_id": "CVE-2024-7097", "vendor": "WSO2", "ghsa_id": null, "product": "WSO2 Open Banking AM, WSO2 Open Banking KM, WSO2 Identity Server as Key Manager, WSO2 API Manager, WSO2 Identity Server, WSO2 Open Banking IAM, WSO2 Enterprise Mobility Manager", "added_date": "2025-05-30T15:04:09.000Z", "cvss_score": 4.3, "epss_score": 0.00665, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.4995, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7097", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "06264185-7e83-4fa8-9e76-de7230ca8f15", "vulnerability": {"vulnId": "CVE-2025-48828", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-27T14:00:00+02:00"}, "gcve": {"object_uuid": "06264185-7e83-4fa8-9e76-de7230ca8f15", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-27T12:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-27T12:00:00+00:00"}, "scope": {"notes": "Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting... | Affected: vBulletin / vBulletin | CVSS: 9.0 (CRITICAL) | EPSS: 0.5764 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-48828", "url": "https://www.cve.org/CVERecord?id=CVE-2025-48828"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-48828"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting...", "cve_id": "CVE-2025-48828", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2025-05-27T12:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.5764, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99059, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-48828", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "77167de5-822c-4a7e-8bb5-19373c9798c8", "vulnerability": {"vulnId": "CVE-2025-32814", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-22T02:00:00+02:00"}, "gcve": {"object_uuid": "77167de5-822c-4a7e-8bb5-19373c9798c8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-22T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur. | Affected: Infoblox / NETMRI | CVSS: 9.8 (CRITICAL) | EPSS: 0.36408 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-32814", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32814"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32814"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.", "cve_id": "CVE-2025-32814", "vendor": "Infoblox", "ghsa_id": null, "product": "NETMRI", "added_date": "2025-05-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.36408, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98444, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32814", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4b38d8b9-e78e-4c04-bf5c-e057d1c6edbb", "vulnerability": {"vulnId": "CVE-2025-4428", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:11:30+02:00"}, "gcve": {"object_uuid": "4b38d8b9-e78e-4c04-bf5c-e057d1c6edbb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:11:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:11:30+00:00"}, "scope": {"notes": "Remote Code Execution | Affected: Ivanti / Endpoint Manager Mobile | CVSS: 7.2 (HIGH) | EPSS: 0.86519 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-4428", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4428"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4428"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution", "cve_id": "CVE-2025-4428", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager Mobile", "added_date": "2025-05-21T13:11:30.190Z", "cvss_score": 7.2, "epss_score": 0.86519, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99734, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4428", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5babed17-cdca-4983-9b54-94838c6dcfbb", "vulnerability": {"vulnId": "CVE-2025-4427", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:11:23+02:00"}, "gcve": {"object_uuid": "5babed17-cdca-4983-9b54-94838c6dcfbb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:11:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:11:23+00:00"}, "scope": {"notes": "Authentication Bypass | Affected: Ivanti / Endpoint Manager Mobile | CVSS: 5.3 (MEDIUM) | EPSS: 0.99927 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-4427", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4427"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4427"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass", "cve_id": "CVE-2025-4427", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager Mobile", "added_date": "2025-05-21T13:11:23.139Z", "cvss_score": 5.3, "epss_score": 0.99927, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99968, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4427", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b647a746-b226-40cb-8ae9-a9ce8d107fe9", "vulnerability": {"vulnId": "CVE-2025-32709", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:11:16+02:00"}, "gcve": {"object_uuid": "b647a746-b226-40cb-8ae9-a9ce8d107fe9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:11:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:11:16+00:00"}, "scope": {"notes": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.0214 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32709", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32709"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32709"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-32709", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-05-21T13:11:16.065Z", "cvss_score": 7.8, "epss_score": 0.0214, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8137, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32709", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d2b81997-eb37-4cea-bc7c-d3ada633afdb", "vulnerability": {"vulnId": "CVE-2025-32706", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:11:09+02:00"}, "gcve": {"object_uuid": "d2b81997-eb37-4cea-bc7c-d3ada633afdb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:11:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:11:09+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.02294 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32706", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32706"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32706"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-32706", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-05-21T13:11:09.018Z", "cvss_score": 7.8, "epss_score": 0.02294, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82629, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32706", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d9cc31d5-2ccd-4086-ad1b-f08a151431d7", "vulnerability": {"vulnId": "CVE-2025-32701", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:11:01+02:00"}, "gcve": {"object_uuid": "d9cc31d5-2ccd-4086-ad1b-f08a151431d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:11:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:11:01+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01392 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-32701", "url": "https://www.cve.org/CVERecord?id=CVE-2025-32701"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-32701"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-32701", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-05-21T13:11:01.860Z", "cvss_score": 7.8, "epss_score": 0.01392, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71342, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-32701", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bcad0f73-60ec-4928-a6c5-80c0cf7a1737", "vulnerability": {"vulnId": "CVE-2025-30400", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:10:54+02:00"}, "gcve": {"object_uuid": "bcad0f73-60ec-4928-a6c5-80c0cf7a1737", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:10:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:10:54+00:00"}, "scope": {"notes": "Microsoft DWM Core Library Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.019 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-30400", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30400"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30400"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-30400", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-05-21T13:10:54.771Z", "cvss_score": 7.8, "epss_score": 0.019, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78934, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30400", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e9131738-a0bb-4dbe-b252-0d3a53d88f1a", "vulnerability": {"vulnId": "CVE-2025-30397", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:10:47+02:00"}, "gcve": {"object_uuid": "e9131738-a0bb-4dbe-b252-0d3a53d88f1a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:10:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:10:47+00:00"}, "scope": {"notes": "Scripting Engine Memory Corruption Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.5 (HIGH) | EPSS: 0.26835 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-30397", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30397"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30397"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Scripting Engine Memory Corruption Vulnerability", "cve_id": "CVE-2025-30397", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-05-21T13:10:47.775Z", "cvss_score": 7.5, "epss_score": 0.26835, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30397", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0e8ac527-202d-4794-adfb-15bee37661eb", "vulnerability": {"vulnId": "CVE-2025-27920", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:10:40+02:00"}, "gcve": {"object_uuid": "0e8ac527-202d-4794-adfb-15bee37661eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:10:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:10:40+00:00"}, "scope": {"notes": "Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in... | Affected: Srimax / Output Messenger | CVSS: 9.8 (CRITICAL) | EPSS: 0.01855 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-27920", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27920"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27920"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in...", "cve_id": "CVE-2025-27920", "vendor": "Srimax", "ghsa_id": null, "product": "Output Messenger", "added_date": "2025-05-21T13:10:40.229Z", "cvss_score": 9.8, "epss_score": 0.01855, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7841, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27920", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6658d6e-b18d-4f26-8fa5-edcef83214ac", "vulnerability": {"vulnId": "CVE-2024-27443", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:10:32+02:00"}, "gcve": {"object_uuid": "a6658d6e-b18d-4f26-8fa5-edcef83214ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:10:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:10:32+00:00"}, "scope": {"notes": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature... | Affected: Zimbra / Zimbra Collaboration (ZCS) | CVSS: 6.1 (MEDIUM) | EPSS: 0.23632 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-27443", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27443"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27443"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature...", "cve_id": "CVE-2024-27443", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration (ZCS)", "added_date": "2025-05-21T13:10:32.092Z", "cvss_score": 6.1, "epss_score": 0.23632, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97745, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27443", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c8d3f2ac-2d70-4051-8ecd-21b892a014f7", "vulnerability": {"vulnId": "CVE-2024-11182", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:10:24+02:00"}, "gcve": {"object_uuid": "c8d3f2ac-2d70-4051-8ecd-21b892a014f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:10:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:10:24+00:00"}, "scope": {"notes": "Stored XSS vulnerability in MDaemon Email Server | Affected: MDaemon / Email Server | CVSS: 5.3 (MEDIUM) | EPSS: 0.17591 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-11182", "url": "https://www.cve.org/CVERecord?id=CVE-2024-11182"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-11182"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stored XSS vulnerability in MDaemon Email Server", "cve_id": "CVE-2024-11182", "vendor": "MDaemon", "ghsa_id": null, "product": "Email Server", "added_date": "2025-05-21T13:10:24.903Z", "cvss_score": 5.3, "epss_score": 0.17591, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9706, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-11182", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7140896b-a640-4df2-b01c-192c7c2a03fc", "vulnerability": {"vulnId": "CVE-2023-38950", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-21T15:10:17+02:00"}, "gcve": {"object_uuid": "7140896b-a640-4df2-b01c-192c7c2a03fc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-21T13:10:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-21T13:10:17+00:00"}, "scope": {"notes": "A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a... | Affected: ZKTeco / BioTime | CVSS: 7.5 (HIGH) | EPSS: 0.92468 | Used in malware: unknown | Listed 377 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38950", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38950"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38950"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a...", "cve_id": "CVE-2023-38950", "vendor": "ZKTeco", "ghsa_id": null, "product": "BioTime", "added_date": "2025-05-21T13:10:17.537Z", "cvss_score": 7.5, "epss_score": 0.92468, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99823, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38950", "ahead_of_cisa_kev": {"unit": "day", "count": 377}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "40bba525-f4c0-483b-97f2-e0650be174ea", "vulnerability": {"vulnId": "CVE-2018-17246", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-20T21:38:21+02:00"}, "gcve": {"object_uuid": "40bba525-f4c0-483b-97f2-e0650be174ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-20T19:38:21+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-20T19:38:21+00:00"}, "scope": {"notes": "Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana... | Affected: Elastic / Kibana | CVSS: 9.8 (CRITICAL) | EPSS: 0.82251 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-17246", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17246"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17246"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana...", "cve_id": "CVE-2018-17246", "vendor": "Elastic", "ghsa_id": null, "product": "Kibana", "added_date": "2025-05-20T19:38:21.380Z", "cvss_score": 9.8, "epss_score": 0.82251, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99649, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17246", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "17087a3f-830c-4c3e-9976-a97933fbd7ec", "vulnerability": {"vulnId": "CVE-2019-16662", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-20T21:38:13+02:00"}, "gcve": {"object_uuid": "17087a3f-830c-4c3e-9976-a97933fbd7ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-20T19:38:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-20T19:38:13+00:00"}, "scope": {"notes": "An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php... | Affected: rConfig / rConfig | CVSS: 9.8 (CRITICAL) | EPSS: 0.97702 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-16662", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16662"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16662"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php...", "cve_id": "CVE-2019-16662", "vendor": "rConfig", "ghsa_id": null, "product": "rConfig", "added_date": "2025-05-20T19:38:13.620Z", "cvss_score": 9.8, "epss_score": 0.97702, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99903, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16662", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "60b03048-8aaa-4d50-bd67-3c4721c8cf0f", "vulnerability": {"vulnId": "CVE-2025-4322", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-20T07:30:48+02:00"}, "gcve": {"object_uuid": "60b03048-8aaa-4d50-bd67-3c4721c8cf0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-20T05:30:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-20T05:30:48+00:00"}, "scope": {"notes": "Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover | Affected: StylemixThemes / Motors - Car Dealer, Rental & Listing WordPress theme | CVSS: 9.8 (CRITICAL) | EPSS: 0.15524 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4322", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4322"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4322"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover", "cve_id": "CVE-2025-4322", "vendor": "StylemixThemes", "ghsa_id": null, "product": "Motors - Car Dealer, Rental & Listing WordPress theme", "added_date": "2025-05-20T05:30:48.000Z", "cvss_score": 9.8, "epss_score": 0.15524, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96711, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4322", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1e165f23-bff6-4ac0-ae49-e246cdf5d21e", "vulnerability": {"vulnId": "CVE-2024-12987", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-16T10:36:30+02:00"}, "gcve": {"object_uuid": "1e165f23-bff6-4ac0-ae49-e246cdf5d21e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-16T08:36:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-16T08:36:30+00:00"}, "scope": {"notes": "DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection | Affected: DrayTek / Vigor2960, Vigor300B | CVSS: 6.9 (MEDIUM) | EPSS: 0.98084 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-12987", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12987"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12987"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection", "cve_id": "CVE-2024-12987", "vendor": "DrayTek", "ghsa_id": null, "product": "Vigor2960, Vigor300B", "added_date": "2025-05-16T08:36:30.620Z", "cvss_score": 6.9, "epss_score": 0.98084, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99911, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12987", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "087fd97b-c5c6-4faa-8a8d-bde5f8008e1c", "vulnerability": {"vulnId": "CVE-2025-47916", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-16T02:00:00+02:00"}, "gcve": {"object_uuid": "087fd97b-c5c6-4faa-8a8d-bde5f8008e1c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-16T00:00:00+00:00"}, "scope": {"notes": "Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the... | Affected: Invisioncommunity / Invision Power Board | CVSS: 10.0 (CRITICAL) | EPSS: 0.83732 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-47916", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47916"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47916"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the...", "cve_id": "CVE-2025-47916", "vendor": "Invisioncommunity", "ghsa_id": null, "product": "Invision Power Board", "added_date": "2025-05-16T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.83732, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99683, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47916", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "978b2dd4-893c-498e-9d4a-855fa0f02784", "vulnerability": {"vulnId": "CVE-2024-48766", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-13T02:00:00+02:00"}, "gcve": {"object_uuid": "978b2dd4-893c-498e-9d4a-855fa0f02784", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-13T00:00:00+00:00"}, "scope": {"notes": "NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related... | Affected: NetAlertX / NetAlertX | CVSS: 8.6 (HIGH) | EPSS: 0.69697 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-48766", "url": "https://www.cve.org/CVERecord?id=CVE-2024-48766"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-48766"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related...", "cve_id": "CVE-2024-48766", "vendor": "NetAlertX", "ghsa_id": null, "product": "NetAlertX", "added_date": "2025-05-13T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.69697, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9935, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-48766", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "baf6ef6a-70dd-46d8-bad4-678a19522b5f", "vulnerability": {"vulnId": "CVE-2025-47204", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-13T02:00:00+02:00"}, "gcve": {"object_uuid": "baf6ef6a-70dd-46d8-bad4-678a19522b5f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-13T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary... | Affected: David Stutz / Bootstrap Multiselect | CVSS: 6.1 (MEDIUM) | EPSS: 0.00438 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-47204", "url": "https://www.cve.org/CVERecord?id=CVE-2025-47204"}, {"id": "GHSA-GV5R-9GXR-V74W", "url": "https://github.com/advisories/GHSA-GV5R-9GXR-V74W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-47204"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary...", "cve_id": "CVE-2025-47204", "vendor": "David Stutz", "ghsa_id": "GHSA-GV5R-9GXR-V74W", "product": "Bootstrap Multiselect", "added_date": "2025-05-13T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.00438, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.35777, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-47204", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "af5b3a33-f28d-4a34-9068-8c4af0c66b4c", "vulnerability": {"vulnId": "CVE-2024-6047", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-07T08:17:12+02:00"}, "gcve": {"object_uuid": "af5b3a33-f28d-4a34-9068-8c4af0c66b4c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-07T06:17:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-07T06:17:12+00:00"}, "scope": {"notes": "GeoVision EOL device - OS Command Injection | Affected: GeoVision / GV_DSP_LPR_V2, GV_IPCAMD_GV_BX1500, GV_IPCAMD_GV_CB220, GV_IPCAMD_GV_EBL1100, GV_IPCAMD_GV_EFD1100, GV_IPCAMD_GV_FD2410, GV_IPCAMD_GV_FD3400, GV_IPCAMD_GV_FE3401, GV_IPCAMD_GV_FE420, GV-VS14_VS14, GV_VS03, GV_VS2410, GV_VS28XX, GV_VS216XX, GV VS04A, GV VS04H, GVLX 4 V2, GVLX 4 V3, GV_IPCAMD_GV_BX130, GV_GM8186_VS14 | CVSS: 9.8 (CRITICAL) | EPSS: 0.10072 | Used in malware: unknown | Listed 391 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-6047", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6047"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6047"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoVision EOL device - OS Command Injection", "cve_id": "CVE-2024-6047", "vendor": "GeoVision", "ghsa_id": null, "product": "GV_DSP_LPR_V2, GV_IPCAMD_GV_BX1500, GV_IPCAMD_GV_CB220, GV_IPCAMD_GV_EBL1100, GV_IPCAMD_GV_EFD1100, GV_IPCAMD_GV_FD2410, GV_IPCAMD_GV_FD3400, GV_IPCAMD_GV_FE3401, GV_IPCAMD_GV_FE420, GV-VS14_VS14, GV_VS03, GV_VS2410, GV_VS28XX, GV_VS216XX, GV VS04A, GV VS04H, GVLX 4 V2, GVLX 4 V3, GV_IPCAMD_GV_BX130, GV_GM8186_VS14", "added_date": "2025-05-07T06:17:12.242Z", "cvss_score": 9.8, "epss_score": 0.10072, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95497, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6047", "ahead_of_cisa_kev": {"unit": "day", "count": 391}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4630cdb9-f74a-4d1f-977f-4bc827d6220e", "vulnerability": {"vulnId": "CVE-2024-11120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-07T08:17:12+02:00"}, "gcve": {"object_uuid": "4630cdb9-f74a-4d1f-977f-4bc827d6220e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-07T06:17:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-07T06:17:12+00:00"}, "scope": {"notes": "GeoVision EOL devices - OS Command Injection | Affected: GeoVision / GV-VS12, GV-VS11, GV-DSP_LPR_V3, GVLX 4 V2, GVLX 4 V3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.28386 | Used in malware: unknown | Listed 391 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-11120", "url": "https://www.cve.org/CVERecord?id=CVE-2024-11120"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-11120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoVision EOL devices - OS Command Injection", "cve_id": "CVE-2024-11120", "vendor": "GeoVision", "ghsa_id": null, "product": "GV-VS12, GV-VS11, GV-DSP_LPR_V3, GVLX 4 V2, GVLX 4 V3", "added_date": "2025-05-07T06:17:12.074Z", "cvss_score": 9.8, "epss_score": 0.28386, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98071, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-11120", "ahead_of_cisa_kev": {"unit": "day", "count": 391}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c07e1ec-dd1c-4b51-a379-37be1cbf9069", "vulnerability": {"vulnId": "CVE-2025-27363", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-06T09:17:25+02:00"}, "gcve": {"object_uuid": "4c07e1ec-dd1c-4b51-a379-37be1cbf9069", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-06T07:17:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-06T07:17:25+00:00"}, "scope": {"notes": "An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font... | Affected: FreeType / FreeType | CVSS: 8.1 (HIGH) | EPSS: 0.27775 | Used in malware: unknown | Listed 392 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-27363", "url": "https://www.cve.org/CVERecord?id=CVE-2025-27363"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-27363"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font...", "cve_id": "CVE-2025-27363", "vendor": "FreeType", "ghsa_id": null, "product": "FreeType", "added_date": "2025-05-06T07:17:25.771Z", "cvss_score": 8.1, "epss_score": 0.27775, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98037, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-27363", "ahead_of_cisa_kev": {"unit": "day", "count": 392}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "15bef577-2fb9-4635-9c86-5589a82e77df", "vulnerability": {"vulnId": "CVE-2025-4281", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-05T18:00:09+02:00"}, "gcve": {"object_uuid": "15bef577-2fb9-4635-9c86-5589a82e77df", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-05T16:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-05T16:00:09+00:00"}, "scope": {"notes": "Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosure | Affected: Shenzhen Sixun Software / Sixun Shanghui Group Business Management System | CVSS: 5.3 (MEDIUM) | EPSS: 0.00318 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4281", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4281"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4281"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Shenzhen Sixun Software Sixun Shanghui Group Business Management System LoadData information disclosure", "cve_id": "CVE-2025-4281", "vendor": "Shenzhen Sixun Software", "ghsa_id": null, "product": "Sixun Shanghui Group Business Management System", "added_date": "2025-05-05T16:00:09.000Z", "cvss_score": 5.3, "epss_score": 0.00318, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.2242, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4281", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1b1604d8-4da5-41ff-bb67-334d960d2248", "vulnerability": {"vulnId": "CVE-2025-34028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-05T10:35:41+02:00"}, "gcve": {"object_uuid": "1b1604d8-4da5-41ff-bb67-334d960d2248", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-05T08:35:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-05T08:35:41+00:00"}, "scope": {"notes": "Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal | Affected: Commvault / Command Center Innovation Release | CVSS: 9.3 (CRITICAL) | EPSS: 0.97604 | Used in malware: unknown | Listed 393 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-34028", "url": "https://www.cve.org/CVERecord?id=CVE-2025-34028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-34028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal", "cve_id": "CVE-2025-34028", "vendor": "Commvault", "ghsa_id": null, "product": "Command Center Innovation Release", "added_date": "2025-05-05T08:35:41.213Z", "cvss_score": 9.3, "epss_score": 0.97604, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-34028", "ahead_of_cisa_kev": {"unit": "day", "count": 393}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "de049106-d696-4ea0-92ed-6b8d37a665d2", "vulnerability": {"vulnId": "CVE-2024-58136", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-05T10:35:41+02:00"}, "gcve": {"object_uuid": "de049106-d696-4ea0-92ed-6b8d37a665d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-05T08:35:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-05T08:35:41+00:00"}, "scope": {"notes": "Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the... | Affected: Yiiframework / Yii | CVSS: 9.0 (CRITICAL) | EPSS: 0.87757 | Used in malware: unknown | Listed 393 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-58136", "url": "https://www.cve.org/CVERecord?id=CVE-2024-58136"}, {"id": "GHSA-GGWG-CMWP-46R5", "url": "https://github.com/advisories/GHSA-GGWG-CMWP-46R5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-58136"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the...", "cve_id": "CVE-2024-58136", "vendor": "Yiiframework", "ghsa_id": "GHSA-GGWG-CMWP-46R5", "product": "Yii", "added_date": "2025-05-05T08:35:41.245Z", "cvss_score": 9.0, "epss_score": 0.87757, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99758, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-58136", "ahead_of_cisa_kev": {"unit": "day", "count": 393}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "607ca7e2-9e88-4bb2-9eb6-c75d83d25cf6", "vulnerability": {"vulnId": "CVE-2025-4270", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-05T09:31:07+02:00"}, "gcve": {"object_uuid": "607ca7e2-9e88-4bb2-9eb6-c75d83d25cf6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-05T07:31:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-05T07:31:07+00:00"}, "scope": {"notes": "TOTOLINK A720R Config cstecgi.cgi information disclosure | Affected: TOTOLINK / A720R | CVSS: 6.9 (MEDIUM) | EPSS: 0.13125 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4270", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4270"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4270"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK A720R Config cstecgi.cgi information disclosure", "cve_id": "CVE-2025-4270", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A720R", "added_date": "2025-05-05T07:31:07.000Z", "cvss_score": 6.9, "epss_score": 0.13125, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96249, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4270", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5768e484-68ec-4446-9bb5-ef56eb1d251e", "vulnerability": {"vulnId": "CVE-2025-3248", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-05T02:00:00+02:00"}, "gcve": {"object_uuid": "5768e484-68ec-4446-9bb5-ef56eb1d251e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-05T00:00:00+00:00"}, "scope": {"notes": "Langflow Unauth RCE | Affected: Langflow-ai / langflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.99993 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-3248", "url": "https://www.cve.org/CVERecord?id=CVE-2025-3248"}, {"id": "GHSA-RVQX-WPFH-MFX7", "url": "https://github.com/advisories/GHSA-RVQX-WPFH-MFX7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-3248"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Langflow Unauth RCE", "cve_id": "CVE-2025-3248", "vendor": "Langflow-ai", "ghsa_id": "GHSA-RVQX-WPFH-MFX7", "product": "langflow", "added_date": "2025-05-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99993, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-3248", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02609dc5-7629-47c2-9b59-e19fc343a55a", "vulnerability": {"vulnId": "CVE-2025-4210", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-02T17:31:04+02:00"}, "gcve": {"object_uuid": "02609dc5-7629-47c2-9b59-e19fc343a55a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-02T15:31:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-02T15:31:04+00:00"}, "scope": {"notes": "Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization | Affected: Casdoor / Casdoor | CVSS: 6.9 (MEDIUM) | EPSS: 0.01822 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-4210", "url": "https://www.cve.org/CVERecord?id=CVE-2025-4210"}, {"id": "GHSA-8W8F-H4CM-C4PG", "url": "https://github.com/advisories/GHSA-8W8F-H4CM-C4PG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-4210"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization", "cve_id": "CVE-2025-4210", "vendor": "Casdoor", "ghsa_id": "GHSA-8W8F-H4CM-C4PG", "product": "Casdoor", "added_date": "2025-05-02T15:31:04.000Z", "cvss_score": 6.9, "epss_score": 0.01822, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-4210", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "aaf60aeb-402e-4f96-8e16-b9cec2f64938", "vulnerability": {"vulnId": "CVE-2017-9844", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-01T10:57:25+02:00"}, "gcve": {"object_uuid": "aaf60aeb-402e-4f96-8e16-b9cec2f64938", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-01T08:57:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-01T08:57:25+00:00"}, "scope": {"notes": "SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized... | Affected: SAP / NetWeaver | CVSS: 7.5 (HIGH) | EPSS: 0.05365 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-9844", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9844"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9844"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized...", "cve_id": "CVE-2017-9844", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver", "added_date": "2025-05-01T08:57:25.878Z", "cvss_score": 7.5, "epss_score": 0.05365, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92398, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9844", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "17a2ef51-d04a-41cf-acfc-fd946d98752c", "vulnerability": {"vulnId": "CVE-2023-44221", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-01T08:22:00+02:00"}, "gcve": {"object_uuid": "17a2ef51-d04a-41cf-acfc-fd946d98752c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-01T06:22:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-01T06:22:00+00:00"}, "scope": {"notes": "Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative... | Affected: SonicWall / SMA100 | CVSS: 7.2 (HIGH) | EPSS: 0.7625 | Used in malware: unknown | Listed 397 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-44221", "url": "https://www.cve.org/CVERecord?id=CVE-2023-44221"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-44221"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative...", "cve_id": "CVE-2023-44221", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA100", "added_date": "2025-05-01T06:22:00.000Z", "cvss_score": 7.2, "epss_score": 0.7625, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99522, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-44221", "ahead_of_cisa_kev": {"unit": "day", "count": 397}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18bb36a3-2d3d-4c28-b704-73b1c93c4b4a", "vulnerability": {"vulnId": "CVE-2025-44846", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-01T02:00:00+02:00"}, "gcve": {"object_uuid": "18bb36a3-2d3d-4c28-b704-73b1c93c4b4a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-01T00:00:00+00:00"}, "scope": {"notes": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl... | Affected: TOTOLINK / CA600-PoE | CVSS: 6.3 (MEDIUM) | EPSS: 0.00936 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-44846", "url": "https://www.cve.org/CVERecord?id=CVE-2025-44846"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-44846"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl...", "cve_id": "CVE-2025-44846", "vendor": "TOTOLINK", "ghsa_id": null, "product": "CA600-PoE", "added_date": "2025-05-01T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.00936, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.59396, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-44846", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c0797702-ca08-45a9-a8bc-318496f58405", "vulnerability": {"vulnId": "CVE-2024-38475", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-05-01T02:00:00+02:00"}, "gcve": {"object_uuid": "c0797702-ca08-45a9-a8bc-318496f58405", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-05-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-05-01T00:00:00+00:00"}, "scope": {"notes": "Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. | Affected: Apache / Apache HTTP Server | CVSS: 9.1 (CRITICAL) | EPSS: 0.99957 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38475", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38475"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38475"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.", "cve_id": "CVE-2024-38475", "vendor": "Apache", "ghsa_id": null, "product": "Apache HTTP Server", "added_date": "2025-05-01T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.99957, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99975, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38475", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e8c5be16-7b88-4f58-af26-ea5fbe57391b", "vulnerability": {"vulnId": "CVE-2025-3928", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-30T17:36:16+02:00"}, "gcve": {"object_uuid": "e8c5be16-7b88-4f58-af26-ea5fbe57391b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-30T15:36:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-30T15:36:16+00:00"}, "scope": {"notes": "Commvault Web Server unspecified vulnerability | Affected: Commvault / Web Server | CVSS: 8.7 (HIGH) | EPSS: 0.02299 | Used in malware: unknown | Listed 398 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-3928", "url": "https://www.cve.org/CVERecord?id=CVE-2025-3928"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-3928"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Commvault Web Server unspecified vulnerability", "cve_id": "CVE-2025-3928", "vendor": "Commvault", "ghsa_id": null, "product": "Web Server", "added_date": "2025-04-30T15:36:16.939Z", "cvss_score": 8.7, "epss_score": 0.02299, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82669, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-3928", "ahead_of_cisa_kev": {"unit": "day", "count": 398}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f5038d4-b9ae-408c-8662-0f4964b969d8", "vulnerability": {"vulnId": "CVE-2025-31324", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T23:26:28+02:00"}, "gcve": {"object_uuid": "6f5038d4-b9ae-408c-8662-0f4964b969d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T21:26:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T21:26:28+00:00"}, "scope": {"notes": "Missing Authorization check in SAP NetWeaver (Visual Composer development server) | Affected: SAP_SE / SAP NetWeaver (Visual Composer development server) | CVSS: 10.0 (CRITICAL) | EPSS: 0.9947 | Used in malware: yes | Listed 400 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-31324", "url": "https://www.cve.org/CVERecord?id=CVE-2025-31324"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-31324"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Missing Authorization check in SAP NetWeaver (Visual Composer development server)", "cve_id": "CVE-2025-31324", "vendor": "SAP_SE", "ghsa_id": null, "product": "SAP NetWeaver (Visual Composer development server)", "added_date": "2025-04-28T21:26:28.000Z", "cvss_score": 10.0, "epss_score": 0.9947, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99943, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-31324", "ahead_of_cisa_kev": {"unit": "day", "count": 400}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f6765a5d-368d-4533-964f-8bfe969f23ec", "vulnerability": {"vulnId": "CVE-2021-25646", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "f6765a5d-368d-4533-964f-8bfe969f23ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Authenticated users can override system configurations in their requests which allows them to execute arbitrary code. | Affected: Apache / Apache Druid | CVSS: 8.8 (HIGH) | EPSS: 0.99001 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-25646", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25646"}, {"id": "GHSA-WRQF-RRRW-W3MG", "url": "https://github.com/advisories/GHSA-WRQF-RRRW-W3MG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25646"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.", "cve_id": "CVE-2021-25646", "vendor": "Apache", "ghsa_id": "GHSA-WRQF-RRRW-W3MG", "product": "Apache Druid", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99001, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25646", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2edc1511-2759-499b-9ea8-3e0c9a54d709", "vulnerability": {"vulnId": "CVE-2023-38646", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "2edc1511-2759-499b-9ea8-3e0c9a54d709", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the... | Affected: Metabase / Metabase | CVSS: 9.8 (CRITICAL) | EPSS: 0.98677 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-38646", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38646"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38646"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the...", "cve_id": "CVE-2023-38646", "vendor": "Metabase", "ghsa_id": null, "product": "Metabase", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98677, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99923, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38646", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "65cd2ade-b324-4f10-af6e-15e5515867f1", "vulnerability": {"vulnId": "CVE-2023-24488", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "65cd2ade-b324-4f10-af6e-15e5515867f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Cross site scripting | Affected: Citrix / Citrix ADC and Citrix Gateway\u202f | CVSS: 6.1 (MEDIUM) | EPSS: 0.80907 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-24488", "url": "https://www.cve.org/CVERecord?id=CVE-2023-24488"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-24488"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross site scripting", "cve_id": "CVE-2023-24488", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ADC and Citrix Gateway\u202f", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.80907, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99621, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-24488", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "16b5cf46-965a-4b07-8f3b-e4101d266ac3", "vulnerability": {"vulnId": "CVE-2022-22274", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "16b5cf46-965a-4b07-8f3b-e4101d266ac3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service... | Affected: SonicWall / SonicOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.75521 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-22274", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22274"}, {"id": "GHSA-8348-4CMV-MVVP", "url": "https://github.com/advisories/GHSA-8348-4CMV-MVVP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22274"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service...", "cve_id": "CVE-2022-22274", "vendor": "SonicWall", "ghsa_id": "GHSA-8348-4CMV-MVVP", "product": "SonicOS", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.75521, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99504, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22274", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ed9c36bb-1ce1-48b1-9a31-bdb69c615aec", "vulnerability": {"vulnId": "CVE-2025-42599", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "ed9c36bb-1ce1-48b1-9a31-bdb69c615aec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request... | Affected: QUALITIA / Active! mail 6 | CVSS: 9.8 (CRITICAL) | EPSS: 0.03298 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-42599", "url": "https://www.cve.org/CVERecord?id=CVE-2025-42599"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-42599"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request...", "cve_id": "CVE-2025-42599", "vendor": "QUALITIA", "ghsa_id": null, "product": "Active! mail 6", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03298, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88106, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-42599", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "369ff061-1907-45a3-847f-abea258447c3", "vulnerability": {"vulnId": "CVE-2024-22024", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "369ff061-1907-45a3-847f-abea258447c3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA... | Affected: Ivanti, Ivant / ICS, IPS | CVSS: 8.3 (HIGH) | EPSS: 0.94721 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-22024", "url": "https://www.cve.org/CVERecord?id=CVE-2024-22024"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-22024"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA...", "cve_id": "CVE-2024-22024", "vendor": "Ivanti, Ivant", "ghsa_id": null, "product": "ICS, IPS", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 8.3, "epss_score": 0.94721, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99857, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-22024", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "af6fc9d1-bc20-41b6-8a35-74f8ceaff8f9", "vulnerability": {"vulnId": "CVE-2021-26294", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "af6fc9d1-bc20-41b6-8a35-74f8ceaff8f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a... | Affected: AfterLogic / [\"Aurora\", \"WebMail Pro\"] | CVSS: 7.5 (HIGH) | EPSS: 0.16899 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-26294", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26294"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26294"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a...", "cve_id": "CVE-2021-26294", "vendor": "AfterLogic", "ghsa_id": null, "product": "[\"Aurora\", \"WebMail Pro\"]", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.16899, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96966, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-26294", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f36a1115-5f4b-4e75-bcbf-ca0cf57b1a67", "vulnerability": {"vulnId": "CVE-2021-25114", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "f36a1115-5f4b-4e75-bcbf-ca0cf57b1a67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection | Affected: Paid Memberships Pro / Paid Memberships Pro | CVSS: 9.8 (CRITICAL) | EPSS: 0.81828 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-25114", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25114"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25114"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection", "cve_id": "CVE-2021-25114", "vendor": "Paid Memberships Pro", "ghsa_id": null, "product": "Paid Memberships Pro", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.81828, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99638, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25114", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a83958ee-0b88-4789-9ff4-a99540ef5033", "vulnerability": {"vulnId": "CVE-2017-17215", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "a83958ee-0b88-4789-9ff4-a99540ef5033", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to... | Affected: Huawei / HG532 | CVSS: 8.8 (HIGH) | EPSS: 0.78278 | Used in malware: yes | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-17215", "url": "https://www.cve.org/CVERecord?id=CVE-2017-17215"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-17215"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to...", "cve_id": "CVE-2017-17215", "vendor": "Huawei", "ghsa_id": null, "product": "HG532", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.78278, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99568, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-17215", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0d9d240a-f68d-4123-adf9-2b44a35c31ed", "vulnerability": {"vulnId": "CVE-2021-26295", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0d9d240a-f68d-4123-adf9-2b44a35c31ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI | Affected: Apache / Apache OFBiz | CVSS: 9.8 (CRITICAL) | EPSS: 0.97822 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-26295", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26295"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26295"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI", "cve_id": "CVE-2021-26295", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97822, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99906, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-26295", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ee7875a4-6a1d-4eae-b560-9bef45cfccbf", "vulnerability": {"vulnId": "CVE-2023-0656", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "ee7875a4-6a1d-4eae-b560-9bef45cfccbf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could... | Affected: SonicWall / SonicOS | CVSS: 7.5 (HIGH) | EPSS: 0.41319 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-0656", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0656"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0656"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could...", "cve_id": "CVE-2023-0656", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicOS", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.41319, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98631, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0656", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d028c804-33aa-442d-94f9-c959d8438996", "vulnerability": {"vulnId": "CVE-2021-25899", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "d028c804-33aa-442d-94f9-c959d8438996", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform... | Affected: Void / Aural Rec Monitor | CVSS: 7.5 (HIGH) | EPSS: 0.12245 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-25899", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25899"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25899"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform...", "cve_id": "CVE-2021-25899", "vendor": "Void", "ghsa_id": null, "product": "Aural Rec Monitor", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.12245, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96058, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25899", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0c7ac9cd-4b3c-457a-8ceb-e2bbf430400c", "vulnerability": {"vulnId": "CVE-2021-25003", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0c7ac9cd-4b3c-457a-8ceb-e2bbf430400c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "WPCargo < 6.9.0 - Unauthenticated RCE | Affected: WPCargo / WPCargo | CVSS: 9.8 (CRITICAL) | EPSS: 0.56148 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-25003", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25003"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25003"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WPCargo < 6.9.0 - Unauthenticated RCE", "cve_id": "CVE-2021-25003", "vendor": "WPCargo", "ghsa_id": null, "product": "WPCargo", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.56148, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99023, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25003", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3a1f987b-f38d-43ff-bf0b-8506b587cc03", "vulnerability": {"vulnId": "CVE-2024-3721", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "3a1f987b-f38d-43ff-bf0b-8506b587cc03", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "TBK DVR-4104/DVR-4216 os command injection | Affected: TBK / DVR-4104, DVR-4216 | CVSS: 6.3 (MEDIUM) | EPSS: 0.86489 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-3721", "url": "https://www.cve.org/CVERecord?id=CVE-2024-3721"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-3721"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TBK DVR-4104/DVR-4216 os command injection", "cve_id": "CVE-2024-3721", "vendor": "TBK", "ghsa_id": null, "product": "DVR-4104, DVR-4216", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.86489, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99732, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-3721", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c27125b0-3f1e-4cfd-a7e4-08419b24c0eb", "vulnerability": {"vulnId": "CVE-2021-32030", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "c27125b0-3f1e-4cfd-a7e4-08419b24c0eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication... | Affected: ASUS / GT-AC2900, Lyra Mini | CVSS: 9.8 (CRITICAL) | EPSS: 0.99393 | Used in malware: unknown | Listed 400 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-32030", "url": "https://www.cve.org/CVERecord?id=CVE-2021-32030"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-32030"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication...", "cve_id": "CVE-2021-32030", "vendor": "ASUS", "ghsa_id": null, "product": "GT-AC2900, Lyra Mini", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99393, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9994, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-32030", "ahead_of_cisa_kev": {"unit": "day", "count": 400}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f34bbaec-d777-4ce9-bf02-6abbf445b87d", "vulnerability": {"vulnId": "CVE-2016-10372", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "f34bbaec-d777-4ce9-bf02-6abbf445b87d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547,... | Affected: Eir / D1000 modem | CVSS: 9.8 (CRITICAL) | EPSS: 0.81772 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-10372", "url": "https://www.cve.org/CVERecord?id=CVE-2016-10372"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-10372"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547,...", "cve_id": "CVE-2016-10372", "vendor": "Eir", "ghsa_id": null, "product": "D1000 modem", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.81772, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99637, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-10372", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "540483f4-26ab-4199-99ac-53d9cebc78e1", "vulnerability": {"vulnId": "CVE-2025-1976", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "540483f4-26ab-4199-99ac-53d9cebc78e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6 | Affected: Brocade / Fabric OS | CVSS: 8.6 (HIGH) | EPSS: 0.0069 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-1976", "url": "https://www.cve.org/CVERecord?id=CVE-2025-1976"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-1976"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6", "cve_id": "CVE-2025-1976", "vendor": "Brocade", "ghsa_id": null, "product": "Fabric OS", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.0069, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51036, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-1976", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5764550a-14ca-4ae0-ad05-1694a774c00b", "vulnerability": {"vulnId": "CVE-2018-9995", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "5764550a-14ca-4ae0-ad05-1694a774c00b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which... | Affected: TBK / DVR4104, DVR4216 | CVSS: 9.8 (CRITICAL) | EPSS: 0.82322 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-9995", "url": "https://www.cve.org/CVERecord?id=CVE-2018-9995"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-9995"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which...", "cve_id": "CVE-2018-9995", "vendor": "TBK", "ghsa_id": null, "product": "DVR4104, DVR4216", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82322, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99652, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-9995", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "192ed9c5-48ac-4c33-839e-bb18f4674cf8", "vulnerability": {"vulnId": "CVE-2023-26801", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "192ed9c5-48ac-4c33-839e-bb18f4674cf8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command... | Affected: LB-LINK / BL-AC1900_2.0, BL-WR9000, BL-X26, BL-LTE300 | CVSS: 9.8 (CRITICAL) | EPSS: 0.69663 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26801", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26801"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26801"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command...", "cve_id": "CVE-2023-26801", "vendor": "LB-LINK", "ghsa_id": null, "product": "BL-AC1900_2.0, BL-WR9000, BL-X26, BL-LTE300", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.69663, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99349, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26801", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "27040150-ef9a-42d6-aff9-36c9887bb07b", "vulnerability": {"vulnId": "CVE-2021-27850", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "27040150-ef9a-42d6-aff9-36c9887bb07b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "Bypass of the fix for CVE-2019-0195 | Affected: Apache / Apache Tapestry | CVSS: 9.8 (CRITICAL) | EPSS: 0.93471 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27850", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27850"}, {"id": "GHSA-MJ8X-CPR8-X39H", "url": "https://github.com/advisories/GHSA-MJ8X-CPR8-X39H"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27850"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Bypass of the fix for CVE-2019-0195", "cve_id": "CVE-2021-27850", "vendor": "Apache", "ghsa_id": "GHSA-MJ8X-CPR8-X39H", "product": "Apache Tapestry", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93471, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99838, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27850", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5e3903d2-ffc1-4e81-b85c-c728f6e40fee", "vulnerability": {"vulnId": "CVE-2021-4191", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "5e3903d2-ffc1-4e81-b85c-c728f6e40fee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with... | Affected: GitLab / GitLab | CVSS: 5.3 (MEDIUM) | EPSS: 0.80004 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-4191", "url": "https://www.cve.org/CVERecord?id=CVE-2021-4191"}, {"id": "GHSA-M37Q-W59J-4VR4", "url": "https://github.com/advisories/GHSA-M37Q-W59J-4VR4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-4191"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with...", "cve_id": "CVE-2021-4191", "vendor": "GitLab", "ghsa_id": "GHSA-M37Q-W59J-4VR4", "product": "GitLab", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.80004, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99605, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-4191", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0afcbb3a-f228-4f6b-90d0-1e50f3471e69", "vulnerability": {"vulnId": "CVE-2019-12780", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0afcbb3a-f228-4f6b-90d0-1e50f3471e69", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-28T00:00:00+00:00"}, "scope": {"notes": "The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A... | Affected: Belkin / Wemo Enabled Crock-Pot | CVSS: 9.8 (CRITICAL) | EPSS: 0.72437 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12780", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12780"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12780"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A...", "cve_id": "CVE-2019-12780", "vendor": "Belkin", "ghsa_id": null, "product": "Wemo Enabled Crock-Pot", "added_date": "2025-04-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.72437, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99425, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12780", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "72b23191-4a84-4ce7-ad8f-49414ecae4be", "vulnerability": {"vulnId": "CVE-2025-3987", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T23:31:06+02:00"}, "gcve": {"object_uuid": "72b23191-4a84-4ce7-ad8f-49414ecae4be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T21:31:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T21:31:06+00:00"}, "scope": {"notes": "TOTOLINK N150RT formWsc command injection | Affected: TOTOLINK / N150RT | CVSS: 5.3 (MEDIUM) | EPSS: 0.10488 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-3987", "url": "https://www.cve.org/CVERecord?id=CVE-2025-3987"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-3987"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK N150RT formWsc command injection", "cve_id": "CVE-2025-3987", "vendor": "TOTOLINK", "ghsa_id": null, "product": "N150RT", "added_date": "2025-04-27T21:31:06.000Z", "cvss_score": 5.3, "epss_score": 0.10488, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95627, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-3987", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8602fc97-50ba-4663-9452-6f2de4cf4b68", "vulnerability": {"vulnId": "CVE-2016-5674", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "8602fc97-50ba-4663-9452-6f2de4cf4b68", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1... | Affected: NUUO, NETGEAR / [\"NVRmini 2\", \"NVRsolo\", \"ReadyNAS Surveillance\"] | CVSS: 9.8 (CRITICAL) | EPSS: 0.9461 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-5674", "url": "https://www.cve.org/CVERecord?id=CVE-2016-5674"}, {"id": "GHSA-FX93-287M-8F7Q", "url": "https://github.com/advisories/GHSA-FX93-287M-8F7Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-5674"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1...", "cve_id": "CVE-2016-5674", "vendor": "NUUO, NETGEAR", "ghsa_id": "GHSA-FX93-287M-8F7Q", "product": "[\"NVRmini 2\", \"NVRsolo\", \"ReadyNAS Surveillance\"]", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9461, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99854, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-5674", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1bd3f4ee-5c97-4cd9-905c-156f6c1a0001", "vulnerability": {"vulnId": "CVE-2019-17506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "1bd3f4ee-5c97-4cd9-905c-156f6c1a0001", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the... | Affected: D-Link / DIR-868L, DIR-817LW | CVSS: 9.8 (CRITICAL) | EPSS: 0.56386 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-17506", "url": "https://www.cve.org/CVERecord?id=CVE-2019-17506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-17506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the...", "cve_id": "CVE-2019-17506", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-868L, DIR-817LW", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.56386, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99031, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-17506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6dad2704-16be-4902-8488-524aad1949bb", "vulnerability": {"vulnId": "CVE-2020-35665", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "6dad2704-16be-4902-8488-524aad1949bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in... | Affected: TerraMaster / TOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.7848 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35665", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35665"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35665"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in...", "cve_id": "CVE-2020-35665", "vendor": "TerraMaster", "ghsa_id": null, "product": "TOS", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7848, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99573, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35665", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e54a6cd2-c495-49e8-b534-7b7fdc8eb7ce", "vulnerability": {"vulnId": "CVE-2018-17431", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "e54a6cd2-c495-49e8-b534-7b7fdc8eb7ce", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL. | Affected: Comodo / UTM Firewall | CVSS: 9.8 (CRITICAL) | EPSS: 0.83912 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-17431", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17431"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17431"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.", "cve_id": "CVE-2018-17431", "vendor": "Comodo", "ghsa_id": null, "product": "UTM Firewall", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83912, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99685, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17431", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6b7670f0-b5be-40f2-a348-6cb34aeacd02", "vulnerability": {"vulnId": "CVE-2024-21899", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "6b7670f0-b5be-40f2-a348-6cb34aeacd02", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "QTS, QuTS hero, QuTScloud | Affected: QNAP / QTS, QuTS hero, QuTScloud | CVSS: 9.8 (CRITICAL) | EPSS: 0.24365 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-21899", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21899"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21899"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "QTS, QuTS hero, QuTScloud", "cve_id": "CVE-2024-21899", "vendor": "QNAP", "ghsa_id": null, "product": "QTS, QuTS hero, QuTScloud", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.24365, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97804, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21899", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9bc979b9-d0ae-4736-8ce5-c1352928856d", "vulnerability": {"vulnId": "CVE-2020-11530", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "9bc979b9-d0ae-4736-8ce5-c1352928856d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter... | Affected: iDangero.us / Chop Slider 3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.95657 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11530", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11530"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11530"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter...", "cve_id": "CVE-2020-11530", "vendor": "iDangero.us", "ghsa_id": null, "product": "Chop Slider 3", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95657, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11530", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8ca16493-336e-4f85-a219-1b58e2f69607", "vulnerability": {"vulnId": "CVE-2017-7927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "8ca16493-336e-4f85-a219-1b58e2f69607", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN,... | Affected: Dahua / Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras | CVSS: 7.3 (HIGH) | EPSS: 0.36747 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-7927", "url": "https://www.cve.org/CVERecord?id=CVE-2017-7927"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-7927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN,...", "cve_id": "CVE-2017-7927", "vendor": "Dahua", "ghsa_id": null, "product": "Dahua Technology Co., Ltd Digital Video Recorders and IP Cameras", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.36747, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98459, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-7927", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "89ef7ddb-f466-4ede-8a6c-e420046d3db7", "vulnerability": {"vulnId": "CVE-2019-5128", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "89ef7ddb-f466-4ede-8a6c-e420046d3db7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable... | Affected: YouPHPTube / YouPHPTube | CVSS: 10.0 (CRITICAL) | EPSS: 0.30174 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-5128", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5128"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5128"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable...", "cve_id": "CVE-2019-5128", "vendor": "YouPHPTube", "ghsa_id": null, "product": "YouPHPTube", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.30174, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9817, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5128", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "59ec4b79-b034-4116-bb28-371613a9d461", "vulnerability": {"vulnId": "CVE-2018-3760", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "59ec4b79-b034-4116-bb28-371613a9d461", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially... | Affected: HackerOne / Sprockets | CVSS: 7.5 (HIGH) | EPSS: 0.26717 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-3760", "url": "https://www.cve.org/CVERecord?id=CVE-2018-3760"}, {"id": "GHSA-PR3H-JJHJ-573X", "url": "https://github.com/advisories/GHSA-PR3H-JJHJ-573X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-3760"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially...", "cve_id": "CVE-2018-3760", "vendor": "HackerOne", "ghsa_id": "GHSA-PR3H-JJHJ-573X", "product": "Sprockets", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.26717, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9797, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-3760", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5da337bc-a7bc-4d32-a53c-c5fb2df2df58", "vulnerability": {"vulnId": "CVE-2023-39026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "5da337bc-a7bc-4d32-a53c-c5fb2df2df58", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-27T00:00:00+00:00"}, "scope": {"notes": "Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive... | Affected: FileMage / Gateway | CVSS: 7.5 (HIGH) | EPSS: 0.17919 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-39026", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive...", "cve_id": "CVE-2023-39026", "vendor": "FileMage", "ghsa_id": null, "product": "Gateway", "added_date": "2025-04-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.17919, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97094, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "81d6d714-3be0-4d04-9aa1-7f8f830f6fc0", "vulnerability": {"vulnId": "CVE-2021-35250", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-26T02:00:00+02:00"}, "gcve": {"object_uuid": "81d6d714-3be0-4d04-9aa1-7f8f830f6fc0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-26T00:00:00+00:00"}, "scope": {"notes": "Directory Transversal Vulnerability in Serv-U 15.3 | Affected: SolarWinds / Serv-U | CVSS: 7.5 (HIGH) | EPSS: 0.12804 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-35250", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35250"}, {"id": "GHSA-7PJC-F7P6-MPFC", "url": "https://github.com/advisories/GHSA-7PJC-F7P6-MPFC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35250"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory Transversal Vulnerability in Serv-U 15.3", "cve_id": "CVE-2021-35250", "vendor": "SolarWinds", "ghsa_id": "GHSA-7PJC-F7P6-MPFC", "product": "Serv-U", "added_date": "2025-04-26T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.12804, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96171, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35250", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b06a3bee-22fa-4173-b262-c6028422525b", "vulnerability": {"vulnId": "CVE-2023-43795", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-26T02:00:00+02:00"}, "gcve": {"object_uuid": "b06a3bee-22fa-4173-b262-c6028422525b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-26T00:00:00+00:00"}, "scope": {"notes": "WPS Server Side Request Forgery in GeoServer | Affected: Geoserver / geoserver | CVSS: 8.6 (HIGH) | EPSS: 0.67715 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-43795", "url": "https://www.cve.org/CVERecord?id=CVE-2023-43795"}, {"id": "GHSA-5PR3-M5HM-9956", "url": "https://github.com/advisories/GHSA-5PR3-M5HM-9956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-43795"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WPS Server Side Request Forgery in GeoServer", "cve_id": "CVE-2023-43795", "vendor": "Geoserver", "ghsa_id": "GHSA-5PR3-M5HM-9956", "product": "geoserver", "added_date": "2025-04-26T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.67715, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99297, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-43795", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dd8785f9-1025-43e0-8a9f-0de2e5d88ba8", "vulnerability": {"vulnId": "CVE-2021-40822", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-26T02:00:00+02:00"}, "gcve": {"object_uuid": "dd8785f9-1025-43e0-8a9f-0de2e5d88ba8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-26T00:00:00+00:00"}, "scope": {"notes": "GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. | Affected: GeoServer / GeoServer | CVSS: 7.5 (HIGH) | EPSS: 0.19259 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-40822", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40822"}, {"id": "GHSA-RR33-J5P5-PPF8", "url": "https://github.com/advisories/GHSA-RR33-J5P5-PPF8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40822"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.", "cve_id": "CVE-2021-40822", "vendor": "GeoServer", "ghsa_id": "GHSA-RR33-J5P5-PPF8", "product": "GeoServer", "added_date": "2025-04-26T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.19259, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97261, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40822", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6cec606e-6047-44bb-8619-bb5956362c94", "vulnerability": {"vulnId": "CVE-2018-13315", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-26T02:00:00+02:00"}, "gcve": {"object_uuid": "6cec606e-6047-44bb-8619-bb5956362c94", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-26T00:00:00+00:00"}, "scope": {"notes": "Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an... | Affected: TOTOLINK / A3002RU | CVSS: 9.8 (CRITICAL) | EPSS: 0.01555 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-13315", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13315"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13315"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an...", "cve_id": "CVE-2018-13315", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A3002RU", "added_date": "2025-04-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01555, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74258, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-13315", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a32781b3-c9db-4704-a370-712f9d95a62c", "vulnerability": {"vulnId": "CVE-2024-0778", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-26T02:00:00+02:00"}, "gcve": {"object_uuid": "a32781b3-c9db-4704-a370-712f9d95a62c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-26T00:00:00+00:00"}, "scope": {"notes": "Uniview ISC 2500-S VM.php setNatConfig os command injection | Affected: Uniview / ISC 2500-S | CVSS: 8.0 (HIGH) | EPSS: 0.32088 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0778", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0778"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0778"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Uniview ISC 2500-S VM.php setNatConfig os command injection", "cve_id": "CVE-2024-0778", "vendor": "Uniview", "ghsa_id": null, "product": "ISC 2500-S", "added_date": "2025-04-26T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.32088, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98266, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0778", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1dfa8ccd-aa7d-4852-88dc-00a1b9c7d13d", "vulnerability": {"vulnId": "CVE-2018-9866", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-26T02:00:00+02:00"}, "gcve": {"object_uuid": "1dfa8ccd-aa7d-4852-88dc-00a1b9c7d13d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-26T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual... | Affected: SonicWall / Global Management System (GMS) | CVSS: 9.8 (CRITICAL) | EPSS: 0.04504 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-9866", "url": "https://www.cve.org/CVERecord?id=CVE-2018-9866"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-9866"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual...", "cve_id": "CVE-2018-9866", "vendor": "SonicWall", "ghsa_id": null, "product": "Global Management System (GMS)", "added_date": "2025-04-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04504, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91203, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-9866", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d3de314d-d00a-47dc-9488-8538412e092b", "vulnerability": {"vulnId": "CVE-2017-12635", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "d3de314d-d00a-47dc-9488-8538412e092b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-25T00:00:00+00:00"}, "scope": {"notes": "Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before... | Affected: Apache / Apache CouchDB | CVSS: 9.8 (CRITICAL) | EPSS: 0.99838 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-12635", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12635"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12635"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before...", "cve_id": "CVE-2017-12635", "vendor": "Apache", "ghsa_id": null, "product": "Apache CouchDB", "added_date": "2025-04-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99838, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9996, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12635", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "39ac3ceb-e0f7-4d34-8967-21a2435c19e8", "vulnerability": {"vulnId": "CVE-2018-10737", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "39ac3ceb-e0f7-4d34-8967-21a2435c19e8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-25T00:00:00+00:00"}, "scope": {"notes": "A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. | Affected: Nagios / XI | CVSS: 7.2 (HIGH) | EPSS: 0.4205 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10737", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10737"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10737"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.", "cve_id": "CVE-2018-10737", "vendor": "Nagios", "ghsa_id": null, "product": "XI", "added_date": "2025-04-25T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.4205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98652, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10737", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "87ce8d9c-0cfb-4187-bc27-f0a41a140f4d", "vulnerability": {"vulnId": "CVE-2019-5127", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "87ce8d9c-0cfb-4187-bc27-f0a41a140f4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-25T00:00:00+00:00"}, "scope": {"notes": "A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable... | Affected: YouPHPTube / YouPHPTube\" | CVSS: 10.0 (CRITICAL) | EPSS: 0.45302 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-5127", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5127"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5127"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable...", "cve_id": "CVE-2019-5127", "vendor": "YouPHPTube", "ghsa_id": null, "product": "YouPHPTube\"", "added_date": "2025-04-25T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.45302, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5127", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a4204f98-5156-48ba-a0ef-cb8d96d9ac8a", "vulnerability": {"vulnId": "CVE-2019-19824", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "a4204f98-5156-48ba-a0ef-cb8d96d9ac8a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-25T00:00:00+00:00"}, "scope": {"notes": "On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the... | Affected: TOTOLINK / Realtek SDK based routers | CVSS: 8.8 (HIGH) | EPSS: 0.25135 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-19824", "url": "https://www.cve.org/CVERecord?id=CVE-2019-19824"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-19824"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the...", "cve_id": "CVE-2019-19824", "vendor": "TOTOLINK", "ghsa_id": null, "product": "Realtek SDK based routers", "added_date": "2025-04-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.25135, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97871, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-19824", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d803ac2a-3a28-41df-b046-90a29d5ea31d", "vulnerability": {"vulnId": "CVE-2019-5129", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "d803ac2a-3a28-41df-b046-90a29d5ea31d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-25T00:00:00+00:00"}, "scope": {"notes": "A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable... | Affected: YouPHPTube / YouPHPTube | CVSS: 10.0 (CRITICAL) | EPSS: 0.38531 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-5129", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5129"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5129"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable...", "cve_id": "CVE-2019-5129", "vendor": "YouPHPTube", "ghsa_id": null, "product": "YouPHPTube", "added_date": "2025-04-25T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.38531, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98533, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5129", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6e115db6-ee57-432e-9f67-7de37ef0c433", "vulnerability": {"vulnId": "CVE-2024-11305", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "6e115db6-ee57-432e-9f67-7de37ef0c433", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "Altenergy Power Control Software status_zigbee get_status_zigbee sql injection | Affected: Altenergy / Power Control Software | CVSS: 5.3 (MEDIUM) | EPSS: 0.0367 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-11305", "url": "https://www.cve.org/CVERecord?id=CVE-2024-11305"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-11305"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Altenergy Power Control Software status_zigbee get_status_zigbee sql injection", "cve_id": "CVE-2024-11305", "vendor": "Altenergy", "ghsa_id": null, "product": "Power Control Software", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.0367, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89295, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-11305", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2ade8eca-02b5-4186-9b74-b800f107c976", "vulnerability": {"vulnId": "CVE-2019-11248", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "2ade8eca-02b5-4186-9b74-b800f107c976", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "Kubernetes kubelet exposes /debug/pprof info on healthz port | Affected: Kubernetes / Kubernetes | CVSS: 6.5 (MEDIUM) | EPSS: 0.7506 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-11248", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11248"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11248"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kubernetes kubelet exposes /debug/pprof info on healthz port", "cve_id": "CVE-2019-11248", "vendor": "Kubernetes", "ghsa_id": null, "product": "Kubernetes", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.7506, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99496, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-11248", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5f05db89-469a-4f27-80d8-802afde0ed71", "vulnerability": {"vulnId": "CVE-2025-24893", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "5f05db89-469a-4f27-80d8-802afde0ed71", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "Remote code execution as guest via SolrSearchMacros request in xwiki | Affected: Xwiki / xwiki-platform | CVSS: 9.8 (CRITICAL) | EPSS: 0.99864 | Used in malware: unknown | Listed 404 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24893", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24893"}, {"id": "GHSA-RR6P-3PFG-562J", "url": "https://github.com/advisories/GHSA-RR6P-3PFG-562J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24893"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote code execution as guest via SolrSearchMacros request in xwiki", "cve_id": "CVE-2025-24893", "vendor": "Xwiki", "ghsa_id": "GHSA-RR6P-3PFG-562J", "product": "xwiki-platform", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99864, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24893", "ahead_of_cisa_kev": {"unit": "day", "count": 404}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5b3938ee-1ac2-429a-8716-ffd0b9b1cb48", "vulnerability": {"vulnId": "CVE-2024-9014", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "5b3938ee-1ac2-429a-8716-ffd0b9b1cb48", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "OAuth2 client id and secret exposed through the web browser in pgAdmin 4 | Affected: Pgadmin.org / pgAdmin 4 | CVSS: 9.9 (CRITICAL) | EPSS: 0.09685 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9014", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9014"}, {"id": "GHSA-JM9X-RX9X-WPQJ", "url": "https://github.com/advisories/GHSA-JM9X-RX9X-WPQJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9014"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OAuth2 client id and secret exposed through the web browser in pgAdmin 4", "cve_id": "CVE-2024-9014", "vendor": "Pgadmin.org", "ghsa_id": "GHSA-JM9X-RX9X-WPQJ", "product": "pgAdmin 4", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.09685, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95364, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9014", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ce519a74-1211-46fe-9eb7-9ebaaec70623", "vulnerability": {"vulnId": "CVE-2024-10914", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "ce519a74-1211-46fe-9eb7-9ebaaec70623", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection | Affected: D-Link / DNS-320, DNS-320LW, DNS-325, DNS-340L | CVSS: 9.2 (CRITICAL) | EPSS: 0.96284 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-10914", "url": "https://www.cve.org/CVERecord?id=CVE-2024-10914"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-10914"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection", "cve_id": "CVE-2024-10914", "vendor": "D-Link", "ghsa_id": null, "product": "DNS-320, DNS-320LW, DNS-325, DNS-340L", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.96284, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-10914", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "631ca36a-f191-45df-9f98-1f9f40bde22e", "vulnerability": {"vulnId": "CVE-2024-0305", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "631ca36a-f191-45df-9f98-1f9f40bde22e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure | Affected: Guangzhou Yingke Electronic Technology / Ncast | CVSS: 5.3 (MEDIUM) | EPSS: 0.66932 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0305", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0305"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0305"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure", "cve_id": "CVE-2024-0305", "vendor": "Guangzhou Yingke Electronic Technology", "ghsa_id": null, "product": "Ncast", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.66932, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99276, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0305", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6972d5a3-37af-4725-90de-eeab7c394d49", "vulnerability": {"vulnId": "CVE-2024-27199", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "6972d5a3-37af-4725-90de-eeab7c394d49", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions  was possible | Affected: JetBrains / TeamCity | CVSS: 7.3 (HIGH) | EPSS: 0.99991 | Used in malware: yes | Listed 404 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-27199", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27199"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27199"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions  was possible", "cve_id": "CVE-2024-27199", "vendor": "JetBrains", "ghsa_id": null, "product": "TeamCity", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.99991, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99986, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-27199", "ahead_of_cisa_kev": {"unit": "day", "count": 404}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "409135e6-340c-4db4-b104-fedf9d77ba96", "vulnerability": {"vulnId": "CVE-2024-25735", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "409135e6-340c-4db4-b104-fedf9d77ba96", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP... | Affected: WyreStorm / Apollo VX20 | CVSS: 9.1 (CRITICAL) | EPSS: 0.50622 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-25735", "url": "https://www.cve.org/CVERecord?id=CVE-2024-25735"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-25735"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP...", "cve_id": "CVE-2024-25735", "vendor": "WyreStorm", "ghsa_id": null, "product": "Apollo VX20", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.50622, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-25735", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1d0c7083-9e07-48e8-8017-cae5acdcb6b9", "vulnerability": {"vulnId": "CVE-2019-18394", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "1d0c7083-9e07-48e8-8017-cae5acdcb6b9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send... | Affected: Ignite Realtime / Openfire | CVSS: 9.8 (CRITICAL) | EPSS: 0.32304 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-18394", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18394"}, {"id": "GHSA-MFJW-X4Q4-69P9", "url": "https://github.com/advisories/GHSA-MFJW-X4Q4-69P9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18394"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send...", "cve_id": "CVE-2019-18394", "vendor": "Ignite Realtime", "ghsa_id": "GHSA-MFJW-X4Q4-69P9", "product": "Openfire", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.32304, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98278, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18394", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7b033640-3402-44a0-93d1-1ba371a54fb4", "vulnerability": {"vulnId": "CVE-2024-27954", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "7b033640-3402-44a0-93d1-1ba371a54fb4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability | Affected: WP Automatic / Automatic | CVSS: 9.3 (CRITICAL) | EPSS: 0.72766 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-27954", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27954"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27954"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability", "cve_id": "CVE-2024-27954", "vendor": "WP Automatic", "ghsa_id": null, "product": "Automatic", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.72766, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99434, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27954", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "01dcd5d4-9817-4df8-96ba-7d33b1d4938c", "vulnerability": {"vulnId": "CVE-2018-11759", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "01dcd5d4-9817-4df8-96ba-7d33b1d4938c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK... | Affected: Apache / Apache Tomcat Connectors | CVSS: 7.5 (HIGH) | EPSS: 0.90647 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11759", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11759"}, {"id": "GHSA-5Q2C-33MG-8M75", "url": "https://github.com/advisories/GHSA-5Q2C-33MG-8M75"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11759"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK...", "cve_id": "CVE-2018-11759", "vendor": "Apache", "ghsa_id": "GHSA-5Q2C-33MG-8M75", "product": "Apache Tomcat Connectors", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.90647, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99801, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11759", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0dab3737-d47f-4910-afb2-a77a8b9f6045", "vulnerability": {"vulnId": "CVE-2021-46422", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "0dab3737-d47f-4910-afb2-a77a8b9f6045", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any... | Affected: Telesquare / SDT-CW3B1 | CVSS: 9.8 (CRITICAL) | EPSS: 0.94342 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-46422", "url": "https://www.cve.org/CVERecord?id=CVE-2021-46422"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-46422"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any...", "cve_id": "CVE-2021-46422", "vendor": "Telesquare", "ghsa_id": null, "product": "SDT-CW3B1", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94342, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99849, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-46422", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8296040e-c56c-47ec-9e95-04125bc0d455", "vulnerability": {"vulnId": "CVE-2024-0204", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "8296040e-c56c-47ec-9e95-04125bc0d455", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-24T00:00:00+00:00"}, "scope": {"notes": "Authentication Bypass in GoAnywhere MFT | Affected: Fortra / GoAnywhere MFT | CVSS: 9.8 (CRITICAL) | EPSS: 0.95086 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0204", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0204"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0204"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication Bypass in GoAnywhere MFT", "cve_id": "CVE-2024-0204", "vendor": "Fortra", "ghsa_id": null, "product": "GoAnywhere MFT", "added_date": "2025-04-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95086, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99862, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0204", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c5d2798f-68ce-46ef-bcfb-576aaeda48a2", "vulnerability": {"vulnId": "CVE-2022-39952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-23T02:00:00+02:00"}, "gcve": {"object_uuid": "c5d2798f-68ce-46ef-bcfb-576aaeda48a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-23T00:00:00+00:00"}, "scope": {"notes": "A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0... | Affected: Fortinet / FortiNAC | CVSS: 9.8 (CRITICAL) | EPSS: 0.99794 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-39952", "url": "https://www.cve.org/CVERecord?id=CVE-2022-39952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-39952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0...", "cve_id": "CVE-2022-39952", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiNAC", "added_date": "2025-04-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99794, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-39952", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8efaea7a-5370-4135-aa21-1f8442836b63", "vulnerability": {"vulnId": "CVE-2010-0219", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-23T02:00:00+02:00"}, "gcve": {"object_uuid": "8efaea7a-5370-4135-aa21-1f8442836b63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-23T00:00:00+00:00"}, "scope": {"notes": "Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of... | Affected: Apache / Axis2 | CVSS: 10.0 (HIGH) | EPSS: 0.90851 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-0219", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0219"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0219"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of...", "cve_id": "CVE-2010-0219", "vendor": "Apache", "ghsa_id": null, "product": "Axis2", "added_date": "2025-04-23T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.90851, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99804, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-0219", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3b78a2e8-57ee-4e21-8fb6-bc1bf8945a06", "vulnerability": {"vulnId": "CVE-2024-0352", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-23T02:00:00+02:00"}, "gcve": {"object_uuid": "3b78a2e8-57ee-4e21-8fb6-bc1bf8945a06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-23T00:00:00+00:00"}, "scope": {"notes": "Likeshop HTTP POST Request File.php userFormImage unrestricted upload | Affected: Likeshop / Likeshop | CVSS: 7.3 (HIGH) | EPSS: 0.72917 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0352", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0352"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0352"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Likeshop HTTP POST Request File.php userFormImage unrestricted upload", "cve_id": "CVE-2024-0352", "vendor": "Likeshop", "ghsa_id": null, "product": "Likeshop", "added_date": "2025-04-23T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.72917, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99439, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0352", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9f29df9d-d789-4ed0-847e-0d634d806da3", "vulnerability": {"vulnId": "CVE-2023-37679", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-23T02:00:00+02:00"}, "gcve": {"object_uuid": "9f29df9d-d789-4ed0-847e-0d634d806da3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-23T00:00:00+00:00"}, "scope": {"notes": "A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. | Affected: NextGen Healthcare / Mirth Connect | CVSS: 9.8 (CRITICAL) | EPSS: 0.99434 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-37679", "url": "https://www.cve.org/CVERecord?id=CVE-2023-37679"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-37679"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.", "cve_id": "CVE-2023-37679", "vendor": "NextGen Healthcare", "ghsa_id": null, "product": "Mirth Connect", "added_date": "2025-04-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99434, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-37679", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2b9489b4-89d1-4744-9f33-a226a1927f11", "vulnerability": {"vulnId": "CVE-2021-21307", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-22T02:00:00+02:00"}, "gcve": {"object_uuid": "2b9489b4-89d1-4744-9f33-a226a1927f11", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-22T00:00:00+00:00"}, "scope": {"notes": "Remote Code Exploit in Lucee Admin | Affected: Lucee / Lucee | CVSS: 8.6 (HIGH) | EPSS: 0.89189 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21307", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21307"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21307"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Exploit in Lucee Admin", "cve_id": "CVE-2021-21307", "vendor": "Lucee", "ghsa_id": null, "product": "Lucee", "added_date": "2025-04-22T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.89189, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99779, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21307", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3782c587-8587-4730-afe2-61d39dd1d10c", "vulnerability": {"vulnId": "CVE-2021-21978", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-22T02:00:00+02:00"}, "gcve": {"object_uuid": "3782c587-8587-4730-afe2-61d39dd1d10c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-22T00:00:00+00:00"}, "scope": {"notes": "VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of... | Affected: VMware / VMware View Planner | CVSS: 9.8 (CRITICAL) | EPSS: 0.99005 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21978", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21978"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21978"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of...", "cve_id": "CVE-2021-21978", "vendor": "VMware", "ghsa_id": null, "product": "VMware View Planner", "added_date": "2025-04-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99005, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21978", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "faa5712c-a360-4204-a458-af1c0aea14e0", "vulnerability": {"vulnId": "CVE-2022-29383", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-22T02:00:00+02:00"}, "gcve": {"object_uuid": "faa5712c-a360-4204-a458-af1c0aea14e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-22T00:00:00+00:00"}, "scope": {"notes": "NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at... | Affected: NETGEAR / ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.48537 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29383", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29383"}, {"id": "GHSA-JMJ9-46JH-6RQF", "url": "https://github.com/advisories/GHSA-JMJ9-46JH-6RQF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29383"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at...", "cve_id": "CVE-2022-29383", "vendor": "NETGEAR", "ghsa_id": "GHSA-JMJ9-46JH-6RQF", "product": "ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3", "added_date": "2025-04-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.48537, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98833, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29383", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d79c55c3-c2f5-4b12-96f1-139dfb195ec0", "vulnerability": {"vulnId": "CVE-2025-28036", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-22T02:00:00+02:00"}, "gcve": {"object_uuid": "d79c55c3-c2f5-4b12-96f1-139dfb195ec0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-22T00:00:00+00:00"}, "scope": {"notes": "TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through... | Affected: TOTOLINK / A950RG | CVSS: 9.8 (CRITICAL) | EPSS: 0.01342 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-28036", "url": "https://www.cve.org/CVERecord?id=CVE-2025-28036"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-28036"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through...", "cve_id": "CVE-2025-28036", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A950RG", "added_date": "2025-04-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01342, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.70313, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-28036", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "994018ca-da16-4443-bc35-85980ecf1c61", "vulnerability": {"vulnId": "CVE-2025-31200", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-17T02:00:00+02:00"}, "gcve": {"object_uuid": "994018ca-da16-4443-bc35-85980ecf1c61", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-17T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1,... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 7.5 (HIGH) | EPSS: 0.18751 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-31200", "url": "https://www.cve.org/CVERecord?id=CVE-2025-31200"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-31200"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1,...", "cve_id": "CVE-2025-31200", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2025-04-17T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.18751, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97196, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-31200", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8dc67699-5f66-4db1-bc24-d00a80060fec", "vulnerability": {"vulnId": "CVE-2025-24054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-17T02:00:00+02:00"}, "gcve": {"object_uuid": "8dc67699-5f66-4db1-bc24-d00a80060fec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-17T00:00:00+00:00"}, "scope": {"notes": "NTLM Hash Disclosure Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 6.5 (MEDIUM) | EPSS: 0.58909 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24054", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NTLM Hash Disclosure Spoofing Vulnerability", "cve_id": "CVE-2025-24054", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-04-17T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.58909, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "60a599d4-6ac6-4833-b274-7373c10b2348", "vulnerability": {"vulnId": "CVE-2025-31201", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-17T02:00:00+02:00"}, "gcve": {"object_uuid": "60a599d4-6ac6-4833-b274-7373c10b2348", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-17T00:00:00+00:00"}, "scope": {"notes": "This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1,... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS | CVSS: 6.8 (MEDIUM) | EPSS: 0.13973 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-31201", "url": "https://www.cve.org/CVERecord?id=CVE-2025-31201"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-31201"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1,...", "cve_id": "CVE-2025-31201", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS, tvOS, visionOS", "added_date": "2025-04-17T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.13973, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9644, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-31201", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2d6b6af6-6a87-4184-8d98-0b667d3f7773", "vulnerability": {"vulnId": "CVE-2021-20035", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-16T02:00:00+02:00"}, "gcve": {"object_uuid": "2d6b6af6-6a87-4184-8d98-0b667d3f7773", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-16T00:00:00+00:00"}, "scope": {"notes": "Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands... | Affected: SonicWall / SMA100 | CVSS: 6.5 (MEDIUM) | EPSS: 0.04181 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20035", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20035"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20035"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands...", "cve_id": "CVE-2021-20035", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA100", "added_date": "2025-04-16T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.04181, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90605, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20035", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d8a7d473-5618-4b77-8fcd-3e036b22a594", "vulnerability": {"vulnId": "CVE-2025-28137", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "d8a7d473-5618-4b77-8fcd-3e036b22a594", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-15T00:00:00+00:00"}, "scope": {"notes": "The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function... | Affected: TOTOLINK / A810R | CVSS: 9.8 (CRITICAL) | EPSS: 0.34089 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-28137", "url": "https://www.cve.org/CVERecord?id=CVE-2025-28137"}, {"id": "GHSA-FCHW-692R-4W73", "url": "https://github.com/advisories/GHSA-FCHW-692R-4W73"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-28137"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function...", "cve_id": "CVE-2025-28137", "vendor": "TOTOLINK", "ghsa_id": "GHSA-FCHW-692R-4W73", "product": "A810R", "added_date": "2025-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.34089, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98358, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-28137", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "233a5a71-2621-48e5-ba9c-156760f3490d", "vulnerability": {"vulnId": "CVE-2025-3102", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-09T11:38:42+02:00"}, "gcve": {"object_uuid": "233a5a71-2621-48e5-ba9c-156760f3490d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-09T09:38:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-09T09:38:42+00:00"}, "scope": {"notes": "SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation | Affected: Brainstorm Force / OttoKit: All-in-One Automation Platform (Formerly SureTriggers) | CVSS: 8.1 (HIGH) | EPSS: 0.76237 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-3102", "url": "https://www.cve.org/CVERecord?id=CVE-2025-3102"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-3102"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation", "cve_id": "CVE-2025-3102", "vendor": "Brainstorm Force", "ghsa_id": null, "product": "OttoKit: All-in-One Automation Platform (Formerly SureTriggers)", "added_date": "2025-04-09T09:38:42.000Z", "cvss_score": 8.1, "epss_score": 0.76237, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99521, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-3102", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "40128b66-f519-4ba1-8ca7-db809895e92c", "vulnerability": {"vulnId": "CVE-2024-53150", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-09T02:00:00+02:00"}, "gcve": {"object_uuid": "40128b66-f519-4ba1-8ca7-db809895e92c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-09T00:00:00+00:00"}, "scope": {"notes": "ALSA: usb-audio: Fix out of bounds reads when finding clock sources | Affected: Linux / Linux | CVSS: 7.1 (HIGH) | EPSS: 0.01354 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-53150", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53150"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53150"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ALSA: usb-audio: Fix out of bounds reads when finding clock sources", "cve_id": "CVE-2024-53150", "vendor": "Linux", "ghsa_id": null, "product": "Linux", "added_date": "2025-04-09T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.01354, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.70576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-53150", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b9d90d42-92fc-4bab-aeea-a7b98b3b5af3", "vulnerability": {"vulnId": "CVE-2024-53197", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-09T02:00:00+02:00"}, "gcve": {"object_uuid": "b9d90d42-92fc-4bab-aeea-a7b98b3b5af3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-09T00:00:00+00:00"}, "scope": {"notes": "ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.03558 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-53197", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53197"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53197"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices", "cve_id": "CVE-2024-53197", "vendor": "Linux", "ghsa_id": null, "product": "Linux", "added_date": "2025-04-09T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03558, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88944, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-53197", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2795ebc0-4c87-4d66-b1b2-bb83f778dc62", "vulnerability": {"vulnId": "CVE-2025-29824", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-08T02:00:00+02:00"}, "gcve": {"object_uuid": "2795ebc0-4c87-4d66-b1b2-bb83f778dc62", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-08T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.13904 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-29824", "url": "https://www.cve.org/CVERecord?id=CVE-2025-29824"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-29824"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-29824", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-04-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.13904, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96427, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-29824", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "177e132b-96e4-4966-afba-9fd1e2aaa00d", "vulnerability": {"vulnId": "CVE-2025-30406", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-08T02:00:00+02:00"}, "gcve": {"object_uuid": "177e132b-96e4-4966-afba-9fd1e2aaa00d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-08T00:00:00+00:00"}, "scope": {"notes": "Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's... | Affected: Gladinet / CentreStack | CVSS: 9.0 (CRITICAL) | EPSS: 0.94343 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-30406", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30406"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30406"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's...", "cve_id": "CVE-2025-30406", "vendor": "Gladinet", "ghsa_id": null, "product": "CentreStack", "added_date": "2025-04-08T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.94343, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9985, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30406", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "99867eb4-a475-4622-8c4f-cb9985dda2a2", "vulnerability": {"vulnId": "CVE-2025-31161", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-07T02:00:00+02:00"}, "gcve": {"object_uuid": "99867eb4-a475-4622-8c4f-cb9985dda2a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-07T00:00:00+00:00"}, "scope": {"notes": "CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is... | Affected: CrushFTP / CrushFTP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99976 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-31161", "url": "https://www.cve.org/CVERecord?id=CVE-2025-31161"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-31161"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is...", "cve_id": "CVE-2025-31161", "vendor": "CrushFTP", "ghsa_id": null, "product": "CrushFTP", "added_date": "2025-04-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99976, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99978, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-31161", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3adec772-ac3c-402b-80da-69ce064d32d8", "vulnerability": {"vulnId": "CVE-2025-22457", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "3adec772-ac3c-402b-80da-69ce064d32d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-04T00:00:00+00:00"}, "scope": {"notes": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA... | Affected: Ivanti / Connect Secure, Policy Secure, Neurons for ZTA gateways | CVSS: 9.0 (CRITICAL) | EPSS: 0.99981 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-22457", "url": "https://www.cve.org/CVERecord?id=CVE-2025-22457"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-22457"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA...", "cve_id": "CVE-2025-22457", "vendor": "Ivanti", "ghsa_id": null, "product": "Connect Secure, Policy Secure, Neurons for ZTA gateways", "added_date": "2025-04-04T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.99981, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99981, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-22457", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "565f3853-1acb-400b-9fae-8cb5b820ec65", "vulnerability": {"vulnId": "CVE-2025-29063", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-02T02:00:00+02:00"}, "gcve": {"object_uuid": "565f3853-1acb-400b-9fae-8cb5b820ec65", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-02T00:00:00+00:00"}, "scope": {"notes": "An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to... | Affected: BL / AC2100 | CVSS: 9.8 (CRITICAL) | EPSS: 0.01077 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-29063", "url": "https://www.cve.org/CVERecord?id=CVE-2025-29063"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-29063"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to...", "cve_id": "CVE-2025-29063", "vendor": "BL", "ghsa_id": null, "product": "AC2100", "added_date": "2025-04-02T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01077, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63754, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-29063", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f7b8eb78-8589-41ac-a97c-4fd61b9872e0", "vulnerability": {"vulnId": "CVE-2025-24813", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-04-01T02:00:00+02:00"}, "gcve": {"object_uuid": "f7b8eb78-8589-41ac-a97c-4fd61b9872e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-04-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-04-01T00:00:00+00:00"}, "scope": {"notes": "Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT | Affected: Apache / Apache Tomcat | CVSS: 9.8 (CRITICAL) | EPSS: 0.99927 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24813", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24813"}, {"id": "GHSA-83QJ-6FR2-VHQG", "url": "https://github.com/advisories/GHSA-83QJ-6FR2-VHQG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24813"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT", "cve_id": "CVE-2025-24813", "vendor": "Apache", "ghsa_id": "GHSA-83QJ-6FR2-VHQG", "product": "Apache Tomcat", "added_date": "2025-04-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99927, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24813", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dcd87324-96fe-4379-8b1e-a74babf79a66", "vulnerability": {"vulnId": "CVE-2024-20439", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "dcd87324-96fe-4379-8b1e-a74babf79a66", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-31T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a... | Affected: Cisco / Cisco Smart License Utility | CVSS: 9.8 (CRITICAL) | EPSS: 0.9709 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20439", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20439"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20439"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a...", "cve_id": "CVE-2024-20439", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Smart License Utility", "added_date": "2025-03-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9709, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99892, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20439", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9781d56c-b761-4fae-8a24-6f297d52e41f", "vulnerability": {"vulnId": "CVE-2025-2783", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-27T01:00:00+01:00"}, "gcve": {"object_uuid": "9781d56c-b761-4fae-8a24-6f297d52e41f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-27T00:00:00+00:00"}, "scope": {"notes": "Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to... | Affected: Google / Chrome | CVSS: 8.3 (HIGH) | EPSS: 0.09238 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-2783", "url": "https://www.cve.org/CVERecord?id=CVE-2025-2783"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-2783"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to...", "cve_id": "CVE-2025-2783", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2025-03-27T00:00:00.000Z", "cvss_score": 8.3, "epss_score": 0.09238, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95207, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-2783", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e967811-2c31-425f-8242-2035a09941f6", "vulnerability": {"vulnId": "CVE-2019-9875", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-26T01:00:00+01:00"}, "gcve": {"object_uuid": "6e967811-2c31-425f-8242-2035a09941f6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-26T00:00:00+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by... | Affected: Sitecore / Sitecore CMS | CVSS: 8.8 (HIGH) | EPSS: 0.13795 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-9875", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9875"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9875"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by...", "cve_id": "CVE-2019-9875", "vendor": "Sitecore", "ghsa_id": null, "product": "Sitecore CMS", "added_date": "2025-03-26T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.13795, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96407, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9875", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b1031f92-b1bc-4546-9ccf-dcd80d0fb9bf", "vulnerability": {"vulnId": "CVE-2019-9874", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-26T01:00:00+01:00"}, "gcve": {"object_uuid": "b1031f92-b1bc-4546-9ccf-dcd80d0fb9bf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-26T00:00:00+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2... | Affected: Sitecore / CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.83736 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-9874", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9874"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9874"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2...", "cve_id": "CVE-2019-9874", "vendor": "Sitecore", "ghsa_id": null, "product": "CMS", "added_date": "2025-03-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83736, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99683, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9874", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6cddf0cc-2532-4204-af8d-68079ce7fe2d", "vulnerability": {"vulnId": "CVE-2025-30154", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-24T01:00:00+01:00"}, "gcve": {"object_uuid": "6cddf0cc-2532-4204-af8d-68079ce7fe2d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-24T00:00:00+00:00"}, "scope": {"notes": "Multiple Reviewdog actions were compromised during a specific time period | Affected: Reviewdog / reviewdog | CVSS: 8.6 (HIGH) | EPSS: 0.02437 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-30154", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30154"}, {"id": "GHSA-QMG3-HPQR-GQVC", "url": "https://github.com/advisories/GHSA-QMG3-HPQR-GQVC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30154"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple Reviewdog actions were compromised during a specific time period", "cve_id": "CVE-2025-30154", "vendor": "Reviewdog", "ghsa_id": "GHSA-QMG3-HPQR-GQVC", "product": "reviewdog", "added_date": "2025-03-24T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.02437, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.837, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30154", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "252098e2-5d07-4fb1-88f4-1e0d10ca6a26", "vulnerability": {"vulnId": "CVE-2025-30349", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-21T01:00:00+01:00"}, "gcve": {"object_uuid": "252098e2-5d07-4fb1-88f4-1e0d10ca6a26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-21T00:00:00+00:00"}, "scope": {"notes": "Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted... | Affected: Horde / IMP | CVSS: 7.2 (HIGH) | EPSS: 0.31292 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-30349", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30349"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30349"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted...", "cve_id": "CVE-2025-30349", "vendor": "Horde", "ghsa_id": null, "product": "IMP", "added_date": "2025-03-21T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.31292, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98226, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30349", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d2acdca4-ae94-4058-9dae-e835b26d5c56", "vulnerability": {"vulnId": "CVE-2025-1316", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "d2acdca4-ae94-4058-9dae-e835b26d5c56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-19T00:00:00+00:00"}, "scope": {"notes": "Edimax IC-7100 IP Camera OS Command Injection | Affected: Edimax / IC-7100 IP Camera | CVSS: 9.3 (CRITICAL) | EPSS: 0.74482 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-1316", "url": "https://www.cve.org/CVERecord?id=CVE-2025-1316"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-1316"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Edimax IC-7100 IP Camera OS Command Injection", "cve_id": "CVE-2025-1316", "vendor": "Edimax", "ghsa_id": null, "product": "IC-7100 IP Camera", "added_date": "2025-03-19T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.74482, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99483, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-1316", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1d4e78de-904b-47c0-abcd-17920ce8e2f5", "vulnerability": {"vulnId": "CVE-2024-48248", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "1d4e78de-904b-47c0-abcd-17920ce8e2f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-19T00:00:00+00:00"}, "scope": {"notes": "NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to... | Affected: NAKIVO / Backup & Replication Director | CVSS: 8.6 (HIGH) | EPSS: 0.94356 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-48248", "url": "https://www.cve.org/CVERecord?id=CVE-2024-48248"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-48248"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to...", "cve_id": "CVE-2024-48248", "vendor": "NAKIVO", "ghsa_id": null, "product": "Backup & Replication Director", "added_date": "2025-03-19T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.94356, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9985, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-48248", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dc05ec2b-bd3d-4d5e-b810-b66a62585bf6", "vulnerability": {"vulnId": "CVE-2025-30259", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "dc05ec2b-bd3d-4d5e-b810-b66a62585bf6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-19T00:00:00+00:00"}, "scope": {"notes": "The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and... | Affected: Meta / WhatsApp cloud service | CVSS: 3.5 (LOW) | EPSS: 0.00256 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-30259", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30259"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30259"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and...", "cve_id": "CVE-2025-30259", "vendor": "Meta", "ghsa_id": null, "product": "WhatsApp cloud service", "added_date": "2025-03-19T00:00:00.000Z", "cvss_score": 3.5, "epss_score": 0.00256, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.15626, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30259", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2e63aa65-c663-4807-a327-f146e180a701", "vulnerability": {"vulnId": "CVE-2017-12637", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "2e63aa65-c663-4807-a327-f146e180a701", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-19T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote... | Affected: SAP / NetWeaver Application Server Java | CVSS: 7.5 (HIGH) | EPSS: 0.95111 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12637", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12637"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12637"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote...", "cve_id": "CVE-2017-12637", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver Application Server Java", "added_date": "2025-03-19T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.95111, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99863, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12637", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9fffd3e2-602b-4725-96a5-dee95951d7cf", "vulnerability": {"vulnId": "CVE-2025-24472", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-18T01:00:00+01:00"}, "gcve": {"object_uuid": "9fffd3e2-602b-4725-96a5-dee95951d7cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-18T00:00:00+00:00"}, "scope": {"notes": "An\u00a0Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0... | Affected: Fortinet / FortiOS, FortiProxy | CVSS: 8.1 (HIGH) | EPSS: 0.07235 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24472", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24472"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24472"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An\u00a0Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0...", "cve_id": "CVE-2025-24472", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiOS, FortiProxy", "added_date": "2025-03-18T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.07235, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94143, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-24472", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "49d6066e-de18-481a-afe5-e5ff09c22260", "vulnerability": {"vulnId": "CVE-2025-30066", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-18T01:00:00+01:00"}, "gcve": {"object_uuid": "49d6066e-de18-481a-afe5-e5ff09c22260", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-18T00:00:00+00:00"}, "scope": {"notes": "tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected... | Affected: Tj-actions / changed-files | CVSS: 8.6 (HIGH) | EPSS: 0.72092 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-30066", "url": "https://www.cve.org/CVERecord?id=CVE-2025-30066"}, {"id": "GHSA-MRRH-FWG8-R2C3", "url": "https://github.com/advisories/GHSA-MRRH-FWG8-R2C3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-30066"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected...", "cve_id": "CVE-2025-30066", "vendor": "Tj-actions", "ghsa_id": "GHSA-MRRH-FWG8-R2C3", "product": "changed-files", "added_date": "2025-03-18T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.72092, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99416, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-30066", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aed00828-383f-423b-bc6f-38ee9a5a2808", "vulnerability": {"vulnId": "CVE-2025-21590", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-13T01:00:00+01:00"}, "gcve": {"object_uuid": "aed00828-383f-423b-bc6f-38ee9a5a2808", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-13T00:00:00+00:00"}, "scope": {"notes": "Junos OS: An local attacker with shell access can execute arbitrary code | Affected: Juniper Networks / Junos OS | CVSS: 6.7 (MEDIUM) | EPSS: 0.01715 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21590", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21590"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21590"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: An local attacker with shell access can execute arbitrary code", "cve_id": "CVE-2025-21590", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2025-03-13T00:00:00.000Z", "cvss_score": 6.7, "epss_score": 0.01715, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21590", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "da0f5a3e-df13-4931-84d1-50b0e8a44147", "vulnerability": {"vulnId": "CVE-2025-24201", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-13T01:00:00+01:00"}, "gcve": {"object_uuid": "da0f5a3e-df13-4931-84d1-50b0e8a44147", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-13T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4... | Affected: Apple / Safari, iOS and iPadOS, iPadOS, macOS, visionOS, watchOS | CVSS: 8.8 (HIGH) | EPSS: 0.03773 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24201", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24201"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24201"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4...", "cve_id": "CVE-2025-24201", "vendor": "Apple", "ghsa_id": null, "product": "Safari, iOS and iPadOS, iPadOS, macOS, visionOS, watchOS", "added_date": "2025-03-13T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03773, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24201", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02f5985c-542a-49e2-9ca4-be6e97d145fc", "vulnerability": {"vulnId": "CVE-2025-26633", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-11T01:00:00+01:00"}, "gcve": {"object_uuid": "02f5985c-542a-49e2-9ca4-be6e97d145fc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-11T00:00:00+00:00"}, "scope": {"notes": "Microsoft Management Console Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.30391 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-26633", "url": "https://www.cve.org/CVERecord?id=CVE-2025-26633"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-26633"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Management Console Security Feature Bypass Vulnerability", "cve_id": "CVE-2025-26633", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-03-11T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.30391, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98182, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-26633", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "07eddab0-3ae1-4ede-a6e2-85035bfc71e5", "vulnerability": {"vulnId": "CVE-2025-24985", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-11T01:00:00+01:00"}, "gcve": {"object_uuid": "07eddab0-3ae1-4ede-a6e2-85035bfc71e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-11T00:00:00+00:00"}, "scope": {"notes": "Windows Fast FAT File System Driver Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.03846 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24985", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24985"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24985"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Fast FAT File System Driver Remote Code Execution Vulnerability", "cve_id": "CVE-2025-24985", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-03-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03846, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89802, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24985", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0499072e-7e9b-44b4-bbbf-cba16cd52cb8", "vulnerability": {"vulnId": "CVE-2025-24991", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-11T01:00:00+01:00"}, "gcve": {"object_uuid": "0499072e-7e9b-44b4-bbbf-cba16cd52cb8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-11T00:00:00+00:00"}, "scope": {"notes": "Windows NTFS Information Disclosure Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 5.5 (MEDIUM) | EPSS: 0.01979 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24991", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24991"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24991"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows NTFS Information Disclosure Vulnerability", "cve_id": "CVE-2025-24991", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-03-11T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.01979, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79774, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24991", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "712a064a-bf0a-44f7-b4f0-221790089ddf", "vulnerability": {"vulnId": "CVE-2025-24984", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-11T01:00:00+01:00"}, "gcve": {"object_uuid": "712a064a-bf0a-44f7-b4f0-221790089ddf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-11T00:00:00+00:00"}, "scope": {"notes": "Windows NTFS Information Disclosure Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 4.6 (MEDIUM) | EPSS: 0.01956 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24984", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24984"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24984"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows NTFS Information Disclosure Vulnerability", "cve_id": "CVE-2025-24984", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-03-11T00:00:00.000Z", "cvss_score": 4.6, "epss_score": 0.01956, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79548, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24984", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2be0382a-e8f6-4ae8-b421-bdb86f247075", "vulnerability": {"vulnId": "CVE-2025-24993", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-11T01:00:00+01:00"}, "gcve": {"object_uuid": "2be0382a-e8f6-4ae8-b421-bdb86f247075", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-11T00:00:00+00:00"}, "scope": {"notes": "Windows NTFS Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.02173 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24993", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24993"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24993"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows NTFS Remote Code Execution Vulnerability", "cve_id": "CVE-2025-24993", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-03-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02173, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8164, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24993", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4409b0d6-cf3c-4a54-a091-ee57d3b6c31d", "vulnerability": {"vulnId": "CVE-2025-24983", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-11T01:00:00+01:00"}, "gcve": {"object_uuid": "4409b0d6-cf3c-4a54-a091-ee57d3b6c31d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-11T00:00:00+00:00"}, "scope": {"notes": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.01348 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24983", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24983"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24983"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-24983", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2025-03-11T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.01348, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.70452, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24983", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "da5d1229-5d38-4876-be9d-3a5224cb3e17", "vulnerability": {"vulnId": "CVE-2024-13159", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "da5d1229-5d38-4876-be9d-3a5224cb3e17", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-10T00:00:00+00:00"}, "scope": {"notes": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote... | Affected: Ivanti / Endpoint Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.99992 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-13159", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13159"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13159"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...", "cve_id": "CVE-2024-13159", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager", "added_date": "2025-03-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99992, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13159", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d8ab90e4-f703-4b4f-9aee-57bca95a6870", "vulnerability": {"vulnId": "CVE-2025-25181", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "d8ab90e4-f703-4b4f-9aee-57bca95a6870", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-10T00:00:00+00:00"}, "scope": {"notes": "A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL... | Affected: Advantive / VeraCore | CVSS: 5.8 (MEDIUM) | EPSS: 0.55549 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-25181", "url": "https://www.cve.org/CVERecord?id=CVE-2025-25181"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-25181"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL...", "cve_id": "CVE-2025-25181", "vendor": "Advantive", "ghsa_id": null, "product": "VeraCore", "added_date": "2025-03-10T00:00:00.000Z", "cvss_score": 5.8, "epss_score": 0.55549, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9901, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-25181", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eaddb855-ba5c-4d6c-bc6f-b33f729f94fb", "vulnerability": {"vulnId": "CVE-2024-57968", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "eaddb855-ba5c-4d6c-bc6f-b33f729f94fb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-10T00:00:00+00:00"}, "scope": {"notes": "Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during... | Affected: Advantive / VeraCore | CVSS: 9.9 (CRITICAL) | EPSS: 0.32284 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-57968", "url": "https://www.cve.org/CVERecord?id=CVE-2024-57968"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-57968"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during...", "cve_id": "CVE-2024-57968", "vendor": "Advantive", "ghsa_id": null, "product": "VeraCore", "added_date": "2025-03-10T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.32284, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98277, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-57968", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cce6a4eb-7c6b-4fc4-b7c9-3e4f6e14fa5e", "vulnerability": {"vulnId": "CVE-2024-13161", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "cce6a4eb-7c6b-4fc4-b7c9-3e4f6e14fa5e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-10T00:00:00+00:00"}, "scope": {"notes": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote... | Affected: Ivanti / Endpoint Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.90081 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-13161", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13161"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13161"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...", "cve_id": "CVE-2024-13161", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager", "added_date": "2025-03-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90081, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99793, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13161", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "851ea01f-e7e3-435d-b0f5-8cea93e68050", "vulnerability": {"vulnId": "CVE-2024-13160", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "851ea01f-e7e3-435d-b0f5-8cea93e68050", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-10T00:00:00+00:00"}, "scope": {"notes": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote... | Affected: Ivanti / Endpoint Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.91247 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-13160", "url": "https://www.cve.org/CVERecord?id=CVE-2024-13160"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-13160"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...", "cve_id": "CVE-2024-13160", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager", "added_date": "2025-03-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91247, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99808, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-13160", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d905d530-e12f-4855-a9ec-887c4266704a", "vulnerability": {"vulnId": "CVE-2025-22225", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-04T01:00:00+01:00"}, "gcve": {"object_uuid": "d905d530-e12f-4855-a9ec-887c4266704a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-04T00:00:00+00:00"}, "scope": {"notes": "VMware ESXi contains an arbitrary write\u00a0vulnerability.\u00a0A malicious actor with privileges within the VMX process may trigger an arbitrary kernel... | Affected: VMware / VMware ESXi, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | CVSS: 8.2 (HIGH) | EPSS: 0.01016 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-22225", "url": "https://www.cve.org/CVERecord?id=CVE-2025-22225"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-22225"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware ESXi contains an arbitrary write\u00a0vulnerability.\u00a0A malicious actor with privileges within the VMX process may trigger an arbitrary kernel...", "cve_id": "CVE-2025-22225", "vendor": "VMware", "ghsa_id": null, "product": "VMware ESXi, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure", "added_date": "2025-03-04T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.01016, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61994, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-22225", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "89cbad39-267b-47a5-ba48-72bae6a46245", "vulnerability": {"vulnId": "CVE-2025-22224", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-04T01:00:00+01:00"}, "gcve": {"object_uuid": "89cbad39-267b-47a5-ba48-72bae6a46245", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-04T00:00:00+00:00"}, "scope": {"notes": "VMware ESXi, and Workstation\u00a0contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write.\u00a0A malicious... | Affected: VMware / ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure | CVSS: 9.3 (CRITICAL) | EPSS: 0.01561 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-22224", "url": "https://www.cve.org/CVERecord?id=CVE-2025-22224"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-22224"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware ESXi, and Workstation\u00a0contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write.\u00a0A malicious...", "cve_id": "CVE-2025-22224", "vendor": "VMware", "ghsa_id": null, "product": "ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure", "added_date": "2025-03-04T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.01561, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74331, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-22224", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7f268df4-9721-4b7e-ae29-31179cb27ac0", "vulnerability": {"vulnId": "CVE-2024-50302", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-04T01:00:00+01:00"}, "gcve": {"object_uuid": "7f268df4-9721-4b7e-ae29-31179cb27ac0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-04T00:00:00+00:00"}, "scope": {"notes": "HID: core: zero-initialize the report buffer | Affected: Linux / Linux | CVSS: 5.5 (MEDIUM) | EPSS: 0.00811 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-50302", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50302"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50302"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HID: core: zero-initialize the report buffer", "cve_id": "CVE-2024-50302", "vendor": "Linux", "ghsa_id": null, "product": "Linux", "added_date": "2025-03-04T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.00811, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55368, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-50302", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "403c325b-b7f9-4bc2-917e-dd2f8aa2a6e7", "vulnerability": {"vulnId": "CVE-2025-22226", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-04T01:00:00+01:00"}, "gcve": {"object_uuid": "403c325b-b7f9-4bc2-917e-dd2f8aa2a6e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-04T00:00:00+00:00"}, "scope": {"notes": "VMware ESXi, Workstation, and Fusion contain\u00a0an information disclosure vulnerability due to an out-of-bounds read in HGFS.\u00a0A malicious... | Affected: VMware / ESXi, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | CVSS: 7.1 (HIGH) | EPSS: 0.01769 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-22226", "url": "https://www.cve.org/CVERecord?id=CVE-2025-22226"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-22226"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware ESXi, Workstation, and Fusion contain\u00a0an information disclosure vulnerability due to an out-of-bounds read in HGFS.\u00a0A malicious...", "cve_id": "CVE-2025-22226", "vendor": "VMware", "ghsa_id": null, "product": "ESXi, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure", "added_date": "2025-03-04T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.01769, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-22226", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "42638b70-8d4e-4c3a-a87e-61b09bbdc027", "vulnerability": {"vulnId": "CVE-2023-20118", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "42638b70-8d4e-4c3a-a87e-61b09bbdc027", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could... | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 6.5 (MEDIUM) | EPSS: 0.54107 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20118", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20118"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20118"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could...", "cve_id": "CVE-2023-20118", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2025-03-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.54107, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20118", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0da7bef8-d0c3-4260-9894-1949c7dd521c", "vulnerability": {"vulnId": "CVE-2024-4885", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0da7bef8-d0c3-4260-9894-1949c7dd521c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-03T00:00:00+00:00"}, "scope": {"notes": "WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability | Affected: Progress Software / WhatsUp Gold | CVSS: 9.8 (CRITICAL) | EPSS: 0.99288 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4885", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4885"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4885"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability", "cve_id": "CVE-2024-4885", "vendor": "Progress Software", "ghsa_id": null, "product": "WhatsUp Gold", "added_date": "2025-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99288, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99937, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4885", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a847c337-4986-4f0a-a00b-5d32f7d82c2b", "vulnerability": {"vulnId": "CVE-2022-43939", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a847c337-4986-4f0a-a00b-5d32f7d82c2b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-03T00:00:00+00:00"}, "scope": {"notes": "Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions | Affected: Hitachi Vantara / Pentaho Business Analytics Server | CVSS: 8.6 (HIGH) | EPSS: 0.92266 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-43939", "url": "https://www.cve.org/CVERecord?id=CVE-2022-43939"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-43939"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions", "cve_id": "CVE-2022-43939", "vendor": "Hitachi Vantara", "ghsa_id": null, "product": "Pentaho Business Analytics Server", "added_date": "2025-03-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.92266, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-43939", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "afd357fb-6270-4693-a74d-ee56a3e22d52", "vulnerability": {"vulnId": "CVE-2018-8639", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "afd357fb-6270-4693-a74d-ee56a3e22d52", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k... | Affected: Microsoft / Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | CVSS: 7.8 (HIGH) | EPSS: 0.22179 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8639", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8639"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8639"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k...", "cve_id": "CVE-2018-8639", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers", "added_date": "2025-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.22179, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97608, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8639", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "581b7f4c-e4f8-4636-8c1b-bc2a29297fba", "vulnerability": {"vulnId": "CVE-2022-43769", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "581b7f4c-e4f8-4636-8c1b-bc2a29297fba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-03-03T00:00:00+00:00"}, "scope": {"notes": "Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) | Affected: Hitachi Vantara / Pentaho Business Analytics Server | CVSS: 8.8 (HIGH) | EPSS: 0.9767 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-43769", "url": "https://www.cve.org/CVERecord?id=CVE-2022-43769"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-43769"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)", "cve_id": "CVE-2022-43769", "vendor": "Hitachi Vantara", "ghsa_id": null, "product": "Pentaho Business Analytics Server", "added_date": "2025-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.9767, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99903, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-43769", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "382d2799-4c2b-48a2-a49c-265ccecf69de", "vulnerability": {"vulnId": "CVE-2023-34192", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-25T01:00:00+01:00"}, "gcve": {"object_uuid": "382d2799-4c2b-48a2-a49c-265ccecf69de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-25T00:00:00+00:00"}, "scope": {"notes": "Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to... | Affected: Zimbra / Zimbra Collaboration Suite | CVSS: 9.0 (CRITICAL) | EPSS: 0.77266 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-34192", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34192"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34192"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to...", "cve_id": "CVE-2023-34192", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration Suite", "added_date": "2025-02-25T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.77266, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99543, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34192", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "04e359bf-00bc-4624-a311-e3f41e4b4f3d", "vulnerability": {"vulnId": "CVE-2024-49035", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-25T01:00:00+01:00"}, "gcve": {"object_uuid": "04e359bf-00bc-4624-a311-e3f41e4b4f3d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-25T00:00:00+00:00"}, "scope": {"notes": "Partner.Microsoft.Com Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Partner Center | CVSS: 8.7 (HIGH) | EPSS: 0.013 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-49035", "url": "https://www.cve.org/CVERecord?id=CVE-2024-49035"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-49035"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Partner.Microsoft.Com Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-49035", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Partner Center", "added_date": "2025-02-25T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.013, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69403, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-49035", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "721bd079-49e4-4eb7-9e8e-79c6e126420c", "vulnerability": {"vulnId": "CVE-2024-20953", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-24T01:00:00+01:00"}, "gcve": {"object_uuid": "721bd079-49e4-4eb7-9e8e-79c6e126420c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-24T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export).   The supported version that is affected is 9.3.6. Easily... | Affected: Oracle / Agile PLM Framework | CVSS: 8.8 (HIGH) | EPSS: 0.03934 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20953", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20953"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20953"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export).   The supported version that is affected is 9.3.6. Easily...", "cve_id": "CVE-2024-20953", "vendor": "Oracle", "ghsa_id": null, "product": "Agile PLM Framework", "added_date": "2025-02-24T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03934, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90048, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20953", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "16897f84-82a5-4475-b94d-d020fff59df0", "vulnerability": {"vulnId": "CVE-2017-3066", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-24T01:00:00+01:00"}, "gcve": {"object_uuid": "16897f84-82a5-4475-b94d-d020fff59df0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-24T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization... | Affected: Adobe / Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier | CVSS: 9.8 (CRITICAL) | EPSS: 0.90597 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-3066", "url": "https://www.cve.org/CVERecord?id=CVE-2017-3066"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-3066"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization...", "cve_id": "CVE-2017-3066", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe ColdFusion ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier", "added_date": "2025-02-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90597, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99801, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-3066", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a711a621-9c32-4767-89f8-50b85a93b1b3", "vulnerability": {"vulnId": "CVE-2025-24989", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-21T01:00:00+01:00"}, "gcve": {"object_uuid": "a711a621-9c32-4767-89f8-50b85a93b1b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-21T00:00:00+00:00"}, "scope": {"notes": "Microsoft Power Pages Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Power Pages | CVSS: 8.2 (HIGH) | EPSS: 0.01622 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24989", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24989"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24989"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Power Pages Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-24989", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Power Pages", "added_date": "2025-02-21T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.01622, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75222, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24989", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b6f56c8d-66f8-4ae1-b8ce-91bcb18db558", "vulnerability": {"vulnId": "CVE-2025-23209", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-20T01:00:00+01:00"}, "gcve": {"object_uuid": "b6f56c8d-66f8-4ae1-b8ce-91bcb18db558", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-20T00:00:00+00:00"}, "scope": {"notes": "Potential RCE with a compromised security key in craft/cms | Affected: Craftcms / cms | CVSS: 8.1 (HIGH) | EPSS: 0.21776 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-23209", "url": "https://www.cve.org/CVERecord?id=CVE-2025-23209"}, {"id": "GHSA-X684-96HH-833X", "url": "https://github.com/advisories/GHSA-X684-96HH-833X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-23209"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Potential RCE with a compromised security key in craft/cms", "cve_id": "CVE-2025-23209", "vendor": "Craftcms", "ghsa_id": "GHSA-X684-96HH-833X", "product": "cms", "added_date": "2025-02-20T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.21776, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97573, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-23209", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "28b85536-34ac-4919-b3b2-0691c2b98369", "vulnerability": {"vulnId": "CVE-2025-0111", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-20T01:00:00+01:00"}, "gcve": {"object_uuid": "28b85536-34ac-4919-b3b2-0691c2b98369", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-20T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 7.1 (HIGH) | EPSS: 0.01999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-0111", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0111"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0111"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface", "cve_id": "CVE-2025-0111", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2025-02-20T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.01999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0111", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aad29b7b-3e0e-4173-a279-900bfc0b6686", "vulnerability": {"vulnId": "CVE-2025-0108", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-18T01:00:00+01:00"}, "gcve": {"object_uuid": "aad29b7b-3e0e-4173-a279-900bfc0b6686", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-18T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Authentication Bypass in the Management Web Interface | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 8.8 (HIGH) | EPSS: 0.98455 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-0108", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0108"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0108"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Authentication Bypass in the Management Web Interface", "cve_id": "CVE-2025-0108", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2025-02-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.98455, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99918, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0108", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "14de1a6e-b9e8-43dd-8186-149a450b6eb6", "vulnerability": {"vulnId": "CVE-2024-53704", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-18T01:00:00+01:00"}, "gcve": {"object_uuid": "14de1a6e-b9e8-43dd-8186-149a450b6eb6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-18T00:00:00+00:00"}, "scope": {"notes": "An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | Affected: SonicWall / SonicOS | CVSS: 8.2 (HIGH) | EPSS: 0.95132 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-53704", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53704"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53704"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.", "cve_id": "CVE-2024-53704", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicOS", "added_date": "2025-02-18T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.95132, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99863, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-53704", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d4036203-a09e-42f7-98b7-d6c4de640c3a", "vulnerability": {"vulnId": "CVE-2025-1338", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-16T12:00:20+01:00"}, "gcve": {"object_uuid": "d4036203-a09e-42f7-98b7-d6c4de640c3a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-16T11:00:20+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-16T11:00:20+00:00"}, "scope": {"notes": "NUUO Camera handle_config.php print_file command injection | Affected: NUUO / Camera | CVSS: 6.9 (MEDIUM) | EPSS: 0.51116 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2025-1338", "url": "https://www.cve.org/CVERecord?id=CVE-2025-1338"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-1338"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NUUO Camera handle_config.php print_file command injection", "cve_id": "CVE-2025-1338", "vendor": "NUUO", "ghsa_id": null, "product": "Camera", "added_date": "2025-02-16T11:00:20.000Z", "cvss_score": 6.9, "epss_score": 0.51116, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98901, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-1338", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "88ec8db9-9dfc-4a34-9fa5-18a8ab014fc5", "vulnerability": {"vulnId": "CVE-2024-57727", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-13T01:00:00+01:00"}, "gcve": {"object_uuid": "88ec8db9-9dfc-4a34-9fa5-18a8ab014fc5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-13T00:00:00+00:00"}, "scope": {"notes": "SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote... | Affected: SimpleHelp / SimpleHelp | CVSS: 9.1 (CRITICAL) | EPSS: 0.96576 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-57727", "url": "https://www.cve.org/CVERecord?id=CVE-2024-57727"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-57727"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote...", "cve_id": "CVE-2024-57727", "vendor": "SimpleHelp", "ghsa_id": null, "product": "SimpleHelp", "added_date": "2025-02-13T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.96576, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99882, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-57727", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "22c4ab01-bff5-4bd4-9342-78013bcdb711", "vulnerability": {"vulnId": "CVE-2024-41710", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-12T01:00:00+01:00"}, "gcve": {"object_uuid": "22c4ab01-bff5-4bd4-9342-78013bcdb711", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-12T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1... | Affected: Mitel / 6800 Series, 6900 Series, 6900w Series SIP Phones, including the 6970 Conference Unit | CVSS: 7.2 (HIGH) | EPSS: 0.41646 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-41710", "url": "https://www.cve.org/CVERecord?id=CVE-2024-41710"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-41710"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1...", "cve_id": "CVE-2024-41710", "vendor": "Mitel", "ghsa_id": null, "product": "6800 Series, 6900 Series, 6900w Series SIP Phones, including the 6970 Conference Unit", "added_date": "2025-02-12T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.41646, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98643, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-41710", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f29d2e99-435e-4823-9893-c0d6238a94d0", "vulnerability": {"vulnId": "CVE-2025-24200", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-12T01:00:00+01:00"}, "gcve": {"object_uuid": "f29d2e99-435e-4823-9893-c0d6238a94d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-12T00:00:00+00:00"}, "scope": {"notes": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS... | Affected: Apple / iOS and iPadOS, iPadOS | CVSS: 6.1 (MEDIUM) | EPSS: 0.04457 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24200", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24200"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24200"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS...", "cve_id": "CVE-2025-24200", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, iPadOS", "added_date": "2025-02-12T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.04457, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91123, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24200", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1e205f5a-eaf1-4ef0-9b49-1f7cc1f5de0a", "vulnerability": {"vulnId": "CVE-2025-21391", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "1e205f5a-eaf1-4ef0-9b49-1f7cc1f5de0a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-11T00:00:00+00:00"}, "scope": {"notes": "Windows Storage Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.1 (HIGH) | EPSS: 0.02303 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21391", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21391"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21391"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Storage Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-21391", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-02-11T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.02303, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82703, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21391", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "609633db-1700-4696-bde0-3c8add73296a", "vulnerability": {"vulnId": "CVE-2024-40890", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "609633db-1700-4696-bde0-3c8add73296a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-11T00:00:00+00:00"}, "scope": {"notes": "**UNSUPPORTED WHEN ASSIGNED**\nA post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A... | Affected: Zyxel / VMG4325-B10A firmware | CVSS: 8.8 (HIGH) | EPSS: 0.20703 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-40890", "url": "https://www.cve.org/CVERecord?id=CVE-2024-40890"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-40890"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "**UNSUPPORTED WHEN ASSIGNED**\nA post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A...", "cve_id": "CVE-2024-40890", "vendor": "Zyxel", "ghsa_id": null, "product": "VMG4325-B10A firmware", "added_date": "2025-02-11T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.20703, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97465, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-40890", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ab86cd71-a03b-4636-909c-e80c55504f43", "vulnerability": {"vulnId": "CVE-2024-40891", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "ab86cd71-a03b-4636-909c-e80c55504f43", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-11T00:00:00+00:00"}, "scope": {"notes": "**UNSUPPORTED WHEN ASSIGNED**\nA post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel... | Affected: Zyxel / VMG4325-B10A firmware | CVSS: 8.8 (HIGH) | EPSS: 0.21536 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-40891", "url": "https://www.cve.org/CVERecord?id=CVE-2024-40891"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-40891"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "**UNSUPPORTED WHEN ASSIGNED**\nA post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel...", "cve_id": "CVE-2024-40891", "vendor": "Zyxel", "ghsa_id": null, "product": "VMG4325-B10A firmware", "added_date": "2025-02-11T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.21536, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97553, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-40891", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f919778-c3a7-47a5-8655-7f1636eca2f5", "vulnerability": {"vulnId": "CVE-2025-21418", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "6f919778-c3a7-47a5-8655-7f1636eca2f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-11T00:00:00+00:00"}, "scope": {"notes": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01568 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21418", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21418"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21418"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-21418", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-02-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01568, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74432, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21418", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bf3ccc12-27fc-40f6-8f95-c9d6c2c3d34c", "vulnerability": {"vulnId": "CVE-2025-0994", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-07T01:00:00+01:00"}, "gcve": {"object_uuid": "bf3ccc12-27fc-40f6-8f95-c9d6c2c3d34c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-07T00:00:00+00:00"}, "scope": {"notes": "Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization... | Affected: Trimble / Cityworks, Cityworks (with office companion) | CVSS: 8.6 (HIGH) | EPSS: 0.31309 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-0994", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0994"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0994"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization...", "cve_id": "CVE-2025-0994", "vendor": "Trimble", "ghsa_id": null, "product": "Cityworks, Cityworks (with office companion)", "added_date": "2025-02-07T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.31309, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98227, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0994", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c0e2c30-c0ee-4a3a-817f-d993f8adc103", "vulnerability": {"vulnId": "CVE-2020-15069", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "4c0e2c30-c0ee-4a3a-817f-d993f8adc103", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-06T00:00:00+00:00"}, "scope": {"notes": "Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless... | Affected: Sophos / XG Firewall | CVSS: 9.8 (CRITICAL) | EPSS: 0.10674 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-15069", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15069"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15069"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless...", "cve_id": "CVE-2020-15069", "vendor": "Sophos", "ghsa_id": null, "product": "XG Firewall", "added_date": "2025-02-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.10674, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95678, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15069", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "38a7ef89-e214-4e8c-9482-18dab68fa1cc", "vulnerability": {"vulnId": "CVE-2022-23748", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "38a7ef89-e214-4e8c-9482-18dab68fa1cc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-06T00:00:00+00:00"}, "scope": {"notes": "mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what... | Affected: Apple / Audinate Dante Application Library for Windows | CVSS: 7.8 (HIGH) | EPSS: 0.09092 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-23748", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23748"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23748"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what...", "cve_id": "CVE-2022-23748", "vendor": "Apple", "ghsa_id": null, "product": "Audinate Dante Application Library for Windows", "added_date": "2025-02-06T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09092, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95156, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23748", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7c20175e-60ba-4a8b-992f-78a92448a110", "vulnerability": {"vulnId": "CVE-2020-29574", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "7c20175e-60ba-4a8b-992f-78a92448a110", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-06T00:00:00+00:00"}, "scope": {"notes": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL... | Affected: Sophos / Cyberoam OS | CVSS: 9.8 (CRITICAL) | EPSS: 0.04658 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-29574", "url": "https://www.cve.org/CVERecord?id=CVE-2020-29574"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-29574"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL...", "cve_id": "CVE-2020-29574", "vendor": "Sophos", "ghsa_id": null, "product": "Cyberoam OS", "added_date": "2025-02-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04658, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9146, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-29574", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "be97e997-b35a-49e9-b614-8aaa8e0c0ae1", "vulnerability": {"vulnId": "CVE-2024-21413", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "be97e997-b35a-49e9-b614-8aaa8e0c0ae1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-06T00:00:00+00:00"}, "scope": {"notes": "Microsoft Outlook Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021 | CVSS: 9.8 (CRITICAL) | EPSS: 0.9466 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21413", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21413"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21413"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Outlook Remote Code Execution Vulnerability", "cve_id": "CVE-2024-21413", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office LTSC 2021", "added_date": "2025-02-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9466, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99855, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21413", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f459059f-b8d7-4911-9a7b-f7f38a81c2ff", "vulnerability": {"vulnId": "CVE-2025-0411", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "f459059f-b8d7-4911-9a7b-f7f38a81c2ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-06T00:00:00+00:00"}, "scope": {"notes": "7-Zip Mark-of-the-Web Bypass Vulnerability | Affected: 7-Zip / 7-Zip | CVSS: 7.0 (HIGH) | EPSS: 0.67071 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-0411", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0411"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0411"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "7-Zip Mark-of-the-Web Bypass Vulnerability", "cve_id": "CVE-2025-0411", "vendor": "7-Zip", "ghsa_id": null, "product": "7-Zip", "added_date": "2025-02-06T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.67071, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9928, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-0411", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d44d506-ff73-47ff-928b-497bdfca96d3", "vulnerability": {"vulnId": "CVE-2024-53104", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-05T01:00:00+01:00"}, "gcve": {"object_uuid": "6d44d506-ff73-47ff-928b-497bdfca96d3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-05T00:00:00+00:00"}, "scope": {"notes": "media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.03395 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-53104", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53104"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53104"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format", "cve_id": "CVE-2024-53104", "vendor": "Linux", "ghsa_id": null, "product": "Linux", "added_date": "2025-02-05T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03395, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88426, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-53104", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c1fd8fe-7f56-47db-9172-f22be663c1c7", "vulnerability": {"vulnId": "CVE-2024-29059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "4c1fd8fe-7f56-47db-9172-f22be663c1c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-04T00:00:00+00:00"}, "scope": {"notes": ".NET Framework Information Disclosure Vulnerability | Affected: Microsoft / Microsoft .NET Framework 4.8, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft .NET Framework 4.6.2, Microsoft .NET Framework 3.5 AND 4.6/4.6.2, Microsoft .NET Framework 2.0 Service Pack 2, Microsoft .NET Framework 3.0 Service Pack 2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1 | CVSS: 7.5 (HIGH) | EPSS: 0.98624 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-29059", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29059"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": ".NET Framework Information Disclosure Vulnerability", "cve_id": "CVE-2024-29059", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft .NET Framework 4.8, Microsoft .NET Framework 3.5 AND 4.8, Microsoft .NET Framework 3.5 AND 4.7.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5 AND 4.8.1, Microsoft .NET Framework 4.6.2, Microsoft .NET Framework 3.5 AND 4.6/4.6.2, Microsoft .NET Framework 2.0 Service Pack 2, Microsoft .NET Framework 3.0 Service Pack 2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1", "added_date": "2025-02-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.98624, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99922, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76f09f91-0084-4f4b-bc27-fa6782f67178", "vulnerability": {"vulnId": "CVE-2018-9276", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "76f09f91-0084-4f4b-bc27-fa6782f67178", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-04T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with... | Affected: Paessler / PRTG Network Monitor | CVSS: 7.2 (HIGH) | EPSS: 0.86996 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-9276", "url": "https://www.cve.org/CVERecord?id=CVE-2018-9276"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-9276"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with...", "cve_id": "CVE-2018-9276", "vendor": "Paessler", "ghsa_id": null, "product": "PRTG Network Monitor", "added_date": "2025-02-04T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.86996, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99744, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-9276", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76f433fd-796a-4239-abd8-9a194b2bd6ea", "vulnerability": {"vulnId": "CVE-2024-45195", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "76f433fd-796a-4239-abd8-9a194b2bd6ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-04T00:00:00+00:00"}, "scope": {"notes": "Apache OFBiz: Confused controller-view authorization logic (forced browsing) | Affected: Apache / Apache OFBiz | CVSS: 7.5 (HIGH) | EPSS: 0.99983 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-45195", "url": "https://www.cve.org/CVERecord?id=CVE-2024-45195"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-45195"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache OFBiz: Confused controller-view authorization logic (forced browsing)", "cve_id": "CVE-2024-45195", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2025-02-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99983, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-45195", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "655ea3f5-1190-408a-a7ef-d4026d7787f7", "vulnerability": {"vulnId": "CVE-2018-19410", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "655ea3f5-1190-408a-a7ef-d4026d7787f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-02-04T00:00:00+00:00"}, "scope": {"notes": "PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including... | Affected: Paessler / PRTG Network Monitor | CVSS: 9.8 (CRITICAL) | EPSS: 0.97939 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19410", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19410"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19410"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including...", "cve_id": "CVE-2018-19410", "vendor": "Paessler", "ghsa_id": null, "product": "PRTG Network Monitor", "added_date": "2025-02-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97939, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99909, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-19410", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4e59f4f7-bd56-4cd8-a8f3-a8a65c7f5c71", "vulnerability": {"vulnId": "CVE-2025-24085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-29T01:00:00+01:00"}, "gcve": {"object_uuid": "4e59f4f7-bd56-4cd8-a8f3-a8a65c7f5c71", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-29T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia... | Affected: Apple / iOS and iPadOS, iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 10.0 (CRITICAL) | EPSS: 0.1751 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-24085", "url": "https://www.cve.org/CVERecord?id=CVE-2025-24085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-24085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia...", "cve_id": "CVE-2025-24085", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2025-01-29T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.1751, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9705, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-24085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bb488e87-c20f-40f4-9836-1c2c5949d8e7", "vulnerability": {"vulnId": "CVE-2025-23006", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-24T01:00:00+01:00"}, "gcve": {"object_uuid": "bb488e87-c20f-40f4-9836-1c2c5949d8e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-24T00:00:00+00:00"}, "scope": {"notes": "Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and... | Affected: SonicWall / SMA1000 | CVSS: 9.8 (CRITICAL) | EPSS: 0.23432 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-23006", "url": "https://www.cve.org/CVERecord?id=CVE-2025-23006"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-23006"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and...", "cve_id": "CVE-2025-23006", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA1000", "added_date": "2025-01-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.23432, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97727, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-23006", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6cd5fca3-7190-4530-9cce-6995e4e46a61", "vulnerability": {"vulnId": "CVE-2020-11023", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-23T01:00:00+01:00"}, "gcve": {"object_uuid": "6cd5fca3-7190-4530-9cce-6995e4e46a61", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-23T00:00:00+00:00"}, "scope": {"notes": "Potential XSS vulnerability in jQuery | Affected: Jquery / jQuery | CVSS: 6.9 (MEDIUM) | EPSS: 0.84887 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11023", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11023"}, {"id": "GHSA-JPCQ-CGW6-V4J6", "url": "https://github.com/advisories/GHSA-JPCQ-CGW6-V4J6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11023"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Potential XSS vulnerability in jQuery", "cve_id": "CVE-2020-11023", "vendor": "Jquery", "ghsa_id": "GHSA-JPCQ-CGW6-V4J6", "product": "jQuery", "added_date": "2025-01-23T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.84887, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99705, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11023", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6039f80-d4b5-4b12-9faa-4189f5f1c637", "vulnerability": {"vulnId": "CVE-2024-50603", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-16T01:00:00+01:00"}, "gcve": {"object_uuid": "a6039f80-d4b5-4b12-9faa-4189f5f1c637", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-16T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements... | Affected: Aviatrix / Controller | CVSS: 10.0 (CRITICAL) | EPSS: 0.98545 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-50603", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50603"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50603"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements...", "cve_id": "CVE-2024-50603", "vendor": "Aviatrix", "ghsa_id": null, "product": "Controller", "added_date": "2025-01-16T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.98545, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99921, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-50603", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d89f5378-a687-4d9f-a92f-a8b56e9a4101", "vulnerability": {"vulnId": "CVE-2024-55591", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-14T01:00:00+01:00"}, "gcve": {"object_uuid": "d89f5378-a687-4d9f-a92f-a8b56e9a4101", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-14T00:00:00+00:00"}, "scope": {"notes": "An\u00a0Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy... | Affected: Fortinet / FortiOS, FortiProxy | CVSS: 9.6 (CRITICAL) | EPSS: 0.94149 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-55591", "url": "https://www.cve.org/CVERecord?id=CVE-2024-55591"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-55591"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An\u00a0Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy...", "cve_id": "CVE-2024-55591", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiOS, FortiProxy", "added_date": "2025-01-14T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.94149, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99847, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-55591", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "edebfaee-c43a-4d7d-bc32-3851c8b2b819", "vulnerability": {"vulnId": "CVE-2025-21334", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-14T01:00:00+01:00"}, "gcve": {"object_uuid": "edebfaee-c43a-4d7d-bc32-3851c8b2b819", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-14T00:00:00+00:00"}, "scope": {"notes": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01561 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21334", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21334"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21334"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-21334", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-01-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01561, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74333, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21334", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "966dc27a-2c01-4aa5-8306-000b882d5a26", "vulnerability": {"vulnId": "CVE-2025-21335", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-14T01:00:00+01:00"}, "gcve": {"object_uuid": "966dc27a-2c01-4aa5-8306-000b882d5a26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-14T00:00:00+00:00"}, "scope": {"notes": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.0139 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21335", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21335"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21335"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-21335", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-01-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.0139, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21335", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0fd4e29-c898-45a1-943c-f086f9518941", "vulnerability": {"vulnId": "CVE-2025-21333", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-14T01:00:00+01:00"}, "gcve": {"object_uuid": "b0fd4e29-c898-45a1-943c-f086f9518941", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-14T00:00:00+00:00"}, "scope": {"notes": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.09988 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-21333", "url": "https://www.cve.org/CVERecord?id=CVE-2025-21333"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-21333"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability", "cve_id": "CVE-2025-21333", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2025-01-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09988, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9547, "used_in_malware": "unknown", "vulnerability_id": "CVE-2025-21333", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "153ea0b8-7d8b-412c-9eaa-fa8620cf9c4e", "vulnerability": {"vulnId": "CVE-2023-48365", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-13T01:00:00+01:00"}, "gcve": {"object_uuid": "153ea0b8-7d8b-412c-9eaa-fa8620cf9c4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-13T00:00:00+00:00"}, "scope": {"notes": "Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation... | Affected: Qlik / Sense Enterprise for Windows | CVSS: 9.6 (CRITICAL) | EPSS: 0.47453 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-48365", "url": "https://www.cve.org/CVERecord?id=CVE-2023-48365"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-48365"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation...", "cve_id": "CVE-2023-48365", "vendor": "Qlik", "ghsa_id": null, "product": "Sense Enterprise for Windows", "added_date": "2025-01-13T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.47453, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98808, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-48365", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "09ac9c9f-6644-47b1-977f-48dc3a9bb966", "vulnerability": {"vulnId": "CVE-2024-12686", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-13T01:00:00+01:00"}, "gcve": {"object_uuid": "09ac9c9f-6644-47b1-977f-48dc3a9bb966", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-13T00:00:00+00:00"}, "scope": {"notes": "Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA) | Affected: BeyondTrust / Remote Support(RS) & Privileged Remote Access(PRA) | CVSS: 6.6 (MEDIUM) | EPSS: 0.137 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-12686", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12686"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12686"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection vulnerability in Remote Support(RS) & Privilege Remote Access (PRA)", "cve_id": "CVE-2024-12686", "vendor": "BeyondTrust", "ghsa_id": null, "product": "Remote Support(RS) & Privileged Remote Access(PRA)", "added_date": "2025-01-13T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.137, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96383, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12686", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "41363cd9-af76-4b9f-bb50-b6e670095190", "vulnerability": {"vulnId": "CVE-2025-0282", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "41363cd9-af76-4b9f-bb50-b6e670095190", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-08T00:00:00+00:00"}, "scope": {"notes": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons... | Affected: Ivanti / Connect Secure, Policy Secure, Neurons for ZTA gateways | CVSS: 9.0 (CRITICAL) | EPSS: 0.99979 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2025-0282", "url": "https://www.cve.org/CVERecord?id=CVE-2025-0282"}, {"id": "previdian", "url": "https://previdian.com/CVE-2025-0282"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons...", "cve_id": "CVE-2025-0282", "vendor": "Ivanti", "ghsa_id": null, "product": "Connect Secure, Policy Secure, Neurons for ZTA gateways", "added_date": "2025-01-08T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.99979, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9998, "used_in_malware": "yes", "vulnerability_id": "CVE-2025-0282", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "172579d6-dfc0-43a1-9815-16b06101323b", "vulnerability": {"vulnId": "CVE-2024-41713", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-07T01:00:00+01:00"}, "gcve": {"object_uuid": "172579d6-dfc0-43a1-9815-16b06101323b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-07T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated... | Affected: Mitel / MiCollab | CVSS: 9.1 (CRITICAL) | EPSS: 0.9811 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-41713", "url": "https://www.cve.org/CVERecord?id=CVE-2024-41713"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-41713"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated...", "cve_id": "CVE-2024-41713", "vendor": "Mitel", "ghsa_id": null, "product": "MiCollab", "added_date": "2025-01-07T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.9811, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99911, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-41713", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b7e6cdcf-b765-44fd-adad-b43227807db1", "vulnerability": {"vulnId": "CVE-2020-2883", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-07T01:00:00+01:00"}, "gcve": {"object_uuid": "b7e6cdcf-b765-44fd-adad-b43227807db1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-07T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.94928 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-2883", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2883"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2883"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...", "cve_id": "CVE-2020-2883", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2025-01-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94928, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9986, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-2883", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7cfef1a9-673e-4720-a913-6fd94b1bb468", "vulnerability": {"vulnId": "CVE-2024-55550", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-07T01:00:00+01:00"}, "gcve": {"object_uuid": "7cfef1a9-673e-4720-a913-6fd94b1bb468", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-07T00:00:00+00:00"}, "scope": {"notes": "Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to... | Affected: Mitel / MiCollab | CVSS: 4.4 (MEDIUM) | EPSS: 0.38155 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-55550", "url": "https://www.cve.org/CVERecord?id=CVE-2024-55550"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-55550"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to...", "cve_id": "CVE-2024-55550", "vendor": "Mitel", "ghsa_id": null, "product": "MiCollab", "added_date": "2025-01-07T00:00:00.000Z", "cvss_score": 4.4, "epss_score": 0.38155, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98517, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-55550", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a748186b-e8de-495e-8b33-5926c0766975", "vulnerability": {"vulnId": "CVE-2024-54764", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2025-01-06T01:00:00+01:00"}, "gcve": {"object_uuid": "a748186b-e8de-495e-8b33-5926c0766975", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2025-01-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2025-01-06T00:00:00+00:00"}, "scope": {"notes": "An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without... | Affected: ipTIME / A2004 | CVSS: 6.5 (MEDIUM) | EPSS: 0.01035 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-54764", "url": "https://www.cve.org/CVERecord?id=CVE-2024-54764"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-54764"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without...", "cve_id": "CVE-2024-54764", "vendor": "ipTIME", "ghsa_id": null, "product": "A2004", "added_date": "2025-01-06T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.01035, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62574, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-54764", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0233319b-24bf-4063-a969-fbb7c5959c75", "vulnerability": {"vulnId": "CVE-2024-3393", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-30T01:00:00+01:00"}, "gcve": {"object_uuid": "0233319b-24bf-4063-a969-fbb7c5959c75", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-30T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS | CVSS: 8.7 (HIGH) | EPSS: 0.28617 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-3393", "url": "https://www.cve.org/CVERecord?id=CVE-2024-3393"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-3393"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet", "cve_id": "CVE-2024-3393", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS", "added_date": "2024-12-30T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.28617, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-3393", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f90e1ac1-cc1f-4171-b375-4013edbb9a24", "vulnerability": {"vulnId": "CVE-2021-44207", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-23T01:00:00+01:00"}, "gcve": {"object_uuid": "f90e1ac1-cc1f-4171-b375-4013edbb9a24", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-23T00:00:00+00:00"}, "scope": {"notes": "Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. | Affected: Acclaim Systems / USAHERDS | CVSS: 8.1 (HIGH) | EPSS: 0.17578 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44207", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44207"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44207"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.", "cve_id": "CVE-2021-44207", "vendor": "Acclaim Systems", "ghsa_id": null, "product": "USAHERDS", "added_date": "2024-12-23T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.17578, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97057, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44207", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d42ba55a-59a1-4211-b755-32ebaf2b78e8", "vulnerability": {"vulnId": "CVE-2024-12356", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-19T01:00:00+01:00"}, "gcve": {"object_uuid": "d42ba55a-59a1-4211-b755-32ebaf2b78e8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-19T00:00:00+00:00"}, "scope": {"notes": "Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA) | Affected: BeyondTrust / Remote Support, Privileged Remote Access | CVSS: 9.8 (CRITICAL) | EPSS: 0.87258 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-12356", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12356"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12356"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)", "cve_id": "CVE-2024-12356", "vendor": "BeyondTrust", "ghsa_id": null, "product": "Remote Support, Privileged Remote Access", "added_date": "2024-12-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.87258, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99748, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12356", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9dc52646-9029-48d7-ac60-f6c665e65e4e", "vulnerability": {"vulnId": "CVE-2021-40407", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-18T01:00:00+01:00"}, "gcve": {"object_uuid": "9dc52646-9029-48d7-ac60-f6c665e65e4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-18T00:00:00+00:00"}, "scope": {"notes": "An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2],... | Affected: Reolink / RLC-410W | CVSS: 9.1 (CRITICAL) | EPSS: 0.47635 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40407", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40407"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40407"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2],...", "cve_id": "CVE-2021-40407", "vendor": "Reolink", "ghsa_id": null, "product": "RLC-410W", "added_date": "2024-12-18T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.47635, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98812, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40407", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ae6c270f-c77b-4f37-9acc-ac8ffb107b99", "vulnerability": {"vulnId": "CVE-2018-14933", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-18T01:00:00+01:00"}, "gcve": {"object_uuid": "ae6c270f-c77b-4f37-9acc-ac8ffb107b99", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-18T00:00:00+00:00"}, "scope": {"notes": "upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir... | Affected: NUUO / NVRmini | CVSS: 9.8 (CRITICAL) | EPSS: 0.94884 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-14933", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14933"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14933"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir...", "cve_id": "CVE-2018-14933", "vendor": "NUUO", "ghsa_id": null, "product": "NVRmini", "added_date": "2024-12-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94884, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99859, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14933", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f9cbae88-27d1-4192-a9b2-f9006e3444bc", "vulnerability": {"vulnId": "CVE-2019-11001", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-18T01:00:00+01:00"}, "gcve": {"object_uuid": "f9cbae88-27d1-4192-a9b2-f9006e3444bc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-18T00:00:00+00:00"}, "scope": {"notes": "On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the \"TestEmail\" functionality... | Affected: Reolink / RLC-410W, C1 Pro, C2 Pro, RLC-422W, RLC-511W | CVSS: 7.2 (HIGH) | EPSS: 0.37542 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11001", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11001"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11001"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the \"TestEmail\" functionality...", "cve_id": "CVE-2019-11001", "vendor": "Reolink", "ghsa_id": null, "product": "RLC-410W, C1 Pro, C2 Pro, RLC-422W, RLC-511W", "added_date": "2024-12-18T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.37542, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98492, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-11001", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9c235dd2-d965-4ac1-be94-df2e9dada75b", "vulnerability": {"vulnId": "CVE-2022-23227", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-18T01:00:00+01:00"}, "gcve": {"object_uuid": "9c235dd2-d965-4ac1-be94-df2e9dada75b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-18T00:00:00+00:00"}, "scope": {"notes": "NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users... | Affected: NUUO / NVRmini2 | CVSS: 9.8 (CRITICAL) | EPSS: 0.48497 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-23227", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23227"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23227"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users...", "cve_id": "CVE-2022-23227", "vendor": "NUUO", "ghsa_id": null, "product": "NVRmini2", "added_date": "2024-12-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.48497, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23227", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1e82518e-a15e-4a92-b4e1-7afb5616587b", "vulnerability": {"vulnId": "CVE-2024-55956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-17T01:00:00+01:00"}, "gcve": {"object_uuid": "1e82518e-a15e-4a92-b4e1-7afb5616587b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-17T00:00:00+00:00"}, "scope": {"notes": "In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary... | Affected: Cleo / [\"Harmony\", \"VLTrader\", \"LexiCom\"] | CVSS: 9.8 (CRITICAL) | EPSS: 0.93968 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-55956", "url": "https://www.cve.org/CVERecord?id=CVE-2024-55956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-55956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary...", "cve_id": "CVE-2024-55956", "vendor": "Cleo", "ghsa_id": null, "product": "[\"Harmony\", \"VLTrader\", \"LexiCom\"]", "added_date": "2024-12-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93968, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99844, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-55956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3668d350-6711-4e4a-83cc-23269c005f9d", "vulnerability": {"vulnId": "CVE-2024-35250", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-16T01:00:00+01:00"}, "gcve": {"object_uuid": "3668d350-6711-4e4a-83cc-23269c005f9d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-16T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.25222 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-35250", "url": "https://www.cve.org/CVERecord?id=CVE-2024-35250"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-35250"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-35250", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-12-16T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.25222, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97877, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-35250", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c61d982c-8616-497b-8f98-057ba80990e1", "vulnerability": {"vulnId": "CVE-2024-20767", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-16T01:00:00+01:00"}, "gcve": {"object_uuid": "c61d982c-8616-497b-8f98-057ba80990e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-16T00:00:00+00:00"}, "scope": {"notes": "ColdFusion | Improper Access Control (CWE-284) | Affected: Adobe / ColdFusion | CVSS: 7.4 (HIGH) | EPSS: 0.98514 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20767", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20767"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20767"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ColdFusion | Improper Access Control (CWE-284)", "cve_id": "CVE-2024-20767", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2024-12-16T00:00:00.000Z", "cvss_score": 7.4, "epss_score": 0.98514, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.9992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20767", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "722cace8-330f-473a-8969-907457b56259", "vulnerability": {"vulnId": "CVE-2024-50623", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-13T01:00:00+01:00"}, "gcve": {"object_uuid": "722cace8-330f-473a-8969-907457b56259", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-13T00:00:00+00:00"}, "scope": {"notes": "In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that... | Affected: Cleo / [\"Harmony\", \"VLTrader\", \"LexiCom\"] | CVSS: 9.8 (CRITICAL) | EPSS: 0.98607 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-50623", "url": "https://www.cve.org/CVERecord?id=CVE-2024-50623"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-50623"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that...", "cve_id": "CVE-2024-50623", "vendor": "Cleo", "ghsa_id": null, "product": "[\"Harmony\", \"VLTrader\", \"LexiCom\"]", "added_date": "2024-12-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98607, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99922, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-50623", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d0592eb-d264-404d-a4e4-5df4b3ab9042", "vulnerability": {"vulnId": "CVE-2024-53677", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-11T16:35:43+01:00"}, "gcve": {"object_uuid": "3d0592eb-d264-404d-a4e4-5df4b3ab9042", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-11T15:35:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-11T15:35:43+00:00"}, "scope": {"notes": "Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks | Affected: Apache / Apache Struts | CVSS: 9.5 (CRITICAL) | EPSS: 0.70143 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-53677", "url": "https://www.cve.org/CVERecord?id=CVE-2024-53677"}, {"id": "GHSA-43MQ-6XMG-29VM", "url": "https://github.com/advisories/GHSA-43MQ-6XMG-29VM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-53677"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks", "cve_id": "CVE-2024-53677", "vendor": "Apache", "ghsa_id": "GHSA-43MQ-6XMG-29VM", "product": "Apache Struts", "added_date": "2024-12-11T15:35:43.000Z", "cvss_score": 9.5, "epss_score": 0.70143, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99363, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-53677", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "deaa6149-8f37-4057-a754-4931469e291c", "vulnerability": {"vulnId": "CVE-2024-49138", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "deaa6149-8f37-4057-a754-4931469e291c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-10T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.26215 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-49138", "url": "https://www.cve.org/CVERecord?id=CVE-2024-49138"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-49138"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-49138", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation)", "added_date": "2024-12-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.26215, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97941, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-49138", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e923b612-9ec1-48df-9fd6-3ef04adccc2f", "vulnerability": {"vulnId": "CVE-2023-32117", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-09T12:30:57+01:00"}, "gcve": {"object_uuid": "e923b612-9ec1-48df-9fd6-3ef04adccc2f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-09T11:30:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-09T11:30:57+00:00"}, "scope": {"notes": "WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability | Affected: SoftLab / Integrate Google Drive | CVSS: 9.8 (CRITICAL) | EPSS: 0.07335 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-32117", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32117"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32117"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability", "cve_id": "CVE-2023-32117", "vendor": "SoftLab", "ghsa_id": null, "product": "Integrate Google Drive", "added_date": "2024-12-09T11:30:57.000Z", "cvss_score": 9.8, "epss_score": 0.07335, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94207, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32117", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ee67416a-3f0f-4a45-87ac-56690058f035", "vulnerability": {"vulnId": "CVE-2024-12209", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-08T06:25:16+01:00"}, "gcve": {"object_uuid": "ee67416a-3f0f-4a45-87ac-56690058f035", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-08T05:25:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-08T05:25:16+00:00"}, "scope": {"notes": "WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion | Affected: Wphealth / WP Umbrella: Update Backup Restore & Monitoring | CVSS: 9.8 (CRITICAL) | EPSS: 0.23222 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-12209", "url": "https://www.cve.org/CVERecord?id=CVE-2024-12209"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-12209"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion", "cve_id": "CVE-2024-12209", "vendor": "Wphealth", "ghsa_id": null, "product": "WP Umbrella: Update Backup Restore & Monitoring", "added_date": "2024-12-08T05:25:16.000Z", "cvss_score": 9.8, "epss_score": 0.23222, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97711, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-12209", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d813dc68-eee3-41bf-ba93-0b9b27f86cb4", "vulnerability": {"vulnId": "CVE-2024-51378", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-04T01:00:00+01:00"}, "gcve": {"object_uuid": "d813dc68-eee3-41bf-ba93-0b9b27f86cb4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-04T00:00:00+00:00"}, "scope": {"notes": "getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and... | Affected: CyberPanel / CyberPanel | CVSS: 10.0 (CRITICAL) | EPSS: 0.94748 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-51378", "url": "https://www.cve.org/CVERecord?id=CVE-2024-51378"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-51378"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and...", "cve_id": "CVE-2024-51378", "vendor": "CyberPanel", "ghsa_id": null, "product": "CyberPanel", "added_date": "2024-12-04T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.94748, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99857, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-51378", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b4af289d-0da8-4e76-bdaa-4ec54e5a3aff", "vulnerability": {"vulnId": "CVE-2023-45727", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b4af289d-0da8-4e76-bdaa-4ec54e5a3aff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-03T00:00:00+00:00"}, "scope": {"notes": "Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and... | Affected: North Grid / Proself Enterprise/Standard Edition, Proself Gateway Edition, Proself Mail Sanitize Edition | CVSS: 7.5 (HIGH) | EPSS: 0.03542 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-45727", "url": "https://www.cve.org/CVERecord?id=CVE-2023-45727"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-45727"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and...", "cve_id": "CVE-2023-45727", "vendor": "North Grid", "ghsa_id": null, "product": "Proself Enterprise/Standard Edition, Proself Gateway Edition, Proself Mail Sanitize Edition", "added_date": "2024-12-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03542, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88903, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-45727", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "be42a5dd-a797-4ff4-89f6-da3a2a060b6b", "vulnerability": {"vulnId": "CVE-2024-11680", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-03T01:00:00+01:00"}, "gcve": {"object_uuid": "be42a5dd-a797-4ff4-89f6-da3a2a060b6b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-03T00:00:00+00:00"}, "scope": {"notes": "ProjectSend Unauthenticated Configuration Modification | Affected: ProjectSend / ProjectSend | CVSS: 9.8 (CRITICAL) | EPSS: 0.91697 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-11680", "url": "https://www.cve.org/CVERecord?id=CVE-2024-11680"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-11680"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ProjectSend Unauthenticated Configuration Modification", "cve_id": "CVE-2024-11680", "vendor": "ProjectSend", "ghsa_id": null, "product": "ProjectSend", "added_date": "2024-12-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91697, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99813, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-11680", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "96364cd0-585a-4222-9d97-ed44aec7f8af", "vulnerability": {"vulnId": "CVE-2024-11667", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-12-03T01:00:00+01:00"}, "gcve": {"object_uuid": "96364cd0-585a-4222-9d97-ed44aec7f8af", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-12-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-12-03T00:00:00+00:00"}, "scope": {"notes": "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series... | Affected: Zyxel / ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, USG20(W)-VPN series firmware | CVSS: 7.5 (HIGH) | EPSS: 0.02929 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-11667", "url": "https://www.cve.org/CVERecord?id=CVE-2024-11667"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-11667"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series...", "cve_id": "CVE-2024-11667", "vendor": "Zyxel", "ghsa_id": null, "product": "ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) series firmware, USG20(W)-VPN series firmware", "added_date": "2024-12-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02929, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86596, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-11667", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "40560f66-879f-41ab-9cd7-6756fba29dfd", "vulnerability": {"vulnId": "CVE-2023-28461", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-25T01:00:00+01:00"}, "gcve": {"object_uuid": "40560f66-879f-41ab-9cd7-6756fba29dfd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-25T00:00:00+00:00"}, "scope": {"notes": "Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN... | Affected: Array Networks / Array AG Series and vxAG | CVSS: 9.8 (CRITICAL) | EPSS: 0.68079 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28461", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28461"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28461"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN...", "cve_id": "CVE-2023-28461", "vendor": "Array Networks", "ghsa_id": null, "product": "Array AG Series and vxAG", "added_date": "2024-11-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68079, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99307, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-28461", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ee813283-e0d0-4136-8104-a30bec2087e1", "vulnerability": {"vulnId": "CVE-2024-44308", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-21T01:00:00+01:00"}, "gcve": {"object_uuid": "ee813283-e0d0-4136-8104-a30bec2087e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-21T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1,... | Affected: Apple / Safari, iOS and iPadOS, macOS, visionOS | CVSS: 8.8 (HIGH) | EPSS: 0.10075 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-44308", "url": "https://www.cve.org/CVERecord?id=CVE-2024-44308"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-44308"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1,...", "cve_id": "CVE-2024-44308", "vendor": "Apple", "ghsa_id": null, "product": "Safari, iOS and iPadOS, macOS, visionOS", "added_date": "2024-11-21T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10075, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95497, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-44308", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c9f959c7-ca1d-4641-ae71-f71cd6d3742a", "vulnerability": {"vulnId": "CVE-2024-21287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-21T01:00:00+01:00"}, "gcve": {"object_uuid": "c9f959c7-ca1d-4641-ae71-f71cd6d3742a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-21T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).   The... | Affected: Oracle / Oracle Agile PLM Framework | CVSS: 7.5 (HIGH) | EPSS: 0.01723 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21287", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).   The...", "cve_id": "CVE-2024-21287", "vendor": "Oracle", "ghsa_id": null, "product": "Oracle Agile PLM Framework", "added_date": "2024-11-21T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01723, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76669, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e832fbe7-69e6-45dc-aa19-3e048047a257", "vulnerability": {"vulnId": "CVE-2024-44309", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-21T01:00:00+01:00"}, "gcve": {"object_uuid": "e832fbe7-69e6-45dc-aa19-3e048047a257", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-21T00:00:00+00:00"}, "scope": {"notes": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS... | Affected: Apple / Safari, iOS and iPadOS, macOS, visionOS | CVSS: 6.3 (MEDIUM) | EPSS: 0.2259 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-44309", "url": "https://www.cve.org/CVERecord?id=CVE-2024-44309"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-44309"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS...", "cve_id": "CVE-2024-44309", "vendor": "Apple", "ghsa_id": null, "product": "Safari, iOS and iPadOS, macOS, visionOS", "added_date": "2024-11-21T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.2259, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97653, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-44309", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f276824-ce61-4de7-a61f-47ebbc7859cc", "vulnerability": {"vulnId": "CVE-2024-38812", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-20T01:00:00+01:00"}, "gcve": {"object_uuid": "2f276824-ce61-4de7-a61f-47ebbc7859cc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-20T00:00:00+00:00"}, "scope": {"notes": "Heap-overflow vulnerability | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation | CVSS: 9.8 (CRITICAL) | EPSS: 0.54571 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38812", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38812"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38812"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap-overflow vulnerability", "cve_id": "CVE-2024-38812", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation", "added_date": "2024-11-20T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.54571, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38812", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a84f542a-2beb-4382-ac45-eb8ce67fe68c", "vulnerability": {"vulnId": "CVE-2024-38813", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-20T01:00:00+01:00"}, "gcve": {"object_uuid": "a84f542a-2beb-4382-ac45-eb8ce67fe68c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-20T00:00:00+00:00"}, "scope": {"notes": "Privilege escalation vulnerability | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation | CVSS: 7.5 (HIGH) | EPSS: 0.17355 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38813", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38813"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38813"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Privilege escalation vulnerability", "cve_id": "CVE-2024-38813", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation", "added_date": "2024-11-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.17355, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9703, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38813", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2bca141c-d27d-445e-a720-2e2dd2a388d5", "vulnerability": {"vulnId": "CVE-2024-9474", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-18T01:00:00+01:00"}, "gcve": {"object_uuid": "2bca141c-d27d-445e-a720-2e2dd2a388d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-18T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 6.9 (MEDIUM) | EPSS: 0.94701 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9474", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9474"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9474"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface", "cve_id": "CVE-2024-9474", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2024-11-18T00:00:00.000Z", "cvss_score": 6.9, "epss_score": 0.94701, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99856, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-9474", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "03381e32-c7ce-4a45-9bdc-f98b323506ef", "vulnerability": {"vulnId": "CVE-2024-1212", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-18T01:00:00+01:00"}, "gcve": {"object_uuid": "03381e32-c7ce-4a45-9bdc-f98b323506ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-18T00:00:00+00:00"}, "scope": {"notes": "LoadMaster Pre-Authenticated OS Command Injection | Affected: Progress Software / LoadMaster | CVSS: 10.0 (CRITICAL) | EPSS: 0.95388 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-1212", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1212"}, {"id": "GHSA-8VV7-J7W3-28WW", "url": "https://github.com/advisories/GHSA-8VV7-J7W3-28WW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1212"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LoadMaster Pre-Authenticated OS Command Injection", "cve_id": "CVE-2024-1212", "vendor": "Progress Software", "ghsa_id": "GHSA-8VV7-J7W3-28WW", "product": "LoadMaster", "added_date": "2024-11-18T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.95388, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99867, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-1212", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "272ac6f1-770e-4930-a415-20710e203ea4", "vulnerability": {"vulnId": "CVE-2024-0012", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-18T01:00:00+01:00"}, "gcve": {"object_uuid": "272ac6f1-770e-4930-a415-20710e203ea4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-18T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 9.3 (CRITICAL) | EPSS: 0.99848 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-0012", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0012"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0012"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)", "cve_id": "CVE-2024-0012", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2024-11-18T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.99848, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9996, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-0012", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "322a394e-5c08-4209-8cc9-a9f395cd1093", "vulnerability": {"vulnId": "CVE-2024-9465", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-14T01:00:00+01:00"}, "gcve": {"object_uuid": "322a394e-5c08-4209-8cc9-a9f395cd1093", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-14T00:00:00+00:00"}, "scope": {"notes": "Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure | Affected: Palo Alto Networks / Expedition | CVSS: 9.2 (CRITICAL) | EPSS: 0.99626 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9465", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9465"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9465"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure", "cve_id": "CVE-2024-9465", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Expedition", "added_date": "2024-11-14T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.99626, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99948, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9465", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "41c66eaf-252b-46a2-b449-a8a211252452", "vulnerability": {"vulnId": "CVE-2024-9463", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-14T01:00:00+01:00"}, "gcve": {"object_uuid": "41c66eaf-252b-46a2-b449-a8a211252452", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-14T00:00:00+00:00"}, "scope": {"notes": "Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure | Affected: Palo Alto Networks / Expedition | CVSS: 9.9 (CRITICAL) | EPSS: 0.98546 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9463", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9463"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9463"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure", "cve_id": "CVE-2024-9463", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Expedition", "added_date": "2024-11-14T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.98546, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99921, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9463", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3e7fceab-5a17-4bb8-904b-74d5c75daf23", "vulnerability": {"vulnId": "CVE-2021-41277", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "3e7fceab-5a17-4bb8-904b-74d5c75daf23", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-12T00:00:00+00:00"}, "scope": {"notes": "GeoJSON URL validation can expose server files and environment variables to unauthorized users | Affected: Metabase / metabase | CVSS: 10.0 (CRITICAL) | EPSS: 0.97178 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-41277", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41277"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41277"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoJSON URL validation can expose server files and environment variables to unauthorized users", "cve_id": "CVE-2021-41277", "vendor": "Metabase", "ghsa_id": null, "product": "metabase", "added_date": "2024-11-12T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.97178, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99894, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41277", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "40e613f9-254c-4173-b678-74263d51a2a9", "vulnerability": {"vulnId": "CVE-2024-43451", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "40e613f9-254c-4173-b678-74263d51a2a9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-12T00:00:00+00:00"}, "scope": {"notes": "NTLM Hash Disclosure Spoofing Vulnerability | Affected: Microsoft / Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 6.5 (MEDIUM) | EPSS: 0.84108 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43451", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43451"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43451"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NTLM Hash Disclosure Spoofing Vulnerability", "cve_id": "CVE-2024-43451", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2024-11-12T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.84108, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99688, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43451", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7d405667-702d-40fb-9c6e-27bacbbc9871", "vulnerability": {"vulnId": "CVE-2021-26086", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "7d405667-702d-40fb-9c6e-27bacbbc9871", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-12T00:00:00+00:00"}, "scope": {"notes": "Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in... | Affected: Atlassian / Jira Server, Jira Data Center | CVSS: 5.3 (MEDIUM) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26086", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26086"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26086"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in...", "cve_id": "CVE-2021-26086", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira Server, Jira Data Center", "added_date": "2024-11-12T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-26086", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c9993d09-6e85-436a-a8e1-5ce888542520", "vulnerability": {"vulnId": "CVE-2024-49039", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "c9993d09-6e85-436a-a8e1-5ce888542520", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-12T00:00:00+00:00"}, "scope": {"notes": "Windows Task Scheduler Elevation of Privilege Vulnerability | Affected: Microsoft / Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.14179 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-49039", "url": "https://www.cve.org/CVERecord?id=CVE-2024-49039"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-49039"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Task Scheduler Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-49039", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2025, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2024-11-12T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.14179, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96475, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-49039", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0ff335b-46c8-4d22-ad26-e8066734e71c", "vulnerability": {"vulnId": "CVE-2014-2120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-12T01:00:00+01:00"}, "gcve": {"object_uuid": "e0ff335b-46c8-4d22-ad26-e8066734e71c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-12T00:00:00+00:00"}, "scope": {"notes": "Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to... | Affected: Cisco / Adaptive Security Appliance (ASA) Software | CVSS: 6.1 (MEDIUM) | EPSS: 0.22558 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-2120", "url": "https://www.cve.org/CVERecord?id=CVE-2014-2120"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-2120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to...", "cve_id": "CVE-2014-2120", "vendor": "Cisco", "ghsa_id": null, "product": "Adaptive Security Appliance (ASA) Software", "added_date": "2024-11-12T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.22558, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97649, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-2120", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a8350523-4e53-4083-9f60-c2f2b157350f", "vulnerability": {"vulnId": "CVE-2024-51211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "a8350523-4e53-4083-9f60-c2f2b157350f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-08T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to... | Affected: OS4ED / openSIS-Classic | CVSS: 9.8 (CRITICAL) | EPSS: 0.02256 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-51211", "url": "https://www.cve.org/CVERecord?id=CVE-2024-51211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-51211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to...", "cve_id": "CVE-2024-51211", "vendor": "OS4ED", "ghsa_id": null, "product": "openSIS-Classic", "added_date": "2024-11-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.02256, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82324, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-51211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6f76c2bd-8abf-48eb-b6bd-ec5cc3b10977", "vulnerability": {"vulnId": "CVE-2024-5910", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-07T01:00:00+01:00"}, "gcve": {"object_uuid": "6f76c2bd-8abf-48eb-b6bd-ec5cc3b10977", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-07T00:00:00+00:00"}, "scope": {"notes": "Expedition: Missing Authentication Leads to Admin Account Takeover | Affected: Palo Alto Networks / Expedition | CVSS: 9.3 (CRITICAL) | EPSS: 0.91783 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-5910", "url": "https://www.cve.org/CVERecord?id=CVE-2024-5910"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-5910"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Expedition: Missing Authentication Leads to Admin Account Takeover", "cve_id": "CVE-2024-5910", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Expedition", "added_date": "2024-11-07T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.91783, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99815, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-5910", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "afbacb0c-1286-4edd-a8d4-bd2d182b8e46", "vulnerability": {"vulnId": "CVE-2019-16278", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-07T01:00:00+01:00"}, "gcve": {"object_uuid": "afbacb0c-1286-4edd-a8d4-bd2d182b8e46", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-07T00:00:00+00:00"}, "scope": {"notes": "Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted... | Affected: Nostromo / nhttpd | CVSS: 9.8 (CRITICAL) | EPSS: 0.99033 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-16278", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16278"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16278"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted...", "cve_id": "CVE-2019-16278", "vendor": "Nostromo", "ghsa_id": null, "product": "nhttpd", "added_date": "2024-11-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99033, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99931, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16278", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "344e63ef-8328-4035-be7d-51f3b773afd3", "vulnerability": {"vulnId": "CVE-2024-51567", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-07T01:00:00+01:00"}, "gcve": {"object_uuid": "344e63ef-8328-4035-be7d-51f3b773afd3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-07T00:00:00+00:00"}, "scope": {"notes": "upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and... | Affected: CyberPanel / CyberPanel | CVSS: 10.0 (CRITICAL) | EPSS: 0.86633 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-51567", "url": "https://www.cve.org/CVERecord?id=CVE-2024-51567"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-51567"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and...", "cve_id": "CVE-2024-51567", "vendor": "CyberPanel", "ghsa_id": null, "product": "CyberPanel", "added_date": "2024-11-07T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.86633, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99736, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-51567", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "af8efbe7-338b-44ce-a35c-b7e45948faa8", "vulnerability": {"vulnId": "CVE-2024-43093", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-07T01:00:00+01:00"}, "gcve": {"object_uuid": "af8efbe7-338b-44ce-a35c-b7e45948faa8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-07T00:00:00+00:00"}, "scope": {"notes": "In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive... | Affected: Google / Android | CVSS: 7.3 (HIGH) | EPSS: 0.00715 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43093", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43093"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43093"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive...", "cve_id": "CVE-2024-43093", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2024-11-07T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.00715, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43093", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "15de42e5-636f-49bd-8e97-14a3d1e6adfb", "vulnerability": {"vulnId": "CVE-2024-8956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-04T01:00:00+01:00"}, "gcve": {"object_uuid": "15de42e5-636f-49bd-8e97-14a3d1e6adfb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-04T00:00:00+00:00"}, "scope": {"notes": "PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication | Affected: PTZOptics / PT30X-SDI, PT30X-NDI | CVSS: 9.1 (CRITICAL) | EPSS: 0.58787 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-8956", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication", "cve_id": "CVE-2024-8956", "vendor": "PTZOptics", "ghsa_id": null, "product": "PT30X-SDI, PT30X-NDI", "added_date": "2024-11-04T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.58787, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99081, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e3b4ca62-6b51-49cc-bbb6-e0c886b52e79", "vulnerability": {"vulnId": "CVE-2024-8957", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-11-04T01:00:00+01:00"}, "gcve": {"object_uuid": "e3b4ca62-6b51-49cc-bbb6-e0c886b52e79", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-11-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-11-04T00:00:00+00:00"}, "scope": {"notes": "PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration | Affected: PTZOptics / PT30X-SDI, PT30X-NDI | CVSS: 7.2 (HIGH) | EPSS: 0.79703 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-8957", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8957"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8957"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration", "cve_id": "CVE-2024-8957", "vendor": "PTZOptics", "ghsa_id": null, "product": "PT30X-SDI, PT30X-NDI", "added_date": "2024-11-04T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.79703, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99599, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8957", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02e59edf-6e96-4d36-aaca-da1de4fb8748", "vulnerability": {"vulnId": "CVE-2024-37383", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "02e59edf-6e96-4d36-aaca-da1de4fb8748", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-24T00:00:00+00:00"}, "scope": {"notes": "Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. | Affected: Roundcube / Roundcube Webmail | CVSS: 6.1 (MEDIUM) | EPSS: 0.73296 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-37383", "url": "https://www.cve.org/CVERecord?id=CVE-2024-37383"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-37383"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.", "cve_id": "CVE-2024-37383", "vendor": "Roundcube", "ghsa_id": null, "product": "Roundcube Webmail", "added_date": "2024-10-24T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.73296, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99448, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-37383", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "77cc52e2-1c93-44a9-badd-a4041cbed418", "vulnerability": {"vulnId": "CVE-2024-20481", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "77cc52e2-1c93-44a9-badd-a4041cbed418", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-24T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense... | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | CVSS: 5.8 (MEDIUM) | EPSS: 0.1575 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20481", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20481"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20481"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense...", "cve_id": "CVE-2024-20481", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software", "added_date": "2024-10-24T00:00:00.000Z", "cvss_score": 5.8, "epss_score": 0.1575, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96769, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20481", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "31f732fd-2e00-40e6-ba88-d9ebd7bc1d07", "vulnerability": {"vulnId": "CVE-2024-47575", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-23T02:00:00+02:00"}, "gcve": {"object_uuid": "31f732fd-2e00-40e6-ba88-d9ebd7bc1d07", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-23T00:00:00+00:00"}, "scope": {"notes": "A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7,... | Affected: Fortinet / FortiManager | CVSS: 9.8 (CRITICAL) | EPSS: 0.94766 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-47575", "url": "https://www.cve.org/CVERecord?id=CVE-2024-47575"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-47575"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7,...", "cve_id": "CVE-2024-47575", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiManager", "added_date": "2024-10-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94766, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99858, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-47575", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02563e40-8b62-40e8-a803-0702005278ec", "vulnerability": {"vulnId": "CVE-2024-38094", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-22T02:00:00+02:00"}, "gcve": {"object_uuid": "02563e40-8b62-40e8-a803-0702005278ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-22T00:00:00+00:00"}, "scope": {"notes": "Microsoft SharePoint Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 7.2 (HIGH) | EPSS: 0.50892 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38094", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38094"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38094"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Remote Code Execution Vulnerability", "cve_id": "CVE-2024-38094", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2024-10-22T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.50892, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98895, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-38094", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9f5e29d1-4d8f-4832-b400-c721b9412e49", "vulnerability": {"vulnId": "CVE-2024-9537", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-21T02:00:00+02:00"}, "gcve": {"object_uuid": "9f5e29d1-4d8f-4832-b400-c721b9412e49", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-21T00:00:00+00:00"}, "scope": {"notes": "ScienceLogic SL1 unspecified vulnerability | Affected: ScienceLogic / SL1 | CVSS: 9.3 (CRITICAL) | EPSS: 0.03826 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9537", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9537"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9537"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ScienceLogic SL1 unspecified vulnerability", "cve_id": "CVE-2024-9537", "vendor": "ScienceLogic", "ghsa_id": null, "product": "SL1", "added_date": "2024-10-21T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.03826, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9537", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4ef0ce1e-4dd7-486f-a9c4-f5f9296d6896", "vulnerability": {"vulnId": "CVE-2024-9593", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-18T19:32:30+02:00"}, "gcve": {"object_uuid": "4ef0ce1e-4dd7-486f-a9c4-f5f9296d6896", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-18T17:32:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-18T17:32:30+00:00"}, "scope": {"notes": "Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution | Affected: Scott Paterson / Time Clock Pro, Time Clock \u2013 A WordPress Employee & Volunteer Time Clock Plugin | CVSS: 8.3 (HIGH) | EPSS: 0.12411 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9593", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9593"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9593"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution", "cve_id": "CVE-2024-9593", "vendor": "Scott Paterson", "ghsa_id": null, "product": "Time Clock Pro, Time Clock \u2013 A WordPress Employee & Volunteer Time Clock Plugin", "added_date": "2024-10-18T17:32:30.000Z", "cvss_score": 8.3, "epss_score": 0.12411, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96089, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9593", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7e52229a-2a7b-4669-a593-ac7b5d3a5d9f", "vulnerability": {"vulnId": "CVE-2024-40711", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-17T02:00:00+02:00"}, "gcve": {"object_uuid": "7e52229a-2a7b-4669-a593-ac7b5d3a5d9f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-17T00:00:00+00:00"}, "scope": {"notes": "A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | Affected: Veeam / Backup and  Recovery | CVSS: 9.8 (CRITICAL) | EPSS: 0.90369 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-40711", "url": "https://www.cve.org/CVERecord?id=CVE-2024-40711"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-40711"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).", "cve_id": "CVE-2024-40711", "vendor": "Veeam", "ghsa_id": null, "product": "Backup and  Recovery", "added_date": "2024-10-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90369, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99797, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-40711", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d5a2301-21cf-40a4-a9b0-f251cb2a2b60", "vulnerability": {"vulnId": "CVE-2024-30088", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-15T02:00:00+02:00"}, "gcve": {"object_uuid": "9d5a2301-21cf-40a4-a9b0-f251cb2a2b60", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-15T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.68202 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-30088", "url": "https://www.cve.org/CVERecord?id=CVE-2024-30088"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-30088"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-30088", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 23H2, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-10-15T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.68202, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9931, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-30088", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8f253b83-eeed-499d-a180-8cca98017650", "vulnerability": {"vulnId": "CVE-2024-28987", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-15T02:00:00+02:00"}, "gcve": {"object_uuid": "8f253b83-eeed-499d-a180-8cca98017650", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-15T00:00:00+00:00"}, "scope": {"notes": "SolarWinds Web Help Desk Hardcoded Credential Vulnerability | Affected: SolarWinds / Web Help Desk | CVSS: 9.1 (CRITICAL) | EPSS: 0.93299 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-28987", "url": "https://www.cve.org/CVERecord?id=CVE-2024-28987"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-28987"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Web Help Desk Hardcoded Credential Vulnerability", "cve_id": "CVE-2024-28987", "vendor": "SolarWinds", "ghsa_id": null, "product": "Web Help Desk", "added_date": "2024-10-15T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.93299, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-28987", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "34580482-11ce-4452-8688-fd1bdc704237", "vulnerability": {"vulnId": "CVE-2024-9680", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-15T02:00:00+02:00"}, "gcve": {"object_uuid": "34580482-11ce-4452-8688-fd1bdc704237", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-15T00:00:00+00:00"}, "scope": {"notes": "An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of... | Affected: Mozilla / Firefox, Firefox ESR, Thunderbird | CVSS: 9.8 (CRITICAL) | EPSS: 0.23184 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9680", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9680"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9680"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of...", "cve_id": "CVE-2024-9680", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Firefox ESR, Thunderbird", "added_date": "2024-10-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.23184, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97707, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-9680", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "615924ea-7625-4ebe-9299-63e958555f15", "vulnerability": {"vulnId": "CVE-2024-9916", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-13T21:00:07+02:00"}, "gcve": {"object_uuid": "615924ea-7625-4ebe-9299-63e958555f15", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-13T19:00:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-13T19:00:07+00:00"}, "scope": {"notes": "HuangDou UTCMS cli.php os command injection | Affected: HuangDou / UTCMS | CVSS: 6.9 (MEDIUM) | EPSS: 0.73617 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9916", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9916"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9916"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HuangDou UTCMS cli.php os command injection", "cve_id": "CVE-2024-9916", "vendor": "HuangDou", "ghsa_id": null, "product": "UTCMS", "added_date": "2024-10-13T19:00:07.000Z", "cvss_score": 6.9, "epss_score": 0.73617, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99458, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9916", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "868949ce-924c-443d-ae18-b88bc32c7d83", "vulnerability": {"vulnId": "CVE-2024-23113", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-09T02:00:00+02:00"}, "gcve": {"object_uuid": "868949ce-924c-443d-ae18-b88bc32c7d83", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-09T00:00:00+00:00"}, "scope": {"notes": "A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13,... | Affected: Fortinet / FortiSwitchManager, FortiOS, FortiPAM, FortiProxy | CVSS: 9.8 (CRITICAL) | EPSS: 0.61725 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-23113", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23113"}, {"id": "GHSA-57PF-F69P-P222", "url": "https://github.com/advisories/GHSA-57PF-F69P-P222"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23113"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13,...", "cve_id": "CVE-2024-23113", "vendor": "Fortinet", "ghsa_id": "GHSA-57PF-F69P-P222", "product": "FortiSwitchManager, FortiOS, FortiPAM, FortiProxy", "added_date": "2024-10-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.61725, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99149, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-23113", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0dc022a6-7a21-40b6-8609-d0eda47ad723", "vulnerability": {"vulnId": "CVE-2024-9380", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-09T02:00:00+02:00"}, "gcve": {"object_uuid": "0dc022a6-7a21-40b6-8609-d0eda47ad723", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-09T00:00:00+00:00"}, "scope": {"notes": "An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin... | Affected: Ivanti / CSA (Cloud Services Appliance) | CVSS: 7.2 (HIGH) | EPSS: 0.59651 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9380", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9380"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9380"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin...", "cve_id": "CVE-2024-9380", "vendor": "Ivanti", "ghsa_id": null, "product": "CSA (Cloud Services Appliance)", "added_date": "2024-10-09T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.59651, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99103, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9380", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ab93ab06-d7d7-4ddf-94a0-4e10f302de72", "vulnerability": {"vulnId": "CVE-2024-9379", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-09T02:00:00+02:00"}, "gcve": {"object_uuid": "ab93ab06-d7d7-4ddf-94a0-4e10f302de72", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-09T00:00:00+00:00"}, "scope": {"notes": "SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run... | Affected: Ivanti / CSA (Cloud Services Appliance) | CVSS: 6.5 (MEDIUM) | EPSS: 0.43782 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-9379", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9379"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9379"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run...", "cve_id": "CVE-2024-9379", "vendor": "Ivanti", "ghsa_id": null, "product": "CSA (Cloud Services Appliance)", "added_date": "2024-10-09T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.43782, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98706, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9379", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d2ef8ef8-cf1e-4b0c-a514-acf714e97813", "vulnerability": {"vulnId": "CVE-2024-43573", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-08T02:00:00+02:00"}, "gcve": {"object_uuid": "d2ef8ef8-cf1e-4b0c-a514-acf714e97813", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-08T00:00:00+00:00"}, "scope": {"notes": "Windows MSHTML Platform Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 6.5 (MEDIUM) | EPSS: 0.46109 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43573", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43573"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43573"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows MSHTML Platform Spoofing Vulnerability", "cve_id": "CVE-2024-43573", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-10-08T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.46109, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98775, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43573", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cf891de5-42b3-408b-8d86-9c2da325ec77", "vulnerability": {"vulnId": "CVE-2024-43572", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-08T02:00:00+02:00"}, "gcve": {"object_uuid": "cf891de5-42b3-408b-8d86-9c2da325ec77", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-08T00:00:00+00:00"}, "scope": {"notes": "Microsoft Management Console Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.66695 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43572", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43572"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43572"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Management Console Remote Code Execution Vulnerability", "cve_id": "CVE-2024-43572", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-10-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.66695, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43572", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d068fb35-bc27-4329-bcbb-2bfb5c37629c", "vulnerability": {"vulnId": "CVE-2024-43047", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-08T02:00:00+02:00"}, "gcve": {"object_uuid": "d068fb35-bc27-4329-bcbb-2bfb5c37629c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-08T00:00:00+00:00"}, "scope": {"notes": "Use After Free in DSP Service | Affected: Qualcomm / Snapdragon | CVSS: 7.8 (HIGH) | EPSS: 0.00674 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43047", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43047"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43047"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use After Free in DSP Service", "cve_id": "CVE-2024-43047", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2024-10-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00674, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50348, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43047", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d784245e-2d56-4654-adab-62aeeec9b3a8", "vulnerability": {"vulnId": "CVE-2024-45519", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-03T02:00:00+02:00"}, "gcve": {"object_uuid": "d784245e-2d56-4654-adab-62aeeec9b3a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-03T00:00:00+00:00"}, "scope": {"notes": "The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1... | Affected: Zimbra / Zimbra Collaboration | CVSS: 10.0 (CRITICAL) | EPSS: 0.99907 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-45519", "url": "https://www.cve.org/CVERecord?id=CVE-2024-45519"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-45519"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1...", "cve_id": "CVE-2024-45519", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration", "added_date": "2024-10-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99907, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99966, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-45519", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "88726ec1-9d02-43b0-8759-85aef9126c40", "vulnerability": {"vulnId": "CVE-2024-29824", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-10-02T02:00:00+02:00"}, "gcve": {"object_uuid": "88726ec1-9d02-43b0-8759-85aef9126c40", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-10-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-10-02T00:00:00+00:00"}, "scope": {"notes": "An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same... | Affected: Ivanti / EPM | CVSS: 8.8 (HIGH) | EPSS: 0.99938 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-29824", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29824"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29824"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same...", "cve_id": "CVE-2024-29824", "vendor": "Ivanti", "ghsa_id": null, "product": "EPM", "added_date": "2024-10-02T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99938, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99971, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29824", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0ea65f7c-bf92-4a04-bf8b-a9cea06eaf92", "vulnerability": {"vulnId": "CVE-2019-0344", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-30T02:00:00+02:00"}, "gcve": {"object_uuid": "0ea65f7c-bf92-4a04-bf8b-a9cea06eaf92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-30T00:00:00+00:00"}, "scope": {"notes": "Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to... | Affected: SAP SE / SAP Commerce Cloud (virtualjdbc extension) | CVSS: 9.8 (CRITICAL) | EPSS: 0.07079 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0344", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0344"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0344"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to...", "cve_id": "CVE-2019-0344", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP Commerce Cloud (virtualjdbc extension)", "added_date": "2024-09-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07079, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94026, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0344", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "37871d07-b93d-4af7-a067-577aae6116f0", "vulnerability": {"vulnId": "CVE-2020-15415", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-30T02:00:00+02:00"}, "gcve": {"object_uuid": "37871d07-b93d-4af7-a067-577aae6116f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-30T00:00:00+00:00"}, "scope": {"notes": "On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via... | Affected: DrayTek / Vigor3900, Vigor2960, Vigor300B | CVSS: 9.8 (CRITICAL) | EPSS: 0.8448 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-15415", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15415"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15415"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via...", "cve_id": "CVE-2020-15415", "vendor": "DrayTek", "ghsa_id": null, "product": "Vigor3900, Vigor2960, Vigor300B", "added_date": "2024-09-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.8448, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99695, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15415", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f87f4b37-b697-4cda-ade5-54ff349b1993", "vulnerability": {"vulnId": "CVE-2023-25280", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-30T02:00:00+02:00"}, "gcve": {"object_uuid": "f87f4b37-b697-4cda-ade5-54ff349b1993", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-30T00:00:00+00:00"}, "scope": {"notes": "OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the... | Affected: D-Link / DIR820LA1_FW105B03 | CVSS: 9.8 (CRITICAL) | EPSS: 0.97864 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-25280", "url": "https://www.cve.org/CVERecord?id=CVE-2023-25280"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-25280"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the...", "cve_id": "CVE-2023-25280", "vendor": "D-Link", "ghsa_id": null, "product": "DIR820LA1_FW105B03", "added_date": "2024-09-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97864, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-25280", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "608fd5e4-a1f0-432d-bb52-c96f3d3e234d", "vulnerability": {"vulnId": "CVE-2024-7593", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-24T02:00:00+02:00"}, "gcve": {"object_uuid": "608fd5e4-a1f0-432d-bb52-c96f3d3e234d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-24T00:00:00+00:00"}, "scope": {"notes": "Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker... | Affected: Ivanti / vTM | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-7593", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7593"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7593"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker...", "cve_id": "CVE-2024-7593", "vendor": "Ivanti", "ghsa_id": null, "product": "vTM", "added_date": "2024-09-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99991, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7593", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "452a031f-f627-4e4a-8c7e-5d1ee7205d06", "vulnerability": {"vulnId": "CVE-2024-9001", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-19T22:00:09+02:00"}, "gcve": {"object_uuid": "452a031f-f627-4e4a-8c7e-5d1ee7205d06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-19T20:00:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-19T20:00:09+00:00"}, "scope": {"notes": "TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection | Affected: TOTOLINK / T10 | CVSS: 5.3 (MEDIUM) | EPSS: 0.03321 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-9001", "url": "https://www.cve.org/CVERecord?id=CVE-2024-9001"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-9001"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection", "cve_id": "CVE-2024-9001", "vendor": "TOTOLINK", "ghsa_id": null, "product": "T10", "added_date": "2024-09-19T20:00:09.000Z", "cvss_score": 5.3, "epss_score": 0.03321, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8819, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-9001", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "325f6c2d-0f83-4d81-8ceb-ce1a866f27e1", "vulnerability": {"vulnId": "CVE-2024-8963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-19T02:00:00+02:00"}, "gcve": {"object_uuid": "325f6c2d-0f83-4d81-8ceb-ce1a866f27e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-19T00:00:00+00:00"}, "scope": {"notes": "Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | Affected: Ivanti / CSA (Cloud Services Appliance) | CVSS: 9.4 (CRITICAL) | EPSS: 0.98607 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-8963", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8963"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.", "cve_id": "CVE-2024-8963", "vendor": "Ivanti", "ghsa_id": null, "product": "CSA (Cloud Services Appliance)", "added_date": "2024-09-19T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.98607, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99922, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8963", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "80fefee9-ae34-44a5-8f83-51686850cf6b", "vulnerability": {"vulnId": "CVE-2022-21445", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "80fefee9-ae34-44a5-8f83-51686850cf6b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-18T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions... | Affected: Oracle / Application Development Framework (ADF) | CVSS: 9.8 (CRITICAL) | EPSS: 0.62478 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-21445", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21445"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21445"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions...", "cve_id": "CVE-2022-21445", "vendor": "Oracle", "ghsa_id": null, "product": "Application Development Framework (ADF)", "added_date": "2024-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.62478, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99166, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21445", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dbd73931-3ddd-4006-b89e-d96d65ec1eba", "vulnerability": {"vulnId": "CVE-2024-27348", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "dbd73931-3ddd-4006-b89e-d96d65ec1eba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-18T00:00:00+00:00"}, "scope": {"notes": "Apache HugeGraph-Server: Command execution in gremlin | Affected: Apache / Apache HugeGraph-Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.9921 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-27348", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27348"}, {"id": "GHSA-29RC-VQ7F-X335", "url": "https://github.com/advisories/GHSA-29RC-VQ7F-X335"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27348"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache HugeGraph-Server: Command execution in gremlin", "cve_id": "CVE-2024-27348", "vendor": "Apache", "ghsa_id": "GHSA-29RC-VQ7F-X335", "product": "Apache HugeGraph-Server", "added_date": "2024-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9921, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99935, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27348", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6c647fe4-c6e9-4a47-8818-e4060250150c", "vulnerability": {"vulnId": "CVE-2020-0618", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "6c647fe4-c6e9-4a47-8818-e4060250150c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-18T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft... | Affected: Microsoft / Microsoft SQL Server, Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU), Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU) | CVSS: 9.8 (CRITICAL) | EPSS: 0.99022 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0618", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0618"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0618"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft...", "cve_id": "CVE-2020-0618", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SQL Server, Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU), Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR), Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)", "added_date": "2024-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99022, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99931, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0618", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2eb7940b-49ea-4e57-837b-095872ad6bfe", "vulnerability": {"vulnId": "CVE-2020-14644", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "2eb7940b-49ea-4e57-837b-095872ad6bfe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-18T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.94548 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-14644", "url": "https://www.cve.org/CVERecord?id=CVE-2020-14644"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-14644"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are...", "cve_id": "CVE-2020-14644", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2024-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94548, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99853, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-14644", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cdc8bc42-2500-4551-8fb5-82d6670dced8", "vulnerability": {"vulnId": "CVE-2014-0502", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "cdc8bc42-2500-4551-8fb5-82d6670dced8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-17T00:00:00+00:00"}, "scope": {"notes": "Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.24817 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0502", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0502"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0502"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before...", "cve_id": "CVE-2014-0502", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2024-09-17T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.24817, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97842, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0502", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "886eed20-9abd-46c3-ad58-4e66b06a2166", "vulnerability": {"vulnId": "CVE-2013-0648", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "886eed20-9abd-46c3-ad58-4e66b06a2166", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-17T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.11094 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0648", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0648"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0648"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171...", "cve_id": "CVE-2013-0648", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2024-09-17T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.11094, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95801, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0648", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1537efd8-4978-4e52-8e89-600873de9da2", "vulnerability": {"vulnId": "CVE-2013-0643", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "1537efd8-4978-4e52-8e89-600873de9da2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-17T00:00:00+00:00"}, "scope": {"notes": "The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.10533 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0643", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0643"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0643"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x...", "cve_id": "CVE-2013-0643", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2024-09-17T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10533, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95638, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0643", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c35c2fe7-99c6-42b1-ac2c-c0074d28d39c", "vulnerability": {"vulnId": "CVE-2014-0497", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-17T02:00:00+02:00"}, "gcve": {"object_uuid": "c35c2fe7-99c6-42b1-ac2c-c0074d28d39c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-17T00:00:00+00:00"}, "scope": {"notes": "Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.99883 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0497", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0497"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0497"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before...", "cve_id": "CVE-2014-0497", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2024-09-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99883, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99964, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0497", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f221bbec-50e6-4c5d-97ac-4e23ff022180", "vulnerability": {"vulnId": "CVE-2024-43461", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "f221bbec-50e6-4c5d-97ac-4e23ff022180", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-16T00:00:00+00:00"}, "scope": {"notes": "Windows MSHTML Platform Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.54486 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-43461", "url": "https://www.cve.org/CVERecord?id=CVE-2024-43461"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-43461"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows MSHTML Platform Spoofing Vulnerability", "cve_id": "CVE-2024-43461", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-09-16T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.54486, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98986, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-43461", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8492fe36-cf6f-4f4b-84cd-7136a4b724bc", "vulnerability": {"vulnId": "CVE-2024-6670", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-16T02:00:00+02:00"}, "gcve": {"object_uuid": "8492fe36-cf6f-4f4b-84cd-7136a4b724bc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-16T00:00:00+00:00"}, "scope": {"notes": "WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability | Affected: Progress Software / WhatsUp Gold | CVSS: 9.8 (CRITICAL) | EPSS: 0.93 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-6670", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6670"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6670"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability", "cve_id": "CVE-2024-6670", "vendor": "Progress Software", "ghsa_id": null, "product": "WhatsUp Gold", "added_date": "2024-09-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9983, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-6670", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "05ac6788-4576-44fd-83c0-e22e5e267705", "vulnerability": {"vulnId": "CVE-2024-6587", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-13T17:59:53+02:00"}, "gcve": {"object_uuid": "05ac6788-4576-44fd-83c0-e22e5e267705", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-13T15:59:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-13T15:59:53+00:00"}, "scope": {"notes": "SSRF in berriai/litellm | Affected: Berriai / berriai/litellm | CVSS: 7.5 (HIGH) | EPSS: 0.35316 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6587", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6587"}, {"id": "GHSA-G26J-5385-HHW3", "url": "https://github.com/advisories/GHSA-G26J-5385-HHW3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6587"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SSRF in berriai/litellm", "cve_id": "CVE-2024-6587", "vendor": "Berriai", "ghsa_id": "GHSA-G26J-5385-HHW3", "product": "berriai/litellm", "added_date": "2024-09-13T15:59:53.000Z", "cvss_score": 7.5, "epss_score": 0.35316, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6587", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "928cd6ef-9350-4a2e-8180-0a9eae8f3e35", "vulnerability": {"vulnId": "CVE-2024-8190", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-13T02:00:00+02:00"}, "gcve": {"object_uuid": "928cd6ef-9350-4a2e-8180-0a9eae8f3e35", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-13T00:00:00+00:00"}, "scope": {"notes": "An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker... | Affected: Ivanti / CSA (Cloud Services Appliance) | CVSS: 7.2 (HIGH) | EPSS: 0.88535 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-8190", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8190"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8190"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker...", "cve_id": "CVE-2024-8190", "vendor": "Ivanti", "ghsa_id": null, "product": "CSA (Cloud Services Appliance)", "added_date": "2024-09-13T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.88535, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99771, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8190", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1dc30b86-3c51-4ec9-95fd-44bbb202a8a5", "vulnerability": {"vulnId": "CVE-2024-8522", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-12T10:30:46+02:00"}, "gcve": {"object_uuid": "1dc30b86-3c51-4ec9-95fd-44bbb202a8a5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-12T08:30:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-12T08:30:46+00:00"}, "scope": {"notes": "LearnPress \u2013 WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' | Affected: Thimpress / LearnPress \u2013 WordPress LMS Plugin | CVSS: 10.0 (CRITICAL) | EPSS: 0.62882 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-8522", "url": "https://www.cve.org/CVERecord?id=CVE-2024-8522"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-8522"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LearnPress \u2013 WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'", "cve_id": "CVE-2024-8522", "vendor": "Thimpress", "ghsa_id": null, "product": "LearnPress \u2013 WordPress LMS Plugin", "added_date": "2024-09-12T08:30:46.000Z", "cvss_score": 10.0, "epss_score": 0.62882, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99175, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-8522", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ca4abb55-3c8f-4c00-86e1-7cbb17d53e4c", "vulnerability": {"vulnId": "CVE-2024-38226", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "ca4abb55-3c8f-4c00-86e1-7cbb17d53e4c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-10T00:00:00+00:00"}, "scope": {"notes": "Microsoft Publisher Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Publisher 2016 | CVSS: 7.3 (HIGH) | EPSS: 0.02667 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38226", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38226"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38226"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Publisher Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-38226", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office 2019, Microsoft Office LTSC 2021, Microsoft Publisher 2016", "added_date": "2024-09-10T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.02667, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8521, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38226", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8052da60-84e5-48ee-a8a9-7a79c22b7eb9", "vulnerability": {"vulnId": "CVE-2024-38217", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "8052da60-84e5-48ee-a8a9-7a79c22b7eb9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-10T00:00:00+00:00"}, "scope": {"notes": "Windows Mark of the Web Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 5.4 (MEDIUM) | EPSS: 0.10026 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38217", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38217"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38217"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Mark of the Web Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-38217", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-09-10T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.10026, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95482, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38217", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "00341c61-6e7d-4b4c-b45a-71fd0e170e29", "vulnerability": {"vulnId": "CVE-2024-38014", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-10T02:00:00+02:00"}, "gcve": {"object_uuid": "00341c61-6e7d-4b4c-b45a-71fd0e170e29", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-10T00:00:00+00:00"}, "scope": {"notes": "Windows Installer Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.06263 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38014", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38014"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38014"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Installer Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-38014", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-09-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.06263, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93357, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38014", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ba059197-346b-4843-99dd-b40752ec51a4", "vulnerability": {"vulnId": "CVE-2024-40766", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-09T02:00:00+02:00"}, "gcve": {"object_uuid": "ba059197-346b-4843-99dd-b40752ec51a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-09T00:00:00+00:00"}, "scope": {"notes": "An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized... | Affected: SonicWall / SonicOS | CVSS: 9.3 (CRITICAL) | EPSS: 0.18379 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-40766", "url": "https://www.cve.org/CVERecord?id=CVE-2024-40766"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-40766"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized...", "cve_id": "CVE-2024-40766", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicOS", "added_date": "2024-09-09T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.18379, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97148, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-40766", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0fe8a5aa-ca6d-4e76-bf4d-fffeabf0f5c2", "vulnerability": {"vulnId": "CVE-2016-3714", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-09T02:00:00+02:00"}, "gcve": {"object_uuid": "0fe8a5aa-ca6d-4e76-bf4d-fffeabf0f5c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-09T00:00:00+00:00"}, "scope": {"notes": "The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before... | Affected: ImageMagick / ImageMagick | CVSS: 8.4 (HIGH) | EPSS: 0.97485 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3714", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3714"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3714"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before...", "cve_id": "CVE-2016-3714", "vendor": "ImageMagick", "ghsa_id": null, "product": "ImageMagick", "added_date": "2024-09-09T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.97485, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.999, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3714", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "48abdf35-839c-48ea-b795-40896bc14b4e", "vulnerability": {"vulnId": "CVE-2017-1000253", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-09T02:00:00+02:00"}, "gcve": {"object_uuid": "48abdf35-839c-48ea-b795-40896bc14b4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-09T00:00:00+00:00"}, "scope": {"notes": "Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86... | Affected: Linux / Kernel | CVSS: 7.8 (HIGH) | EPSS: 0.10695 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-1000253", "url": "https://www.cve.org/CVERecord?id=CVE-2017-1000253"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-1000253"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86...", "cve_id": "CVE-2017-1000253", "vendor": "Linux", "ghsa_id": null, "product": "Kernel", "added_date": "2024-09-09T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10695, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95686, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-1000253", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "324b2763-7817-4eba-9b4c-90b5e1cb24af", "vulnerability": {"vulnId": "CVE-2024-45506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-04T02:00:00+02:00"}, "gcve": {"object_uuid": "324b2763-7817-4eba-9b4c-90b5e1cb24af", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-04T00:00:00+00:00"}, "scope": {"notes": "HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding... | Affected: HAProxy / HAProxy | CVSS: 7.5 (HIGH) | EPSS: 0.01203 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-45506", "url": "https://www.cve.org/CVERecord?id=CVE-2024-45506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-45506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding...", "cve_id": "CVE-2024-45506", "vendor": "HAProxy", "ghsa_id": null, "product": "HAProxy", "added_date": "2024-09-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01203, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.67132, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-45506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f85536f0-ab03-4906-b942-f83c35a3cd6d", "vulnerability": {"vulnId": "CVE-2021-20123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-03T02:00:00+02:00"}, "gcve": {"object_uuid": "f85536f0-ab03-4906-b942-f83c35a3cd6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-03T00:00:00+00:00"}, "scope": {"notes": "A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet... | Affected: Draytek / Draytek VigorConnect | CVSS: 7.5 (HIGH) | EPSS: 0.90234 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20123", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20123"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet...", "cve_id": "CVE-2021-20123", "vendor": "Draytek", "ghsa_id": null, "product": "Draytek VigorConnect", "added_date": "2024-09-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.90234, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99796, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fa971b39-7428-43ac-bcec-6a289ae89c20", "vulnerability": {"vulnId": "CVE-2021-20124", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-03T02:00:00+02:00"}, "gcve": {"object_uuid": "fa971b39-7428-43ac-bcec-6a289ae89c20", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-03T00:00:00+00:00"}, "scope": {"notes": "A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An... | Affected: Draytek / Draytek VigorConnect | CVSS: 7.5 (HIGH) | EPSS: 0.96308 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20124", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20124"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20124"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An...", "cve_id": "CVE-2021-20124", "vendor": "Draytek", "ghsa_id": null, "product": "Draytek VigorConnect", "added_date": "2024-09-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.96308, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99879, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20124", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4b880a5e-9e98-4e2c-b31f-bda6f7570f30", "vulnerability": {"vulnId": "CVE-2024-7262", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-09-03T02:00:00+02:00"}, "gcve": {"object_uuid": "4b880a5e-9e98-4e2c-b31f-bda6f7570f30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-09-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-09-03T00:00:00+00:00"}, "scope": {"notes": "Arbitrary Code Execution in WPS Office | Affected: Kingsoft / WPS Office | CVSS: 9.3 (CRITICAL) | EPSS: 0.02937 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-7262", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7262"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7262"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary Code Execution in WPS Office", "cve_id": "CVE-2024-7262", "vendor": "Kingsoft", "ghsa_id": null, "product": "WPS Office", "added_date": "2024-09-03T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.02937, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86622, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7262", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "73d342f5-9064-4ffb-be43-be4da4b65093", "vulnerability": {"vulnId": "CVE-2024-7965", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-28T02:00:00+02:00"}, "gcve": {"object_uuid": "73d342f5-9064-4ffb-be43-be4da4b65093", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-28T00:00:00+00:00"}, "scope": {"notes": "Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.18528 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-7965", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7965"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7965"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2024-7965", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-08-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.18528, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9717, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7965", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5af7e7ec-5f90-4973-af57-c92b462af0d4", "vulnerability": {"vulnId": "CVE-2024-38856", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-27T02:00:00+02:00"}, "gcve": {"object_uuid": "5af7e7ec-5f90-4973-af57-c92b462af0d4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-27T00:00:00+00:00"}, "scope": {"notes": "Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code | Affected: Apache / Apache OFBiz | CVSS: 9.8 (CRITICAL) | EPSS: 0.99427 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38856", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38856"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38856"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code", "cve_id": "CVE-2024-38856", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2024-08-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99427, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38856", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0b77f18a-7b2c-4101-8677-1ebe7076b753", "vulnerability": {"vulnId": "CVE-2024-7971", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-26T02:00:00+02:00"}, "gcve": {"object_uuid": "0b77f18a-7b2c-4101-8677-1ebe7076b753", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-26T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.21103 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-7971", "url": "https://www.cve.org/CVERecord?id=CVE-2024-7971"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-7971"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page....", "cve_id": "CVE-2024-7971", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-08-26T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.21103, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97513, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-7971", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f4f995f3-4b73-4b94-8689-329ae891f27c", "vulnerability": {"vulnId": "CVE-2024-39717", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-23T02:00:00+02:00"}, "gcve": {"object_uuid": "f4f995f3-4b73-4b94-8689-329ae891f27c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-23T00:00:00+00:00"}, "scope": {"notes": "The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged... | Affected: Versa / Director | CVSS: 6.6 (MEDIUM) | EPSS: 0.04006 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-39717", "url": "https://www.cve.org/CVERecord?id=CVE-2024-39717"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-39717"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged...", "cve_id": "CVE-2024-39717", "vendor": "Versa", "ghsa_id": null, "product": "Director", "added_date": "2024-08-23T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.04006, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90227, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-39717", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "36fd333d-016e-4870-99ad-6debf308eca5", "vulnerability": {"vulnId": "CVE-2024-28000", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-21T09:11:12+02:00"}, "gcve": {"object_uuid": "36fd333d-016e-4870-99ad-6debf308eca5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-21T07:11:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-21T07:11:12+00:00"}, "scope": {"notes": "WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability | Affected: LiteSpeed Technologies / LiteSpeed Cache | CVSS: 9.8 (CRITICAL) | EPSS: 0.68266 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-28000", "url": "https://www.cve.org/CVERecord?id=CVE-2024-28000"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-28000"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability", "cve_id": "CVE-2024-28000", "vendor": "LiteSpeed Technologies", "ghsa_id": null, "product": "LiteSpeed Cache", "added_date": "2024-08-21T07:11:12.000Z", "cvss_score": 9.8, "epss_score": 0.68266, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99312, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-28000", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "37df7b0b-0e22-4ad3-8faf-426e4c8c3b45", "vulnerability": {"vulnId": "CVE-2021-33044", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "37df7b0b-0e22-4ad3-8faf-426e4c8c3b45", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-21T00:00:00+00:00"}, "scope": {"notes": "The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity... | Affected: Dahua / Some Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devices | CVSS: 9.8 (CRITICAL) | EPSS: 0.99987 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-33044", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33044"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33044"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity...", "cve_id": "CVE-2021-33044", "vendor": "Dahua", "ghsa_id": null, "product": "Some Dahua IP Camera, Video Intercom, PTZ Dome Camera, Thermal Camera devices", "added_date": "2024-08-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99987, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99984, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33044", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "90b9b58b-82fc-4a5a-893e-16a936c495bd", "vulnerability": {"vulnId": "CVE-2021-31196", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "90b9b58b-82fc-4a5a-893e-16a936c495bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-21T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2019 Cumulative Update 9 | CVSS: 7.2 (HIGH) | EPSS: 0.54056 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31196", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31196"}, {"id": "GHSA-5JV9-CFF9-2J3M", "url": "https://github.com/advisories/GHSA-5JV9-CFF9-2J3M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31196"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-31196", "vendor": "Microsoft", "ghsa_id": "GHSA-5JV9-CFF9-2J3M", "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2019 Cumulative Update 9", "added_date": "2024-08-21T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.54056, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98975, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31196", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20beaace-0f09-4cf7-a654-be192061022c", "vulnerability": {"vulnId": "CVE-2022-0185", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "20beaace-0f09-4cf7-a654-be192061022c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-21T00:00:00+00:00"}, "scope": {"notes": "A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel... | Affected: Linux / kernel | CVSS: 8.4 (HIGH) | EPSS: 0.25151 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0185", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0185"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0185"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel...", "cve_id": "CVE-2022-0185", "vendor": "Linux", "ghsa_id": null, "product": "kernel", "added_date": "2024-08-21T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.25151, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97873, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0185", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3a86134a-2f92-49e8-b308-71c434d50353", "vulnerability": {"vulnId": "CVE-2021-33045", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "3a86134a-2f92-49e8-b308-71c434d50353", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-21T00:00:00+00:00"}, "scope": {"notes": "The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity... | Affected: Dahua / Some Dahua IP Camera, Video Intercom, NVR, XVR devices | CVSS: 9.8 (CRITICAL) | EPSS: 0.99593 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-33045", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33045"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33045"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity...", "cve_id": "CVE-2021-33045", "vendor": "Dahua", "ghsa_id": null, "product": "Some Dahua IP Camera, Video Intercom, NVR, XVR devices", "added_date": "2024-08-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99593, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33045", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "40ea9142-d9cf-459d-b27f-acbc3798fe7a", "vulnerability": {"vulnId": "CVE-2024-23897", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-19T02:00:00+02:00"}, "gcve": {"object_uuid": "40ea9142-d9cf-459d-b27f-acbc3798fe7a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-19T00:00:00+00:00"}, "scope": {"notes": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by... | Affected: Jenkins Project / Jenkins | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-23897", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23897"}, {"id": "GHSA-6F9G-CXWR-Q5JR", "url": "https://github.com/advisories/GHSA-6F9G-CXWR-Q5JR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23897"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by...", "cve_id": "CVE-2024-23897", "vendor": "Jenkins Project", "ghsa_id": "GHSA-6F9G-CXWR-Q5JR", "product": "Jenkins", "added_date": "2024-08-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99995, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-23897", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "448e5ab1-4da8-4e17-abc1-c11961bb33a9", "vulnerability": {"vulnId": "CVE-2024-28986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-15T02:00:00+02:00"}, "gcve": {"object_uuid": "448e5ab1-4da8-4e17-abc1-c11961bb33a9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-15T00:00:00+00:00"}, "scope": {"notes": "SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability | Affected: SolarWinds / Web Help Desk | CVSS: 9.8 (CRITICAL) | EPSS: 0.84628 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-28986", "url": "https://www.cve.org/CVERecord?id=CVE-2024-28986"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-28986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability", "cve_id": "CVE-2024-28986", "vendor": "SolarWinds", "ghsa_id": null, "product": "Web Help Desk", "added_date": "2024-08-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84628, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99699, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-28986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f5be7ce-33e7-4ebc-98a3-21fe9cbfc4d3", "vulnerability": {"vulnId": "CVE-2024-38107", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-13T02:00:00+02:00"}, "gcve": {"object_uuid": "2f5be7ce-33e7-4ebc-98a3-21fe9cbfc4d3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-13T00:00:00+00:00"}, "scope": {"notes": "Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2 | CVSS: 7.8 (HIGH) | EPSS: 0.01635 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38107", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38107"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38107"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Power Dependency Coordinator Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-38107", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 11 Version 24H2", "added_date": "2024-08-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01635, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75424, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38107", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b755e5bc-e825-4ecc-94c6-edf30f2259f8", "vulnerability": {"vulnId": "CVE-2024-38193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-13T02:00:00+02:00"}, "gcve": {"object_uuid": "b755e5bc-e825-4ecc-94c6-edf30f2259f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-13T00:00:00+00:00"}, "scope": {"notes": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.28529 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38193", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-38193", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2024-08-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.28529, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98078, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d4b2cfc-5be5-4620-84e7-11666955638a", "vulnerability": {"vulnId": "CVE-2024-38213", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-13T02:00:00+02:00"}, "gcve": {"object_uuid": "9d4b2cfc-5be5-4620-84e7-11666955638a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-13T00:00:00+00:00"}, "scope": {"notes": "Windows Mark of the Web Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 6.5 (MEDIUM) | EPSS: 0.13626 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38213", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38213"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38213"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Mark of the Web Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-38213", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2024-08-13T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.13626, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96366, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38213", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "049e749a-5fb7-40bc-8b9e-18242615a157", "vulnerability": {"vulnId": "CVE-2024-38178", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-13T02:00:00+02:00"}, "gcve": {"object_uuid": "049e749a-5fb7-40bc-8b9e-18242615a157", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-13T00:00:00+00:00"}, "scope": {"notes": "Scripting Engine Memory Corruption Vulnerability | Affected: Microsoft / Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.5 (HIGH) | EPSS: 0.4138 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38178", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38178"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38178"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Scripting Engine Memory Corruption Vulnerability", "cve_id": "CVE-2024-38178", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2024-08-13T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.4138, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38178", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5e97cc1b-0cb8-49d6-8706-ef683326a9a3", "vulnerability": {"vulnId": "CVE-2024-38189", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-13T02:00:00+02:00"}, "gcve": {"object_uuid": "5e97cc1b-0cb8-49d6-8706-ef683326a9a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-13T00:00:00+00:00"}, "scope": {"notes": "Microsoft Project Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Project 2016, Microsoft Office LTSC 2021 | CVSS: 8.8 (HIGH) | EPSS: 0.08194 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38189", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38189"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38189"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Project Remote Code Execution Vulnerability", "cve_id": "CVE-2024-38189", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Project 2016, Microsoft Office LTSC 2021", "added_date": "2024-08-13T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.08194, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94707, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38189", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7a5af278-80d5-4c60-a9f0-46c62ed8b0f8", "vulnerability": {"vulnId": "CVE-2024-38106", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-13T02:00:00+02:00"}, "gcve": {"object_uuid": "7a5af278-80d5-4c60-a9f0-46c62ed8b0f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-13T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2 | CVSS: 7.0 (HIGH) | EPSS: 0.06337 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38106", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38106"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38106"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-38106", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 11 Version 24H2", "added_date": "2024-08-13T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.06337, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93423, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38106", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6ff24f4f-6b0e-403e-a1be-6944c0ea5a90", "vulnerability": {"vulnId": "CVE-2024-32113", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-07T02:00:00+02:00"}, "gcve": {"object_uuid": "6ff24f4f-6b0e-403e-a1be-6944c0ea5a90", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-07T00:00:00+00:00"}, "scope": {"notes": "Apache OFBiz: Path traversal leading to RCE | Affected: Apache / Apache OFBiz | CVSS: 9.1 (CRITICAL) | EPSS: 0.99919 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-32113", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32113"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32113"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache OFBiz: Path traversal leading to RCE", "cve_id": "CVE-2024-32113", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2024-08-07T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.99919, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99968, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32113", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "711ce96d-0afd-48b2-9b0e-8daf47c7808f", "vulnerability": {"vulnId": "CVE-2024-36971", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-07T02:00:00+02:00"}, "gcve": {"object_uuid": "711ce96d-0afd-48b2-9b0e-8daf47c7808f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-07T00:00:00+00:00"}, "scope": {"notes": "net: fix __dst_negative_advice() race | Affected: Linux / Linux | CVSS: 7.8 (HIGH) | EPSS: 0.02701 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-36971", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36971"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36971"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "net: fix __dst_negative_advice() race", "cve_id": "CVE-2024-36971", "vendor": "Linux", "ghsa_id": null, "product": "Linux", "added_date": "2024-08-07T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02701, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85412, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36971", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4168c303-b10c-4c31-9e67-d760cfc793e3", "vulnerability": {"vulnId": "CVE-2018-0824", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-08-05T02:00:00+02:00"}, "gcve": {"object_uuid": "4168c303-b10c-4c31-9e67-d760cfc793e3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-08-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-08-05T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in \"Microsoft COM for Windows\" when it fails to properly handle serialized objects, aka \"Microsoft COM... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.73185 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0824", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0824"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0824"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in \"Microsoft COM for Windows\" when it fails to properly handle serialized objects, aka \"Microsoft COM...", "cve_id": "CVE-2018-0824", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2024-08-05T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.73185, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99445, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0824", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6c7149c-4f94-4ecc-b4ab-0d5c7f5bd805", "vulnerability": {"vulnId": "CVE-2024-6220", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-31T11:34:09+02:00"}, "gcve": {"object_uuid": "a6c7149c-4f94-4ecc-b4ab-0d5c7f5bd805", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-31T09:34:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-31T09:34:09+00:00"}, "scope": {"notes": "\u7b80\u6570\u91c7\u96c6\u5668 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload | Affected: Zhengdon / \u7b80\u6570\u91c7\u96c6\u5668 | CVSS: 9.8 (CRITICAL) | EPSS: 0.35463 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6220", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6220"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6220"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "\u7b80\u6570\u91c7\u96c6\u5668 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2024-6220", "vendor": "Zhengdon", "ghsa_id": null, "product": "\u7b80\u6570\u91c7\u96c6\u5668", "added_date": "2024-07-31T09:34:09.000Z", "cvss_score": 9.8, "epss_score": 0.35463, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98408, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6220", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e2e16c2a-ef54-42bc-8c9f-b414087b8ec3", "vulnerability": {"vulnId": "CVE-2024-37085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-30T02:00:00+02:00"}, "gcve": {"object_uuid": "e2e16c2a-ef54-42bc-8c9f-b414087b8ec3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-30T00:00:00+00:00"}, "scope": {"notes": "VMware ESXi contains an authentication bypass vulnerability.\u00a0A malicious actor with sufficient Active Directory (AD) permissions can gain full... | Affected: VMware / VMware ESXi, VMware Cloud Foundation | CVSS: 6.8 (MEDIUM) | EPSS: 0.2677 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-37085", "url": "https://www.cve.org/CVERecord?id=CVE-2024-37085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-37085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware ESXi contains an authentication bypass vulnerability.\u00a0A malicious actor with sufficient Active Directory (AD) permissions can gain full...", "cve_id": "CVE-2024-37085", "vendor": "VMware", "ghsa_id": null, "product": "VMware ESXi, VMware Cloud Foundation", "added_date": "2024-07-30T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.2677, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97972, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-37085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bf0b85be-a186-4a53-a33a-b2a4b2661df5", "vulnerability": {"vulnId": "CVE-2024-4879", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "bf0b85be-a186-4a53-a33a-b2a4b2661df5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-29T00:00:00+00:00"}, "scope": {"notes": "Jelly Template Injection Vulnerability in ServiceNow UI Macros | Affected: ServiceNow / Now Platform | CVSS: 9.3 (CRITICAL) | EPSS: 0.99976 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4879", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4879"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4879"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Jelly Template Injection Vulnerability in ServiceNow UI Macros", "cve_id": "CVE-2024-4879", "vendor": "ServiceNow", "ghsa_id": null, "product": "Now Platform", "added_date": "2024-07-29T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.99976, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4879", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "beb8fc64-9b80-4563-b9a5-c5c832afc4b7", "vulnerability": {"vulnId": "CVE-2024-5217", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "beb8fc64-9b80-4563-b9a5-c5c832afc4b7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-29T00:00:00+00:00"}, "scope": {"notes": "Incomplete Input Validation in GlideExpression Script | Affected: ServiceNow / Now Platform | CVSS: 9.2 (CRITICAL) | EPSS: 0.99628 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-5217", "url": "https://www.cve.org/CVERecord?id=CVE-2024-5217"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-5217"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incomplete Input Validation in GlideExpression Script", "cve_id": "CVE-2024-5217", "vendor": "ServiceNow", "ghsa_id": null, "product": "Now Platform", "added_date": "2024-07-29T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.99628, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99948, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-5217", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cb858d9d-8df3-4ec9-9e22-65f733c94248", "vulnerability": {"vulnId": "CVE-2023-45249", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "cb858d9d-8df3-4ec9-9e22-65f733c94248", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-29T00:00:00+00:00"}, "scope": {"notes": "Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build... | Affected: Acronis / Acronis Cyber Infrastructure | CVSS: 9.8 (CRITICAL) | EPSS: 0.53255 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-45249", "url": "https://www.cve.org/CVERecord?id=CVE-2023-45249"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-45249"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build...", "cve_id": "CVE-2023-45249", "vendor": "Acronis", "ghsa_id": null, "product": "Acronis Cyber Infrastructure", "added_date": "2024-07-29T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.53255, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98952, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-45249", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "09d26c0f-9e1a-4914-8fa9-92cc831eb615", "vulnerability": {"vulnId": "CVE-2012-4792", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-23T02:00:00+02:00"}, "gcve": {"object_uuid": "09d26c0f-9e1a-4914-8fa9-92cc831eb615", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-23T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.78823 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-4792", "url": "https://www.cve.org/CVERecord?id=CVE-2012-4792"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-4792"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site...", "cve_id": "CVE-2012-4792", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2024-07-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.78823, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99583, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-4792", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7428105e-84ef-4423-8bd7-81375b7c3147", "vulnerability": {"vulnId": "CVE-2024-39891", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-23T02:00:00+02:00"}, "gcve": {"object_uuid": "7428105e-84ef-4423-8bd7-81375b7c3147", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-23T00:00:00+00:00"}, "scope": {"notes": "In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to... | Affected: Twilio / Authy | CVSS: 5.3 (MEDIUM) | EPSS: 0.01669 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-39891", "url": "https://www.cve.org/CVERecord?id=CVE-2024-39891"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-39891"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to...", "cve_id": "CVE-2024-39891", "vendor": "Twilio", "ghsa_id": null, "product": "Authy", "added_date": "2024-07-23T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.01669, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7592, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-39891", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e45315da-17c3-4148-ad4d-8c23878ecfe5", "vulnerability": {"vulnId": "CVE-2024-28995", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-17T02:00:00+02:00"}, "gcve": {"object_uuid": "e45315da-17c3-4148-ad4d-8c23878ecfe5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-17T00:00:00+00:00"}, "scope": {"notes": "SolarWinds Serv-U L Directory Transversal Vulnerability | Affected: SolarWinds / SolarWinds Serv-U | CVSS: 8.6 (HIGH) | EPSS: 0.99614 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-28995", "url": "https://www.cve.org/CVERecord?id=CVE-2024-28995"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-28995"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Serv-U L Directory Transversal Vulnerability", "cve_id": "CVE-2024-28995", "vendor": "SolarWinds", "ghsa_id": null, "product": "SolarWinds Serv-U", "added_date": "2024-07-17T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.99614, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99948, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-28995", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9a8f1012-264d-4f0d-ae4e-1c2070e59f4f", "vulnerability": {"vulnId": "CVE-2022-22948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-17T02:00:00+02:00"}, "gcve": {"object_uuid": "9a8f1012-264d-4f0d-ae4e-1c2070e59f4f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-17T00:00:00+00:00"}, "scope": {"notes": "The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative... | Affected: VMware / VMware vCenter Server and VMware Cloud Foundation | CVSS: 6.5 (MEDIUM) | EPSS: 0.13282 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22948", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative...", "cve_id": "CVE-2022-22948", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server and VMware Cloud Foundation", "added_date": "2024-07-17T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.13282, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96279, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5a2b66ff-7532-4e88-bfa3-3667623ca3ab", "vulnerability": {"vulnId": "CVE-2024-36401", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-15T02:00:00+02:00"}, "gcve": {"object_uuid": "5a2b66ff-7532-4e88-bfa3-3667623ca3ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-15T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver | Affected: Geoserver / geoserver | CVSS: 9.8 (CRITICAL) | EPSS: 0.99813 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-36401", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36401"}, {"id": "GHSA-6JJ6-GM7P-FCVV", "url": "https://github.com/advisories/GHSA-6JJ6-GM7P-FCVV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36401"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver", "cve_id": "CVE-2024-36401", "vendor": "Geoserver", "ghsa_id": "GHSA-6JJ6-GM7P-FCVV", "product": "geoserver", "added_date": "2024-07-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99813, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99958, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36401", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c71cfcc3-3071-4073-867d-b0d9fffbf6dc", "vulnerability": {"vulnId": "CVE-2024-23692", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-09T02:00:00+02:00"}, "gcve": {"object_uuid": "c71cfcc3-3071-4073-867d-b0d9fffbf6dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-09T00:00:00+00:00"}, "scope": {"notes": "Rejetto HTTP File Server 2.3m Unauthenticated RCE | Affected: Rejetto / HTTP File Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99485 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-23692", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23692"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23692"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Rejetto HTTP File Server 2.3m Unauthenticated RCE", "cve_id": "CVE-2024-23692", "vendor": "Rejetto", "ghsa_id": null, "product": "HTTP File Server", "added_date": "2024-07-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99485, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99944, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-23692", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ddd61ad3-5e5b-458c-bd13-b1012cf997c3", "vulnerability": {"vulnId": "CVE-2024-38080", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-09T02:00:00+02:00"}, "gcve": {"object_uuid": "ddd61ad3-5e5b-458c-bd13-b1012cf997c3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-09T00:00:00+00:00"}, "scope": {"notes": "Windows Hyper-V Elevation of Privilege Vulnerability | Affected: Microsoft / Windows Server 2022, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.07115 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38080", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38080"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38080"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Hyper-V Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-38080", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2022, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-07-09T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07115, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94055, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38080", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "67d46b3d-e994-4dcc-89bc-9d9b11542544", "vulnerability": {"vulnId": "CVE-2024-38112", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-09T02:00:00+02:00"}, "gcve": {"object_uuid": "67d46b3d-e994-4dcc-89bc-9d9b11542544", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-09T00:00:00+00:00"}, "scope": {"notes": "Windows MSHTML Platform Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 10 Version 1507, Windows 11 version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows 10 Version 1809, Windows Server 2012 R2, Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 21H2, Windows Server 2019 | CVSS: 7.5 (HIGH) | EPSS: 0.84225 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-38112", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38112"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38112"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows MSHTML Platform Spoofing Vulnerability", "cve_id": "CVE-2024-38112", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 10 Version 1507, Windows 11 version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows 10 Version 21H2, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows 10 Version 1809, Windows Server 2012 R2, Windows 11 version 22H3, Windows Server 2012 R2 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 21H2, Windows Server 2019", "added_date": "2024-07-09T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.84225, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99691, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38112", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f4b02d54-3ae3-4fcd-8525-3cac56b43bb8", "vulnerability": {"vulnId": "CVE-2024-6298", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-05T13:06:35+02:00"}, "gcve": {"object_uuid": "f4b02d54-3ae3-4fcd-8525-3cac56b43bb8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-05T11:06:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-05T11:06:35+00:00"}, "scope": {"notes": "remote code execution | Affected: ABB / ASPECT-Enterprise, NEXUS Series, MATRIX Series | CVSS: 9.4 (CRITICAL) | EPSS: 0.1901 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6298", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6298"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6298"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "remote code execution", "cve_id": "CVE-2024-6298", "vendor": "ABB", "ghsa_id": null, "product": "ASPECT-Enterprise, NEXUS Series, MATRIX Series", "added_date": "2024-07-05T11:06:35.000Z", "cvss_score": 9.4, "epss_score": 0.1901, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97225, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6298", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8e751031-953b-4460-84fd-24677ef4f7c7", "vulnerability": {"vulnId": "CVE-2024-20399", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-02T02:00:00+02:00"}, "gcve": {"object_uuid": "8e751031-953b-4460-84fd-24677ef4f7c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-02T00:00:00+00:00"}, "scope": {"notes": "Cisco NX-OS Software CLI Command Injection Vulnerability | Affected: Cisco / Cisco NX-OS Software | CVSS: 6.0 (MEDIUM) | EPSS: 0.04306 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20399", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20399"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20399"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco NX-OS Software CLI Command Injection Vulnerability", "cve_id": "CVE-2024-20399", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco NX-OS Software", "added_date": "2024-07-02T00:00:00.000Z", "cvss_score": 6.0, "epss_score": 0.04306, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9084, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20399", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e74afa40-8f48-4e23-84fb-8ba8babcd4be", "vulnerability": {"vulnId": "CVE-2024-36991", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-07-01T18:31:03+02:00"}, "gcve": {"object_uuid": "e74afa40-8f48-4e23-84fb-8ba8babcd4be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-07-01T16:31:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-07-01T16:31:03+00:00"}, "scope": {"notes": "Path Traversal on the \u201c/modules/messaging/\u201c endpoint in Splunk Enterprise on Windows | Affected: Splunk / Splunk Enterprise | CVSS: 7.5 (HIGH) | EPSS: 0.13006 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-36991", "url": "https://www.cve.org/CVERecord?id=CVE-2024-36991"}, {"id": "GHSA-FG59-J242-RCJ9", "url": "https://github.com/advisories/GHSA-FG59-J242-RCJ9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-36991"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path Traversal on the \u201c/modules/messaging/\u201c endpoint in Splunk Enterprise on Windows", "cve_id": "CVE-2024-36991", "vendor": "Splunk", "ghsa_id": "GHSA-FG59-J242-RCJ9", "product": "Splunk Enterprise", "added_date": "2024-07-01T16:31:03.000Z", "cvss_score": 7.5, "epss_score": 0.13006, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96218, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-36991", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "04faa7f9-c25e-4d4f-afb2-cbb68eec2395", "vulnerability": {"vulnId": "CVE-2024-38514", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-28T20:11:02+02:00"}, "gcve": {"object_uuid": "04faa7f9-c25e-4d4f-afb2-cbb68eec2395", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-28T18:11:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-28T18:11:02+00:00"}, "scope": {"notes": "NextChat Server-Side Request Forgery (SSRF) | Affected: ChatGPTNextWeb / ChatGPT-Next-Web | CVSS: 7.4 (HIGH) | EPSS: 0.02168 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-38514", "url": "https://www.cve.org/CVERecord?id=CVE-2024-38514"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-38514"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NextChat Server-Side Request Forgery (SSRF)", "cve_id": "CVE-2024-38514", "vendor": "ChatGPTNextWeb", "ghsa_id": null, "product": "ChatGPT-Next-Web", "added_date": "2024-06-28T18:11:02.000Z", "cvss_score": 7.4, "epss_score": 0.02168, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81599, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-38514", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "160c9450-911c-42d1-a86e-b2294110ea42", "vulnerability": {"vulnId": "CVE-2020-13965", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "160c9450-911c-42d1-a86e-b2294110ea42", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-26T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is... | Affected: Roundcube / Webmail | CVSS: 6.1 (MEDIUM) | EPSS: 0.76596 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-13965", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13965"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13965"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is...", "cve_id": "CVE-2020-13965", "vendor": "Roundcube", "ghsa_id": null, "product": "Webmail", "added_date": "2024-06-26T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.76596, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99529, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13965", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1acee94d-fad6-4712-8db9-3205e202b912", "vulnerability": {"vulnId": "CVE-2022-24816", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "1acee94d-fad6-4712-8db9-3205e202b912", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-26T00:00:00+00:00"}, "scope": {"notes": "Improper Control of Generation of Code in jai-ext | Affected: Geosolutions-it / jai-ext | CVSS: 10.0 (CRITICAL) | EPSS: 0.99911 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24816", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24816"}, {"id": "GHSA-V92F-JX6P-73RX", "url": "https://github.com/advisories/GHSA-V92F-JX6P-73RX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24816"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Control of Generation of Code in jai-ext", "cve_id": "CVE-2022-24816", "vendor": "Geosolutions-it", "ghsa_id": "GHSA-V92F-JX6P-73RX", "product": "jai-ext", "added_date": "2024-06-26T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99911, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99966, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24816", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c48de786-bf75-4e8f-a118-7071227294af", "vulnerability": {"vulnId": "CVE-2022-2586", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-26T02:00:00+02:00"}, "gcve": {"object_uuid": "c48de786-bf75-4e8f-a118-7071227294af", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-26T00:00:00+00:00"}, "scope": {"notes": "It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table... | Affected: Linux Kernel Organization / linux | CVSS: 5.3 (MEDIUM) | EPSS: 0.10202 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-2586", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2586"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2586"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table...", "cve_id": "CVE-2022-2586", "vendor": "Linux Kernel Organization", "ghsa_id": null, "product": "linux", "added_date": "2024-06-26T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.10202, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95536, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2586", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b51ebeba-30de-4c64-9084-9ebbb4a5c0a6", "vulnerability": {"vulnId": "CVE-2024-5806", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-25T17:04:37+02:00"}, "gcve": {"object_uuid": "b51ebeba-30de-4c64-9084-9ebbb4a5c0a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-25T15:04:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-25T15:04:37+00:00"}, "scope": {"notes": "MOVEit Transfer Authentication Bypass Vulnerability | Affected: Progress Software / MOVEit Transfer | CVSS: 9.1 (CRITICAL) | EPSS: 0.81474 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-5806", "url": "https://www.cve.org/CVERecord?id=CVE-2024-5806"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-5806"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MOVEit Transfer Authentication Bypass Vulnerability", "cve_id": "CVE-2024-5806", "vendor": "Progress Software", "ghsa_id": null, "product": "MOVEit Transfer", "added_date": "2024-06-25T15:04:37.000Z", "cvss_score": 9.1, "epss_score": 0.81474, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99632, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-5806", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6fbd4377-5142-4231-9764-d2939834d335", "vulnerability": {"vulnId": "CVE-2024-4841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-23T16:33:33+02:00"}, "gcve": {"object_uuid": "6fbd4377-5142-4231-9764-d2939834d335", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-23T14:33:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-23T14:33:33+00:00"}, "scope": {"notes": "Path Traversal in parisneo/lollms-webui | Affected: Parisneo / parisneo/lollms-webui | CVSS: 4.0 (MEDIUM) | EPSS: 0.00668 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-4841", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4841"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path Traversal in parisneo/lollms-webui", "cve_id": "CVE-2024-4841", "vendor": "Parisneo", "ghsa_id": null, "product": "parisneo/lollms-webui", "added_date": "2024-06-23T14:33:33.000Z", "cvss_score": 4.0, "epss_score": 0.00668, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50092, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "69db7fa5-7fff-404e-abad-7b66dc02dbff", "vulnerability": {"vulnId": "CVE-2024-6188", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-20T15:31:04+02:00"}, "gcve": {"object_uuid": "69db7fa5-7fff-404e-abad-7b66dc02dbff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-20T13:31:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-20T13:31:04+00:00"}, "scope": {"notes": "Parsec Automation TrackSYS pagedefinition direct request | Affected: Parsec Automation / TrackSYS | CVSS: 6.9 (MEDIUM) | EPSS: 0.02036 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-6188", "url": "https://www.cve.org/CVERecord?id=CVE-2024-6188"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-6188"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Parsec Automation TrackSYS pagedefinition direct request", "cve_id": "CVE-2024-6188", "vendor": "Parsec Automation", "ghsa_id": null, "product": "TrackSYS", "added_date": "2024-06-20T13:31:04.000Z", "cvss_score": 6.9, "epss_score": 0.02036, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80375, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-6188", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "029a47aa-9942-49eb-9eb5-a5d2bfc2f2f7", "vulnerability": {"vulnId": "CVE-2024-34102", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-13T11:05:02+02:00"}, "gcve": {"object_uuid": "029a47aa-9942-49eb-9eb5-a5d2bfc2f2f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-13T09:05:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-13T09:05:02+00:00"}, "scope": {"notes": "XXE can expose crypt key and other secrets granting full admin access | Affected: Adobe / Adobe Commerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.99994 | Used in malware: unknown | Listed 34 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-34102", "url": "https://www.cve.org/CVERecord?id=CVE-2024-34102"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-34102"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "XXE can expose crypt key and other secrets granting full admin access", "cve_id": "CVE-2024-34102", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Commerce", "added_date": "2024-06-13T09:05:02.253Z", "cvss_score": 9.8, "epss_score": 0.99994, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-34102", "ahead_of_cisa_kev": {"unit": "day", "count": 34}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "af3d0a8d-d629-4db8-b1db-f8cad3bf4b43", "vulnerability": {"vulnId": "CVE-2024-32896", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "af3d0a8d-d629-4db8-b1db-f8cad3bf4b43", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-13T00:00:00+00:00"}, "scope": {"notes": "there is a possible way to bypass  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.02985 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-32896", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32896"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32896"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "there is a possible way to bypass  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution...", "cve_id": "CVE-2024-32896", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2024-06-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02985, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86829, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32896", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "00cf4b1d-aa33-4d44-9dd6-315e7e11b6ff", "vulnerability": {"vulnId": "CVE-2024-26169", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "00cf4b1d-aa33-4d44-9dd6-315e7e11b6ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-13T00:00:00+00:00"}, "scope": {"notes": "Windows Error Reporting Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.04014 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-26169", "url": "https://www.cve.org/CVERecord?id=CVE-2024-26169"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-26169"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Error Reporting Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-26169", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2024-06-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04014, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90245, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-26169", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3f4956ba-8a3a-4ecd-8b7f-290390c36916", "vulnerability": {"vulnId": "CVE-2024-4358", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "3f4956ba-8a3a-4ecd-8b7f-290390c36916", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-13T00:00:00+00:00"}, "scope": {"notes": "Registration Authentication Bypass Vulnerability | Affected: Progress Software / Telerik Report Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.97482 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4358", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4358"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4358"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Registration Authentication Bypass Vulnerability", "cve_id": "CVE-2024-4358", "vendor": "Progress Software", "ghsa_id": null, "product": "Telerik Report Server", "added_date": "2024-06-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97482, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.999, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4358", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e621d8dd-2660-4706-ad98-825897ec54c1", "vulnerability": {"vulnId": "CVE-2024-4577", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-12T02:00:00+02:00"}, "gcve": {"object_uuid": "e621d8dd-2660-4706-ad98-825897ec54c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-12T00:00:00+00:00"}, "scope": {"notes": "Argument Injection in PHP-CGI | Affected: PHP Group / PHP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99987 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4577", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4577"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4577"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Argument Injection in PHP-CGI", "cve_id": "CVE-2024-4577", "vendor": "PHP Group", "ghsa_id": null, "product": "PHP", "added_date": "2024-06-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99987, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99983, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-4577", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2aa39c6c-1cef-4612-a100-196ad0362764", "vulnerability": {"vulnId": "CVE-2024-4610", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-12T02:00:00+02:00"}, "gcve": {"object_uuid": "2aa39c6c-1cef-4612-a100-196ad0362764", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-12T00:00:00+00:00"}, "scope": {"notes": "Mali GPU Kernel Driver allows improper GPU memory processing operations | Affected: Arm / Bifrost GPU Kernel Driver, Valhall GPU Kernel Driver | CVSS: 7.8 (HIGH) | EPSS: 0.00758 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4610", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4610"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4610"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mali GPU Kernel Driver allows improper GPU memory processing operations", "cve_id": "CVE-2024-4610", "vendor": "Arm", "ghsa_id": null, "product": "Bifrost GPU Kernel Driver, Valhall GPU Kernel Driver", "added_date": "2024-06-12T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00758, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.53542, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4610", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b308c785-3c9c-4347-99e2-4586ee4bea1d", "vulnerability": {"vulnId": "CVE-2017-3506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-06-03T02:00:00+02:00"}, "gcve": {"object_uuid": "b308c785-3c9c-4347-99e2-4586ee4bea1d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-06-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-06-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... | Affected: Oracle / WebLogic Server | CVSS: 7.4 (HIGH) | EPSS: 0.96281 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-3506", "url": "https://www.cve.org/CVERecord?id=CVE-2017-3506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-3506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...", "cve_id": "CVE-2017-3506", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2024-06-03T00:00:00.000Z", "cvss_score": 7.4, "epss_score": 0.96281, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-3506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "386c9a80-61bd-4ea8-855c-4b288bb0d06c", "vulnerability": {"vulnId": "CVE-2024-1086", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-30T02:00:00+02:00"}, "gcve": {"object_uuid": "386c9a80-61bd-4ea8-855c-4b288bb0d06c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-30T00:00:00+00:00"}, "scope": {"notes": "Use-after-free in Linux kernel's netfilter: nf_tables component | Affected: Linux / Kernel | CVSS: 7.8 (HIGH) | EPSS: 0.28058 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-1086", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1086"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1086"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free in Linux kernel's netfilter: nf_tables component", "cve_id": "CVE-2024-1086", "vendor": "Linux", "ghsa_id": null, "product": "Kernel", "added_date": "2024-05-30T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.28058, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98054, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-1086", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6663a89a-48ee-4c59-9c7c-3d3b14b296a0", "vulnerability": {"vulnId": "CVE-2024-24919", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-30T02:00:00+02:00"}, "gcve": {"object_uuid": "6663a89a-48ee-4c59-9c7c-3d3b14b296a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-30T00:00:00+00:00"}, "scope": {"notes": "Information disclosure | Affected: Check Point / Check Point Quantum Gateway, Spark Gateway and CloudGuard Network | CVSS: 8.6 (HIGH) | EPSS: 0.99978 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-24919", "url": "https://www.cve.org/CVERecord?id=CVE-2024-24919"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-24919"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Information disclosure", "cve_id": "CVE-2024-24919", "vendor": "Check Point", "ghsa_id": null, "product": "Check Point Quantum Gateway, Spark Gateway and CloudGuard Network", "added_date": "2024-05-30T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.99978, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9998, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-24919", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f2884bb6-03b8-4ce1-84d1-de20de85e5ad", "vulnerability": {"vulnId": "CVE-2024-4978", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-29T02:00:00+02:00"}, "gcve": {"object_uuid": "f2884bb6-03b8-4ce1-84d1-de20de85e5ad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-29T00:00:00+00:00"}, "scope": {"notes": "Malicious Code in Justice AV Solutions (JAVS) Viewer | Affected: Justice AV Solutions / Viewer | CVSS: 8.7 (HIGH) | EPSS: 0.26937 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4978", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4978"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4978"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Malicious Code in Justice AV Solutions (JAVS) Viewer", "cve_id": "CVE-2024-4978", "vendor": "Justice AV Solutions", "ghsa_id": null, "product": "Viewer", "added_date": "2024-05-29T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.26937, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4978", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eb3d4d59-681e-47f6-9317-24d4e03412c1", "vulnerability": {"vulnId": "CVE-2024-34854", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-28T18:30:49+02:00"}, "gcve": {"object_uuid": "eb3d4d59-681e-47f6-9317-24d4e03412c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-28T16:30:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-28T16:30:49+00:00"}, "scope": {"notes": "F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` | Affected: F-logic / DataCube3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.12752 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-34854", "url": "https://www.cve.org/CVERecord?id=CVE-2024-34854"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-34854"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`", "cve_id": "CVE-2024-34854", "vendor": "F-logic", "ghsa_id": null, "product": "DataCube3", "added_date": "2024-05-28T16:30:49.000Z", "cvss_score": 9.8, "epss_score": 0.12752, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96157, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-34854", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bf1ebcea-7b1a-4230-af57-b3e3d1be52c4", "vulnerability": {"vulnId": "CVE-2024-5274", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-28T02:00:00+02:00"}, "gcve": {"object_uuid": "bf1ebcea-7b1a-4230-af57-b3e3d1be52c4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-28T00:00:00+00:00"}, "scope": {"notes": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.07472 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-5274", "url": "https://www.cve.org/CVERecord?id=CVE-2024-5274"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-5274"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...", "cve_id": "CVE-2024-5274", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-05-28T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.07472, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94284, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-5274", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dce7ce84-b524-4d1d-acbd-301b3a28e520", "vulnerability": {"vulnId": "CVE-2020-17519", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "dce7ce84-b524-4d1d-acbd-301b3a28e520", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-23T00:00:00+00:00"}, "scope": {"notes": "Apache Flink directory traversal attack: reading remote files through the REST API | Affected: Apache / Apache Flink | CVSS: 7.5 (HIGH) | EPSS: 0.97809 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-17519", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17519"}, {"id": "GHSA-395W-QHQR-9FR6", "url": "https://github.com/advisories/GHSA-395W-QHQR-9FR6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17519"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Flink directory traversal attack: reading remote files through the REST API", "cve_id": "CVE-2020-17519", "vendor": "Apache", "ghsa_id": "GHSA-395W-QHQR-9FR6", "product": "Apache Flink", "added_date": "2024-05-23T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.97809, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17519", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9ae04c7f-95ef-400b-8c4c-76b7f5090fc7", "vulnerability": {"vulnId": "CVE-2024-21683", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-22T01:00:00+02:00"}, "gcve": {"object_uuid": "9ae04c7f-95ef-400b-8c4c-76b7f5090fc7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-21T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-21T23:00:00+00:00"}, "scope": {"notes": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.\n\nThis RCE (Remote... | Affected: Atlassian / Confluence Data Center | CVSS: 8.8 (HIGH) | EPSS: 0.88267 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-21683", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21683"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21683"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.\n\nThis RCE (Remote...", "cve_id": "CVE-2024-21683", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Data Center", "added_date": "2024-05-21T23:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.88267, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99767, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21683", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "932ea5bf-3276-4906-b7d9-11297cde6c96", "vulnerability": {"vulnId": "CVE-2024-27130", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-21T18:08:46+02:00"}, "gcve": {"object_uuid": "932ea5bf-3276-4906-b7d9-11297cde6c96", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-21T16:08:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-21T16:08:46+00:00"}, "scope": {"notes": "QTS, QuTS hero | Affected: QNAP / QTS, QuTS hero | CVSS: 7.2 (HIGH) | EPSS: 0.3752 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-27130", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27130"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27130"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "QTS, QuTS hero", "cve_id": "CVE-2024-27130", "vendor": "QNAP", "ghsa_id": null, "product": "QTS, QuTS hero", "added_date": "2024-05-21T16:08:46.000Z", "cvss_score": 7.2, "epss_score": 0.3752, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9849, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-27130", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a082d960-99a6-4704-b85a-e79e904bc6aa", "vulnerability": {"vulnId": "CVE-2024-34193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-20T19:32:46+02:00"}, "gcve": {"object_uuid": "a082d960-99a6-4704-b85a-e79e904bc6aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-20T17:32:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-20T17:32:46+00:00"}, "scope": {"notes": "smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause... | Affected: Smanga / smanga | CVSS: 7.5 (HIGH) | EPSS: 0.00623 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-34193", "url": "https://www.cve.org/CVERecord?id=CVE-2024-34193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-34193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vulnerability that can cause...", "cve_id": "CVE-2024-34193", "vendor": "Smanga", "ghsa_id": null, "product": "smanga", "added_date": "2024-05-20T17:32:46.000Z", "cvss_score": 7.5, "epss_score": 0.00623, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.47954, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-34193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1c41f8cb-cfb3-458a-a193-62c41c29955d", "vulnerability": {"vulnId": "CVE-2024-4947", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-20T02:00:00+02:00"}, "gcve": {"object_uuid": "1c41f8cb-cfb3-458a-a193-62c41c29955d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-20T00:00:00+00:00"}, "scope": {"notes": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.15236 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4947", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4947"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4947"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...", "cve_id": "CVE-2024-4947", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-05-20T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.15236, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96663, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4947", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a2f2d9be-374e-4a91-8b68-d6e0e16ec720", "vulnerability": {"vulnId": "CVE-2023-43208", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-20T02:00:00+02:00"}, "gcve": {"object_uuid": "a2f2d9be-374e-4a91-8b68-d6e0e16ec720", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-20T00:00:00+00:00"}, "scope": {"notes": "NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is... | Affected: NextGen Healthcare / Mirth Connect | CVSS: 9.8 (CRITICAL) | EPSS: 0.82708 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-43208", "url": "https://www.cve.org/CVERecord?id=CVE-2023-43208"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-43208"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is...", "cve_id": "CVE-2023-43208", "vendor": "NextGen Healthcare", "ghsa_id": null, "product": "Mirth Connect", "added_date": "2024-05-20T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82708, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99659, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-43208", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f873963f-e7e4-41b3-bd00-c705c75d74cf", "vulnerability": {"vulnId": "CVE-2024-4761", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-16T02:00:00+02:00"}, "gcve": {"object_uuid": "f873963f-e7e4-41b3-bd00-c705c75d74cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-16T00:00:00+00:00"}, "scope": {"notes": "Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.11007 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4761", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4761"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4761"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted...", "cve_id": "CVE-2024-4761", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-05-16T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.11007, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95777, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4761", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b2781325-ac45-4b45-8876-d085c54863d1", "vulnerability": {"vulnId": "CVE-2021-40655", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-16T02:00:00+02:00"}, "gcve": {"object_uuid": "b2781325-ac45-4b45-8876-d085c54863d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-16T00:00:00+00:00"}, "scope": {"notes": "An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a... | Affected: D-Link / DIR-605 B2 Firmware | CVSS: 7.5 (HIGH) | EPSS: 0.86659 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40655", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40655"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40655"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a...", "cve_id": "CVE-2021-40655", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-605 B2 Firmware", "added_date": "2024-05-16T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.86659, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99736, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40655", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "41256304-7824-48fc-b956-510bcb3b9a7b", "vulnerability": {"vulnId": "CVE-2014-100005", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-16T02:00:00+02:00"}, "gcve": {"object_uuid": "41256304-7824-48fc-b956-510bcb3b9a7b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-16T00:00:00+00:00"}, "scope": {"notes": "Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers... | Affected: D-Link / DIR-600 router | CVSS: 8.0 (HIGH) | EPSS: 0.43456 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-100005", "url": "https://www.cve.org/CVERecord?id=CVE-2014-100005"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-100005"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers...", "cve_id": "CVE-2014-100005", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-600 router", "added_date": "2024-05-16T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.43456, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98699, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-100005", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2c6df769-4748-4240-b94e-94d4cb6e068e", "vulnerability": {"vulnId": "CVE-2024-30040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-14T02:00:00+02:00"}, "gcve": {"object_uuid": "2c6df769-4748-4240-b94e-94d4cb6e068e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-14T00:00:00+00:00"}, "scope": {"notes": "Windows MSHTML Platform Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.03939 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-30040", "url": "https://www.cve.org/CVERecord?id=CVE-2024-30040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-30040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows MSHTML Platform Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-30040", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2024-05-14T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03939, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90059, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-30040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "73296860-bad8-473c-9dc6-94d9595ff89c", "vulnerability": {"vulnId": "CVE-2024-30051", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-14T02:00:00+02:00"}, "gcve": {"object_uuid": "73296860-bad8-473c-9dc6-94d9595ff89c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-14T00:00:00+00:00"}, "scope": {"notes": "Windows DWM Core Library Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.05641 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-30051", "url": "https://www.cve.org/CVERecord?id=CVE-2024-30051"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-30051"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows DWM Core Library Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-30051", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2024-05-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05641, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92717, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-30051", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0ba7e4e-2033-48f3-94d1-14827159e24c", "vulnerability": {"vulnId": "CVE-2024-4671", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-13T02:00:00+02:00"}, "gcve": {"object_uuid": "f0ba7e4e-2033-48f3-94d1-14827159e24c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-13T00:00:00+00:00"}, "scope": {"notes": "Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.08348 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4671", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4671"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4671"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to...", "cve_id": "CVE-2024-4671", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-05-13T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.08348, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94793, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4671", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fa4469c1-9dc9-4918-8a01-444f71d839e4", "vulnerability": {"vulnId": "CVE-2024-32739", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-09T16:58:30+02:00"}, "gcve": {"object_uuid": "fa4469c1-9dc9-4918-8a01-444f71d839e4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-09T14:58:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-09T14:58:30+00:00"}, "scope": {"notes": "CyberPower PowerPanel Enterprise SQL Injection | Affected: CyberPower / CyberPower PowerPanel Enterprise | CVSS: 7.5 (HIGH) | EPSS: 0.05408 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-32739", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32739"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32739"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CyberPower PowerPanel Enterprise SQL Injection", "cve_id": "CVE-2024-32739", "vendor": "CyberPower", "ghsa_id": null, "product": "CyberPower PowerPanel Enterprise", "added_date": "2024-05-09T14:58:30.000Z", "cvss_score": 7.5, "epss_score": 0.05408, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92441, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32739", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "79900dae-2259-4714-9cb4-cd948f78245c", "vulnerability": {"vulnId": "CVE-2024-32737", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-09T16:57:57+02:00"}, "gcve": {"object_uuid": "79900dae-2259-4714-9cb4-cd948f78245c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-09T14:57:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-09T14:57:57+00:00"}, "scope": {"notes": "CyberPower PowerPanel Enterprise SQL Injection | Affected: CyberPower / CyberPower PowerPanel Enterprise | CVSS: 7.5 (HIGH) | EPSS: 0.05408 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-32737", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32737"}, {"id": "GHSA-76HV-682V-6FPM", "url": "https://github.com/advisories/GHSA-76HV-682V-6FPM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32737"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CyberPower PowerPanel Enterprise SQL Injection", "cve_id": "CVE-2024-32737", "vendor": "CyberPower", "ghsa_id": "GHSA-76HV-682V-6FPM", "product": "CyberPower PowerPanel Enterprise", "added_date": "2024-05-09T14:57:57.000Z", "cvss_score": 7.5, "epss_score": 0.05408, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92442, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32737", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9a558fb6-492b-48ba-88c5-967c72dac7e6", "vulnerability": {"vulnId": "CVE-2024-32736", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-09T16:57:38+02:00"}, "gcve": {"object_uuid": "9a558fb6-492b-48ba-88c5-967c72dac7e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-09T14:57:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-09T14:57:38+00:00"}, "scope": {"notes": "CyberPower PowerPanel Enterprise SQL Injection | Affected: CyberPower / CyberPower PowerPanel Enterprise | CVSS: 7.5 (HIGH) | EPSS: 0.05408 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-32736", "url": "https://www.cve.org/CVERecord?id=CVE-2024-32736"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-32736"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CyberPower PowerPanel Enterprise SQL Injection", "cve_id": "CVE-2024-32736", "vendor": "CyberPower", "ghsa_id": null, "product": "CyberPower PowerPanel Enterprise", "added_date": "2024-05-09T14:57:38.000Z", "cvss_score": 7.5, "epss_score": 0.05408, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92442, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-32736", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d54d2fe7-00aa-4246-9210-1dad2c540c29", "vulnerability": {"vulnId": "CVE-2023-7028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-05-01T02:00:00+02:00"}, "gcve": {"object_uuid": "d54d2fe7-00aa-4246-9210-1dad2c540c29", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-05-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-05-01T00:00:00+00:00"}, "scope": {"notes": "Weak Password Recovery Mechanism for Forgotten Password in GitLab | Affected: GitLab / GitLab | CVSS: 10.0 (CRITICAL) | EPSS: 0.94647 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-7028", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weak Password Recovery Mechanism for Forgotten Password in GitLab", "cve_id": "CVE-2023-7028", "vendor": "GitLab", "ghsa_id": null, "product": "GitLab", "added_date": "2024-05-01T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.94647, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99855, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b35486b6-4516-44b6-ac3b-3dbea879bfd7", "vulnerability": {"vulnId": "CVE-2024-29988", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-30T02:00:00+02:00"}, "gcve": {"object_uuid": "b35486b6-4516-44b6-ac3b-3dbea879bfd7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-30T00:00:00+00:00"}, "scope": {"notes": "SmartScreen Prompt Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.44875 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-29988", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29988"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29988"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SmartScreen Prompt Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-29988", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-04-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.44875, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98739, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29988", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b6d5203-2852-4806-b9ff-c243cadad6c8", "vulnerability": {"vulnId": "CVE-2024-20359", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "9b6d5203-2852-4806-b9ff-c243cadad6c8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-24T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive... | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | CVSS: 6.0 (MEDIUM) | EPSS: 0.19434 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20359", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20359"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20359"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive...", "cve_id": "CVE-2024-20359", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software", "added_date": "2024-04-24T00:00:00.000Z", "cvss_score": 6.0, "epss_score": 0.19434, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9729, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20359", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2a5ddfc1-6105-4994-bc37-ba82fb0891d4", "vulnerability": {"vulnId": "CVE-2024-4040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "2a5ddfc1-6105-4994-bc37-ba82fb0891d4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-24T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated arbitrary file read and remote code execution in CrushFTP | Affected: CrushFTP / CrushFTP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99539 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-4040", "url": "https://www.cve.org/CVERecord?id=CVE-2024-4040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-4040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated arbitrary file read and remote code execution in CrushFTP", "cve_id": "CVE-2024-4040", "vendor": "CrushFTP", "ghsa_id": null, "product": "CrushFTP", "added_date": "2024-04-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99539, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99945, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-4040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "37cbad6d-193e-44bd-983b-be2471306903", "vulnerability": {"vulnId": "CVE-2024-20353", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-24T02:00:00+02:00"}, "gcve": {"object_uuid": "37cbad6d-193e-44bd-983b-be2471306903", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-24T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)... | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | CVSS: 8.6 (HIGH) | EPSS: 0.70686 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-20353", "url": "https://www.cve.org/CVERecord?id=CVE-2024-20353"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-20353"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...", "cve_id": "CVE-2024-20353", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software", "added_date": "2024-04-24T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.70686, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99379, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-20353", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b890068b-5447-4d95-9dce-5094a2581085", "vulnerability": {"vulnId": "CVE-2022-38028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-23T02:00:00+02:00"}, "gcve": {"object_uuid": "b890068b-5447-4d95-9dce-5094a2581085", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-23T00:00:00+00:00"}, "scope": {"notes": "Windows Print Spooler Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.14949 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-38028", "url": "https://www.cve.org/CVERecord?id=CVE-2022-38028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-38028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Print Spooler Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-38028", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2024-04-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.14949, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96612, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-38028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "df195c60-cf88-4bca-ad40-64fda9c7b180", "vulnerability": {"vulnId": "CVE-2023-51409", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-12T15:15:12+02:00"}, "gcve": {"object_uuid": "df195c60-cf88-4bca-ad40-64fda9c7b180", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-12T13:15:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-12T13:15:12+00:00"}, "scope": {"notes": "WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability | Affected: Jordy Meow / AI Engine: ChatGPT Chatbot | CVSS: 10.0 (CRITICAL) | EPSS: 0.63077 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-51409", "url": "https://www.cve.org/CVERecord?id=CVE-2023-51409"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-51409"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability", "cve_id": "CVE-2023-51409", "vendor": "Jordy Meow", "ghsa_id": null, "product": "AI Engine: ChatGPT Chatbot", "added_date": "2024-04-12T13:15:12.000Z", "cvss_score": 10.0, "epss_score": 0.63077, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99181, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-51409", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "249d4c6d-8ffb-4dfd-a2c0-8606ab9d6e45", "vulnerability": {"vulnId": "CVE-2024-3400", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-12T02:00:00+02:00"}, "gcve": {"object_uuid": "249d4c6d-8ffb-4dfd-a2c0-8606ab9d6e45", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-12T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | Affected: Palo Alto Networks / PAN-OS, Cloud NGFW, Prisma Access | CVSS: 10.0 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-3400", "url": "https://www.cve.org/CVERecord?id=CVE-2024-3400"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-3400"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect", "cve_id": "CVE-2024-3400", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "PAN-OS, Cloud NGFW, Prisma Access", "added_date": "2024-04-12T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 1.0, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-3400", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "758d1ac4-5393-4c39-b8cf-07ad64e80586", "vulnerability": {"vulnId": "CVE-2024-3273", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "758d1ac4-5393-4c39-b8cf-07ad64e80586", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-11T00:00:00+00:00"}, "scope": {"notes": "D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection | Affected: D-Link / DNS-320L, DNS-325, DNS-327L, DNS-340L | CVSS: 7.3 (HIGH) | EPSS: 0.99997 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-3273", "url": "https://www.cve.org/CVERecord?id=CVE-2024-3273"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-3273"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection", "cve_id": "CVE-2024-3273", "vendor": "D-Link", "ghsa_id": null, "product": "DNS-320L, DNS-325, DNS-327L, DNS-340L", "added_date": "2024-04-11T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.99997, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-3273", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b810c96f-9174-45b6-8bc0-df9aed3843ae", "vulnerability": {"vulnId": "CVE-2024-3272", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "b810c96f-9174-45b6-8bc0-df9aed3843ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-11T00:00:00+00:00"}, "scope": {"notes": "D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials | Affected: D-Link / DNS-320L, DNS-325, DNS-327L, DNS-340L | CVSS: 9.8 (CRITICAL) | EPSS: 0.98038 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-3272", "url": "https://www.cve.org/CVERecord?id=CVE-2024-3272"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-3272"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials", "cve_id": "CVE-2024-3272", "vendor": "D-Link", "ghsa_id": null, "product": "DNS-320L, DNS-325, DNS-327L, DNS-340L", "added_date": "2024-04-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98038, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9991, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-3272", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7c9bde94-e706-4487-a18e-967faa2dfdcf", "vulnerability": {"vulnId": "CVE-2024-30269", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-08T16:19:56+02:00"}, "gcve": {"object_uuid": "7c9bde94-e706-4487-a18e-967faa2dfdcf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-08T14:19:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-08T14:19:56+00:00"}, "scope": {"notes": "DataEase has database configuration information exposure vulnerability | Affected: Dataease / dataease | CVSS: 5.3 (MEDIUM) | EPSS: 0.15875 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-30269", "url": "https://www.cve.org/CVERecord?id=CVE-2024-30269"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-30269"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DataEase has database configuration information exposure vulnerability", "cve_id": "CVE-2024-30269", "vendor": "Dataease", "ghsa_id": null, "product": "dataease", "added_date": "2024-04-08T14:19:56.000Z", "cvss_score": 5.3, "epss_score": 0.15875, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96788, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-30269", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d38221de-72ab-4b29-9316-ac240abe3dc4", "vulnerability": {"vulnId": "CVE-2024-30891", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-05T02:00:00+02:00"}, "gcve": {"object_uuid": "d38221de-72ab-4b29-9316-ac240abe3dc4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-05T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters... | Affected: Tenda / AC18 | CVSS: 8.8 (HIGH) | EPSS: 0.01896 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-30891", "url": "https://www.cve.org/CVERecord?id=CVE-2024-30891"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-30891"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters...", "cve_id": "CVE-2024-30891", "vendor": "Tenda", "ghsa_id": null, "product": "AC18", "added_date": "2024-04-05T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.01896, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78889, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-30891", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5fabfc92-ab39-41f1-a917-778fd46311f5", "vulnerability": {"vulnId": "CVE-2024-29745", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "5fabfc92-ab39-41f1-a917-778fd46311f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-04T00:00:00+00:00"}, "scope": {"notes": "there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution... | Affected: Google / Android | CVSS: 5.5 (MEDIUM) | EPSS: 0.00482 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-29745", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29745"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29745"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution...", "cve_id": "CVE-2024-29745", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2024-04-04T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.00482, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.39288, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29745", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "01f1e215-2279-4edc-a8aa-75f3035d6306", "vulnerability": {"vulnId": "CVE-2024-29748", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "01f1e215-2279-4edc-a8aa-75f3035d6306", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-04-04T00:00:00+00:00"}, "scope": {"notes": "there is a possible way to bypass  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.0067 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-29748", "url": "https://www.cve.org/CVERecord?id=CVE-2024-29748"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-29748"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "there is a possible way to bypass  due to a logic error in the code. This could lead to local escalation of privilege with no additional execution...", "cve_id": "CVE-2024-29748", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2024-04-04T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.0067, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50165, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-29748", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "693ef032-f4e5-487e-9860-40208b20f123", "vulnerability": {"vulnId": "CVE-2023-24955", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-26T01:00:00+01:00"}, "gcve": {"object_uuid": "693ef032-f4e5-487e-9860-40208b20f123", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-26T00:00:00+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition | CVSS: 7.2 (HIGH) | EPSS: 0.85395 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-24955", "url": "https://www.cve.org/CVERecord?id=CVE-2023-24955"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-24955"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability", "cve_id": "CVE-2023-24955", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition", "added_date": "2024-03-26T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.85395, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99714, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-24955", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "29cbe9b5-afcc-4aee-96c7-86797ae073eb", "vulnerability": {"vulnId": "CVE-2019-7256", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "29cbe9b5-afcc-4aee-96c7-86797ae073eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-25T00:00:00+00:00"}, "scope": {"notes": "Linear eMerge E3-Series devices allow Command Injections. | Affected: Linear / eMerge E3-Series | CVSS: 9.8 (CRITICAL) | EPSS: 0.97081 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7256", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7256"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7256"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linear eMerge E3-Series devices allow Command Injections.", "cve_id": "CVE-2019-7256", "vendor": "Linear", "ghsa_id": null, "product": "eMerge E3-Series", "added_date": "2024-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97081, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99892, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7256", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d2664e7a-c05d-4819-94b8-55dc1d56ce89", "vulnerability": {"vulnId": "CVE-2023-48788", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "d2664e7a-c05d-4819-94b8-55dc1d56ce89", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-25T00:00:00+00:00"}, "scope": {"notes": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2,... | Affected: Fortinet / FortiClientEMS | CVSS: 9.3 (CRITICAL) | EPSS: 0.98446 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-48788", "url": "https://www.cve.org/CVERecord?id=CVE-2023-48788"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-48788"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2,...", "cve_id": "CVE-2023-48788", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiClientEMS", "added_date": "2024-03-25T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.98446, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99917, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-48788", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0ddc382e-eb47-4b6e-86f9-814041619f63", "vulnerability": {"vulnId": "CVE-2021-44529", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "0ddc382e-eb47-4b6e-86f9-814041619f63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-25T00:00:00+00:00"}, "scope": {"notes": "A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with... | Affected: Ivanti / Ivanti EPM | CVSS: 9.8 (CRITICAL) | EPSS: 0.99105 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44529", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44529"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44529"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with...", "cve_id": "CVE-2021-44529", "vendor": "Ivanti", "ghsa_id": null, "product": "Ivanti EPM", "added_date": "2024-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99105, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99932, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-44529", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d326fd3f-fd58-4b33-a2ac-e116b16aefba", "vulnerability": {"vulnId": "CVE-2024-28734", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-19T01:00:00+01:00"}, "gcve": {"object_uuid": "d326fd3f-fd58-4b33-a2ac-e116b16aefba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-19T00:00:00+00:00"}, "scope": {"notes": "Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET... | Affected: Unit4 / Unit4 Financials | CVSS: 6.1 (MEDIUM) | EPSS: 0.01791 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-28734", "url": "https://www.cve.org/CVERecord?id=CVE-2024-28734"}, {"id": "GHSA-WRFJ-MM2V-57MH", "url": "https://github.com/advisories/GHSA-WRFJ-MM2V-57MH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-28734"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET...", "cve_id": "CVE-2024-28734", "vendor": "Unit4", "ghsa_id": "GHSA-WRFJ-MM2V-57MH", "product": "Unit4 Financials", "added_date": "2024-03-19T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01791, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77569, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-28734", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b2a50a26-1cfe-4391-9522-771997ef538e", "vulnerability": {"vulnId": "CVE-2024-2353", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-10T08:31:04+01:00"}, "gcve": {"object_uuid": "b2a50a26-1cfe-4391-9522-771997ef538e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-10T07:31:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-10T07:31:04+00:00"}, "scope": {"notes": "Totolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection | Affected: Totolink / X6000R | CVSS: 8.8 (HIGH) | EPSS: 0.03952 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-2353", "url": "https://www.cve.org/CVERecord?id=CVE-2024-2353"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-2353"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Totolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection", "cve_id": "CVE-2024-2353", "vendor": "Totolink", "ghsa_id": null, "product": "X6000R", "added_date": "2024-03-10T07:31:04.000Z", "cvss_score": 8.8, "epss_score": 0.03952, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90096, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-2353", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "90229923-cbf6-4f51-a6f0-062356820035", "vulnerability": {"vulnId": "CVE-2024-2330", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-09T10:00:08+01:00"}, "gcve": {"object_uuid": "90229923-cbf6-4f51-a6f0-062356820035", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-09T09:00:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-09T09:00:08+00:00"}, "scope": {"notes": "Netentsec NS-ASG Application Security Gateway index.php sql injection | Affected: Netentsec / NS-ASG Application Security Gateway | CVSS: 6.3 (MEDIUM) | EPSS: 0.17622 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-2330", "url": "https://www.cve.org/CVERecord?id=CVE-2024-2330"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-2330"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Netentsec NS-ASG Application Security Gateway index.php sql injection", "cve_id": "CVE-2024-2330", "vendor": "Netentsec", "ghsa_id": null, "product": "NS-ASG Application Security Gateway", "added_date": "2024-03-09T09:00:08.000Z", "cvss_score": 6.3, "epss_score": 0.17622, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97064, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-2330", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e47145e5-95ba-456e-9bcc-7dac23cffa9c", "vulnerability": {"vulnId": "CVE-2024-27198", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "e47145e5-95ba-456e-9bcc-7dac23cffa9c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-07T00:00:00+00:00"}, "scope": {"notes": "In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | Affected: JetBrains / TeamCity | CVSS: 9.8 (CRITICAL) | EPSS: 0.99938 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-27198", "url": "https://www.cve.org/CVERecord?id=CVE-2024-27198"}, {"id": "GHSA-XH94-49WQ-7H2H", "url": "https://github.com/advisories/GHSA-XH94-49WQ-7H2H"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-27198"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible", "cve_id": "CVE-2024-27198", "vendor": "JetBrains", "ghsa_id": "GHSA-XH94-49WQ-7H2H", "product": "TeamCity", "added_date": "2024-03-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99938, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99971, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-27198", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b365c24-06e3-45de-a519-7b4d36725c7e", "vulnerability": {"vulnId": "CVE-2024-23225", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-06T01:00:00+01:00"}, "gcve": {"object_uuid": "8b365c24-06e3-45de-a519-7b4d36725c7e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-06T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4,... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.01481 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-23225", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23225"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23225"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4,...", "cve_id": "CVE-2024-23225", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2024-03-06T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01481, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-23225", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "58852e6f-7397-4fa0-b3ae-0b6cb3b98150", "vulnerability": {"vulnId": "CVE-2024-23296", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-06T01:00:00+01:00"}, "gcve": {"object_uuid": "58852e6f-7397-4fa0-b3ae-0b6cb3b98150", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-06T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4,... | Affected: Apple / iOS and iPadOS, macOS, tvOS, visionOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.01411 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-23296", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23296"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23296"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4,...", "cve_id": "CVE-2024-23296", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS, tvOS, visionOS, watchOS", "added_date": "2024-03-06T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01411, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71697, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-23296", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "269c0bbc-dc9d-45e4-be69-ddfc00c8fe9c", "vulnerability": {"vulnId": "CVE-2021-36380", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-05T01:00:00+01:00"}, "gcve": {"object_uuid": "269c0bbc-dc9d-45e4-be69-ddfc00c8fe9c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-05T00:00:00+00:00"}, "scope": {"notes": "Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. | Affected: Sunhillo / SureLine | CVSS: 9.8 (CRITICAL) | EPSS: 0.97647 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36380", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36380"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36380"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.", "cve_id": "CVE-2021-36380", "vendor": "Sunhillo", "ghsa_id": null, "product": "SureLine", "added_date": "2024-03-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97647, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36380", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "218891a1-cbf9-450d-9659-08438ee35800", "vulnerability": {"vulnId": "CVE-2023-21237", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-05T01:00:00+01:00"}, "gcve": {"object_uuid": "218891a1-cbf9-450d-9659-08438ee35800", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-05T00:00:00+00:00"}, "scope": {"notes": "In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or... | Affected: Google / Android | CVSS: 5.5 (MEDIUM) | EPSS: 0.00266 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21237", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21237"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21237"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or...", "cve_id": "CVE-2023-21237", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2024-03-05T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.00266, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.16716, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21237", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "15560793-dcb5-4626-9368-50e1d5bdbbad", "vulnerability": {"vulnId": "CVE-2024-21338", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-04T01:00:00+01:00"}, "gcve": {"object_uuid": "15560793-dcb5-4626-9368-50e1d5bdbbad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-04T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.5981 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21338", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21338"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21338"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-21338", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-03-04T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.5981, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99106, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-21338", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c472e2cc-7cb6-47a1-8b99-f612fae8e77e", "vulnerability": {"vulnId": "CVE-2024-0692", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-03-01T09:55:35+01:00"}, "gcve": {"object_uuid": "c472e2cc-7cb6-47a1-8b99-f612fae8e77e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-03-01T08:55:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-03-01T08:55:35+00:00"}, "scope": {"notes": "SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability | Affected: SolarWinds / Security Event Manager  | CVSS: 8.8 (HIGH) | EPSS: 0.92245 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0692", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0692"}, {"id": "GHSA-3FJ5-F9X9-2HVX", "url": "https://github.com/advisories/GHSA-3FJ5-F9X9-2HVX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0692"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability", "cve_id": "CVE-2024-0692", "vendor": "SolarWinds", "ghsa_id": "GHSA-3FJ5-F9X9-2HVX", "product": "Security Event Manager ", "added_date": "2024-03-01T08:55:35.000Z", "cvss_score": 8.8, "epss_score": 0.92245, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0692", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "316e394c-48ff-4c6f-8c9a-f9485526c4e1", "vulnerability": {"vulnId": "CVE-2023-29360", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-29T01:00:00+01:00"}, "gcve": {"object_uuid": "316e394c-48ff-4c6f-8c9a-f9485526c4e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-29T00:00:00+00:00"}, "scope": {"notes": "Microsoft Streaming Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 8.4 (HIGH) | EPSS: 0.2162 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29360", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29360"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29360"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Streaming Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-29360", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2024-02-29T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.2162, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9756, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29360", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d3ac6a6c-ad4b-4c45-81ce-8def3e4454cd", "vulnerability": {"vulnId": "CVE-2024-1709", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-22T01:00:00+01:00"}, "gcve": {"object_uuid": "d3ac6a6c-ad4b-4c45-81ce-8def3e4454cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-22T00:00:00+00:00"}, "scope": {"notes": "Authentication bypass using an alternate path or channel | Affected: ConnectWise / ScreenConnect | CVSS: 10.0 (CRITICAL) | EPSS: 0.9998 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-1709", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1709"}, {"id": "GHSA-CG3J-75XH-7FV3", "url": "https://github.com/advisories/GHSA-CG3J-75XH-7FV3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1709"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Authentication bypass using an alternate path or channel", "cve_id": "CVE-2024-1709", "vendor": "ConnectWise", "ghsa_id": "GHSA-CG3J-75XH-7FV3", "product": "ScreenConnect", "added_date": "2024-02-22T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.9998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99981, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-1709", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f42bdfb-4d8b-4eec-8b42-09b6210ac6cd", "vulnerability": {"vulnId": "CVE-2020-3259", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "5f42bdfb-4d8b-4eec-8b42-09b6210ac6cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-15T00:00:00+00:00"}, "scope": {"notes": "Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software | CVSS: 7.5 (HIGH) | EPSS: 0.71789 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3259", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3259"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3259"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability", "cve_id": "CVE-2020-3259", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software", "added_date": "2024-02-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.71789, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99409, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-3259", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0389cca1-e7da-4e83-afd2-a64f4d323451", "vulnerability": {"vulnId": "CVE-2024-21410", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "0389cca1-e7da-4e83-afd2-a64f4d323451", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-15T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 13, Microsoft Exchange Server 2019 Cumulative Update 14 | CVSS: 9.8 (CRITICAL) | EPSS: 0.12561 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21410", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21410"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21410"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability", "cve_id": "CVE-2024-21410", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 13, Microsoft Exchange Server 2019 Cumulative Update 14", "added_date": "2024-02-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.12561, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96118, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21410", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "12b86890-eb58-4b49-a50d-b9499ab36654", "vulnerability": {"vulnId": "CVE-2024-21412", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-13T01:00:00+01:00"}, "gcve": {"object_uuid": "12b86890-eb58-4b49-a50d-b9499ab36654", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-13T00:00:00+00:00"}, "scope": {"notes": "Internet Shortcut Files Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 8.1 (HIGH) | EPSS: 0.9941 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21412", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21412"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21412"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Internet Shortcut Files Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-21412", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2024-02-13T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.9941, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99941, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-21412", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3ea04ae8-14de-42b6-a2ad-904251af85b8", "vulnerability": {"vulnId": "CVE-2024-21351", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-13T01:00:00+01:00"}, "gcve": {"object_uuid": "3ea04ae8-14de-42b6-a2ad-904251af85b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-13T00:00:00+00:00"}, "scope": {"notes": "Windows SmartScreen Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2019, Windows Server 2022 | CVSS: 7.6 (HIGH) | EPSS: 0.27798 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21351", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21351"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21351"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows SmartScreen Security Feature Bypass Vulnerability", "cve_id": "CVE-2024-21351", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2019, Windows Server 2022", "added_date": "2024-02-13T00:00:00.000Z", "cvss_score": 7.6, "epss_score": 0.27798, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98038, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-21351", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dd9ec9a6-bd7b-4a77-8412-b5bb32cb7488", "vulnerability": {"vulnId": "CVE-2023-43770", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-12T01:00:00+01:00"}, "gcve": {"object_uuid": "dd9ec9a6-bd7b-4a77-8412-b5bb32cb7488", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-12T00:00:00+00:00"}, "scope": {"notes": "Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of... | Affected: Roundcube / Roundcube Webmail | CVSS: 6.1 (MEDIUM) | EPSS: 0.6366 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-43770", "url": "https://www.cve.org/CVERecord?id=CVE-2023-43770"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-43770"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of...", "cve_id": "CVE-2023-43770", "vendor": "Roundcube", "ghsa_id": null, "product": "Roundcube Webmail", "added_date": "2024-02-12T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.6366, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99195, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-43770", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e712e545-3be3-4059-832f-ac784bd19be3", "vulnerability": {"vulnId": "CVE-2024-21762", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-09T01:00:00+01:00"}, "gcve": {"object_uuid": "e712e545-3be3-4059-832f-ac784bd19be3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-09T00:00:00+00:00"}, "scope": {"notes": "A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0... | Affected: Fortinet / FortiProxy, FortiOS | CVSS: 9.6 (CRITICAL) | EPSS: 0.83428 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21762", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21762"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21762"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0...", "cve_id": "CVE-2024-21762", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiProxy, FortiOS", "added_date": "2024-02-09T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.83428, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99675, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-21762", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0b9f3c1e-3858-487b-a586-60e251480507", "vulnerability": {"vulnId": "CVE-2024-23660", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-08T01:00:00+01:00"}, "gcve": {"object_uuid": "0b9f3c1e-3858-487b-a586-60e251480507", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-08T00:00:00+00:00"}, "scope": {"notes": "The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and... | Affected: Binance / Trust Wallet | CVSS: 7.5 (HIGH) | EPSS: 0.00552 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-23660", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23660"}, {"id": "GHSA-HCM7-VVXH-5CRX", "url": "https://github.com/advisories/GHSA-HCM7-VVXH-5CRX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23660"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and...", "cve_id": "CVE-2024-23660", "vendor": "Binance", "ghsa_id": "GHSA-HCM7-VVXH-5CRX", "product": "Trust Wallet", "added_date": "2024-02-08T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.00552, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.44075, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-23660", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7df31775-b245-4dbc-9975-ad1bb8ca55ed", "vulnerability": {"vulnId": "CVE-2023-4762", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-06T01:00:00+01:00"}, "gcve": {"object_uuid": "7df31775-b245-4dbc-9975-ad1bb8ca55ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-06T00:00:00+00:00"}, "scope": {"notes": "Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.41375 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-4762", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4762"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4762"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page....", "cve_id": "CVE-2023-4762", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-02-06T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.41375, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4762", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9db40f96-0923-41fc-813a-c503a3b06058", "vulnerability": {"vulnId": "CVE-2024-22320", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-02T03:16:32+01:00"}, "gcve": {"object_uuid": "9db40f96-0923-41fc-813a-c503a3b06058", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-02T02:16:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-02T02:16:32+00:00"}, "scope": {"notes": "IBM Operational Decision Manager code execution | Affected: IBM / Operational Decision Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.73398 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-22320", "url": "https://www.cve.org/CVERecord?id=CVE-2024-22320"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-22320"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Operational Decision Manager code execution", "cve_id": "CVE-2024-22320", "vendor": "IBM", "ghsa_id": null, "product": "Operational Decision Manager", "added_date": "2024-02-02T02:16:32.000Z", "cvss_score": 9.8, "epss_score": 0.73398, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99452, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-22320", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5f73957f-c0b5-42aa-b94a-5fd3b0c79818", "vulnerability": {"vulnId": "CVE-2024-22927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-02-01T01:00:00+01:00"}, "gcve": {"object_uuid": "5f73957f-c0b5-42aa-b94a-5fd3b0c79818", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-02-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-02-01T00:00:00+00:00"}, "scope": {"notes": "Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | Affected: EyouCMS / EyouCMS | CVSS: 6.1 (MEDIUM) | EPSS: 0.01019 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-22927", "url": "https://www.cve.org/CVERecord?id=CVE-2024-22927"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-22927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.", "cve_id": "CVE-2024-22927", "vendor": "EyouCMS", "ghsa_id": null, "product": "EyouCMS", "added_date": "2024-02-01T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01019, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62056, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-22927", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ed3fdc40-6922-4904-8350-3e248d371dde", "vulnerability": {"vulnId": "CVE-2022-48618", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-31T01:00:00+01:00"}, "gcve": {"object_uuid": "ed3fdc40-6922-4904-8350-3e248d371dde", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-31T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An... | Affected: Apple / tvOS, macOS, iOS and iPadOS, watchOS | CVSS: 7.0 (HIGH) | EPSS: 0.00487 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-48618", "url": "https://www.cve.org/CVERecord?id=CVE-2022-48618"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-48618"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An...", "cve_id": "CVE-2022-48618", "vendor": "Apple", "ghsa_id": null, "product": "tvOS, macOS, iOS and iPadOS, watchOS", "added_date": "2024-01-31T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.00487, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.39644, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-48618", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "105f4f14-8f93-4a46-95e0-7913cf302aba", "vulnerability": {"vulnId": "CVE-2024-21893", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-31T01:00:00+01:00"}, "gcve": {"object_uuid": "105f4f14-8f93-4a46-95e0-7913cf302aba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-31T00:00:00+00:00"}, "scope": {"notes": "A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and... | Affected: Ivanti / ICS, IPS | CVSS: 8.2 (HIGH) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21893", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21893"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21893"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and...", "cve_id": "CVE-2024-21893", "vendor": "Ivanti", "ghsa_id": null, "product": "ICS, IPS", "added_date": "2024-01-31T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99999, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-21893", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4bd76534-bbbf-4e45-83d1-4f151cd3cd70", "vulnerability": {"vulnId": "CVE-2024-24329", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-30T01:00:00+01:00"}, "gcve": {"object_uuid": "4bd76534-bbbf-4e45-83d1-4f151cd3cd70", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-30T00:00:00+00:00"}, "scope": {"notes": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the... | Affected: TOTOLINK / A3300R | CVSS: 9.8 (CRITICAL) | EPSS: 0.06172 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-24329", "url": "https://www.cve.org/CVERecord?id=CVE-2024-24329"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-24329"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the...", "cve_id": "CVE-2024-24329", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A3300R", "added_date": "2024-01-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06172, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93273, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-24329", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9c9f5237-e11e-4cdc-99d0-87b503c8c748", "vulnerability": {"vulnId": "CVE-2024-24328", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-30T01:00:00+01:00"}, "gcve": {"object_uuid": "9c9f5237-e11e-4cdc-99d0-87b503c8c748", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-30T00:00:00+00:00"}, "scope": {"notes": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the... | Affected: TOTOLINK / A3300R | CVSS: 9.8 (CRITICAL) | EPSS: 0.06172 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-24328", "url": "https://www.cve.org/CVERecord?id=CVE-2024-24328"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-24328"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the...", "cve_id": "CVE-2024-24328", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A3300R", "added_date": "2024-01-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06172, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93273, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-24328", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2b5b79fd-0a6f-481a-9485-2f06652f7560", "vulnerability": {"vulnId": "CVE-2024-1021", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-29T23:00:08+01:00"}, "gcve": {"object_uuid": "2b5b79fd-0a6f-481a-9485-2f06652f7560", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-29T22:00:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-29T22:00:08+00:00"}, "scope": {"notes": "Rebuild HTTP Request readRawText server-side request forgery | Affected: Rebuild / Rebuild | CVSS: 6.3 (MEDIUM) | EPSS: 0.34713 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-1021", "url": "https://www.cve.org/CVERecord?id=CVE-2024-1021"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-1021"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Rebuild HTTP Request readRawText server-side request forgery", "cve_id": "CVE-2024-1021", "vendor": "Rebuild", "ghsa_id": null, "product": "Rebuild", "added_date": "2024-01-29T22:00:08.000Z", "cvss_score": 6.3, "epss_score": 0.34713, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98381, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-1021", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "41773b7e-ee0d-4766-aed1-9183cd5171d1", "vulnerability": {"vulnId": "CVE-2024-22729", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-25T01:00:00+01:00"}, "gcve": {"object_uuid": "41773b7e-ee0d-4766-aed1-9183cd5171d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-25T00:00:00+00:00"}, "scope": {"notes": "NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page. | Affected: Netis / MW5360 | CVSS: 9.8 (CRITICAL) | EPSS: 0.70779 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-22729", "url": "https://www.cve.org/CVERecord?id=CVE-2024-22729"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-22729"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.", "cve_id": "CVE-2024-22729", "vendor": "Netis", "ghsa_id": null, "product": "MW5360", "added_date": "2024-01-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.70779, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99383, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-22729", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "371aa9ae-c3a6-4beb-accf-0b931eb00dea", "vulnerability": {"vulnId": "CVE-2023-51833", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-25T01:00:00+01:00"}, "gcve": {"object_uuid": "371aa9ae-c3a6-4beb-accf-0b931eb00dea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-25T00:00:00+00:00"}, "scope": {"notes": "A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in... | Affected: TRENDnet / TEW-411BRPplus | CVSS: 8.1 (HIGH) | EPSS: 0.04429 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-51833", "url": "https://www.cve.org/CVERecord?id=CVE-2023-51833"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-51833"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in...", "cve_id": "CVE-2023-51833", "vendor": "TRENDnet", "ghsa_id": null, "product": "TEW-411BRPplus", "added_date": "2024-01-25T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.04429, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91066, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-51833", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0ab9fc04-81ca-4f00-9459-7b406c17bbe2", "vulnerability": {"vulnId": "CVE-2023-22527", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-24T01:00:00+01:00"}, "gcve": {"object_uuid": "0ab9fc04-81ca-4f00-9459-7b406c17bbe2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-24T00:00:00+00:00"}, "scope": {"notes": "A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an... | Affected: Atlassian / Confluence Data Center, Confluence Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99984 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-22527", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22527"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22527"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an...", "cve_id": "CVE-2023-22527", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Data Center, Confluence Server", "added_date": "2024-01-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99984, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99982, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-22527", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8d5c7571-cab7-45f5-8388-84cf33fbb598", "vulnerability": {"vulnId": "CVE-2024-22768", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-23T05:31:40+01:00"}, "gcve": {"object_uuid": "8d5c7571-cab7-45f5-8388-84cf33fbb598", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-23T04:31:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-23T04:31:40+00:00"}, "scope": {"notes": "Hitron Systems DVR HVR-4781 Improper Input Validation Vulnerability  | Affected: Hitron Systems / DVR HVR-4781 | CVSS: 7.4 (HIGH) | EPSS: 0.00562 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-22768", "url": "https://www.cve.org/CVERecord?id=CVE-2024-22768"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-22768"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hitron Systems DVR HVR-4781 Improper Input Validation Vulnerability ", "cve_id": "CVE-2024-22768", "vendor": "Hitron Systems", "ghsa_id": null, "product": "DVR HVR-4781", "added_date": "2024-01-23T04:31:40.000Z", "cvss_score": 7.4, "epss_score": 0.00562, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.44678, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-22768", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "06a837d7-0fff-4542-9cdb-d34eb73bb306", "vulnerability": {"vulnId": "CVE-2024-23222", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-23T01:00:00+01:00"}, "gcve": {"object_uuid": "06a837d7-0fff-4542-9cdb-d34eb73bb306", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-23T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS... | Affected: Apple / Safari, iOS and iPadOS, macOS, tvOS, visionOS | CVSS: 8.8 (HIGH) | EPSS: 0.10593 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-23222", "url": "https://www.cve.org/CVERecord?id=CVE-2024-23222"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-23222"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS...", "cve_id": "CVE-2024-23222", "vendor": "Apple", "ghsa_id": null, "product": "Safari, iOS and iPadOS, macOS, tvOS, visionOS", "added_date": "2024-01-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10593, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95655, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-23222", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72a9f7c2-2bb9-4462-8fca-49222c58d6b4", "vulnerability": {"vulnId": "CVE-2023-34048", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-22T01:00:00+01:00"}, "gcve": {"object_uuid": "72a9f7c2-2bb9-4462-8fca-49222c58d6b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-22T00:00:00+00:00"}, "scope": {"notes": "VMware vCenter Server Out-of-Bounds Write Vulnerability | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server) | CVSS: 9.8 (CRITICAL) | EPSS: 0.99428 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-34048", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34048"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34048"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware vCenter Server Out-of-Bounds Write Vulnerability", "cve_id": "CVE-2023-34048", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server)", "added_date": "2024-01-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99428, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34048", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1640ca6a-c39b-41c6-a975-3748ab0c6a3a", "vulnerability": {"vulnId": "CVE-2023-6184", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-18T02:04:15+01:00"}, "gcve": {"object_uuid": "1640ca6a-c39b-41c6-a975-3748ab0c6a3a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-18T01:04:15+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-18T01:04:15+00:00"}, "scope": {"notes": "Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | Affected: Cloud Software Group / Citrix Session Recording | CVSS: 5.0 (MEDIUM) | EPSS: 0.4661 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6184", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6184"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6184"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting", "cve_id": "CVE-2023-6184", "vendor": "Cloud Software Group", "ghsa_id": null, "product": "Citrix Session Recording", "added_date": "2024-01-18T01:04:15.000Z", "cvss_score": 5.0, "epss_score": 0.4661, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98787, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6184", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "49b09bb0-4bbe-4556-bdb7-a8b609f65c6b", "vulnerability": {"vulnId": "CVE-2023-35082", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "49b09bb0-4bbe-4556-bdb7-a8b609f65c6b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-18T00:00:00+00:00"}, "scope": {"notes": "An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of... | Affected: Ivanti / EPMM | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-35082", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35082"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35082"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of...", "cve_id": "CVE-2023-35082", "vendor": "Ivanti", "ghsa_id": null, "product": "EPMM", "added_date": "2024-01-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99996, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-35082", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "63c84565-dcbd-45e1-91b9-30a89ddf6b83", "vulnerability": {"vulnId": "CVE-2023-6548", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-17T01:00:00+01:00"}, "gcve": {"object_uuid": "63c84565-dcbd-45e1-91b9-30a89ddf6b83", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-17T00:00:00+00:00"}, "scope": {"notes": "Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway\u00a0allows an attacker with\u00a0access\u00a0to... | Affected: Cloud Software Group / NetScaler ADC, NetScaler Gateway | CVSS: 5.5 (MEDIUM) | EPSS: 0.03191 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-6548", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6548"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6548"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway\u00a0allows an attacker with\u00a0access\u00a0to...", "cve_id": "CVE-2023-6548", "vendor": "Cloud Software Group", "ghsa_id": null, "product": "NetScaler ADC, NetScaler Gateway", "added_date": "2024-01-17T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.03191, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87651, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6548", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "37550da8-e58f-4e91-abfa-89a185391f17", "vulnerability": {"vulnId": "CVE-2023-6549", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-17T01:00:00+01:00"}, "gcve": {"object_uuid": "37550da8-e58f-4e91-abfa-89a185391f17", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-17T00:00:00+00:00"}, "scope": {"notes": "Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of... | Affected: Cloud Software Group / NetScaler ADC | CVSS: 8.2 (HIGH) | EPSS: 0.57633 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-6549", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6549"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6549"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of...", "cve_id": "CVE-2023-6549", "vendor": "Cloud Software Group", "ghsa_id": null, "product": "NetScaler ADC", "added_date": "2024-01-17T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.57633, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99058, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6549", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7ea8d5f7-147e-4e62-a134-ed3b3ec68723", "vulnerability": {"vulnId": "CVE-2024-0519", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-17T01:00:00+01:00"}, "gcve": {"object_uuid": "7ea8d5f7-147e-4e62-a134-ed3b3ec68723", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-17T00:00:00+00:00"}, "scope": {"notes": "Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.03802 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-0519", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0519"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0519"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2024-0519", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-01-17T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03802, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89674, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0519", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8715bf20-0a88-46ba-bedd-7b24043e78aa", "vulnerability": {"vulnId": "CVE-2024-0235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-16T16:57:04+01:00"}, "gcve": {"object_uuid": "8715bf20-0a88-46ba-bedd-7b24043e78aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-16T15:57:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-16T15:57:04+00:00"}, "scope": {"notes": "EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure | Affected: EventON / EventON | CVSS: 5.3 (MEDIUM) | EPSS: 0.37957 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0235", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0235"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure", "cve_id": "CVE-2024-0235", "vendor": "EventON", "ghsa_id": null, "product": "EventON", "added_date": "2024-01-16T15:57:04.000Z", "cvss_score": 5.3, "epss_score": 0.37957, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98508, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9e48f1ad-ef04-4b74-9ad4-5bf49747ccf3", "vulnerability": {"vulnId": "CVE-2018-15133", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-16T01:00:00+01:00"}, "gcve": {"object_uuid": "9e48f1ad-ef04-4b74-9ad4-5bf49747ccf3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-16T00:00:00+00:00"}, "scope": {"notes": "In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially... | Affected: Laravel / Laravel Framework | CVSS: 8.1 (HIGH) | EPSS: 0.76814 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-15133", "url": "https://www.cve.org/CVERecord?id=CVE-2018-15133"}, {"id": "GHSA-QVQM-H22R-4CP9", "url": "https://github.com/advisories/GHSA-QVQM-H22R-4CP9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-15133"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially...", "cve_id": "CVE-2018-15133", "vendor": "Laravel", "ghsa_id": "GHSA-QVQM-H22R-4CP9", "product": "Laravel Framework", "added_date": "2024-01-16T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.76814, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99535, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-15133", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20a572f6-a9b0-4a84-af64-ca129fb458fe", "vulnerability": {"vulnId": "CVE-2023-6634", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-11T09:32:28+01:00"}, "gcve": {"object_uuid": "20a572f6-a9b0-4a84-af64-ca129fb458fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-11T08:32:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-11T08:32:28+00:00"}, "scope": {"notes": "The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function.... | Affected: Thimpress / LearnPress \u2013 WordPress LMS Plugin | CVSS: 8.1 (HIGH) | EPSS: 0.08544 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6634", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6634"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6634"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function....", "cve_id": "CVE-2023-6634", "vendor": "Thimpress", "ghsa_id": null, "product": "LearnPress \u2013 WordPress LMS Plugin", "added_date": "2024-01-11T08:32:28.000Z", "cvss_score": 8.1, "epss_score": 0.08544, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6634", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b8fabeb3-bfb3-475a-a2f1-5814e08fce26", "vulnerability": {"vulnId": "CVE-2023-6266", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-11T09:32:27+01:00"}, "gcve": {"object_uuid": "b8fabeb3-bfb3-475a-a2f1-5814e08fce26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-11T08:32:27+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-11T08:32:27+00:00"}, "scope": {"notes": "The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the... | Affected: Migrate / Backup Migration | CVSS: 7.5 (HIGH) | EPSS: 0.02055 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6266", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6266"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6266"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the...", "cve_id": "CVE-2023-6266", "vendor": "Migrate", "ghsa_id": null, "product": "Backup Migration", "added_date": "2024-01-11T08:32:27.000Z", "cvss_score": 7.5, "epss_score": 0.02055, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80575, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6266", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f19632b-abb3-464e-8c11-17b05c65e85a", "vulnerability": {"vulnId": "CVE-2024-21887", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "8f19632b-abb3-464e-8c11-17b05c65e85a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-10T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)  allows an... | Affected: Ivanti / ICS, IPS | CVSS: 9.1 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2024-21887", "url": "https://www.cve.org/CVERecord?id=CVE-2024-21887"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-21887"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)  allows an...", "cve_id": "CVE-2024-21887", "vendor": "Ivanti", "ghsa_id": null, "product": "ICS, IPS", "added_date": "2024-01-10T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99999, "used_in_malware": "yes", "vulnerability_id": "CVE-2024-21887", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "03caf600-f7cd-4177-b1c6-06e8ad9d807e", "vulnerability": {"vulnId": "CVE-2023-46805", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "03caf600-f7cd-4177-b1c6-06e8ad9d807e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-10T00:00:00+00:00"}, "scope": {"notes": "An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access... | Affected: Ivanti / ICS, IPS | CVSS: 8.2 (HIGH) | EPSS: 0.99986 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-46805", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46805"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46805"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access...", "cve_id": "CVE-2023-46805", "vendor": "Ivanti", "ghsa_id": null, "product": "ICS, IPS", "added_date": "2024-01-10T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.99986, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99983, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-46805", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f71b596d-2a86-43cb-b09b-12e61bf847d4", "vulnerability": {"vulnId": "CVE-2023-29357", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "f71b596d-2a86-43cb-b09b-12e61bf847d4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-10T00:00:00+00:00"}, "scope": {"notes": "Microsoft SharePoint Server Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft SharePoint Server 2019 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99984 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29357", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29357"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29357"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-29357", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Server 2019", "added_date": "2024-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99984, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99982, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-29357", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b6af3b0f-a5bf-47c8-922d-14be7608b892", "vulnerability": {"vulnId": "CVE-2024-0297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T05:31:03+01:00"}, "gcve": {"object_uuid": "b6af3b0f-a5bf-47c8-922d-14be7608b892", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T04:31:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T04:31:03+00:00"}, "scope": {"notes": "Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection | Affected: Totolink / N200RE | CVSS: 7.3 (HIGH) | EPSS: 0.03834 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0297", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Totolink N200RE cstecgi.cgi UploadFirmwareFile os command injection", "cve_id": "CVE-2024-0297", "vendor": "Totolink", "ghsa_id": null, "product": "N200RE", "added_date": "2024-01-08T04:31:03.000Z", "cvss_score": 7.3, "epss_score": 0.03834, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6e0158e7-37f7-42c0-bda3-be59d4fe48d5", "vulnerability": {"vulnId": "CVE-2024-0292", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T03:00:05+01:00"}, "gcve": {"object_uuid": "6e0158e7-37f7-42c0-bda3-be59d4fe48d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T02:00:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T02:00:05+00:00"}, "scope": {"notes": "Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection | Affected: Totolink / LR1200GB | CVSS: 6.3 (MEDIUM) | EPSS: 0.04909 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2024-0292", "url": "https://www.cve.org/CVERecord?id=CVE-2024-0292"}, {"id": "previdian", "url": "https://previdian.com/CVE-2024-0292"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Totolink LR1200GB cstecgi.cgi setOpModeCfg os command injection", "cve_id": "CVE-2024-0292", "vendor": "Totolink", "ghsa_id": null, "product": "LR1200GB", "added_date": "2024-01-08T02:00:05.000Z", "cvss_score": 6.3, "epss_score": 0.04909, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91833, "used_in_malware": "unknown", "vulnerability_id": "CVE-2024-0292", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "337e6ded-1afe-4233-916f-e2c8f0d27b3b", "vulnerability": {"vulnId": "CVE-2023-41990", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "337e6ded-1afe-4233-916f-e2c8f0d27b3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS... | Affected: Apple / iOS and iPadOS, tvOS, macOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.01388 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41990", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41990"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41990"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS...", "cve_id": "CVE-2023-41990", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, tvOS, macOS, watchOS", "added_date": "2024-01-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01388, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71262, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41990", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8d29a117-90a7-44d5-902c-d290bf34ec16", "vulnerability": {"vulnId": "CVE-2016-20017", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "8d29a117-90a7-44d5-902c-d290bf34ec16", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T00:00:00+00:00"}, "scope": {"notes": "D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in... | Affected: D-Link / DSL-2750B | CVSS: 9.8 (CRITICAL) | EPSS: 0.64238 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-20017", "url": "https://www.cve.org/CVERecord?id=CVE-2016-20017"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-20017"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in...", "cve_id": "CVE-2016-20017", "vendor": "D-Link", "ghsa_id": null, "product": "DSL-2750B", "added_date": "2024-01-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.64238, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99208, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-20017", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e2db9ca7-ced6-4f4a-bab5-88a602041d43", "vulnerability": {"vulnId": "CVE-2023-29300", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "e2db9ca7-ced6-4f4a-bab5-88a602041d43", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution | Affected: Adobe / ColdFusion | CVSS: 9.8 (CRITICAL) | EPSS: 0.99991 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29300", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29300"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29300"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution", "cve_id": "CVE-2023-29300", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2024-01-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99991, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99986, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-29300", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f4d18faf-78a5-437d-bd30-af68c9466cf0", "vulnerability": {"vulnId": "CVE-2023-23752", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "f4d18faf-78a5-437d-bd30-af68c9466cf0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T00:00:00+00:00"}, "scope": {"notes": "[20230201] - Core - Improper access check in webservice endpoints | Affected: Joomla! Project / Joomla! CMS | CVSS: 5.3 (MEDIUM) | EPSS: 0.99827 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-23752", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23752"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23752"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "[20230201] - Core - Improper access check in webservice endpoints", "cve_id": "CVE-2023-23752", "vendor": "Joomla! Project", "ghsa_id": null, "product": "Joomla! CMS", "added_date": "2024-01-08T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.99827, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9996, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23752", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d01a6ef7-6632-48e1-8dce-f26639e33086", "vulnerability": {"vulnId": "CVE-2023-27524", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "d01a6ef7-6632-48e1-8dce-f26639e33086", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T00:00:00+00:00"}, "scope": {"notes": "Apache Superset: Session validation vulnerability when using provided default SECRET_KEY | Affected: Apache / Apache Superset | CVSS: 8.9 (HIGH) | EPSS: 0.97405 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-27524", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27524"}, {"id": "GHSA-5CX2-VQ3H-X52C", "url": "https://github.com/advisories/GHSA-5CX2-VQ3H-X52C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27524"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Superset: Session validation vulnerability when using provided default SECRET_KEY", "cve_id": "CVE-2023-27524", "vendor": "Apache", "ghsa_id": "GHSA-5CX2-VQ3H-X52C", "product": "Apache Superset", "added_date": "2024-01-08T00:00:00.000Z", "cvss_score": 8.9, "epss_score": 0.97405, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99898, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27524", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0a2ebfa3-9e13-49bc-82be-138b39c6e2b4", "vulnerability": {"vulnId": "CVE-2023-38203", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-08T01:00:00+01:00"}, "gcve": {"object_uuid": "0a2ebfa3-9e13-49bc-82be-138b39c6e2b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-08T00:00:00+00:00"}, "scope": {"notes": "Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE | Affected: Adobe / ColdFusion | CVSS: 9.8 (CRITICAL) | EPSS: 0.97074 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38203", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38203"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38203"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE", "cve_id": "CVE-2023-38203", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2024-01-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97074, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99891, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-38203", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0cf1fd1-68e7-4ae1-92b0-de2193a9cf1f", "vulnerability": {"vulnId": "CVE-2023-7101", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-02T01:00:00+01:00"}, "gcve": {"object_uuid": "b0cf1fd1-68e7-4ae1-92b0-de2193a9cf1f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-02T00:00:00+00:00"}, "scope": {"notes": "Arbitrary Code Execution (ACE) Vulnerability | Affected: Douglas Wilson / Spreadsheet::ParseExcel | CVSS: 7.8 (HIGH) | EPSS: 0.19106 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-7101", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7101"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7101"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary Code Execution (ACE) Vulnerability", "cve_id": "CVE-2023-7101", "vendor": "Douglas Wilson", "ghsa_id": null, "product": "Spreadsheet::ParseExcel", "added_date": "2024-01-02T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.19106, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97243, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7101", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ff013642-b6a2-45dc-aaf9-953771c12028", "vulnerability": {"vulnId": "CVE-2023-7024", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2024-01-02T01:00:00+01:00"}, "gcve": {"object_uuid": "ff013642-b6a2-45dc-aaf9-953771c12028", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2024-01-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2024-01-02T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.06671 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-7024", "url": "https://www.cve.org/CVERecord?id=CVE-2023-7024"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-7024"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2023-7024", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2024-01-02T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.06671, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93687, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-7024", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aa4213fc-d78f-4412-9ac0-29b7c21e81f7", "vulnerability": {"vulnId": "CVE-2023-47565", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-21T01:00:00+01:00"}, "gcve": {"object_uuid": "aa4213fc-d78f-4412-9ac0-29b7c21e81f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-21T00:00:00+00:00"}, "scope": {"notes": "Legacy VioStor NVR | Affected: QNAP / VioStor NVR | CVSS: 8.0 (HIGH) | EPSS: 0.73277 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-47565", "url": "https://www.cve.org/CVERecord?id=CVE-2023-47565"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-47565"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Legacy VioStor NVR", "cve_id": "CVE-2023-47565", "vendor": "QNAP", "ghsa_id": null, "product": "VioStor NVR", "added_date": "2023-12-21T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.73277, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99447, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-47565", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "86f8e28c-57ac-4194-9d10-e6edfb324e18", "vulnerability": {"vulnId": "CVE-2023-49897", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-21T01:00:00+01:00"}, "gcve": {"object_uuid": "86f8e28c-57ac-4194-9d10-e6edfb324e18", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-21T00:00:00+00:00"}, "scope": {"notes": "An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this... | Affected: FXC / AE1021PE, AE1021 | CVSS: 8.8 (HIGH) | EPSS: 0.50447 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-49897", "url": "https://www.cve.org/CVERecord?id=CVE-2023-49897"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-49897"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this...", "cve_id": "CVE-2023-49897", "vendor": "FXC", "ghsa_id": null, "product": "AE1021PE, AE1021", "added_date": "2023-12-21T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.50447, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98881, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-49897", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7da921ed-5dd3-4cf8-a5e9-cc7cf2a4fbe1", "vulnerability": {"vulnId": "CVE-2023-6553", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-15T11:59:46+01:00"}, "gcve": {"object_uuid": "7da921ed-5dd3-4cf8-a5e9-cc7cf2a4fbe1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-15T10:59:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-15T10:59:46+00:00"}, "scope": {"notes": "The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the... | Affected: Migrate / Backup Migration | CVSS: 9.8 (CRITICAL) | EPSS: 0.97846 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6553", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6553"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6553"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the...", "cve_id": "CVE-2023-6553", "vendor": "Migrate", "ghsa_id": null, "product": "Backup Migration", "added_date": "2023-12-15T10:59:46.000Z", "cvss_score": 9.8, "epss_score": 0.97846, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6553", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "99ae3bb1-89ac-4c08-a4d8-ddbecdbf631b", "vulnerability": {"vulnId": "CVE-2023-6448", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-11T01:00:00+01:00"}, "gcve": {"object_uuid": "99ae3bb1-89ac-4c08-a4d8-ddbecdbf631b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-11T00:00:00+00:00"}, "scope": {"notes": "Unitronics VisiLogic uses a default administrative password | Affected: Unitronics / VisiLogic | CVSS: 9.8 (CRITICAL) | EPSS: 0.02072 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-6448", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6448"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6448"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unitronics VisiLogic uses a default administrative password", "cve_id": "CVE-2023-6448", "vendor": "Unitronics", "ghsa_id": null, "product": "VisiLogic", "added_date": "2023-12-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.02072, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80745, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6448", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fddcdd97-814f-47b7-a417-644969b3c5cb", "vulnerability": {"vulnId": "CVE-2023-41266", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-07T01:00:00+01:00"}, "gcve": {"object_uuid": "fddcdd97-814f-47b7-a417-644969b3c5cb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-07T00:00:00+00:00"}, "scope": {"notes": "A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and... | Affected: Qlik / Qlik Sense Enterprise for Windows | CVSS: 8.2 (HIGH) | EPSS: 0.84843 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41266", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41266"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41266"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and...", "cve_id": "CVE-2023-41266", "vendor": "Qlik", "ghsa_id": null, "product": "Qlik Sense Enterprise for Windows", "added_date": "2023-12-07T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.84843, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99704, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-41266", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "24a7b5e4-6dd8-403f-94cd-4ce501109916", "vulnerability": {"vulnId": "CVE-2023-41265", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-07T01:00:00+01:00"}, "gcve": {"object_uuid": "24a7b5e4-6dd8-403f-94cd-4ce501109916", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-07T00:00:00+00:00"}, "scope": {"notes": "An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7... | Affected: Qlik / Qlik Sense Enterprise for Windows | CVSS: 9.6 (CRITICAL) | EPSS: 0.88215 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41265", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41265"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41265"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7...", "cve_id": "CVE-2023-41265", "vendor": "Qlik", "ghsa_id": null, "product": "Qlik Sense Enterprise for Windows", "added_date": "2023-12-07T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.88215, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99766, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-41265", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4938ac0e-ee5e-4f2e-8a65-6f70acb68152", "vulnerability": {"vulnId": "CVE-2023-33106", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-05T01:00:00+01:00"}, "gcve": {"object_uuid": "4938ac0e-ee5e-4f2e-8a65-6f70acb68152", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-05T00:00:00+00:00"}, "scope": {"notes": "Use of Out-of-range Pointer Offset in Graphics | Affected: Qualcomm / Snapdragon | CVSS: 8.4 (HIGH) | EPSS: 0.00924 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33106", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33106"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33106"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use of Out-of-range Pointer Offset in Graphics", "cve_id": "CVE-2023-33106", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2023-12-05T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.00924, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.59, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33106", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e5454c67-bc04-4a2e-ac5b-43c29e6dc834", "vulnerability": {"vulnId": "CVE-2022-22071", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-05T01:00:00+01:00"}, "gcve": {"object_uuid": "e5454c67-bc04-4a2e-ac5b-43c29e6dc834", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-05T00:00:00+00:00"}, "scope": {"notes": "Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto,... | Affected: Qualcomm / Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music | CVSS: 8.4 (HIGH) | EPSS: 0.00455 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22071", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22071"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22071"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto,...", "cve_id": "CVE-2022-22071", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music", "added_date": "2023-12-05T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.00455, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.37163, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22071", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1ba26f89-a211-494b-b03f-82b499547ea5", "vulnerability": {"vulnId": "CVE-2023-33107", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-05T01:00:00+01:00"}, "gcve": {"object_uuid": "1ba26f89-a211-494b-b03f-82b499547ea5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-05T00:00:00+00:00"}, "scope": {"notes": "Integer Overflow or Wraparound in Graphics Linux | Affected: Qualcomm / Snapdragon | CVSS: 8.4 (HIGH) | EPSS: 0.00892 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33107", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33107"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33107"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer Overflow or Wraparound in Graphics Linux", "cve_id": "CVE-2023-33107", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2023-12-05T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.00892, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.57976, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33107", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cb066f44-f143-4a4d-aee2-1947f50dfd50", "vulnerability": {"vulnId": "CVE-2023-33063", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-05T01:00:00+01:00"}, "gcve": {"object_uuid": "cb066f44-f143-4a4d-aee2-1947f50dfd50", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-05T00:00:00+00:00"}, "scope": {"notes": "Use After Free in DSP Services | Affected: Qualcomm / Snapdragon | CVSS: 7.8 (HIGH) | EPSS: 0.00694 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33063", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33063"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33063"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use After Free in DSP Services", "cve_id": "CVE-2023-33063", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon", "added_date": "2023-12-05T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00694, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5118, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33063", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c2fe777-9d1a-42f9-9068-525c900cc16c", "vulnerability": {"vulnId": "CVE-2023-42917", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-04T01:00:00+01:00"}, "gcve": {"object_uuid": "4c2fe777-9d1a-42f9-9068-525c900cc16c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-04T00:00:00+00:00"}, "scope": {"notes": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2,... | Affected: Apple / Safari, macOS, iOS and iPadOS | CVSS: 8.8 (HIGH) | EPSS: 0.09295 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-42917", "url": "https://www.cve.org/CVERecord?id=CVE-2023-42917"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-42917"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2,...", "cve_id": "CVE-2023-42917", "vendor": "Apple", "ghsa_id": null, "product": "Safari, macOS, iOS and iPadOS", "added_date": "2023-12-04T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.09295, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95226, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-42917", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c60aedc2-02a9-43be-9ce8-8bf0a605c16a", "vulnerability": {"vulnId": "CVE-2023-42916", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-12-04T01:00:00+01:00"}, "gcve": {"object_uuid": "c60aedc2-02a9-43be-9ce8-8bf0a605c16a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-12-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-12-04T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2,... | Affected: Apple / Safari, macOS, iOS and iPadOS | CVSS: 6.5 (MEDIUM) | EPSS: 0.17823 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-42916", "url": "https://www.cve.org/CVERecord?id=CVE-2023-42916"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-42916"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2,...", "cve_id": "CVE-2023-42916", "vendor": "Apple", "ghsa_id": null, "product": "Safari, macOS, iOS and iPadOS", "added_date": "2023-12-04T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.17823, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97085, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-42916", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b3172e37-a31f-4eec-b24e-70921284e754", "vulnerability": {"vulnId": "CVE-2023-6345", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-30T01:00:00+01:00"}, "gcve": {"object_uuid": "b3172e37-a31f-4eec-b24e-70921284e754", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-30T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.16468 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-6345", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6345"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6345"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially...", "cve_id": "CVE-2023-6345", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2023-11-30T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.16468, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6345", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b93bd81a-8f4b-4ac8-a098-e298f5f0380c", "vulnerability": {"vulnId": "CVE-2023-49103", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-30T01:00:00+01:00"}, "gcve": {"object_uuid": "b93bd81a-8f4b-4ac8-a098-e298f5f0380c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-30T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party... | Affected: ownCloud / owncloud/graphapi | CVSS: 10.0 (CRITICAL) | EPSS: 0.78428 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-49103", "url": "https://www.cve.org/CVERecord?id=CVE-2023-49103"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-49103"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party...", "cve_id": "CVE-2023-49103", "vendor": "ownCloud", "ghsa_id": null, "product": "owncloud/graphapi", "added_date": "2023-11-30T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.78428, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99572, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-49103", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "93f79a71-b82d-4f78-8b53-00ff07aa24f1", "vulnerability": {"vulnId": "CVE-2023-4220", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-28T08:11:47+01:00"}, "gcve": {"object_uuid": "93f79a71-b82d-4f78-8b53-00ff07aa24f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-28T07:11:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-28T07:11:47+00:00"}, "scope": {"notes": "Chamilo LMS Unauthenticated Big Upload File Remote Code Execution | Affected: Chamilo / Chamilo | CVSS: 8.1 (HIGH) | EPSS: 0.76084 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-4220", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4220"}, {"id": "GHSA-9WC2-3GQ5-2F4C", "url": "https://github.com/advisories/GHSA-9WC2-3GQ5-2F4C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4220"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Chamilo LMS Unauthenticated Big Upload File Remote Code Execution", "cve_id": "CVE-2023-4220", "vendor": "Chamilo", "ghsa_id": "GHSA-9WC2-3GQ5-2F4C", "product": "Chamilo", "added_date": "2023-11-28T07:11:47.000Z", "cvss_score": 8.1, "epss_score": 0.76084, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99518, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4220", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "42c6316e-9a43-440e-b243-9ed14fbd0938", "vulnerability": {"vulnId": "CVE-2023-3368", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-28T08:05:26+01:00"}, "gcve": {"object_uuid": "42c6316e-9a43-440e-b243-9ed14fbd0938", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-28T07:05:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-28T07:05:26+00:00"}, "scope": {"notes": "Chamilo LMS Unauthenticated Command Injection | Affected: Chamilo / Chamilo | CVSS: 9.8 (CRITICAL) | EPSS: 0.69671 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3368", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3368"}, {"id": "GHSA-X9XC-JG9P-2J7F", "url": "https://github.com/advisories/GHSA-X9XC-JG9P-2J7F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3368"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Chamilo LMS Unauthenticated Command Injection", "cve_id": "CVE-2023-3368", "vendor": "Chamilo", "ghsa_id": "GHSA-X9XC-JG9P-2J7F", "product": "Chamilo", "added_date": "2023-11-28T07:05:26.000Z", "cvss_score": 9.8, "epss_score": 0.69671, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99349, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3368", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "08d3fa06-2065-4ee3-b38e-d8e4bcd06178", "vulnerability": {"vulnId": "CVE-2023-4911", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-21T01:00:00+01:00"}, "gcve": {"object_uuid": "08d3fa06-2065-4ee3-b38e-d8e4bcd06178", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-21T00:00:00+00:00"}, "scope": {"notes": "Glibc: buffer overflow in ld.so leading to privilege escalation | Affected: Red Hat / , Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Extended Update Support, Red Hat Virtualization 4 for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 | CVSS: 7.8 (HIGH) | EPSS: 0.81422 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-4911", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4911"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4911"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Glibc: buffer overflow in ld.so leading to privilege escalation", "cve_id": "CVE-2023-4911", "vendor": "Red Hat", "ghsa_id": null, "product": ", Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Extended Update Support, Red Hat Virtualization 4 for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7", "added_date": "2023-11-21T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.81422, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99631, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4911", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e9e6f6d6-a6b8-48a7-bff4-127e7655eb07", "vulnerability": {"vulnId": "CVE-2023-6038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-16T17:06:43+01:00"}, "gcve": {"object_uuid": "e9e6f6d6-a6b8-48a7-bff4-127e7655eb07", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-16T16:06:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-16T16:06:43+00:00"}, "scope": {"notes": "Local File Inclusion in h2oai/h2o-3 | Affected: h2oai / h2oai/h2o-3 | CVSS: 9.3 (CRITICAL) | EPSS: 0.0434 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-6038", "url": "https://www.cve.org/CVERecord?id=CVE-2023-6038"}, {"id": "GHSA-6MV8-95X5-XCQ9", "url": "https://github.com/advisories/GHSA-6MV8-95X5-XCQ9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-6038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Local File Inclusion in h2oai/h2o-3", "cve_id": "CVE-2023-6038", "vendor": "h2oai", "ghsa_id": "GHSA-6MV8-95X5-XCQ9", "product": "h2oai/h2o-3", "added_date": "2023-11-16T16:06:43.000Z", "cvss_score": 9.3, "epss_score": 0.0434, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90901, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-6038", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "15b220b2-ded3-4c98-b633-b5299a61af4d", "vulnerability": {"vulnId": "CVE-2023-36584", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-16T01:00:00+01:00"}, "gcve": {"object_uuid": "15b220b2-ded3-4c98-b633-b5299a61af4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-16T00:00:00+00:00"}, "scope": {"notes": "Windows Mark of the Web Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 5.4 (MEDIUM) | EPSS: 0.03055 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36584", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36584"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36584"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Mark of the Web Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-36584", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-11-16T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.03055, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87122, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36584", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ddf1a8a0-f46d-4520-a25e-91b6d61ff6a3", "vulnerability": {"vulnId": "CVE-2020-2551", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-16T01:00:00+01:00"}, "gcve": {"object_uuid": "ddf1a8a0-f46d-4520-a25e-91b6d61ff6a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-16T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.93217 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-2551", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2551"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2551"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are...", "cve_id": "CVE-2020-2551", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2023-11-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93217, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99833, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-2551", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "43c478d8-70ed-4375-990c-990262dc5b7b", "vulnerability": {"vulnId": "CVE-2023-1671", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-16T01:00:00+01:00"}, "gcve": {"object_uuid": "43c478d8-70ed-4375-990c-990262dc5b7b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-16T00:00:00+00:00"}, "scope": {"notes": "A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of... | Affected: Sophos / Sophos Web Appliance | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-1671", "url": "https://www.cve.org/CVERecord?id=CVE-2023-1671"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-1671"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of...", "cve_id": "CVE-2023-1671", "vendor": "Sophos", "ghsa_id": null, "product": "Sophos Web Appliance", "added_date": "2023-11-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-1671", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7aa789e1-247d-4401-9225-5aa4bc0705f3", "vulnerability": {"vulnId": "CVE-2023-36036", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-14T01:00:00+01:00"}, "gcve": {"object_uuid": "7aa789e1-247d-4401-9225-5aa4bc0705f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-14T00:00:00+00:00"}, "scope": {"notes": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2 | CVSS: 7.8 (HIGH) | EPSS: 0.1667 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36036", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36036"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36036"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-36036", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2", "added_date": "2023-11-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.1667, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36036", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0b64b162-0482-4cbd-86c3-002a5abecf9a", "vulnerability": {"vulnId": "CVE-2023-36033", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-14T01:00:00+01:00"}, "gcve": {"object_uuid": "0b64b162-0482-4cbd-86c3-002a5abecf9a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-14T00:00:00+00:00"}, "scope": {"notes": "Windows DWM Core Library Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.11977 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36033", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36033"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36033"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows DWM Core Library Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-36033", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation)", "added_date": "2023-11-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.11977, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96006, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36033", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76c44dbf-7155-4d1b-818a-ccb8fe71f67b", "vulnerability": {"vulnId": "CVE-2023-36025", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-14T01:00:00+01:00"}, "gcve": {"object_uuid": "76c44dbf-7155-4d1b-818a-ccb8fe71f67b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-14T00:00:00+00:00"}, "scope": {"notes": "Windows SmartScreen Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.88085 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36025", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36025"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36025"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows SmartScreen Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-36025", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-11-14T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.88085, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99763, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36025", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06af69f2-2bc8-4879-929d-b6d54ab0dd17", "vulnerability": {"vulnId": "CVE-2022-45835", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T04:06:01+01:00"}, "gcve": {"object_uuid": "06af69f2-2bc8-4879-929d-b6d54ab0dd17", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T03:06:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T03:06:01+00:00"}, "scope": {"notes": "WordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF) | Affected: PhonePe / PhonePe Payment Solutions | CVSS: 5.8 (MEDIUM) | EPSS: 0.37673 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-45835", "url": "https://www.cve.org/CVERecord?id=CVE-2022-45835"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-45835"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress PhonePe Payment Solutions Plugin <= 1.0.15 is vulnerable to Server Side Request Forgery (SSRF)", "cve_id": "CVE-2022-45835", "vendor": "PhonePe", "ghsa_id": null, "product": "PhonePe Payment Solutions", "added_date": "2023-11-13T03:06:01.000Z", "cvss_score": 5.8, "epss_score": 0.37673, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98496, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-45835", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8582abb8-d90a-4d5d-9537-1952226a7374", "vulnerability": {"vulnId": "CVE-2023-36846", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "8582abb8-d90a-4d5d-9537-1952226a7374", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T00:00:00+00:00"}, "scope": {"notes": "Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files | Affected: Juniper Networks / Junos OS | CVSS: 5.3 (MEDIUM) | EPSS: 0.93473 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36846", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36846"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36846"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files", "cve_id": "CVE-2023-36846", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2023-11-13T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.93473, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99839, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36846", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e3d01a2d-ebd8-43ab-aca6-7911ae94bc39", "vulnerability": {"vulnId": "CVE-2023-36844", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "e3d01a2d-ebd8-43ab-aca6-7911ae94bc39", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T00:00:00+00:00"}, "scope": {"notes": "Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables | Affected: Juniper Networks / Junos OS | CVSS: 5.3 (MEDIUM) | EPSS: 0.89958 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36844", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36844"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36844"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables", "cve_id": "CVE-2023-36844", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2023-11-13T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.89958, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99792, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36844", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3ae1953c-cf34-4326-8e70-b9876963e892", "vulnerability": {"vulnId": "CVE-2023-36845", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "3ae1953c-cf34-4326-8e70-b9876963e892", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T00:00:00+00:00"}, "scope": {"notes": "Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable | Affected: Juniper Networks / Junos OS | CVSS: 9.8 (CRITICAL) | EPSS: 0.9507 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36845", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36845"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36845"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable", "cve_id": "CVE-2023-36845", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2023-11-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9507, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99862, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36845", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "53005015-b96a-4c32-84a9-3f07b9f3e9cd", "vulnerability": {"vulnId": "CVE-2023-47246", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "53005015-b96a-4c32-84a9-3f07b9f3e9cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T00:00:00+00:00"}, "scope": {"notes": "In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot,... | Affected: SysAid / SysAid On-Premise | CVSS: 9.8 (CRITICAL) | EPSS: 0.98851 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-47246", "url": "https://www.cve.org/CVERecord?id=CVE-2023-47246"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-47246"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot,...", "cve_id": "CVE-2023-47246", "vendor": "SysAid", "ghsa_id": null, "product": "SysAid On-Premise", "added_date": "2023-11-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98851, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99926, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-47246", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "78cfd6a9-e0e1-4a77-928b-4b6e9771ec57", "vulnerability": {"vulnId": "CVE-2023-36847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "78cfd6a9-e0e1-4a77-928b-4b6e9771ec57", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T00:00:00+00:00"}, "scope": {"notes": "Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files | Affected: Juniper Networks / Junos OS | CVSS: 5.3 (MEDIUM) | EPSS: 0.83455 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36847", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files", "cve_id": "CVE-2023-36847", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2023-11-13T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.83455, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99676, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36847", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a9852ba6-43db-4bc1-a475-bd9017c8bd8d", "vulnerability": {"vulnId": "CVE-2023-36851", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-13T01:00:00+01:00"}, "gcve": {"object_uuid": "a9852ba6-43db-4bc1-a475-bd9017c8bd8d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-13T00:00:00+00:00"}, "scope": {"notes": "Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files | Affected: Juniper Networks / Junos OS | CVSS: 5.3 (MEDIUM) | EPSS: 0.01123 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36851", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36851"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36851"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files", "cve_id": "CVE-2023-36851", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2023-11-13T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.01123, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.65021, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36851", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ec7d5434-6bed-4487-b8df-28dffbaf36f9", "vulnerability": {"vulnId": "CVE-2023-29552", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "ec7d5434-6bed-4487-b8df-28dffbaf36f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-08T00:00:00+00:00"}, "scope": {"notes": "The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the... | Affected: VMware / Service Location Protocol (SLP) | CVSS: 7.5 (HIGH) | EPSS: 0.63975 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29552", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29552"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29552"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the...", "cve_id": "CVE-2023-29552", "vendor": "VMware", "ghsa_id": null, "product": "Service Location Protocol (SLP)", "added_date": "2023-11-08T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.63975, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99201, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29552", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76e54221-330a-4358-95da-ddd1f70bdeea", "vulnerability": {"vulnId": "CVE-2023-22518", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-07T01:00:00+01:00"}, "gcve": {"object_uuid": "76e54221-330a-4358-95da-ddd1f70bdeea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-07T00:00:00+00:00"}, "scope": {"notes": "All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows... | Affected: Atlassian / Confluence Data Center, Confluence Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-22518", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22518"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22518"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows...", "cve_id": "CVE-2023-22518", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Data Center, Confluence Server", "added_date": "2023-11-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99996, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-22518", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d9a4bf6-fe0e-4ec8-a136-34c976c3816b", "vulnerability": {"vulnId": "CVE-2023-47253", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-06T01:00:00+01:00"}, "gcve": {"object_uuid": "3d9a4bf6-fe0e-4ec8-a136-34c976c3816b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-06T00:00:00+00:00"}, "scope": {"notes": "Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php... | Affected: Qualitor / Qualitor | CVSS: 9.8 (CRITICAL) | EPSS: 0.14308 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-47253", "url": "https://www.cve.org/CVERecord?id=CVE-2023-47253"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-47253"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php...", "cve_id": "CVE-2023-47253", "vendor": "Qualitor", "ghsa_id": null, "product": "Qualitor", "added_date": "2023-11-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14308, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96502, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-47253", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e4a6b3de-f619-4c5e-9512-4f59a42d6ef6", "vulnerability": {"vulnId": "CVE-2023-46604", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-11-02T01:00:00+01:00"}, "gcve": {"object_uuid": "e4a6b3de-f619-4c5e-9512-4f59a42d6ef6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-11-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-11-02T00:00:00+00:00"}, "scope": {"notes": "Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack | Affected: Apache / Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module | CVSS: 10.0 (CRITICAL) | EPSS: 0.99891 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-46604", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46604"}, {"id": "GHSA-CRG9-44H2-XW35", "url": "https://github.com/advisories/GHSA-CRG9-44H2-XW35"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46604"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack", "cve_id": "CVE-2023-46604", "vendor": "Apache", "ghsa_id": "GHSA-CRG9-44H2-XW35", "product": "Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module", "added_date": "2023-11-02T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99891, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99964, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-46604", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f24b93c6-7de3-4ba3-9e0f-1898d4686950", "vulnerability": {"vulnId": "CVE-2023-46748", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-31T01:00:00+01:00"}, "gcve": {"object_uuid": "f24b93c6-7de3-4ba3-9e0f-1898d4686950", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-31T00:00:00+00:00"}, "scope": {"notes": "BIG-IP Configuration utility authenticated SQL injection vulnerability | Affected: F5 / BIG-IP | CVSS: 8.8 (HIGH) | EPSS: 0.04468 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-46748", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46748"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46748"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BIG-IP Configuration utility authenticated SQL injection vulnerability", "cve_id": "CVE-2023-46748", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2023-10-31T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.04468, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91141, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-46748", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d348c5b-a946-40a6-864e-77501080d4d0", "vulnerability": {"vulnId": "CVE-2023-46747", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-31T01:00:00+01:00"}, "gcve": {"object_uuid": "3d348c5b-a946-40a6-864e-77501080d4d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-31T00:00:00+00:00"}, "scope": {"notes": "BIG-IP Configuration utility unauthenticated remote code execution vulnerability | Affected: F5 / BIG-IP | CVSS: 9.8 (CRITICAL) | EPSS: 0.96515 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-46747", "url": "https://www.cve.org/CVERecord?id=CVE-2023-46747"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-46747"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BIG-IP Configuration utility unauthenticated remote code execution vulnerability", "cve_id": "CVE-2023-46747", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2023-10-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96515, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99881, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-46747", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f92583f-dbf2-4734-bae4-b84405deca92", "vulnerability": {"vulnId": "CVE-2023-5631", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-26T02:00:00+02:00"}, "gcve": {"object_uuid": "2f92583f-dbf2-4734-bae4-b84405deca92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-26T00:00:00+00:00"}, "scope": {"notes": "Stored XSS vulnerability in Roundcube | Affected: Roundcube / Roundcubemail | CVSS: 6.1 (MEDIUM) | EPSS: 0.75873 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-5631", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5631"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5631"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stored XSS vulnerability in Roundcube", "cve_id": "CVE-2023-5631", "vendor": "Roundcube", "ghsa_id": null, "product": "Roundcubemail", "added_date": "2023-10-26T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.75873, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99513, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5631", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e5f6d7ec-a432-4707-99e8-61ebc9f23966", "vulnerability": {"vulnId": "CVE-2023-20273", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-23T02:00:00+02:00"}, "gcve": {"object_uuid": "e5f6d7ec-a432-4707-99e8-61ebc9f23966", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-23T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges... | Affected: Cisco / Cisco IOS XE Software | CVSS: 7.2 (HIGH) | EPSS: 0.89634 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20273", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20273"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20273"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges...", "cve_id": "CVE-2023-20273", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XE Software", "added_date": "2023-10-23T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.89634, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99785, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20273", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f4b3aca1-0766-4c96-b98d-856a2a08196c", "vulnerability": {"vulnId": "CVE-2023-5683", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-21T07:00:06+02:00"}, "gcve": {"object_uuid": "f4b3aca1-0766-4c96-b98d-856a2a08196c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-21T05:00:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-21T05:00:06+00:00"}, "scope": {"notes": "Byzoro Smart S85F Management Platform importconf.php os command injection | Affected: Byzoro / Smart S85F Management Platform | CVSS: 6.3 (MEDIUM) | EPSS: 0.1798 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5683", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5683"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5683"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Byzoro Smart S85F Management Platform importconf.php os command injection", "cve_id": "CVE-2023-5683", "vendor": "Byzoro", "ghsa_id": null, "product": "Smart S85F Management Platform", "added_date": "2023-10-21T05:00:06.000Z", "cvss_score": 6.3, "epss_score": 0.1798, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97104, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5683", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fd879e54-c3f0-4d5c-bf57-e24e087e2292", "vulnerability": {"vulnId": "CVE-2023-38192", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-21T02:00:00+02:00"}, "gcve": {"object_uuid": "fd879e54-c3f0-4d5c-bf57-e24e087e2292", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-21T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords. | Affected: SuperWebMailer / SuperWebMailer 9.00.0.01710 | CVSS: 6.1 (MEDIUM) | EPSS: 0.01107 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-38192", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38192"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38192"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.", "cve_id": "CVE-2023-38192", "vendor": "SuperWebMailer", "ghsa_id": null, "product": "SuperWebMailer 9.00.0.01710", "added_date": "2023-10-21T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01107, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64619, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38192", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "99fbd586-08ed-4e48-bb76-ce7cd94f9230", "vulnerability": {"vulnId": "CVE-2023-4966", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-18T02:00:00+02:00"}, "gcve": {"object_uuid": "99fbd586-08ed-4e48-bb76-ce7cd94f9230", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-18T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated sensitive information disclosure | Affected: Citrix / NetScaler ADC, NetScaler Gateway | CVSS: 9.4 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-4966", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4966"}, {"id": "GHSA-2G42-2PWG-93CJ", "url": "https://github.com/advisories/GHSA-2G42-2PWG-93CJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4966"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated sensitive information disclosure", "cve_id": "CVE-2023-4966", "vendor": "Citrix", "ghsa_id": "GHSA-2G42-2PWG-93CJ", "product": "NetScaler ADC, NetScaler Gateway", "added_date": "2023-10-18T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99997, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-4966", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b514be57-53b5-4605-81c7-c65adc121431", "vulnerability": {"vulnId": "CVE-2023-20198", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-16T02:00:00+02:00"}, "gcve": {"object_uuid": "b514be57-53b5-4605-81c7-c65adc121431", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-16T00:00:00+00:00"}, "scope": {"notes": "Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are... | Affected: Cisco / Cisco IOS XE Software | CVSS: 10.0 (CRITICAL) | EPSS: 0.99571 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20198", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20198"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20198"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are...", "cve_id": "CVE-2023-20198", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XE Software", "added_date": "2023-10-16T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99571, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20198", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5a27945d-de34-4040-a568-da6dd8caec47", "vulnerability": {"vulnId": "CVE-2023-5360", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-13T16:44:23+02:00"}, "gcve": {"object_uuid": "5a27945d-de34-4040-a568-da6dd8caec47", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-13T14:44:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-13T14:44:23+00:00"}, "scope": {"notes": "Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload | Affected: Royal Elementor / Royal Elementor Addons and Templates | CVSS: 9.8 (CRITICAL) | EPSS: 0.81695 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5360", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5360"}, {"id": "GHSA-2RRM-7H4W-QG5G", "url": "https://github.com/advisories/GHSA-2RRM-7H4W-QG5G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5360"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2023-5360", "vendor": "Royal Elementor", "ghsa_id": "GHSA-2RRM-7H4W-QG5G", "product": "Royal Elementor Addons and Templates", "added_date": "2023-10-13T14:44:23.000Z", "cvss_score": 9.8, "epss_score": 0.81695, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99636, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5360", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "afba4d9c-2a98-44da-9e6f-810921658b13", "vulnerability": {"vulnId": "CVE-2023-30801", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-10T15:46:46+02:00"}, "gcve": {"object_uuid": "afba4d9c-2a98-44da-9e6f-810921658b13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-10T13:46:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-10T13:46:46+00:00"}, "scope": {"notes": "qBittorrent Web UI Default Credentials Lead to RCE | Affected: qBittorrent / qBittorrent client | CVSS: 9.8 (CRITICAL) | EPSS: 0.00908 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-30801", "url": "https://www.cve.org/CVERecord?id=CVE-2023-30801"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-30801"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "qBittorrent Web UI Default Credentials Lead to RCE", "cve_id": "CVE-2023-30801", "vendor": "qBittorrent", "ghsa_id": null, "product": "qBittorrent client", "added_date": "2023-10-10T13:46:46.775Z", "cvss_score": 9.8, "epss_score": 0.00908, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58483, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-30801", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "648ae1eb-34fb-4f08-bf56-49653a94b2a9", "vulnerability": {"vulnId": "CVE-2023-41763", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-10T02:00:00+02:00"}, "gcve": {"object_uuid": "648ae1eb-34fb-4f08-bf56-49653a94b2a9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-10T00:00:00+00:00"}, "scope": {"notes": "Skype for Business Elevation of Privilege Vulnerability | Affected: Microsoft / Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU7 | CVSS: 5.3 (MEDIUM) | EPSS: 0.90353 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41763", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41763"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41763"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Skype for Business Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-41763", "vendor": "Microsoft", "ghsa_id": null, "product": "Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU7", "added_date": "2023-10-10T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.90353, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99797, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41763", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6fd21e9c-df4a-4b94-a6fd-1379eb69560f", "vulnerability": {"vulnId": "CVE-2023-20109", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-10T02:00:00+02:00"}, "gcve": {"object_uuid": "6fd21e9c-df4a-4b94-a6fd-1379eb69560f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-10T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an... | Affected: Cisco / IOS, Cisco IOS XE Software | CVSS: 6.6 (MEDIUM) | EPSS: 0.02484 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20109", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20109"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20109"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an...", "cve_id": "CVE-2023-20109", "vendor": "Cisco", "ghsa_id": null, "product": "IOS, Cisco IOS XE Software", "added_date": "2023-10-10T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.02484, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84024, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20109", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ae66e070-b00b-441e-9d12-58c2c998cde7", "vulnerability": {"vulnId": "CVE-2023-21608", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-10T02:00:00+02:00"}, "gcve": {"object_uuid": "ae66e070-b00b-441e-9d12-58c2c998cde7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-10T00:00:00+00:00"}, "scope": {"notes": "Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability | Affected: Adobe / Acrobat Reader | CVSS: 7.8 (HIGH) | EPSS: 0.61475 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21608", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21608"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21608"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability", "cve_id": "CVE-2023-21608", "vendor": "Adobe", "ghsa_id": null, "product": "Acrobat Reader", "added_date": "2023-10-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.61475, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99143, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21608", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02866f33-934e-472e-96c8-037f50d6e23a", "vulnerability": {"vulnId": "CVE-2023-36563", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-10T02:00:00+02:00"}, "gcve": {"object_uuid": "02866f33-934e-472e-96c8-037f50d6e23a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-10T00:00:00+00:00"}, "scope": {"notes": "Microsoft WordPad Information Disclosure Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 6.5 (MEDIUM) | EPSS: 0.20719 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36563", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36563"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36563"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft WordPad Information Disclosure Vulnerability", "cve_id": "CVE-2023-36563", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-10-10T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.20719, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97468, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36563", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "765a7992-5cb2-49ed-8f42-4387da030623", "vulnerability": {"vulnId": "CVE-2023-44487", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-10T02:00:00+02:00"}, "gcve": {"object_uuid": "765a7992-5cb2-49ed-8f42-4387da030623", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-10T00:00:00+00:00"}, "scope": {"notes": "The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as... | Affected: Google / Cloud Platform | CVSS: 7.5 (HIGH) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-44487", "url": "https://www.cve.org/CVERecord?id=CVE-2023-44487"}, {"id": "GHSA-QPPJ-FM5R-HXR3", "url": "https://github.com/advisories/GHSA-QPPJ-FM5R-HXR3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-44487"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as...", "cve_id": "CVE-2023-44487", "vendor": "Google", "ghsa_id": "GHSA-QPPJ-FM5R-HXR3", "product": "Cloud Platform", "added_date": "2023-10-10T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-44487", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0f20f558-901a-4667-b30a-435b084f356e", "vulnerability": {"vulnId": "CVE-2023-40044", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "0f20f558-901a-4667-b30a-435b084f356e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-05T00:00:00+00:00"}, "scope": {"notes": "WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability | Affected: Progress Software / WS_FTP Server | CVSS: 10.0 (CRITICAL) | EPSS: 0.90553 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-40044", "url": "https://www.cve.org/CVERecord?id=CVE-2023-40044"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-40044"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability", "cve_id": "CVE-2023-40044", "vendor": "Progress Software", "ghsa_id": null, "product": "WS_FTP Server", "added_date": "2023-10-05T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.90553, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.998, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-40044", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72a23b1a-5e71-4e8c-8d2e-f8db253a13c5", "vulnerability": {"vulnId": "CVE-2023-22515", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "72a23b1a-5e71-4e8c-8d2e-f8db253a13c5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-05T00:00:00+00:00"}, "scope": {"notes": "Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown... | Affected: Atlassian / Confluence Data Center, Confluence Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99156 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-22515", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22515"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22515"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown...", "cve_id": "CVE-2023-22515", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Data Center, Confluence Server", "added_date": "2023-10-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99156, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99933, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-22515", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9a25e8d5-0f64-44a8-b9cd-926851f3a144", "vulnerability": {"vulnId": "CVE-2023-42824", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-05T02:00:00+02:00"}, "gcve": {"object_uuid": "9a25e8d5-0f64-44a8-b9cd-926851f3a144", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-05T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their... | Affected: Apple / iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.00935 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-42824", "url": "https://www.cve.org/CVERecord?id=CVE-2023-42824"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-42824"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their...", "cve_id": "CVE-2023-42824", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS", "added_date": "2023-10-05T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00935, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.59357, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-42824", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "998cf57f-3a30-490d-8624-b7cad17b78e6", "vulnerability": {"vulnId": "CVE-2023-42793", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-04T02:00:00+02:00"}, "gcve": {"object_uuid": "998cf57f-3a30-490d-8624-b7cad17b78e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-04T00:00:00+00:00"}, "scope": {"notes": "In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible | Affected: JetBrains / TeamCity | CVSS: 9.8 (CRITICAL) | EPSS: 0.99988 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-42793", "url": "https://www.cve.org/CVERecord?id=CVE-2023-42793"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-42793"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible", "cve_id": "CVE-2023-42793", "vendor": "JetBrains", "ghsa_id": null, "product": "TeamCity", "added_date": "2023-10-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99988, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99984, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-42793", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c06bb79d-fbda-4807-b49a-a847901caccc", "vulnerability": {"vulnId": "CVE-2023-28229", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-04T02:00:00+02:00"}, "gcve": {"object_uuid": "c06bb79d-fbda-4807-b49a-a847901caccc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-04T00:00:00+00:00"}, "scope": {"notes": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.01671 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28229", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28229"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28229"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-28229", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-10-04T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.01671, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75953, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28229", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b4b4fcd-ff76-42b5-a6a6-9398af613997", "vulnerability": {"vulnId": "CVE-2023-4211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-03T02:00:00+02:00"}, "gcve": {"object_uuid": "9b4b4fcd-ff76-42b5-a6a6-9398af613997", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-03T00:00:00+00:00"}, "scope": {"notes": "Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations | Affected: Arm / Midgard GPU Kernel Driver, Bifrost GPU Kernel Driver, Valhall GPU Kernel Driver, Arm 5th Gen GPU Architecture Kernel  Driver | CVSS: 5.5 (MEDIUM) | EPSS: 0.01098 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-4211", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations", "cve_id": "CVE-2023-4211", "vendor": "Arm", "ghsa_id": null, "product": "Midgard GPU Kernel Driver, Bifrost GPU Kernel Driver, Valhall GPU Kernel Driver, Arm 5th Gen GPU Architecture Kernel  Driver", "added_date": "2023-10-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.01098, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "97049b6c-5aea-49a8-823d-d66ddb81bc42", "vulnerability": {"vulnId": "CVE-2023-5217", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-10-02T02:00:00+02:00"}, "gcve": {"object_uuid": "97049b6c-5aea-49a8-823d-d66ddb81bc42", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-10-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-10-02T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially... | Affected: Google / Chrome, libvpx | CVSS: 8.8 (HIGH) | EPSS: 0.49013 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-5217", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5217"}, {"id": "GHSA-QQVQ-6XGJ-JW8G", "url": "https://github.com/advisories/GHSA-QQVQ-6XGJ-JW8G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5217"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially...", "cve_id": "CVE-2023-5217", "vendor": "Google", "ghsa_id": "GHSA-QQVQ-6XGJ-JW8G", "product": "Chrome, libvpx", "added_date": "2023-10-02T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.49013, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98848, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5217", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8d7220f9-e359-4634-9d2e-8c8017bb8bb6", "vulnerability": {"vulnId": "CVE-2023-5285", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-29T21:31:05+02:00"}, "gcve": {"object_uuid": "8d7220f9-e359-4634-9d2e-8c8017bb8bb6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-29T19:31:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-29T19:31:05+00:00"}, "scope": {"notes": "Tongda OA 2017 delete.php sql injection | Affected: Tongda / OA 2017 | CVSS: 6.3 (MEDIUM) | EPSS: 0.00705 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-5285", "url": "https://www.cve.org/CVERecord?id=CVE-2023-5285"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-5285"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tongda OA 2017 delete.php sql injection", "cve_id": "CVE-2023-5285", "vendor": "Tongda", "ghsa_id": null, "product": "OA 2017", "added_date": "2023-09-29T19:31:05.000Z", "cvss_score": 6.3, "epss_score": 0.00705, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51623, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-5285", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e622e2ca-1199-48d3-bba7-dac3a3c850a4", "vulnerability": {"vulnId": "CVE-2023-43654", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-29T00:10:09+02:00"}, "gcve": {"object_uuid": "e622e2ca-1199-48d3-bba7-dac3a3c850a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-28T22:10:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-28T22:10:09+00:00"}, "scope": {"notes": "TorchServe Server-Side Request Forgery | Affected: Pytorch / serve | CVSS: 10.0 (CRITICAL) | EPSS: 0.4065 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-43654", "url": "https://www.cve.org/CVERecord?id=CVE-2023-43654"}, {"id": "GHSA-8FXR-QFR9-P34W", "url": "https://github.com/advisories/GHSA-8FXR-QFR9-P34W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-43654"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TorchServe Server-Side Request Forgery", "cve_id": "CVE-2023-43654", "vendor": "Pytorch", "ghsa_id": "GHSA-8FXR-QFR9-P34W", "product": "serve", "added_date": "2023-09-28T22:10:09.000Z", "cvss_score": 10.0, "epss_score": 0.4065, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-43654", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bfad67ff-baae-436c-a6fc-4930f162da8e", "vulnerability": {"vulnId": "CVE-2018-14667", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-28T02:00:00+02:00"}, "gcve": {"object_uuid": "bfad67ff-baae-436c-a6fc-4930f162da8e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-28T00:00:00+00:00"}, "scope": {"notes": "The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote,... | Affected: Red Hat / RichFaces Framework | CVSS: 9.8 (CRITICAL) | EPSS: 0.74202 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-14667", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14667"}, {"id": "GHSA-J7MW-7CRR-658V", "url": "https://github.com/advisories/GHSA-J7MW-7CRR-658V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14667"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote,...", "cve_id": "CVE-2018-14667", "vendor": "Red Hat", "ghsa_id": "GHSA-J7MW-7CRR-658V", "product": "RichFaces Framework", "added_date": "2023-09-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74202, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99476, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14667", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ff9b68bc-ae3e-4a80-b7d9-f7bde01a0760", "vulnerability": {"vulnId": "CVE-2023-41992", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-25T02:00:00+02:00"}, "gcve": {"object_uuid": "ff9b68bc-ae3e-4a80-b7d9-f7bde01a0760", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-25T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local... | Affected: Apple / macOS, iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.09515 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41992", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41992"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41992"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local...", "cve_id": "CVE-2023-41992", "vendor": "Apple", "ghsa_id": null, "product": "macOS, iOS and iPadOS", "added_date": "2023-09-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09515, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95305, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41992", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "43fce639-2291-4f61-875a-4fddc250e48f", "vulnerability": {"vulnId": "CVE-2023-41993", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-25T02:00:00+02:00"}, "gcve": {"object_uuid": "43fce639-2291-4f61-875a-4fddc250e48f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-25T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution.... | Affected: Apple / macOS | CVSS: 8.8 (HIGH) | EPSS: 0.24349 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41993", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41993"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41993"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution....", "cve_id": "CVE-2023-41993", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2023-09-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.24349, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97802, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41993", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f381682e-049f-47de-9bc4-73e278481f73", "vulnerability": {"vulnId": "CVE-2023-41991", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-25T02:00:00+02:00"}, "gcve": {"object_uuid": "f381682e-049f-47de-9bc4-73e278481f73", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-25T00:00:00+00:00"}, "scope": {"notes": "A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.1338 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41991", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41991"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41991"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to...", "cve_id": "CVE-2023-41991", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2023-09-25T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.1338, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41991", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "312eec8d-ce3d-4412-9bcc-ddef5d143d26", "vulnerability": {"vulnId": "CVE-2023-41179", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-21T02:00:00+02:00"}, "gcve": {"object_uuid": "312eec8d-ce3d-4412-9bcc-ddef5d143d26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-21T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and... | Affected: Trend Micro / Trend Micro Apex One, Trend Micro Worry-Free Business Security, Trend Micro Worry-Free Business Security Services | CVSS: 7.2 (HIGH) | EPSS: 0.04251 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41179", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41179"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41179"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and...", "cve_id": "CVE-2023-41179", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex One, Trend Micro Worry-Free Business Security, Trend Micro Worry-Free Business Security Services", "added_date": "2023-09-21T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.04251, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9074, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41179", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c752ae5e-bb5a-4210-b688-ab9b7d05ab83", "vulnerability": {"vulnId": "CVE-2023-28434", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-19T02:00:00+02:00"}, "gcve": {"object_uuid": "c752ae5e-bb5a-4210-b688-ab9b7d05ab83", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-19T00:00:00+00:00"}, "scope": {"notes": "MinIO is vulnerable to privilege escalation on Linux/MacOS | Affected: Minio / minio | CVSS: 8.8 (HIGH) | EPSS: 0.07917 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28434", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28434"}, {"id": "GHSA-2PXW-R47W-4P8C", "url": "https://github.com/advisories/GHSA-2PXW-R47W-4P8C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28434"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MinIO is vulnerable to privilege escalation on Linux/MacOS", "cve_id": "CVE-2023-28434", "vendor": "Minio", "ghsa_id": "GHSA-2PXW-R47W-4P8C", "product": "minio", "added_date": "2023-09-19T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.07917, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94551, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28434", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d9f5baa7-0324-4a34-b0f8-7b1d04781756", "vulnerability": {"vulnId": "CVE-2014-8361", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "d9f5baa7-0324-4a34-b0f8-7b1d04781756", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-18T00:00:00+00:00"}, "scope": {"notes": "The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in... | Affected: Realtek / SDK | CVSS: 9.8 (CRITICAL) | EPSS: 0.99975 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-8361", "url": "https://www.cve.org/CVERecord?id=CVE-2014-8361"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-8361"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in...", "cve_id": "CVE-2014-8361", "vendor": "Realtek", "ghsa_id": null, "product": "SDK", "added_date": "2023-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99975, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99978, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-8361", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a02fe923-63ad-4ce0-a52a-ec43e6e62ce0", "vulnerability": {"vulnId": "CVE-2017-6884", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "a02fe923-63ad-4ce0-a52a-ec43e6e62ce0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-18T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in... | Affected: Zyxel / EMG2926 | CVSS: 8.8 (HIGH) | EPSS: 0.34607 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6884", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6884"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6884"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in...", "cve_id": "CVE-2017-6884", "vendor": "Zyxel", "ghsa_id": null, "product": "EMG2926", "added_date": "2023-09-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.34607, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98376, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-6884", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "df29deef-8d2c-4bff-9b0a-8cbf0dae47f1", "vulnerability": {"vulnId": "CVE-2022-22265", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "df29deef-8d2c-4bff-9b0a-8cbf0dae47f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-18T00:00:00+00:00"}, "scope": {"notes": "An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 5.0 (MEDIUM) | EPSS: 0.00392 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22265", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22265"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22265"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code...", "cve_id": "CVE-2022-22265", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-09-18T00:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.00392, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.30868, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22265", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1d904e2f-dc42-43e7-8da2-fa9861cdb195", "vulnerability": {"vulnId": "CVE-2021-3129", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-18T02:00:00+02:00"}, "gcve": {"object_uuid": "1d904e2f-dc42-43e7-8da2-fa9861cdb195", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-18T00:00:00+00:00"}, "scope": {"notes": "Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure... | Affected: Facade / Ignition | CVSS: 9.8 (CRITICAL) | EPSS: 0.99943 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-3129", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3129"}, {"id": "GHSA-4QWP-7C67-JMCC", "url": "https://github.com/advisories/GHSA-4QWP-7C67-JMCC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3129"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure...", "cve_id": "CVE-2021-3129", "vendor": "Facade", "ghsa_id": "GHSA-4QWP-7C67-JMCC", "product": "Ignition", "added_date": "2023-09-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99943, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99972, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-3129", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c750a47a-1532-4422-a7c5-dd50dbe3cbf4", "vulnerability": {"vulnId": "CVE-2023-26369", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "c750a47a-1532-4422-a7c5-dd50dbe3cbf4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-14T00:00:00+00:00"}, "scope": {"notes": "[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild | Affected: Adobe / Acrobat Reader | CVSS: 7.8 (HIGH) | EPSS: 0.06746 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-26369", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26369"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26369"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild", "cve_id": "CVE-2023-26369", "vendor": "Adobe", "ghsa_id": null, "product": "Acrobat Reader", "added_date": "2023-09-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.06746, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93763, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26369", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "82558550-acff-4890-a238-7f5fd2f11782", "vulnerability": {"vulnId": "CVE-2023-20269", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-13T02:00:00+02:00"}, "gcve": {"object_uuid": "82558550-acff-4890-a238-7f5fd2f11782", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-13T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)... | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | CVSS: 5.0 (MEDIUM) | EPSS: 0.25453 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20269", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20269"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20269"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...", "cve_id": "CVE-2023-20269", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software", "added_date": "2023-09-13T00:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.25453, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97891, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-20269", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9e9ded44-da6d-40c3-8ec0-d4afb96e146d", "vulnerability": {"vulnId": "CVE-2023-4863", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-13T02:00:00+02:00"}, "gcve": {"object_uuid": "9e9ded44-da6d-40c3-8ec0-d4afb96e146d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-13T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds... | Affected: Google / Chrome, libwebp | CVSS: 8.8 (HIGH) | EPSS: 0.99979 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-4863", "url": "https://www.cve.org/CVERecord?id=CVE-2023-4863"}, {"id": "GHSA-J7HP-H8JX-5PPR", "url": "https://github.com/advisories/GHSA-J7HP-H8JX-5PPR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-4863"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds...", "cve_id": "CVE-2023-4863", "vendor": "Google", "ghsa_id": "GHSA-J7HP-H8JX-5PPR", "product": "Chrome, libwebp", "added_date": "2023-09-13T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99979, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-4863", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8da50224-b7eb-4ebd-a91f-240a9f52571f", "vulnerability": {"vulnId": "CVE-2023-35674", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-13T02:00:00+02:00"}, "gcve": {"object_uuid": "8da50224-b7eb-4ebd-a91f-240a9f52571f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-13T00:00:00+00:00"}, "scope": {"notes": "In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.02615 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-35674", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35674"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35674"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local...", "cve_id": "CVE-2023-35674", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2023-09-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02615, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84881, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35674", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b93cec26-bb5e-4e4f-a758-891bff617605", "vulnerability": {"vulnId": "CVE-2023-36802", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-12T02:00:00+02:00"}, "gcve": {"object_uuid": "b93cec26-bb5e-4e4f-a758-891bff617605", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-12T00:00:00+00:00"}, "scope": {"notes": "Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2 | CVSS: 7.8 (HIGH) | EPSS: 0.27909 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36802", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36802"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36802"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-36802", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2", "added_date": "2023-09-12T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.27909, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98045, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36802", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9dd1ab70-5fe8-4de3-b6e8-2f9853755668", "vulnerability": {"vulnId": "CVE-2023-36761", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-12T02:00:00+02:00"}, "gcve": {"object_uuid": "9dd1ab70-5fe8-4de3-b6e8-2f9853755668", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-12T00:00:00+00:00"}, "scope": {"notes": "Microsoft Word Information Disclosure Vulnerability | Affected: Microsoft / Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Word 2016, Microsoft Word 2013 Service Pack 1 | CVSS: 6.5 (MEDIUM) | EPSS: 0.1957 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36761", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36761"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36761"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Word Information Disclosure Vulnerability", "cve_id": "CVE-2023-36761", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office 2019, Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Word 2016, Microsoft Word 2013 Service Pack 1", "added_date": "2023-09-12T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.1957, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97308, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36761", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2cc7bf71-4cee-4373-98b6-55ade08acbfe", "vulnerability": {"vulnId": "CVE-2023-41064", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "2cc7bf71-4cee-4373-98b6-55ade08acbfe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-11T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9,... | Affected: Apple / macOS, iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.53403 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41064", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41064"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41064"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9,...", "cve_id": "CVE-2023-41064", "vendor": "Apple", "ghsa_id": null, "product": "macOS, iOS and iPadOS", "added_date": "2023-09-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.53403, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98958, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41064", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9eb90a21-f16f-4101-97dd-e13781fcd911", "vulnerability": {"vulnId": "CVE-2023-41061", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-11T02:00:00+02:00"}, "gcve": {"object_uuid": "9eb90a21-f16f-4101-97dd-e13781fcd911", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-11T00:00:00+00:00"}, "scope": {"notes": "A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted... | Affected: Apple / iOS and iPadOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.03778 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-41061", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41061"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41061"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted...", "cve_id": "CVE-2023-41061", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, watchOS", "added_date": "2023-09-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03778, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89607, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41061", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0c17f49-e21c-4640-91c5-dc23d0c71643", "vulnerability": {"vulnId": "CVE-2023-33246", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-09-06T02:00:00+02:00"}, "gcve": {"object_uuid": "f0c17f49-e21c-4640-91c5-dc23d0c71643", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-09-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-09-06T00:00:00+00:00"}, "scope": {"notes": "Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function | Affected: Apache / Apache RocketMQ | CVSS: 9.8 (CRITICAL) | EPSS: 0.96568 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33246", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33246"}, {"id": "GHSA-X3CQ-8F32-5F63", "url": "https://github.com/advisories/GHSA-X3CQ-8F32-5F63"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33246"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function", "cve_id": "CVE-2023-33246", "vendor": "Apache", "ghsa_id": "GHSA-X3CQ-8F32-5F63", "product": "Apache RocketMQ", "added_date": "2023-09-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96568, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99882, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33246", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fd2adbe7-45a6-41a4-8991-b09973737f06", "vulnerability": {"vulnId": "CVE-2023-41642", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-31T02:00:00+02:00"}, "gcve": {"object_uuid": "fd2adbe7-45a6-41a4-8991-b09973737f06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-31T00:00:00+00:00"}, "scope": {"notes": "Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow... | Affected: GruppoSCAI / RealGimm | CVSS: 6.1 (MEDIUM) | EPSS: 0.01117 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-41642", "url": "https://www.cve.org/CVERecord?id=CVE-2023-41642"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-41642"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow...", "cve_id": "CVE-2023-41642", "vendor": "GruppoSCAI", "ghsa_id": null, "product": "RealGimm", "added_date": "2023-08-31T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.01117, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.64872, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-41642", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d2f2cd32-965f-4560-ace6-bb13b2330849", "vulnerability": {"vulnId": "CVE-2023-38831", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-24T02:00:00+02:00"}, "gcve": {"object_uuid": "d2f2cd32-965f-4560-ace6-bb13b2330849", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-24T00:00:00+00:00"}, "scope": {"notes": "RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue... | Affected: RARLAB / WinRAR | CVSS: 7.8 (HIGH) | EPSS: 0.99815 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38831", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38831"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38831"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue...", "cve_id": "CVE-2023-38831", "vendor": "RARLAB", "ghsa_id": null, "product": "WinRAR", "added_date": "2023-08-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.99815, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99958, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-38831", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e8ddd94-eef6-469d-8469-18649d7bb7aa", "vulnerability": {"vulnId": "CVE-2023-32315", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-24T02:00:00+02:00"}, "gcve": {"object_uuid": "6e8ddd94-eef6-469d-8469-18649d7bb7aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-24T00:00:00+00:00"}, "scope": {"notes": "Openfire administration console authentication bypass | Affected: Ignite Realtime / Openfire | CVSS: 8.6 (HIGH) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32315", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32315"}, {"id": "GHSA-GW42-F939-FHVM", "url": "https://github.com/advisories/GHSA-GW42-F939-FHVM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32315"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Openfire administration console authentication bypass", "cve_id": "CVE-2023-32315", "vendor": "Ignite Realtime", "ghsa_id": "GHSA-GW42-F939-FHVM", "product": "Openfire", "added_date": "2023-08-24T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32315", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e8a97bc7-3964-460e-9ab3-31d25808cbf3", "vulnerability": {"vulnId": "CVE-2023-38035", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "e8a97bc7-3964-460e-9ab3-31d25808cbf3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-22T00:00:00+00:00"}, "scope": {"notes": "A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass... | Affected: Ivanti / MobileIron Sentry | CVSS: 9.8 (CRITICAL) | EPSS: 0.9995 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38035", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38035"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38035"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass...", "cve_id": "CVE-2023-38035", "vendor": "Ivanti", "ghsa_id": null, "product": "MobileIron Sentry", "added_date": "2023-08-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9995, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99974, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-38035", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "99eed08c-bc0b-401f-9233-8cd9db1eb909", "vulnerability": {"vulnId": "CVE-2023-27532", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "99eed08c-bc0b-401f-9233-8cd9db1eb909", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-22T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This... | Affected: Veeam / Veeam Backup & Replication | CVSS: 7.5 (HIGH) | EPSS: 0.81326 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-27532", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27532"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27532"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This...", "cve_id": "CVE-2023-27532", "vendor": "Veeam", "ghsa_id": null, "product": "Veeam Backup & Replication", "added_date": "2023-08-22T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.81326, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99628, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-27532", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7072ce10-d698-4c01-ade6-fdda8126ab62", "vulnerability": {"vulnId": "CVE-2023-26359", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-21T02:00:00+02:00"}, "gcve": {"object_uuid": "7072ce10-d698-4c01-ade6-fdda8126ab62", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-21T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution | Affected: Adobe / ColdFusion | CVSS: 9.8 (CRITICAL) | EPSS: 0.16988 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-26359", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26359"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26359"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution", "cve_id": "CVE-2023-26359", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2023-08-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.16988, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26359", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a864e5e6-69e6-44bc-a59c-03cba00f202e", "vulnerability": {"vulnId": "CVE-2023-40711", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-20T02:00:00+02:00"}, "gcve": {"object_uuid": "a864e5e6-69e6-44bc-a59c-03cba00f202e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-20T00:00:00+00:00"}, "scope": {"notes": "Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to... | Affected: Veilid / Veilid | CVSS: 7.5 (HIGH) | EPSS: 0.00983 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-40711", "url": "https://www.cve.org/CVERecord?id=CVE-2023-40711"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-40711"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to...", "cve_id": "CVE-2023-40711", "vendor": "Veilid", "ghsa_id": null, "product": "Veilid", "added_date": "2023-08-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.00983, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60941, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-40711", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "30043630-1ff3-4264-af52-2508a55a5eb3", "vulnerability": {"vulnId": "CVE-2023-24489", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-16T02:00:00+02:00"}, "gcve": {"object_uuid": "30043630-1ff3-4264-af52-2508a55a5eb3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-16T00:00:00+00:00"}, "scope": {"notes": "A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated... | Affected: Citrix / Citrix ShareFile Storage Zones Controller | CVSS: 9.8 (CRITICAL) | EPSS: 0.97343 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-24489", "url": "https://www.cve.org/CVERecord?id=CVE-2023-24489"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-24489"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated...", "cve_id": "CVE-2023-24489", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ShareFile Storage Zones Controller", "added_date": "2023-08-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97343, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-24489", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dbbb217c-2752-48a5-b64e-f9d26fcbd285", "vulnerability": {"vulnId": "CVE-2023-39964", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-10T19:39:11+02:00"}, "gcve": {"object_uuid": "dbbb217c-2752-48a5-b64e-f9d26fcbd285", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-10T17:39:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-10T17:39:11+00:00"}, "scope": {"notes": "1Panel O&M management panel has a background arbitrary file reading vulnerability | Affected: 1Panel-dev / 1Panel | CVSS: 7.5 (HIGH) | EPSS: 0.00972 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-39964", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39964"}, {"id": "GHSA-PV7Q-V9MV-9MH5", "url": "https://github.com/advisories/GHSA-PV7Q-V9MV-9MH5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39964"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "1Panel O&M management panel has a background arbitrary file reading vulnerability", "cve_id": "CVE-2023-39964", "vendor": "1Panel-dev", "ghsa_id": "GHSA-PV7Q-V9MV-9MH5", "product": "1Panel", "added_date": "2023-08-10T17:39:11.000Z", "cvss_score": 7.5, "epss_score": 0.00972, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60582, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39964", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b670ec0d-b444-4611-a23d-5e54a9f07f7c", "vulnerability": {"vulnId": "CVE-2023-39910", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-09T02:00:00+02:00"}, "gcve": {"object_uuid": "b670ec0d-b444-4611-a23d-5e54a9f07f7c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-09T00:00:00+00:00"}, "scope": {"notes": "The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an... | Affected: Libbitcoin / Libbitcoin Explorer | CVSS: 7.5 (HIGH) | EPSS: 0.01804 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-39910", "url": "https://www.cve.org/CVERecord?id=CVE-2023-39910"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-39910"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an...", "cve_id": "CVE-2023-39910", "vendor": "Libbitcoin", "ghsa_id": null, "product": "Libbitcoin Explorer", "added_date": "2023-08-09T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01804, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77742, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-39910", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d11e88a3-d288-4346-a7cd-21cae6d5acf7", "vulnerability": {"vulnId": "CVE-2023-38180", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-09T02:00:00+02:00"}, "gcve": {"object_uuid": "d11e88a3-d288-4346-a7cd-21cae6d5acf7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-09T00:00:00+00:00"}, "scope": {"notes": ".NET and Visual Studio Denial of Service Vulnerability | Affected: Microsoft / .NET 6.0, .NET 7.0, ASP.NET Core 2.1, Microsoft Visual Studio 2022 version 17.2, Microsoft Visual Studio 2022 version 17.4, Microsoft Visual Studio 2022 version 17.6 | CVSS: 7.5 (HIGH) | EPSS: 0.14016 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38180", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38180"}, {"id": "GHSA-VMCH-3W2X-VHGQ", "url": "https://github.com/advisories/GHSA-VMCH-3W2X-VHGQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38180"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": ".NET and Visual Studio Denial of Service Vulnerability", "cve_id": "CVE-2023-38180", "vendor": "Microsoft", "ghsa_id": "GHSA-VMCH-3W2X-VHGQ", "product": ".NET 6.0, .NET 7.0, ASP.NET Core 2.1, Microsoft Visual Studio 2022 version 17.2, Microsoft Visual Studio 2022 version 17.4, Microsoft Visual Studio 2022 version 17.6", "added_date": "2023-08-09T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.14016, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96448, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38180", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0dbdfa16-1f27-4496-ac53-48ed72ba0743", "vulnerability": {"vulnId": "CVE-2017-18368", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-07T02:00:00+02:00"}, "gcve": {"object_uuid": "0dbdfa16-1f27-4496-ac53-48ed72ba0743", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-07T00:00:00+00:00"}, "scope": {"notes": "The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the... | Affected: ZyXEL / P660HN-T1A v1 TCLinux Fw | CVSS: 9.8 (CRITICAL) | EPSS: 0.94425 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-18368", "url": "https://www.cve.org/CVERecord?id=CVE-2017-18368"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-18368"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the...", "cve_id": "CVE-2017-18368", "vendor": "ZyXEL", "ghsa_id": null, "product": "P660HN-T1A v1 TCLinux Fw", "added_date": "2023-08-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94425, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99851, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-18368", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "faf95986-7564-41f3-aa54-407c5cd4a400", "vulnerability": {"vulnId": "CVE-2023-3162", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-08-01T09:50:22+02:00"}, "gcve": {"object_uuid": "faf95986-7564-41f3-aa54-407c5cd4a400", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-08-01T07:50:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-08-01T07:50:22+00:00"}, "scope": {"notes": "The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This... | Affected: Webtoffee / Stripe Payment Plugin for WooCommerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.0119 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3162", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3162"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3162"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This...", "cve_id": "CVE-2023-3162", "vendor": "Webtoffee", "ghsa_id": null, "product": "Stripe Payment Plugin for WooCommerce", "added_date": "2023-08-01T07:50:22.000Z", "cvss_score": 9.8, "epss_score": 0.0119, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.66831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3162", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e368bbaa-1609-418d-8607-0d87bb61ba3d", "vulnerability": {"vulnId": "CVE-2023-35081", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-31T02:00:00+02:00"}, "gcve": {"object_uuid": "e368bbaa-1609-418d-8607-0d87bb61ba3d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-31T00:00:00+00:00"}, "scope": {"notes": "A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3,  11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an... | Affected: Ivanti / EPMM | CVSS: 7.2 (HIGH) | EPSS: 0.63577 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-35081", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35081"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35081"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3,  11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an...", "cve_id": "CVE-2023-35081", "vendor": "Ivanti", "ghsa_id": null, "product": "EPMM", "added_date": "2023-07-31T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.63577, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99192, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35081", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b80f1344-07b2-4d63-8034-5656c74e4907", "vulnerability": {"vulnId": "CVE-2023-37580", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-27T02:00:00+02:00"}, "gcve": {"object_uuid": "b80f1344-07b2-4d63-8034-5656c74e4907", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-27T00:00:00+00:00"}, "scope": {"notes": "Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client. | Affected: Zimbra / Zimbra Collaboration | CVSS: 6.1 (MEDIUM) | EPSS: 0.49083 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-37580", "url": "https://www.cve.org/CVERecord?id=CVE-2023-37580"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-37580"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.", "cve_id": "CVE-2023-37580", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration", "added_date": "2023-07-27T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.49083, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9885, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-37580", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d10fe9a-6f14-4424-8643-fd6bac90be8d", "vulnerability": {"vulnId": "CVE-2023-38433", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-26T09:44:04+02:00"}, "gcve": {"object_uuid": "9d10fe9a-6f14-4424-8643-fd6bac90be8d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-26T07:44:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-26T07:44:04+00:00"}, "scope": {"notes": "Fujitsu Real-time Video Transmission Gear \"IP series\" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize... | Affected: Fujitsu / IP-HE950E, IP-HE950D, IP-HE900E, IP-HE900D, IP-900E / IP-920E, IP-900D / IP-900\u2161D / IP-920D, IP-90, IP-9610 | CVSS: 7.5 (HIGH) | EPSS: 0.03722 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-38433", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38433"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38433"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fujitsu Real-time Video Transmission Gear \"IP series\" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize...", "cve_id": "CVE-2023-38433", "vendor": "Fujitsu", "ghsa_id": null, "product": "IP-HE950E, IP-HE950D, IP-HE900E, IP-HE900D, IP-900E / IP-920E, IP-900D / IP-900\u2161D / IP-920D, IP-90, IP-9610", "added_date": "2023-07-26T07:44:04.000Z", "cvss_score": 7.5, "epss_score": 0.03722, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89448, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38433", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "df9972ba-063f-4c85-84ca-6dc42531c574", "vulnerability": {"vulnId": "CVE-2023-38606", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-26T02:00:00+02:00"}, "gcve": {"object_uuid": "df9972ba-063f-4c85-84ca-6dc42531c574", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-26T00:00:00+00:00"}, "scope": {"notes": "This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and... | Affected: Apple / tvOS, iOS and iPadOS, macOS, watchOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.02899 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38606", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38606"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38606"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and...", "cve_id": "CVE-2023-38606", "vendor": "Apple", "ghsa_id": null, "product": "tvOS, iOS and iPadOS, macOS, watchOS", "added_date": "2023-07-26T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.02899, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86457, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38606", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b3ea6e45-a12e-49ad-ae5d-61b95179b076", "vulnerability": {"vulnId": "CVE-2023-35078", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-25T02:00:00+02:00"}, "gcve": {"object_uuid": "b3ea6e45-a12e-49ad-ae5d-61b95179b076", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-25T00:00:00+00:00"}, "scope": {"notes": "An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application... | Affected: Ivanti / Endpoint Manager Mobile | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-35078", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35078"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35078"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application...", "cve_id": "CVE-2023-35078", "vendor": "Ivanti", "ghsa_id": null, "product": "Endpoint Manager Mobile", "added_date": "2023-07-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99998, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-35078", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "63f3b250-b774-4de1-abc7-26d292711509", "vulnerability": {"vulnId": "CVE-2023-3793", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-20T21:31:04+02:00"}, "gcve": {"object_uuid": "63f3b250-b774-4de1-abc7-26d292711509", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-20T19:31:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-20T19:31:04+00:00"}, "scope": {"notes": "Weaver e-cology HTTP POST Request filelFileDownloadForOutDoc.class sql injection | Affected: Weaver / e-cology | CVSS: 5.5 (MEDIUM) | EPSS: 0.00492 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3793", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3793"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3793"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver e-cology HTTP POST Request filelFileDownloadForOutDoc.class sql injection", "cve_id": "CVE-2023-3793", "vendor": "Weaver", "ghsa_id": null, "product": "e-cology", "added_date": "2023-07-20T19:31:04.000Z", "cvss_score": 5.5, "epss_score": 0.00492, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.3998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3793", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2968b888-c9fa-4438-a0a0-cc6ac6fd43ad", "vulnerability": {"vulnId": "CVE-2023-29298", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-20T02:00:00+02:00"}, "gcve": {"object_uuid": "2968b888-c9fa-4438-a0a0-cc6ac6fd43ad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-20T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion Improper Access Control Security feature bypass | Affected: Adobe / ColdFusion | CVSS: 7.5 (HIGH) | EPSS: 0.9979 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29298", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29298"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29298"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion Improper Access Control Security feature bypass", "cve_id": "CVE-2023-29298", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2023-07-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.9979, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99955, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29298", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5edbc56-0f64-48e5-bd1d-a10ad56f2a72", "vulnerability": {"vulnId": "CVE-2023-38205", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-20T02:00:00+02:00"}, "gcve": {"object_uuid": "a5edbc56-0f64-48e5-bd1d-a10ad56f2a72", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-20T00:00:00+00:00"}, "scope": {"notes": "ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298 | Affected: Adobe / ColdFusion | CVSS: 7.5 (HIGH) | EPSS: 0.99742 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-38205", "url": "https://www.cve.org/CVERecord?id=CVE-2023-38205"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-38205"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298", "cve_id": "CVE-2023-38205", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2023-07-20T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99742, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99953, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-38205", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4b0bce30-b0cb-40ba-ba3c-363c83a16a51", "vulnerability": {"vulnId": "CVE-2023-3519", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-19T02:00:00+02:00"}, "gcve": {"object_uuid": "4b0bce30-b0cb-40ba-ba3c-363c83a16a51", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-19T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated remote code execution | Affected: Citrix / NetScaler ADC, NetScaler Gateway | CVSS: 9.8 (CRITICAL) | EPSS: 0.99749 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-3519", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3519"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3519"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated remote code execution", "cve_id": "CVE-2023-3519", "vendor": "Citrix", "ghsa_id": null, "product": "NetScaler ADC, NetScaler Gateway", "added_date": "2023-07-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99749, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99954, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-3519", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1133cf8a-555e-4e6a-8906-56020edaec62", "vulnerability": {"vulnId": "CVE-2023-28121", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-17T12:27:14+02:00"}, "gcve": {"object_uuid": "1133cf8a-555e-4e6a-8906-56020edaec62", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-17T10:27:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-17T10:27:14+00:00"}, "scope": {"notes": "An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of... | Affected: WooCommerce / WooCommerce Payments | CVSS: 9.8 (CRITICAL) | EPSS: 0.8651 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-28121", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28121"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28121"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of...", "cve_id": "CVE-2023-28121", "vendor": "WooCommerce", "ghsa_id": null, "product": "WooCommerce Payments", "added_date": "2023-07-17T10:27:14.000Z", "cvss_score": 9.8, "epss_score": 0.8651, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99733, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28121", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f3cb52fb-7160-4d6c-9297-99d46a90c4f2", "vulnerability": {"vulnId": "CVE-2023-36884", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-17T02:00:00+02:00"}, "gcve": {"object_uuid": "f3cb52fb-7160-4d6c-9297-99d46a90c4f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-17T00:00:00+00:00"}, "scope": {"notes": "Windows Search Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 7.5 (HIGH) | EPSS: 0.98932 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36884", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36884"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36884"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Search Remote Code Execution Vulnerability", "cve_id": "CVE-2023-36884", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2023-07-17T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.98932, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99928, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-36884", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cda47c41-b8e6-4846-be77-db6596ff41a4", "vulnerability": {"vulnId": "CVE-2022-29303", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-13T02:00:00+02:00"}, "gcve": {"object_uuid": "cda47c41-b8e6-4846-be77-db6596ff41a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-13T00:00:00+00:00"}, "scope": {"notes": "SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php. | Affected: SolarView / Compact | CVSS: 9.8 (CRITICAL) | EPSS: 0.97997 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-29303", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29303"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29303"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.", "cve_id": "CVE-2022-29303", "vendor": "SolarView", "ghsa_id": null, "product": "Compact", "added_date": "2023-07-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97997, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99909, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29303", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9216d60d-2eb3-48a9-8ba6-0e2080cbb482", "vulnerability": {"vulnId": "CVE-2023-37450", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-13T02:00:00+02:00"}, "gcve": {"object_uuid": "9216d60d-2eb3-48a9-8ba6-0e2080cbb482", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-13T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5,... | Affected: Apple / Safari, tvOS, iOS and iPadOS, macOS, watchOS | CVSS: 8.8 (HIGH) | EPSS: 0.1895 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-37450", "url": "https://www.cve.org/CVERecord?id=CVE-2023-37450"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-37450"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5,...", "cve_id": "CVE-2023-37450", "vendor": "Apple", "ghsa_id": null, "product": "Safari, tvOS, iOS and iPadOS, macOS, watchOS", "added_date": "2023-07-13T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.1895, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97221, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-37450", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2b2b8c07-63ba-48a0-94de-15770179cd6b", "vulnerability": {"vulnId": "CVE-2023-36874", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "2b2b8c07-63ba-48a0-94de-15770179cd6b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-11T00:00:00+00:00"}, "scope": {"notes": "Windows Error Reporting Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.42564 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-36874", "url": "https://www.cve.org/CVERecord?id=CVE-2023-36874"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-36874"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Error Reporting Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-36874", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-07-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.42564, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9867, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-36874", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cddad85a-7742-41e8-b338-1d5fbc7c905a", "vulnerability": {"vulnId": "CVE-2022-31199", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "cddad85a-7742-41e8-b338-1d5fbc7c905a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-11T00:00:00+00:00"}, "scope": {"notes": "Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor... | Affected: Netwrix / Auditor | CVSS: 9.8 (CRITICAL) | EPSS: 0.36009 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-31199", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31199"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31199"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor...", "cve_id": "CVE-2022-31199", "vendor": "Netwrix", "ghsa_id": null, "product": "Auditor", "added_date": "2023-07-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.36009, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9843, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-31199", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2aeec7e2-b143-4145-89ae-faf6d6363ba0", "vulnerability": {"vulnId": "CVE-2023-32046", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "2aeec7e2-b143-4145-89ae-faf6d6363ba0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-11T00:00:00+00:00"}, "scope": {"notes": "Windows MSHTML Platform Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.10049 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32046", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32046"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32046"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows MSHTML Platform Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-32046", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-07-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10049, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95487, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32046", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "33c75857-43ed-4c9f-8179-2924284cfbcb", "vulnerability": {"vulnId": "CVE-2023-32049", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "33c75857-43ed-4c9f-8179-2924284cfbcb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-11T00:00:00+00:00"}, "scope": {"notes": "Windows SmartScreen Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.04156 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32049", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32049"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32049"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows SmartScreen Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-32049", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2023-07-11T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.04156, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9055, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32049", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac86d698-29cd-498e-8b25-90ece0a8b58a", "vulnerability": {"vulnId": "CVE-2023-35311", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-11T02:00:00+02:00"}, "gcve": {"object_uuid": "ac86d698-29cd-498e-8b25-90ece0a8b58a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-11T00:00:00+00:00"}, "scope": {"notes": "Microsoft Outlook Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Outlook 2016, Microsoft Outlook 2013, Microsoft Outlook 2013 Service Pack 1 | CVSS: 8.8 (HIGH) | EPSS: 0.15522 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-35311", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35311"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35311"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Outlook Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-35311", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021, Microsoft Office 2019, Microsoft Outlook 2016, Microsoft Outlook 2013, Microsoft Outlook 2013 Service Pack 1", "added_date": "2023-07-11T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.15522, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96711, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35311", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7ea149e8-74df-41d5-81ce-8fe0125caf1e", "vulnerability": {"vulnId": "CVE-2023-3608", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-10T23:31:03+02:00"}, "gcve": {"object_uuid": "7ea149e8-74df-41d5-81ce-8fe0125caf1e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-10T21:31:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-10T21:31:03+00:00"}, "scope": {"notes": "Ruijie BCR810W Tracert Page os command injection | Affected: Ruijie / BCR810W | CVSS: 4.7 (MEDIUM) | EPSS: 0.12292 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-3608", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3608"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3608"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruijie BCR810W Tracert Page os command injection", "cve_id": "CVE-2023-3608", "vendor": "Ruijie", "ghsa_id": null, "product": "BCR810W", "added_date": "2023-07-10T21:31:03.000Z", "cvss_score": 4.7, "epss_score": 0.12292, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96068, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3608", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b6c1776c-0b9c-46a1-bd15-1a57ebdc7fe7", "vulnerability": {"vulnId": "CVE-2023-2796", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-10T14:40:07+02:00"}, "gcve": {"object_uuid": "b6c1776c-0b9c-46a1-bd15-1a57ebdc7fe7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-10T12:40:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-10T12:40:07+00:00"}, "scope": {"notes": "EventON < 2.1.2 - Unauthenticated Event Access | Affected: EventON / EventON | CVSS: 5.3 (MEDIUM) | EPSS: 0.42674 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-2796", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2796"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2796"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "EventON < 2.1.2 - Unauthenticated Event Access", "cve_id": "CVE-2023-2796", "vendor": "EventON", "ghsa_id": null, "product": "EventON", "added_date": "2023-07-10T12:40:07.000Z", "cvss_score": 5.3, "epss_score": 0.42674, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98674, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2796", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d2a2a75f-d17d-4456-9d7c-145b669afdf4", "vulnerability": {"vulnId": "CVE-2021-29256", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-07-07T02:00:00+02:00"}, "gcve": {"object_uuid": "d2a2a75f-d17d-4456-9d7c-145b669afdf4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-07-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-07-07T00:00:00+00:00"}, "scope": {"notes": ". The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege... | Affected: Arm / Mali GPU kernel driver | CVSS: 8.8 (HIGH) | EPSS: 0.02988 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-29256", "url": "https://www.cve.org/CVERecord?id=CVE-2021-29256"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-29256"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": ". The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege...", "cve_id": "CVE-2021-29256", "vendor": "Arm", "ghsa_id": null, "product": "Mali GPU kernel driver", "added_date": "2023-07-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.02988, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8684, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-29256", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7a29748f-2824-41ff-bfdb-f7430a2b1e5c", "vulnerability": {"vulnId": "CVE-2021-25487", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "7a29748f-2824-41ff-bfdb-f7430a2b1e5c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 7.3 (HIGH) | EPSS: 0.00635 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25487", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25487"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25487"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in...", "cve_id": "CVE-2021-25487", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.00635, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.48531, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25487", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d8ee51d-8470-4690-b187-36281bb1d92b", "vulnerability": {"vulnId": "CVE-2019-20500", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "3d8ee51d-8470-4690-b187-36281bb1d92b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the... | Affected: D-Link / DWL-2600AP | CVSS: 7.8 (HIGH) | EPSS: 0.97109 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-20500", "url": "https://www.cve.org/CVERecord?id=CVE-2019-20500"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-20500"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the...", "cve_id": "CVE-2019-20500", "vendor": "D-Link", "ghsa_id": null, "product": "DWL-2600AP", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.97109, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99892, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-20500", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "84dd4314-2c9e-43a9-9a63-69642c4b0e30", "vulnerability": {"vulnId": "CVE-2021-25372", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "84dd4314-2c9e-43a9-9a63-69642c4b0e30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 6.1 (MEDIUM) | EPSS: 0.00804 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25372", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25372"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25372"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.", "cve_id": "CVE-2021-25372", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.00804, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55144, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25372", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e63014cb-a97c-4a05-a5b9-572b1dcdf3c1", "vulnerability": {"vulnId": "CVE-2021-25371", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "e63014cb-a97c-4a05-a5b9-572b1dcdf3c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 6.1 (MEDIUM) | EPSS: 0.00802 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25371", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25371"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25371"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.", "cve_id": "CVE-2021-25371", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.00802, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55035, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25371", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c363a7ae-9328-47bc-b980-891b4afc3034", "vulnerability": {"vulnId": "CVE-2021-25394", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "c363a7ae-9328-47bc-b980-891b4afc3034", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 6.4 (MEDIUM) | EPSS: 0.00401 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25394", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25394"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25394"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio...", "cve_id": "CVE-2021-25394", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 6.4, "epss_score": 0.00401, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.31958, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25394", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "99a671f9-600f-4fe7-be9b-fd2f0f0c3863", "vulnerability": {"vulnId": "CVE-2019-17621", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "99a671f9-600f-4fe7-be9b-fd2f0f0c3863", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute... | Affected: D-Link / DIR-859 Wi-Fi router | CVSS: 9.8 (CRITICAL) | EPSS: 0.89624 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-17621", "url": "https://www.cve.org/CVERecord?id=CVE-2019-17621"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-17621"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute...", "cve_id": "CVE-2019-17621", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-859 Wi-Fi router", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.89624, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99785, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-17621", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1bb8b480-a847-4747-a327-ad89c8a7d2a2", "vulnerability": {"vulnId": "CVE-2021-25395", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "1bb8b480-a847-4747-a327-ad89c8a7d2a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 6.4 (MEDIUM) | EPSS: 0.00366 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25395", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25395"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25395"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is...", "cve_id": "CVE-2021-25395", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 6.4, "epss_score": 0.00366, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.2812, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25395", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7acbf1c1-3bae-4340-89ff-c96e748d844e", "vulnerability": {"vulnId": "CVE-2021-25489", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-29T02:00:00+02:00"}, "gcve": {"object_uuid": "7acbf1c1-3bae-4340-89ff-c96e748d844e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-29T00:00:00+00:00"}, "scope": {"notes": "Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 3.3 (LOW) | EPSS: 0.00531 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25489", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25489"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25489"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string...", "cve_id": "CVE-2021-25489", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-06-29T00:00:00.000Z", "cvss_score": 3.3, "epss_score": 0.00531, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.42751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25489", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02c1a6a3-6f8d-49e9-b591-c73f010630b8", "vulnerability": {"vulnId": "CVE-2023-32435", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "02c1a6a3-6f8d-49e9-b591-c73f010630b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-23T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS... | Affected: Apple / macOS, iOS and iPadOS, Safari | CVSS: 8.8 (HIGH) | EPSS: 0.22951 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32435", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32435"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32435"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS...", "cve_id": "CVE-2023-32435", "vendor": "Apple", "ghsa_id": null, "product": "macOS, iOS and iPadOS, Safari", "added_date": "2023-06-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.22951, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97687, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32435", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6eed0478-2084-4c3f-b97d-39aab4ea8f02", "vulnerability": {"vulnId": "CVE-2023-27992", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "6eed0478-2084-4c3f-b97d-39aab4ea8f02", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-23T00:00:00+00:00"}, "scope": {"notes": "The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to\u00a0V5.21(AAZF.14)C0, NAS540 firmware... | Affected: Zyxel / NAS326 firmware, NAS540 firmware, NAS542 firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.82828 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-27992", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27992"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27992"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to\u00a0V5.21(AAZF.14)C0, NAS540 firmware...", "cve_id": "CVE-2023-27992", "vendor": "Zyxel", "ghsa_id": null, "product": "NAS326 firmware, NAS540 firmware, NAS542 firmware", "added_date": "2023-06-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82828, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99662, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27992", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d728bcbb-dfe4-4b0d-9852-572d2e733794", "vulnerability": {"vulnId": "CVE-2023-20867", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "d728bcbb-dfe4-4b0d-9852-572d2e733794", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-23T00:00:00+00:00"}, "scope": {"notes": "VMware Tools Authentication Bypass Vulnerability | Affected: VMware / VMware Tools | CVSS: 3.9 (LOW) | EPSS: 0.1353 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20867", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20867"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20867"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Tools Authentication Bypass Vulnerability", "cve_id": "CVE-2023-20867", "vendor": "VMware", "ghsa_id": null, "product": "VMware Tools", "added_date": "2023-06-23T00:00:00.000Z", "cvss_score": 3.9, "epss_score": 0.1353, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20867", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20846ba1-51d3-4f0d-afdb-9c4f5f41a581", "vulnerability": {"vulnId": "CVE-2023-32434", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "20846ba1-51d3-4f0d-afdb-9c4f5f41a581", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-23T00:00:00+00:00"}, "scope": {"notes": "An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS... | Affected: Apple / macOS, iOS and iPadOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.51517 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32434", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32434"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32434"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS...", "cve_id": "CVE-2023-32434", "vendor": "Apple", "ghsa_id": null, "product": "macOS, iOS and iPadOS, watchOS", "added_date": "2023-06-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.51517, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98912, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32434", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cfd25853-e101-458a-a264-8bff5c1f2146", "vulnerability": {"vulnId": "CVE-2023-32439", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-23T02:00:00+02:00"}, "gcve": {"object_uuid": "cfd25853-e101-458a-a264-8bff5c1f2146", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-23T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS... | Affected: Apple / iOS and iPadOS, Safari, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.23968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32439", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32439"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32439"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS...", "cve_id": "CVE-2023-32439", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, Safari, macOS", "added_date": "2023-06-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.23968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97772, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32439", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c61b3f6d-42be-4064-858b-06bb57b8dcc9", "vulnerability": {"vulnId": "CVE-2021-44026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-22T02:00:00+02:00"}, "gcve": {"object_uuid": "c61b3f6d-42be-4064-858b-06bb57b8dcc9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-22T00:00:00+00:00"}, "scope": {"notes": "Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. | Affected: Roundcube / Roundcube Webmail | CVSS: 9.8 (CRITICAL) | EPSS: 0.69882 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44026", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.", "cve_id": "CVE-2021-44026", "vendor": "Roundcube", "ghsa_id": null, "product": "Roundcube Webmail", "added_date": "2023-06-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.69882, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99356, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "52f5a1dc-782a-4599-9614-4c2534f2c2b7", "vulnerability": {"vulnId": "CVE-2016-0165", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-22T02:00:00+02:00"}, "gcve": {"object_uuid": "52f5a1dc-782a-4599-9614-4c2534f2c2b7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-22T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.13732 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0165", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0165"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0165"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and...", "cve_id": "CVE-2016-0165", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2023-06-22T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.13732, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96395, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0165", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "006802a1-f92e-40b9-87e7-b0ac34fe3000", "vulnerability": {"vulnId": "CVE-2016-9079", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-22T02:00:00+02:00"}, "gcve": {"object_uuid": "006802a1-f92e-40b9-87e7-b0ac34fe3000", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-22T00:00:00+00:00"}, "scope": {"notes": "A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild... | Affected: Mozilla / Firefox, Firefox ESR, Thunderbird | CVSS: 7.5 (HIGH) | EPSS: 0.87423 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-9079", "url": "https://www.cve.org/CVERecord?id=CVE-2016-9079"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-9079"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild...", "cve_id": "CVE-2016-9079", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Firefox ESR, Thunderbird", "added_date": "2023-06-22T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.87423, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99754, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-9079", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "794282ef-8553-43e1-be39-825706d3ccfb", "vulnerability": {"vulnId": "CVE-2023-20887", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-22T02:00:00+02:00"}, "gcve": {"object_uuid": "794282ef-8553-43e1-be39-825706d3ccfb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-22T00:00:00+00:00"}, "scope": {"notes": "Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for... | Affected: VMware / Aria Operations for Networks (Formerly vRealize Network Insight) | CVSS: 9.8 (CRITICAL) | EPSS: 0.98281 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20887", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20887"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20887"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for...", "cve_id": "CVE-2023-20887", "vendor": "VMware", "ghsa_id": null, "product": "Aria Operations for Networks (Formerly vRealize Network Insight)", "added_date": "2023-06-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98281, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20887", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c8a3ffd6-2eff-4425-9bae-4141df675825", "vulnerability": {"vulnId": "CVE-2020-35730", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-22T02:00:00+02:00"}, "gcve": {"object_uuid": "c8a3ffd6-2eff-4425-9bae-4141df675825", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-22T00:00:00+00:00"}, "scope": {"notes": "An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text... | Affected: Roundcube / Webmail | CVSS: 6.1 (MEDIUM) | EPSS: 0.32688 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-35730", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35730"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35730"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text...", "cve_id": "CVE-2020-35730", "vendor": "Roundcube", "ghsa_id": null, "product": "Webmail", "added_date": "2023-06-22T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.32688, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98297, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35730", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "81d66f77-4a12-4014-b3f0-072569494f05", "vulnerability": {"vulnId": "CVE-2020-12641", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-22T02:00:00+02:00"}, "gcve": {"object_uuid": "81d66f77-4a12-4014-b3f0-072569494f05", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-22T00:00:00+00:00"}, "scope": {"notes": "rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting... | Affected: Roundcube / Webmail | CVSS: 9.8 (CRITICAL) | EPSS: 0.84336 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-12641", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12641"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12641"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting...", "cve_id": "CVE-2020-12641", "vendor": "Roundcube", "ghsa_id": null, "product": "Webmail", "added_date": "2023-06-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84336, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99693, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-12641", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1c937ed4-418c-49b1-93f0-703f1eeac26a", "vulnerability": {"vulnId": "CVE-2023-27997", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-13T02:00:00+02:00"}, "gcve": {"object_uuid": "1c937ed4-418c-49b1-93f0-703f1eeac26a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-13T00:00:00+00:00"}, "scope": {"notes": "A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,... | Affected: Fortinet / FortiOS-6K7K, FortiProxy, FortiOS | CVSS: 9.2 (CRITICAL) | EPSS: 0.85689 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-27997", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27997"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27997"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,...", "cve_id": "CVE-2023-27997", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiOS-6K7K, FortiProxy, FortiOS", "added_date": "2023-06-13T00:00:00.000Z", "cvss_score": 9.2, "epss_score": 0.85689, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9972, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-27997", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1d8097aa-4964-495d-945b-4643b8e23fd0", "vulnerability": {"vulnId": "CVE-2023-34105", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-12T18:30:39+02:00"}, "gcve": {"object_uuid": "1d8097aa-4964-495d-945b-4643b8e23fd0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-12T16:30:39+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-12T16:30:39+00:00"}, "scope": {"notes": "SRS has command injection vulnerability in demonstration api-server for HTTP callback. | Affected: Ossrs / srs | CVSS: 7.5 (HIGH) | EPSS: 0.08689 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-34105", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34105"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34105"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SRS has command injection vulnerability in demonstration api-server for HTTP callback.", "cve_id": "CVE-2023-34105", "vendor": "Ossrs", "ghsa_id": null, "product": "srs", "added_date": "2023-06-12T16:30:39.000Z", "cvss_score": 7.5, "epss_score": 0.08689, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-34105", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1808ebac-4cdc-4b2d-a472-d9e3f8d4b7d1", "vulnerability": {"vulnId": "CVE-2023-35042", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-12T02:00:00+02:00"}, "gcve": {"object_uuid": "1808ebac-4cdc-4b2d-a472-d9e3f8d4b7d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-12T00:00:00+00:00"}, "scope": {"notes": "GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData... | Affected: GeoServer / GeoServer | CVSS: 9.8 (CRITICAL) | EPSS: 0.43235 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-35042", "url": "https://www.cve.org/CVERecord?id=CVE-2023-35042"}, {"id": "GHSA-59X6-G4JR-4HXC", "url": "https://github.com/advisories/GHSA-59X6-G4JR-4HXC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-35042"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData...", "cve_id": "CVE-2023-35042", "vendor": "GeoServer", "ghsa_id": "GHSA-59X6-G4JR-4HXC", "product": "GeoServer", "added_date": "2023-06-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.43235, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98687, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-35042", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f668293-c2a7-472e-b7d3-444a85fae83b", "vulnerability": {"vulnId": "CVE-2019-25141", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-07T03:51:28+02:00"}, "gcve": {"object_uuid": "8f668293-c2a7-472e-b7d3-444a85fae83b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-07T01:51:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-07T01:51:28+00:00"}, "scope": {"notes": "The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing... | Affected: Smub / Easy WP SMTP by SendLayer \u2013 WordPress SMTP and Email Log Plugin | CVSS: 9.8 (CRITICAL) | EPSS: 0.04498 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-25141", "url": "https://www.cve.org/CVERecord?id=CVE-2019-25141"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-25141"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing...", "cve_id": "CVE-2019-25141", "vendor": "Smub", "ghsa_id": null, "product": "Easy WP SMTP by SendLayer \u2013 WordPress SMTP and Email Log Plugin", "added_date": "2023-06-07T01:51:28.000Z", "cvss_score": 9.8, "epss_score": 0.04498, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91191, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-25141", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "352a45ce-26d7-462d-90cb-976ba9c81f87", "vulnerability": {"vulnId": "CVE-2023-3079", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-07T02:00:00+02:00"}, "gcve": {"object_uuid": "352a45ce-26d7-462d-90cb-976ba9c81f87", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-07T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.3211 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-3079", "url": "https://www.cve.org/CVERecord?id=CVE-2023-3079"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-3079"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2023-3079", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2023-06-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.3211, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98267, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-3079", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "68bad27d-5cec-41d1-93d3-f99024880df1", "vulnerability": {"vulnId": "CVE-2023-33009", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "68bad27d-5cec-41d1-93d3-f99024880df1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-05T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series... | Affected: Zyxel / ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.28144 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33009", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33009"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33009"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series...", "cve_id": "CVE-2023-33009", "vendor": "Zyxel", "ghsa_id": null, "product": "ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware", "added_date": "2023-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.28144, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98058, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33009", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7e0a511c-e528-4744-a478-277009e89119", "vulnerability": {"vulnId": "CVE-2023-33010", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-05T02:00:00+02:00"}, "gcve": {"object_uuid": "7e0a511c-e528-4744-a478-277009e89119", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-05T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series... | Affected: Zyxel / ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.28813 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-33010", "url": "https://www.cve.org/CVERecord?id=CVE-2023-33010"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-33010"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series...", "cve_id": "CVE-2023-33010", "vendor": "Zyxel", "ghsa_id": null, "product": "ATP series firmware, USG FLEX series firmware, USG FLEX 50(W) firmware, USG20(W)-VPN firmware, VPN series firmware, ZyWALL/USG series firmware", "added_date": "2023-06-05T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.28813, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98098, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-33010", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "db583069-c657-4aa2-9951-fbae2c324e3f", "vulnerability": {"vulnId": "CVE-2023-34362", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-02T02:00:00+02:00"}, "gcve": {"object_uuid": "db583069-c657-4aa2-9951-fbae2c324e3f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-02T00:00:00+00:00"}, "scope": {"notes": "In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL... | Affected: Progress Software / MOVEit Transfer | CVSS: 9.8 (CRITICAL) | EPSS: 0.99934 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-34362", "url": "https://www.cve.org/CVERecord?id=CVE-2023-34362"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-34362"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL...", "cve_id": "CVE-2023-34362", "vendor": "Progress Software", "ghsa_id": null, "product": "MOVEit Transfer", "added_date": "2023-06-02T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99934, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9997, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-34362", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c106ff75-32cc-4211-b3ce-515cc7bc09b1", "vulnerability": {"vulnId": "CVE-2023-27639", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "c106ff75-32cc-4211-b3ce-515cc7bc09b1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-01T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the... | Affected: PrestaShop / Custom Product Designer | CVSS: 7.5 (HIGH) | EPSS: 0.03551 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27639", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27639"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27639"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the...", "cve_id": "CVE-2023-27639", "vendor": "PrestaShop", "ghsa_id": null, "product": "Custom Product Designer", "added_date": "2023-06-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03551, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27639", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1102ac3e-d993-4168-b649-bb76706f050a", "vulnerability": {"vulnId": "CVE-2023-27640", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-06-01T02:00:00+02:00"}, "gcve": {"object_uuid": "1102ac3e-d993-4168-b649-bb76706f050a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-06-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-06-01T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the... | Affected: PrestaShop / Custom Product Designer | CVSS: 7.5 (HIGH) | EPSS: 0.03573 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27640", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27640"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27640"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the...", "cve_id": "CVE-2023-27640", "vendor": "PrestaShop", "ghsa_id": null, "product": "Custom Product Designer", "added_date": "2023-06-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03573, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27640", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ef874864-b2dd-496f-8a6d-c2f4289d6ba9", "vulnerability": {"vulnId": "CVE-2023-28771", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-31T02:00:00+02:00"}, "gcve": {"object_uuid": "ef874864-b2dd-496f-8a6d-c2f4289d6ba9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-31T00:00:00+00:00"}, "scope": {"notes": "Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG... | Affected: Zyxel / ZyWALL/USG series firmware, VPN series firmware, USG FLEX series firmware, ATP series firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.99284 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28771", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28771"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28771"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG...", "cve_id": "CVE-2023-28771", "vendor": "Zyxel", "ghsa_id": null, "product": "ZyWALL/USG series firmware, VPN series firmware, USG FLEX series firmware, ATP series firmware", "added_date": "2023-05-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99284, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99937, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28771", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "25831641-9152-42f9-8cef-0e7f8cedd57d", "vulnerability": {"vulnId": "CVE-2023-2868", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-26T02:00:00+02:00"}, "gcve": {"object_uuid": "25831641-9152-42f9-8cef-0e7f8cedd57d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-26T00:00:00+00:00"}, "scope": {"notes": "Remote Code injection in Barracuda Email Security Gateway | Affected: Barracuda / Barracuda Email Security Gateway | CVSS: 9.4 (CRITICAL) | EPSS: 0.87691 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-2868", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2868"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2868"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code injection in Barracuda Email Security Gateway", "cve_id": "CVE-2023-2868", "vendor": "Barracuda", "ghsa_id": null, "product": "Barracuda Email Security Gateway", "added_date": "2023-05-26T00:00:00.000Z", "cvss_score": 9.4, "epss_score": 0.87691, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99757, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2868", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "11a8989c-068e-4a04-bd56-af37567838b4", "vulnerability": {"vulnId": "CVE-2023-28204", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-22T02:00:00+02:00"}, "gcve": {"object_uuid": "11a8989c-068e-4a04-bd56-af37567838b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-22T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6... | Affected: Apple / macOS, Safari, watchOS, iOS and iPadOS, tvOS | CVSS: 6.5 (MEDIUM) | EPSS: 0.14292 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28204", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28204"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28204"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6...", "cve_id": "CVE-2023-28204", "vendor": "Apple", "ghsa_id": null, "product": "macOS, Safari, watchOS, iOS and iPadOS, tvOS", "added_date": "2023-05-22T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.14292, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96497, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28204", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9fafc7c6-0c5c-4ecd-98b2-a2da4643a25f", "vulnerability": {"vulnId": "CVE-2023-32409", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-22T02:00:00+02:00"}, "gcve": {"object_uuid": "9fafc7c6-0c5c-4ecd-98b2-a2da4643a25f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-22T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS... | Affected: Apple / macOS, Safari, watchOS, iOS and iPadOS, tvOS | CVSS: 8.6 (HIGH) | EPSS: 0.1653 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32409", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32409"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32409"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS...", "cve_id": "CVE-2023-32409", "vendor": "Apple", "ghsa_id": null, "product": "macOS, Safari, watchOS, iOS and iPadOS, tvOS", "added_date": "2023-05-22T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.1653, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96914, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32409", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "28dda6c1-f159-4c7d-8c73-c7e21603caf6", "vulnerability": {"vulnId": "CVE-2023-32373", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-22T02:00:00+02:00"}, "gcve": {"object_uuid": "28dda6c1-f159-4c7d-8c73-c7e21603caf6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-22T00:00:00+00:00"}, "scope": {"notes": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6... | Affected: Apple / macOS, Safari, watchOS, iOS and iPadOS, tvOS | CVSS: 8.8 (HIGH) | EPSS: 0.12172 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-32373", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32373"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32373"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6...", "cve_id": "CVE-2023-32373", "vendor": "Apple", "ghsa_id": null, "product": "macOS, Safari, watchOS, iOS and iPadOS, tvOS", "added_date": "2023-05-22T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.12172, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9604, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32373", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fc22d2f1-029c-4bd4-8f1d-50f006fe5560", "vulnerability": {"vulnId": "CVE-2023-2806", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-19T10:31:02+02:00"}, "gcve": {"object_uuid": "fc22d2f1-029c-4bd4-8f1d-50f006fe5560", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-19T08:31:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-19T08:31:02+00:00"}, "scope": {"notes": "Weaver e-cology API RequestInfoByXml xml external entity reference | Affected: Weaver / e-cology | CVSS: 5.5 (MEDIUM) | EPSS: 0.00984 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-2806", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2806"}, {"id": "GHSA-J7M6-XXHH-82QR", "url": "https://github.com/advisories/GHSA-J7M6-XXHH-82QR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2806"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver e-cology API RequestInfoByXml xml external entity reference", "cve_id": "CVE-2023-2806", "vendor": "Weaver", "ghsa_id": "GHSA-J7M6-XXHH-82QR", "product": "e-cology", "added_date": "2023-05-19T08:31:02.000Z", "cvss_score": 5.5, "epss_score": 0.00984, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.60967, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2806", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f4ddd708-8928-456e-ba32-057683d40503", "vulnerability": {"vulnId": "CVE-2004-1464", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-19T02:00:00+02:00"}, "gcve": {"object_uuid": "f4ddd708-8928-456e-ba32-057683d40503", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-19T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP... | Affected: Cisco / IOS | CVSS: 5.9 (MEDIUM) | EPSS: 0.0484 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2004-1464", "url": "https://www.cve.org/CVERecord?id=CVE-2004-1464"}, {"id": "previdian", "url": "https://previdian.com/CVE-2004-1464"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP...", "cve_id": "CVE-2004-1464", "vendor": "Cisco", "ghsa_id": null, "product": "IOS", "added_date": "2023-05-19T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.0484, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91728, "used_in_malware": "unknown", "vulnerability_id": "CVE-2004-1464", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "119a5182-944f-4665-96fd-357ca8f56c71", "vulnerability": {"vulnId": "CVE-2023-21492", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-19T02:00:00+02:00"}, "gcve": {"object_uuid": "119a5182-944f-4665-96fd-357ca8f56c71", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-19T00:00:00+00:00"}, "scope": {"notes": "Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 4.4 (MEDIUM) | EPSS: 0.02554 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21492", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21492"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21492"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.", "cve_id": "CVE-2023-21492", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2023-05-19T00:00:00.000Z", "cvss_score": 4.4, "epss_score": 0.02554, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84497, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21492", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "301bffda-d7f0-4994-b5f6-b5ebbbba7d7a", "vulnerability": {"vulnId": "CVE-2016-6415", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-19T02:00:00+02:00"}, "gcve": {"object_uuid": "301bffda-d7f0-4994-b5f6-b5ebbbba7d7a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-19T00:00:00+00:00"}, "scope": {"notes": "The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x,... | Affected: Cisco / IOS, IOS XE, IOS XR, PIX | CVSS: 7.5 (HIGH) | EPSS: 0.87687 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-6415", "url": "https://www.cve.org/CVERecord?id=CVE-2016-6415"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-6415"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x,...", "cve_id": "CVE-2016-6415", "vendor": "Cisco", "ghsa_id": null, "product": "IOS, IOS XE, IOS XR, PIX", "added_date": "2023-05-19T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.87687, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99757, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-6415", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a2b1f246-81cc-4285-9d20-c8254f532d28", "vulnerability": {"vulnId": "CVE-2023-32243", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-17T11:33:52+02:00"}, "gcve": {"object_uuid": "a2b1f246-81cc-4285-9d20-c8254f532d28", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-17T09:33:52+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-17T09:33:52+00:00"}, "scope": {"notes": "WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation | Affected: WPDeveloper / Essential Addons for Elementor | CVSS: 9.8 (CRITICAL) | EPSS: 0.75531 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-32243", "url": "https://www.cve.org/CVERecord?id=CVE-2023-32243"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-32243"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation", "cve_id": "CVE-2023-32243", "vendor": "WPDeveloper", "ghsa_id": null, "product": "Essential Addons for Elementor", "added_date": "2023-05-17T09:33:52.000Z", "cvss_score": 9.8, "epss_score": 0.75531, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99504, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-32243", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "905bf206-7582-418e-a5fb-bf55db1eb4d8", "vulnerability": {"vulnId": "CVE-2015-5317", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "905bf206-7582-418e-a5fb-bf55db1eb4d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name... | Affected: Jenkins / Jenkins | CVSS: 7.5 (HIGH) | EPSS: 0.23003 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-5317", "url": "https://www.cve.org/CVERecord?id=CVE-2015-5317"}, {"id": "GHSA-8PQX-3RXX-F5PM", "url": "https://github.com/advisories/GHSA-8PQX-3RXX-F5PM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-5317"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name...", "cve_id": "CVE-2015-5317", "vendor": "Jenkins", "ghsa_id": "GHSA-8PQX-3RXX-F5PM", "product": "Jenkins", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.23003, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97691, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-5317", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3f6d6d42-423f-4538-bc4a-281d9f35b96f", "vulnerability": {"vulnId": "CVE-2016-3427", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "3f6d6d42-423f-4538-bc4a-281d9f35b96f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.92334 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3427", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3427"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3427"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect...", "cve_id": "CVE-2016-3427", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.92334, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3427", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6595fd9d-759a-46ae-ae2e-cb552c78129e", "vulnerability": {"vulnId": "CVE-2010-3904", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "6595fd9d-759a-46ae-ae2e-cb552c78129e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36... | Affected: Linux / Linux Kernel | CVSS: 7.8 (HIGH) | EPSS: 0.14468 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-3904", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3904"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3904"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36...", "cve_id": "CVE-2010-3904", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.14468, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96529, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3904", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "873597db-ca8e-4c0a-8b4e-970fafa11268", "vulnerability": {"vulnId": "CVE-2021-3560", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "873597db-ca8e-4c0a-8b4e-970fafa11268", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the... | Affected: Linux / polkit | CVSS: 7.8 (HIGH) | EPSS: 0.23708 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-3560", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3560"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3560"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the...", "cve_id": "CVE-2021-3560", "vendor": "Linux", "ghsa_id": null, "product": "polkit", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.23708, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97753, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3560", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "219702b7-02e0-4604-ac54-f5a352a9bf92", "vulnerability": {"vulnId": "CVE-2016-8735", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "219702b7-02e0-4604-ac54-f5a352a9bf92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before... | Affected: Apache / Apache Tomcat | CVSS: 9.8 (CRITICAL) | EPSS: 0.90338 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-8735", "url": "https://www.cve.org/CVERecord?id=CVE-2016-8735"}, {"id": "GHSA-CW54-59PW-4G8C", "url": "https://github.com/advisories/GHSA-CW54-59PW-4G8C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-8735"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before...", "cve_id": "CVE-2016-8735", "vendor": "Apache", "ghsa_id": "GHSA-CW54-59PW-4G8C", "product": "Apache Tomcat", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90338, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99796, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-8735", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b39105c6-98fc-4af1-8791-731a1be3d506", "vulnerability": {"vulnId": "CVE-2014-0196", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "b39105c6-98fc-4af1-8791-731a1be3d506", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the \"LECHO &... | Affected: Linux / kernel | CVSS: 5.5 (MEDIUM) | EPSS: 0.22475 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0196", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0196"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0196"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the \"LECHO &...", "cve_id": "CVE-2014-0196", "vendor": "Linux", "ghsa_id": null, "product": "kernel", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.22475, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9764, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0196", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d048e724-9377-40f9-b3c3-a3b0e5502592", "vulnerability": {"vulnId": "CVE-2023-25717", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-12T02:00:00+02:00"}, "gcve": {"object_uuid": "d048e724-9377-40f9-b3c3-a3b0e5502592", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-12T00:00:00+00:00"}, "scope": {"notes": "Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a... | Affected: Ruckus Wireless / Admin | CVSS: 9.8 (CRITICAL) | EPSS: 0.98069 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-25717", "url": "https://www.cve.org/CVERecord?id=CVE-2023-25717"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-25717"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a...", "cve_id": "CVE-2023-25717", "vendor": "Ruckus Wireless", "ghsa_id": null, "product": "Admin", "added_date": "2023-05-12T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98069, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9991, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-25717", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4ddc2f0d-7dc7-4b03-88a6-643a7b11f0d5", "vulnerability": {"vulnId": "CVE-2023-30194", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-10T02:00:00+02:00"}, "gcve": {"object_uuid": "4ddc2f0d-7dc7-4b03-88a6-643a7b11f0d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-10T00:00:00+00:00"}, "scope": {"notes": "Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook(). | Affected: Prestashop / posstaticfooter | CVSS: 9.8 (CRITICAL) | EPSS: 0.32413 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-30194", "url": "https://www.cve.org/CVERecord?id=CVE-2023-30194"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-30194"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().", "cve_id": "CVE-2023-30194", "vendor": "Prestashop", "ghsa_id": null, "product": "posstaticfooter", "added_date": "2023-05-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.32413, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98285, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-30194", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c7651f81-9e20-49be-b15c-1771bd7ba70d", "vulnerability": {"vulnId": "CVE-2023-24932", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-09T19:03:07+02:00"}, "gcve": {"object_uuid": "c7651f81-9e20-49be-b15c-1771bd7ba70d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-09T17:03:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-09T17:03:07+00:00"}, "scope": {"notes": "Secure Boot Security Feature Bypass Vulnerability | Affected: Microsoft / Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 6.7 (MEDIUM) | EPSS: 0.10561 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-24932", "url": "https://www.cve.org/CVERecord?id=CVE-2023-24932"}, {"id": "GHSA-CGCM-2V5Q-V3W9", "url": "https://github.com/advisories/GHSA-CGCM-2V5Q-V3W9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-24932"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Secure Boot Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-24932", "vendor": "Microsoft", "ghsa_id": "GHSA-CGCM-2V5Q-V3W9", "product": "Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-05-09T17:03:07.282Z", "cvss_score": 6.7, "epss_score": 0.10561, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95647, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-24932", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1203b50a-89e7-4853-9378-a1eea238988f", "vulnerability": {"vulnId": "CVE-2023-29336", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-09T02:00:00+02:00"}, "gcve": {"object_uuid": "1203b50a-89e7-4853-9378-a1eea238988f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-09T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.40919 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29336", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29336"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29336"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-29336", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-05-09T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.40919, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98618, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29336", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a36fb12d-1e7e-4c76-813c-4adc7c926efd", "vulnerability": {"vulnId": "CVE-2023-2523", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-04T20:00:05+02:00"}, "gcve": {"object_uuid": "a36fb12d-1e7e-4c76-813c-4adc7c926efd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-04T18:00:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-04T18:00:05+00:00"}, "scope": {"notes": "Weaver E-Office unrestricted upload | Affected: Weaver / E-Office | CVSS: 7.3 (HIGH) | EPSS: 0.32895 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-2523", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2523"}, {"id": "GHSA-W8G9-XRV8-VFW2", "url": "https://github.com/advisories/GHSA-W8G9-XRV8-VFW2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2523"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Weaver E-Office unrestricted upload", "cve_id": "CVE-2023-2523", "vendor": "Weaver", "ghsa_id": "GHSA-W8G9-XRV8-VFW2", "product": "E-Office", "added_date": "2023-05-04T18:00:05.000Z", "cvss_score": 7.3, "epss_score": 0.32895, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98309, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2523", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a885efb-8c72-4d3b-93d3-68c26c2e98ec", "vulnerability": {"vulnId": "CVE-2021-45046", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-01T02:00:00+02:00"}, "gcve": {"object_uuid": "2a885efb-8c72-4d3b-93d3-68c26c2e98ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-01T00:00:00+00:00"}, "scope": {"notes": "Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack | Affected: Apache / Apache Log4j | CVSS: 9.0 (CRITICAL) | EPSS: 0.99977 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-45046", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45046"}, {"id": "GHSA-7RJR-3Q55-VV33", "url": "https://github.com/advisories/GHSA-7RJR-3Q55-VV33"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45046"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack", "cve_id": "CVE-2021-45046", "vendor": "Apache", "ghsa_id": "GHSA-7RJR-3Q55-VV33", "product": "Apache Log4j", "added_date": "2023-05-01T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.99977, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9998, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-45046", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ebceaa8c-d924-413d-b261-9d15bbd54791", "vulnerability": {"vulnId": "CVE-2023-21839", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-01T02:00:00+02:00"}, "gcve": {"object_uuid": "ebceaa8c-d924-413d-b261-9d15bbd54791", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-01T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 7.5 (HIGH) | EPSS: 0.999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21839", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21839"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21839"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are...", "cve_id": "CVE-2023-21839", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2023-05-01T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99965, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21839", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0e4b553-4e16-46e8-8839-96cbfd627023", "vulnerability": {"vulnId": "CVE-2023-1389", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-05-01T02:00:00+02:00"}, "gcve": {"object_uuid": "e0e4b553-4e16-46e8-8839-96cbfd627023", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-05-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-05-01T00:00:00+00:00"}, "scope": {"notes": "TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the... | Affected: TP-Link / TP-Link Archer AX21 (AX1800) | CVSS: 8.8 (HIGH) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-1389", "url": "https://www.cve.org/CVERecord?id=CVE-2023-1389"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-1389"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the...", "cve_id": "CVE-2023-1389", "vendor": "TP-Link", "ghsa_id": null, "product": "TP-Link Archer AX21 (AX1800)", "added_date": "2023-05-01T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-1389", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "40cc6da2-f9f6-42ca-9a98-8b1dc01e9615", "vulnerability": {"vulnId": "CVE-2023-28770", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-27T02:00:00+02:00"}, "gcve": {"object_uuid": "40cc6da2-f9f6-42ca-9a98-8b1dc01e9615", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-27T00:00:00+00:00"}, "scope": {"notes": "The sensitive information exposure vulnerability in the CGI \u201cExport_Log\u201d and the binary \u201czcmd\u201d in Zyxel DX5401-B0 firmware versions prior to... | Affected: Zyxel / DX5401-B0 firmware | CVSS: 7.5 (HIGH) | EPSS: 0.57778 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-28770", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28770"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28770"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The sensitive information exposure vulnerability in the CGI \u201cExport_Log\u201d and the binary \u201czcmd\u201d in Zyxel DX5401-B0 firmware versions prior to...", "cve_id": "CVE-2023-28770", "vendor": "Zyxel", "ghsa_id": null, "product": "DX5401-B0 firmware", "added_date": "2023-04-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.57778, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99061, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28770", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4bd7ac82-763a-4721-998f-d6b6a312aa9a", "vulnerability": {"vulnId": "CVE-2023-27350", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-21T02:00:00+02:00"}, "gcve": {"object_uuid": "4bd7ac82-763a-4721-998f-d6b6a312aa9a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-21T00:00:00+00:00"}, "scope": {"notes": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication... | Affected: PaperCut / NG | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-27350", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27350"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27350"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication...", "cve_id": "CVE-2023-27350", "vendor": "PaperCut", "ghsa_id": null, "product": "NG", "added_date": "2023-04-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99995, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-27350", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "665c1526-b968-4941-81a8-0be0a90a21f5", "vulnerability": {"vulnId": "CVE-2023-2136", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-21T02:00:00+02:00"}, "gcve": {"object_uuid": "665c1526-b968-4941-81a8-0be0a90a21f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-21T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.05739 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-2136", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2136"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2136"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially...", "cve_id": "CVE-2023-2136", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2023-04-21T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.05739, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92822, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2136", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02850216-a6ab-46ff-ab28-09bca634f42b", "vulnerability": {"vulnId": "CVE-2023-28432", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-21T02:00:00+02:00"}, "gcve": {"object_uuid": "02850216-a6ab-46ff-ab28-09bca634f42b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-21T00:00:00+00:00"}, "scope": {"notes": "Minio Information Disclosure in Cluster Deployment | Affected: Minio / minio | CVSS: 7.5 (HIGH) | EPSS: 0.83957 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28432", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28432"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28432"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Minio Information Disclosure in Cluster Deployment", "cve_id": "CVE-2023-28432", "vendor": "Minio", "ghsa_id": null, "product": "minio", "added_date": "2023-04-21T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.83957, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99687, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28432", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ab875f86-6ce3-4e80-80c6-26d711f7f964", "vulnerability": {"vulnId": "CVE-2017-6742", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-19T02:00:00+02:00"}, "gcve": {"object_uuid": "ab875f86-6ce3-4e80-80c6-26d711f7f964", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-19T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely... | Affected: Cisco, IntelliShield / Cisco IOS XE Software, Universal Product | CVSS: 8.8 (HIGH) | EPSS: 0.21424 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6742", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6742"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6742"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...", "cve_id": "CVE-2017-6742", "vendor": "Cisco, IntelliShield", "ghsa_id": null, "product": "Cisco IOS XE Software, Universal Product", "added_date": "2023-04-19T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.21424, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97542, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6742", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "875d3147-3874-43dd-a373-92c1f3d577fe", "vulnerability": {"vulnId": "CVE-2019-8526", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-17T02:00:00+02:00"}, "gcve": {"object_uuid": "875d3147-3874-43dd-a373-92c1f3d577fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-17T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to... | Affected: Apple / macOS | CVSS: 7.8 (HIGH) | EPSS: 0.00701 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-8526", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8526"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8526"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.4. An application may be able to...", "cve_id": "CVE-2019-8526", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2023-04-17T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00701, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.51479, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8526", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c020a04d-d1de-4a3d-a1f3-f5876cbd1178", "vulnerability": {"vulnId": "CVE-2023-2033", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-17T02:00:00+02:00"}, "gcve": {"object_uuid": "c020a04d-d1de-4a3d-a1f3-f5876cbd1178", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-17T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.40798 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-2033", "url": "https://www.cve.org/CVERecord?id=CVE-2023-2033"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-2033"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2023-2033", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2023-04-17T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.40798, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98614, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-2033", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a903f5b6-1b12-4bd6-94eb-3ce801c6a0bd", "vulnerability": {"vulnId": "CVE-2022-38840", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-16T02:00:00+02:00"}, "gcve": {"object_uuid": "a903f5b6-1b12-4bd6-94eb-3ce801c6a0bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-16T00:00:00+00:00"}, "scope": {"notes": "cgi-bin/xmlstatus.cgi in G\u00fcralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local... | Affected: G\u00fcralp / MAN-EAM-0003 | CVSS: 7.5 (HIGH) | EPSS: 0.09803 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-38840", "url": "https://www.cve.org/CVERecord?id=CVE-2022-38840"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-38840"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "cgi-bin/xmlstatus.cgi in G\u00fcralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local...", "cve_id": "CVE-2022-38840", "vendor": "G\u00fcralp", "ghsa_id": null, "product": "MAN-EAM-0003", "added_date": "2023-04-16T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.09803, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95408, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-38840", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4d1272f1-0245-456c-8956-38ff1e1f3e5f", "vulnerability": {"vulnId": "CVE-2023-29492", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "4d1272f1-0245-456c-8956-38ff1e1f3e5f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-13T00:00:00+00:00"}, "scope": {"notes": "Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not... | Affected: Novi Survey / Novi Survey | CVSS: 9.8 (CRITICAL) | EPSS: 0.0269 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-29492", "url": "https://www.cve.org/CVERecord?id=CVE-2023-29492"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-29492"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not...", "cve_id": "CVE-2023-29492", "vendor": "Novi Survey", "ghsa_id": null, "product": "Novi Survey", "added_date": "2023-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.0269, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85351, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-29492", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c575f4d5-40c4-42ea-b5ac-c37c272b292a", "vulnerability": {"vulnId": "CVE-2023-20963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "c575f4d5-40c4-42ea-b5ac-c37c272b292a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-13T00:00:00+00:00"}, "scope": {"notes": "In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.01465 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-20963", "url": "https://www.cve.org/CVERecord?id=CVE-2023-20963"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-20963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges...", "cve_id": "CVE-2023-20963", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2023-04-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01465, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-20963", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "44155f88-5adf-4d92-882a-61c486ef731c", "vulnerability": {"vulnId": "CVE-2023-28252", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "44155f88-5adf-4d92-882a-61c486ef731c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-11T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.48973 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28252", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28252"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28252"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-28252", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-04-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.48973, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98847, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-28252", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3ec46ef3-50dd-49de-b725-f9e235247bbb", "vulnerability": {"vulnId": "CVE-2023-28205", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-10T02:00:00+02:00"}, "gcve": {"object_uuid": "3ec46ef3-50dd-49de-b725-f9e235247bbb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-10T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS... | Affected: Apple / iOS and iPadOS, Safari, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.27076 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28205", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28205"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28205"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS...", "cve_id": "CVE-2023-28205", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, Safari, macOS", "added_date": "2023-04-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.27076, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28205", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0788b825-5e70-4719-8f58-d2ae40aa2f55", "vulnerability": {"vulnId": "CVE-2023-27076", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-10T02:00:00+02:00"}, "gcve": {"object_uuid": "0788b825-5e70-4719-8f58-d2ae40aa2f55", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-10T00:00:00+00:00"}, "scope": {"notes": "Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter. | Affected: Tenda / G103 | CVSS: 9.8 (CRITICAL) | EPSS: 0.2293 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27076", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27076"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27076"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.", "cve_id": "CVE-2023-27076", "vendor": "Tenda", "ghsa_id": null, "product": "G103", "added_date": "2023-04-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.2293, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97685, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27076", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "66f359d8-4aa5-489d-87d2-f1b81ae3be16", "vulnerability": {"vulnId": "CVE-2023-26067", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-10T02:00:00+02:00"}, "gcve": {"object_uuid": "66f359d8-4aa5-489d-87d2-f1b81ae3be16", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-10T00:00:00+00:00"}, "scope": {"notes": "Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). | Affected: Lexmark / Lexmark devices | CVSS: 8.1 (HIGH) | EPSS: 0.37835 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26067", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26067"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26067"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).", "cve_id": "CVE-2023-26067", "vendor": "Lexmark", "ghsa_id": null, "product": "Lexmark devices", "added_date": "2023-04-10T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.37835, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98503, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26067", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "56021151-6a0e-4669-b5a3-9dcb75fb54db", "vulnerability": {"vulnId": "CVE-2023-28206", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-10T02:00:00+02:00"}, "gcve": {"object_uuid": "56021151-6a0e-4669-b5a3-9dcb75fb54db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-10T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 8.6 (HIGH) | EPSS: 0.23215 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-28206", "url": "https://www.cve.org/CVERecord?id=CVE-2023-28206"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-28206"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS...", "cve_id": "CVE-2023-28206", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2023-04-10T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.23215, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9771, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-28206", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bde98aa0-ec08-4c9d-a633-d709c507fbe5", "vulnerability": {"vulnId": "CVE-2023-26083", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-07T02:00:00+02:00"}, "gcve": {"object_uuid": "bde98aa0-ec08-4c9d-a633-d709c507fbe5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-07T00:00:00+00:00"}, "scope": {"notes": "Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all... | Affected: Arm / Mali GPU Kernel Driver | CVSS: 3.3 (LOW) | EPSS: 0.01218 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-26083", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26083"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26083"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all...", "cve_id": "CVE-2023-26083", "vendor": "Arm", "ghsa_id": null, "product": "Mali GPU Kernel Driver", "added_date": "2023-04-07T00:00:00.000Z", "cvss_score": 3.3, "epss_score": 0.01218, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.67526, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26083", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9bf21a20-871a-4472-817d-f5e6d647f66d", "vulnerability": {"vulnId": "CVE-2021-27878", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-07T02:00:00+02:00"}, "gcve": {"object_uuid": "9bf21a20-871a-4472-817d-f5e6d647f66d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-07T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication,... | Affected: Veritas / Backup Exec | CVSS: 8.8 (HIGH) | EPSS: 0.23952 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27878", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27878"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27878"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication,...", "cve_id": "CVE-2021-27878", "vendor": "Veritas", "ghsa_id": null, "product": "Backup Exec", "added_date": "2023-04-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.23952, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9777, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27878", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d2269e60-704e-42a8-8707-9c915716a774", "vulnerability": {"vulnId": "CVE-2019-1388", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-07T02:00:00+02:00"}, "gcve": {"object_uuid": "d2269e60-704e-42a8-8707-9c915716a774", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-07T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.08589 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1388", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1388"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1388"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows...", "cve_id": "CVE-2019-1388", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2023-04-07T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.08589, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94921, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1388", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b64b5ec-7cb7-4455-83bf-9f1e44bf05e1", "vulnerability": {"vulnId": "CVE-2021-27876", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-07T02:00:00+02:00"}, "gcve": {"object_uuid": "9b64b5ec-7cb7-4455-83bf-9f1e44bf05e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-07T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication,... | Affected: Veritas / Backup Exec | CVSS: 8.1 (HIGH) | EPSS: 0.13518 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27876", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27876"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27876"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication,...", "cve_id": "CVE-2021-27876", "vendor": "Veritas", "ghsa_id": null, "product": "Backup Exec", "added_date": "2023-04-07T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.13518, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96337, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27876", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "419097f6-4667-42e1-85f2-8cd783d7739a", "vulnerability": {"vulnId": "CVE-2021-27877", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-07T02:00:00+02:00"}, "gcve": {"object_uuid": "419097f6-4667-42e1-85f2-8cd783d7739a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-07T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This... | Affected: Veritas / Backup Exec | CVSS: 8.2 (HIGH) | EPSS: 0.6491 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27877", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27877"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27877"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This...", "cve_id": "CVE-2021-27877", "vendor": "Veritas", "ghsa_id": null, "product": "Backup Exec", "added_date": "2023-04-07T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.6491, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99228, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27877", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c7b807cc-586f-430d-a437-0b3be117d936", "vulnerability": {"vulnId": "CVE-2022-27926", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-04-03T02:00:00+02:00"}, "gcve": {"object_uuid": "c7b807cc-586f-430d-a437-0b3be117d936", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-04-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-04-03T00:00:00+00:00"}, "scope": {"notes": "A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows... | Affected: Zimbra / Collaboration | CVSS: 6.1 (MEDIUM) | EPSS: 0.17634 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-27926", "url": "https://www.cve.org/CVERecord?id=CVE-2022-27926"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-27926"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows...", "cve_id": "CVE-2022-27926", "vendor": "Zimbra", "ghsa_id": null, "product": "Collaboration", "added_date": "2023-04-03T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.17634, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97065, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-27926", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5e74e408-dc8f-41d9-929f-cd54654d2cf3", "vulnerability": {"vulnId": "CVE-2023-27163", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "5e74e408-dc8f-41d9-929f-cd54654d2cf3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-31T00:00:00+00:00"}, "scope": {"notes": "request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This... | Affected: Request-baskets / request-baskets | CVSS: 6.5 (MEDIUM) | EPSS: 0.06591 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27163", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27163"}, {"id": "GHSA-58G2-VGPG-335Q", "url": "https://github.com/advisories/GHSA-58G2-VGPG-335Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27163"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This...", "cve_id": "CVE-2023-27163", "vendor": "Request-baskets", "ghsa_id": "GHSA-58G2-VGPG-335Q", "product": "request-baskets", "added_date": "2023-03-31T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.06591, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93635, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27163", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8639b030-4285-4a59-a63f-bd89d20ab88b", "vulnerability": {"vulnId": "CVE-2023-27159", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "8639b030-4285-4a59-a63f-bd89d20ab88b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-31T00:00:00+00:00"}, "scope": {"notes": "Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability... | Affected: Appwrite / Appwrite | CVSS: 7.5 (HIGH) | EPSS: 0.36419 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27159", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27159"}, {"id": "GHSA-HXGX-584X-VWM8", "url": "https://github.com/advisories/GHSA-HXGX-584X-VWM8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27159"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability...", "cve_id": "CVE-2023-27159", "vendor": "Appwrite", "ghsa_id": "GHSA-HXGX-584X-VWM8", "product": "Appwrite", "added_date": "2023-03-31T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.36419, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98444, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27159", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "acb3201c-c3ac-49d4-bc78-f6e85c0f6b15", "vulnerability": {"vulnId": "CVE-2022-38181", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "acb3201c-c3ac-49d4-bc78-f6e85c0f6b15", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost... | Affected: Arm / Mali GPU kernel driver | CVSS: 8.8 (HIGH) | EPSS: 0.14093 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-38181", "url": "https://www.cve.org/CVERecord?id=CVE-2022-38181"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-38181"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost...", "cve_id": "CVE-2022-38181", "vendor": "Arm", "ghsa_id": null, "product": "Mali GPU kernel driver", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.14093, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96458, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-38181", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9710c21b-7b04-4748-bcfa-a3ecaa058a47", "vulnerability": {"vulnId": "CVE-2021-30900", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "9710c21b-7b04-4748-bcfa-a3ecaa058a47", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS... | Affected: Apple / iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.05204 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30900", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30900"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30900"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS...", "cve_id": "CVE-2021-30900", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05204, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92224, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30900", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cca714ad-7bfc-4463-90fe-19f0af1d2455", "vulnerability": {"vulnId": "CVE-2017-7494", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "cca714ad-7bfc-4463-90fe-19f0af1d2455", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to... | Affected: Samba / samba | CVSS: 9.8 (CRITICAL) | EPSS: 0.99448 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-7494", "url": "https://www.cve.org/CVERecord?id=CVE-2017-7494"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-7494"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to...", "cve_id": "CVE-2017-7494", "vendor": "Samba", "ghsa_id": null, "product": "samba", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99448, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99942, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-7494", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6f03b8d-dd84-4a59-a7b3-f850fb09ff82", "vulnerability": {"vulnId": "CVE-2023-0266", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "a6f03b8d-dd84-4a59-a7b3-f850fb09ff82", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel | Affected: Linux / Linux Kernel | CVSS: 7.9 (HIGH) | EPSS: 0.03702 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-0266", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0266"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0266"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel", "cve_id": "CVE-2023-0266", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 7.9, "epss_score": 0.03702, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89388, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0266", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "719e7b8c-51f9-4ef4-92ae-4c118dd4ec10", "vulnerability": {"vulnId": "CVE-2022-22706", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "719e7b8c-51f9-4ef4-92ae-4c118dd4ec10", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through... | Affected: Arm / Mali GPU Kernel Driver | CVSS: 7.8 (HIGH) | EPSS: 0.01062 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22706", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22706"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22706"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through...", "cve_id": "CVE-2022-22706", "vendor": "Arm", "ghsa_id": null, "product": "Mali GPU Kernel Driver", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01062, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.63347, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22706", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "706f6a71-3953-4ad2-b4b2-9f9f94f0c9a8", "vulnerability": {"vulnId": "CVE-2022-39197", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "706f6a71-3953-4ad2-b4b2-9f9f94f0c9a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on... | Affected: HelpSystems / Cobalt Strike | CVSS: 6.1 (MEDIUM) | EPSS: 0.46446 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-39197", "url": "https://www.cve.org/CVERecord?id=CVE-2022-39197"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-39197"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on...", "cve_id": "CVE-2022-39197", "vendor": "HelpSystems", "ghsa_id": null, "product": "Cobalt Strike", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.46446, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98784, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-39197", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ca2d149b-52da-4ac3-b63b-743cec50800d", "vulnerability": {"vulnId": "CVE-2013-3163", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "ca2d149b-52da-4ac3-b63b-743cec50800d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.70676 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3163", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3163"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3163"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...", "cve_id": "CVE-2013-3163", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.70676, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99379, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3163", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "830709e8-acc6-4a6d-89f3-6335d7ae240e", "vulnerability": {"vulnId": "CVE-2022-3038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "830709e8-acc6-4a6d-89f3-6335d7ae240e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.24738 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-3038", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3038"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2022-3038", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.24738, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3038", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a87f21c2-25fb-46ef-9fd4-9047284bf040", "vulnerability": {"vulnId": "CVE-2022-42948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-30T02:00:00+02:00"}, "gcve": {"object_uuid": "a87f21c2-25fb-46ef-9fd4-9047284bf040", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-30T00:00:00+00:00"}, "scope": {"notes": "Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible... | Affected: HelpSystems / Cobalt Strike | CVSS: 9.8 (CRITICAL) | EPSS: 0.02706 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-42948", "url": "https://www.cve.org/CVERecord?id=CVE-2022-42948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-42948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible...", "cve_id": "CVE-2022-42948", "vendor": "HelpSystems", "ghsa_id": null, "product": "Cobalt Strike", "added_date": "2023-03-30T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.02706, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85443, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-42948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b39405ae-3ac5-4740-a73e-372a685a3017", "vulnerability": {"vulnId": "CVE-2023-27637", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-22T01:00:00+01:00"}, "gcve": {"object_uuid": "b39405ae-3ac5-4740-a73e-372a685a3017", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-22T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a... | Affected: Tshirtecommerce / Custom Product Designer for PrestaShop | CVSS: 9.8 (CRITICAL) | EPSS: 0.03299 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27637", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27637"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27637"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a...", "cve_id": "CVE-2023-27637", "vendor": "Tshirtecommerce", "ghsa_id": null, "product": "Custom Product Designer for PrestaShop", "added_date": "2023-03-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03299, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88108, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27637", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "487d5625-3583-4acf-8b91-135c8553167b", "vulnerability": {"vulnId": "CVE-2023-26360", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "487d5625-3583-4acf-8b91-135c8553167b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-15T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion Improper Access Control Arbitrary code execution | Affected: Adobe / ColdFusion | CVSS: 8.6 (HIGH) | EPSS: 0.97339 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-26360", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26360"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26360"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion Improper Access Control Arbitrary code execution", "cve_id": "CVE-2023-26360", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2023-03-15T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.97339, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26360", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0cf214dd-4fd1-49bd-9367-06fedf19f2b0", "vulnerability": {"vulnId": "CVE-2023-23397", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-14T01:00:00+01:00"}, "gcve": {"object_uuid": "0cf214dd-4fd1-49bd-9367-06fedf19f2b0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-14T00:00:00+00:00"}, "scope": {"notes": "Microsoft Outlook Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Office LTSC 2021, Microsoft Outlook 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Outlook 2013 Service Pack 1 | CVSS: 9.8 (CRITICAL) | EPSS: 0.97159 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-23397", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23397"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23397"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Outlook Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-23397", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office LTSC 2021, Microsoft Outlook 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019, Microsoft Outlook 2013 Service Pack 1", "added_date": "2023-03-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97159, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99893, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23397", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ef92224-1a01-434d-b3c2-81f1dad71f37", "vulnerability": {"vulnId": "CVE-2022-41328", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-14T01:00:00+01:00"}, "gcve": {"object_uuid": "2ef92224-1a01-434d-b3c2-81f1dad71f37", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-14T00:00:00+00:00"}, "scope": {"notes": "A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through... | Affected: Fortinet / FortiOS | CVSS: 6.5 (MEDIUM) | EPSS: 0.10682 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41328", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41328"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41328"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through...", "cve_id": "CVE-2022-41328", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiOS", "added_date": "2023-03-14T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.10682, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95681, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41328", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9f74016d-6232-4bb3-9ad5-f20cd8606dd1", "vulnerability": {"vulnId": "CVE-2023-24880", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-14T01:00:00+01:00"}, "gcve": {"object_uuid": "9f74016d-6232-4bb3-9ad5-f20cd8606dd1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-14T00:00:00+00:00"}, "scope": {"notes": "Windows SmartScreen Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 4.4 (MEDIUM) | EPSS: 0.78005 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-24880", "url": "https://www.cve.org/CVERecord?id=CVE-2023-24880"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-24880"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows SmartScreen Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-24880", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2023-03-14T00:00:00.000Z", "cvss_score": 4.4, "epss_score": 0.78005, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99563, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-24880", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "360ccf8f-4ad7-402f-baad-f44086807852", "vulnerability": {"vulnId": "CVE-2023-27587", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-13T01:00:00+01:00"}, "gcve": {"object_uuid": "360ccf8f-4ad7-402f-baad-f44086807852", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-13T00:00:00+00:00"}, "scope": {"notes": "ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior... | Affected: Rozbb / readtomyshoe | CVSS: 7.4 (HIGH) | EPSS: 0.03857 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-27587", "url": "https://www.cve.org/CVERecord?id=CVE-2023-27587"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-27587"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior...", "cve_id": "CVE-2023-27587", "vendor": "Rozbb", "ghsa_id": null, "product": "readtomyshoe", "added_date": "2023-03-13T00:00:00.000Z", "cvss_score": 7.4, "epss_score": 0.03857, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89834, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-27587", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d5574cda-8a94-4f78-8e83-06654f6b43ff", "vulnerability": {"vulnId": "CVE-2020-5741", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "d5574cda-8a94-4f78-8e83-06654f6b43ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-10T00:00:00+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | Affected: Plex / Plex Media Server (Windows) | CVSS: 7.2 (HIGH) | EPSS: 0.72936 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5741", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5741"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5741"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.", "cve_id": "CVE-2020-5741", "vendor": "Plex", "ghsa_id": null, "product": "Plex Media Server (Windows)", "added_date": "2023-03-10T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.72936, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99439, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5741", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4eb79336-d398-4249-b2c5-ad4c67c4a2fb", "vulnerability": {"vulnId": "CVE-2021-39144", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-10T01:00:00+01:00"}, "gcve": {"object_uuid": "4eb79336-d398-4249-b2c5-ad4c67c4a2fb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-10T00:00:00+00:00"}, "scope": {"notes": "XStream is vulnerable to a Remote Command Execution attack | Affected: X-stream / xstream | CVSS: 8.5 (HIGH) | EPSS: 0.98124 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-39144", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39144"}, {"id": "GHSA-J9H8-PHRW-H4FH", "url": "https://github.com/advisories/GHSA-J9H8-PHRW-H4FH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39144"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "XStream is vulnerable to a Remote Command Execution attack", "cve_id": "CVE-2021-39144", "vendor": "X-stream", "ghsa_id": "GHSA-J9H8-PHRW-H4FH", "product": "xstream", "added_date": "2023-03-10T00:00:00.000Z", "cvss_score": 8.5, "epss_score": 0.98124, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99912, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39144", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7b362c8e-bbac-498f-991f-34f493a12903", "vulnerability": {"vulnId": "CVE-2022-35914", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "7b362c8e-bbac-498f-991f-34f493a12903", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-07T00:00:00+00:00"}, "scope": {"notes": "/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection. | Affected: GLPI / GLPI | CVSS: 9.8 (CRITICAL) | EPSS: 0.9988 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-35914", "url": "https://www.cve.org/CVERecord?id=CVE-2022-35914"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-35914"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.", "cve_id": "CVE-2022-35914", "vendor": "GLPI", "ghsa_id": null, "product": "GLPI", "added_date": "2023-03-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9988, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99964, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-35914", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0a5dc7a-c7fc-4835-804c-1025d6bef91b", "vulnerability": {"vulnId": "CVE-2022-33891", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "e0a5dc7a-c7fc-4835-804c-1025d6bef91b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-07T00:00:00+00:00"}, "scope": {"notes": "Apache Spark shell command injection vulnerability via Spark UI | Affected: Apache / Apache Spark | CVSS: 8.8 (HIGH) | EPSS: 0.93076 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-33891", "url": "https://www.cve.org/CVERecord?id=CVE-2022-33891"}, {"id": "GHSA-4X9R-J582-CGR8", "url": "https://github.com/advisories/GHSA-4X9R-J582-CGR8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-33891"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Spark shell command injection vulnerability via Spark UI", "cve_id": "CVE-2022-33891", "vendor": "Apache", "ghsa_id": "GHSA-4X9R-J582-CGR8", "product": "Apache Spark", "added_date": "2023-03-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.93076, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99832, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-33891", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "98d63573-76c2-4298-b9dd-38d794f0defa", "vulnerability": {"vulnId": "CVE-2022-28810", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "98d63573-76c2-4298-b9dd-38d794f0defa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-03-07T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as... | Affected: Zoho / ManageEngine ADSelfService Plus | CVSS: 6.8 (MEDIUM) | EPSS: 0.70966 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-28810", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28810"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28810"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as...", "cve_id": "CVE-2022-28810", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine ADSelfService Plus", "added_date": "2023-03-07T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.70966, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99388, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28810", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "50344053-406b-4946-8464-564716c3a978", "vulnerability": {"vulnId": "CVE-2023-0552", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-27T16:24:31+01:00"}, "gcve": {"object_uuid": "50344053-406b-4946-8464-564716c3a978", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-27T15:24:31+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-27T15:24:31+00:00"}, "scope": {"notes": "Pie Register < 3.8.2.3 - Open Redirect | Affected: Pie Register / Pie Register | CVSS: 5.4 (MEDIUM) | EPSS: 0.24263 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-0552", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0552"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0552"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pie Register < 3.8.2.3 - Open Redirect", "cve_id": "CVE-2023-0552", "vendor": "Pie Register", "ghsa_id": null, "product": "Pie Register", "added_date": "2023-02-27T15:24:31.000Z", "cvss_score": 5.4, "epss_score": 0.24263, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97794, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0552", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c77b7aec-5489-451a-89ed-905fc15d5c41", "vulnerability": {"vulnId": "CVE-2022-36537", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-27T01:00:00+01:00"}, "gcve": {"object_uuid": "c77b7aec-5489-451a-89ed-905fc15d5c41", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-27T00:00:00+00:00"}, "scope": {"notes": "ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the... | Affected: Potix / ZK Framework | CVSS: 7.5 (HIGH) | EPSS: 0.95397 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-36537", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36537"}, {"id": "GHSA-6278-2Q4M-CMF3", "url": "https://github.com/advisories/GHSA-6278-2Q4M-CMF3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36537"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the...", "cve_id": "CVE-2022-36537", "vendor": "Potix", "ghsa_id": "GHSA-6278-2Q4M-CMF3", "product": "ZK Framework", "added_date": "2023-02-27T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.95397, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99868, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-36537", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "51df2006-8416-496f-b71a-247f64800897", "vulnerability": {"vulnId": "CVE-2023-26609", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-27T01:00:00+01:00"}, "gcve": {"object_uuid": "51df2006-8416-496f-b71a-247f64800897", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-27T00:00:00+00:00"}, "scope": {"notes": "ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field. | Affected: ABUS / TVIP 20000-21150 | CVSS: 7.2 (HIGH) | EPSS: 0.38722 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-26609", "url": "https://www.cve.org/CVERecord?id=CVE-2023-26609"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-26609"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.", "cve_id": "CVE-2023-26609", "vendor": "ABUS", "ghsa_id": null, "product": "TVIP 20000-21150", "added_date": "2023-02-27T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.38722, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98541, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-26609", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "03971f2c-3e4d-43d3-af54-7e313204403b", "vulnerability": {"vulnId": "CVE-2023-23295", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-23T01:00:00+01:00"}, "gcve": {"object_uuid": "03971f2c-3e4d-43d3-af54-7e313204403b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-23T00:00:00+00:00"}, "scope": {"notes": "Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify... | Affected: Korenix / Jetwave 4200 Series and JetWave 3000 Series | CVSS: 8.8 (HIGH) | EPSS: 0.0383 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-23295", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23295"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23295"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify...", "cve_id": "CVE-2023-23295", "vendor": "Korenix", "ghsa_id": null, "product": "Jetwave 4200 Series and JetWave 3000 Series", "added_date": "2023-02-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.0383, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89756, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23295", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8211e7eb-32fe-4080-9309-54447a422692", "vulnerability": {"vulnId": "CVE-2023-23063", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-22T01:00:00+01:00"}, "gcve": {"object_uuid": "8211e7eb-32fe-4080-9309-54447a422692", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-22T00:00:00+00:00"}, "scope": {"notes": "Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi. | Affected: Cellinx / NVT | CVSS: 7.5 (HIGH) | EPSS: 0.02431 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-23063", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23063"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23063"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.", "cve_id": "CVE-2023-23063", "vendor": "Cellinx", "ghsa_id": null, "product": "NVT", "added_date": "2023-02-22T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02431, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83663, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23063", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4f5a39a5-b3b1-46b4-826e-9707a6ffd350", "vulnerability": {"vulnId": "CVE-2022-41223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-21T01:00:00+01:00"}, "gcve": {"object_uuid": "4f5a39a5-b3b1-46b4-826e-9707a6ffd350", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-21T00:00:00+00:00"}, "scope": {"notes": "The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection... | Affected: Mitel / MiVoice Connect | CVSS: 6.8 (MEDIUM) | EPSS: 0.10657 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41223", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41223"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection...", "cve_id": "CVE-2022-41223", "vendor": "Mitel", "ghsa_id": null, "product": "MiVoice Connect", "added_date": "2023-02-21T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.10657, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95672, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-41223", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "00b72518-ce4e-48c5-b53d-77dc13cd81e0", "vulnerability": {"vulnId": "CVE-2022-47986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-21T01:00:00+01:00"}, "gcve": {"object_uuid": "00b72518-ce4e-48c5-b53d-77dc13cd81e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-21T00:00:00+00:00"}, "scope": {"notes": "IBM Aspera Faspex code execution | Affected: IBM / Aspera Faspex | CVSS: 9.8 (CRITICAL) | EPSS: 0.99968 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-47986", "url": "https://www.cve.org/CVERecord?id=CVE-2022-47986"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-47986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Aspera Faspex code execution", "cve_id": "CVE-2022-47986", "vendor": "IBM", "ghsa_id": null, "product": "Aspera Faspex", "added_date": "2023-02-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99968, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99977, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-47986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "26fffeac-83e3-44fa-b87b-ce73ef585cb5", "vulnerability": {"vulnId": "CVE-2022-40765", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-21T01:00:00+01:00"}, "gcve": {"object_uuid": "26fffeac-83e3-44fa-b87b-ce73ef585cb5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-21T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with... | Affected: Mitel / MiVoice Connect | CVSS: 6.8 (MEDIUM) | EPSS: 0.10566 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-40765", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40765"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40765"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with...", "cve_id": "CVE-2022-40765", "vendor": "Mitel", "ghsa_id": null, "product": "MiVoice Connect", "added_date": "2023-02-21T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.10566, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95649, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-40765", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "356be545-3a8a-4ef9-88ed-74dba8cd3ee5", "vulnerability": {"vulnId": "CVE-2022-46169", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-16T01:00:00+01:00"}, "gcve": {"object_uuid": "356be545-3a8a-4ef9-88ed-74dba8cd3ee5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-16T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated Command Injection | Affected: Cacti / cacti | CVSS: 9.8 (CRITICAL) | EPSS: 0.99826 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-46169", "url": "https://www.cve.org/CVERecord?id=CVE-2022-46169"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-46169"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated Command Injection", "cve_id": "CVE-2022-46169", "vendor": "Cacti", "ghsa_id": null, "product": "cacti", "added_date": "2023-02-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99826, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99959, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-46169", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fe5ecbc1-a1a6-458f-9cbf-405c8a6a8e85", "vulnerability": {"vulnId": "CVE-2023-23529", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "fe5ecbc1-a1a6-458f-9cbf-405c8a6a8e85", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-14T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS... | Affected: Apple / iOS and iPadOS, Safari, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.09502 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-23529", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23529"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23529"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS...", "cve_id": "CVE-2023-23529", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, Safari, macOS", "added_date": "2023-02-14T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.09502, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.953, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-23529", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "edb3d7c1-f81f-4560-9d6e-049a58224559", "vulnerability": {"vulnId": "CVE-2023-21823", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "edb3d7c1-f81f-4560-9d6e-049a58224559", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-14T00:00:00+00:00"}, "scope": {"notes": "Windows Graphics Component Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Office for Android, Microsoft Office for iOS, Microsoft Office for Universal, Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 7.8 (HIGH) | EPSS: 0.05563 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21823", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21823"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21823"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Graphics Component Remote Code Execution Vulnerability", "cve_id": "CVE-2023-21823", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office for Android, Microsoft Office for iOS, Microsoft Office for Universal, Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2023-02-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05563, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21823", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "656cad50-b3e8-4d95-9d0f-5e0fa68d35c7", "vulnerability": {"vulnId": "CVE-2023-23376", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "656cad50-b3e8-4d95-9d0f-5e0fa68d35c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-14T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 7.8 (HIGH) | EPSS: 0.10853 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-23376", "url": "https://www.cve.org/CVERecord?id=CVE-2023-23376"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-23376"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-23376", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2023-02-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10853, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95729, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-23376", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18236d5d-dad6-46fb-b61f-4230f54ae86a", "vulnerability": {"vulnId": "CVE-2023-21715", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-14T01:00:00+01:00"}, "gcve": {"object_uuid": "18236d5d-dad6-46fb-b61f-4230f54ae86a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-14T00:00:00+00:00"}, "scope": {"notes": "Microsoft Publisher Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise | CVSS: 7.3 (HIGH) | EPSS: 0.12011 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21715", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21715"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21715"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Publisher Security Feature Bypass Vulnerability", "cve_id": "CVE-2023-21715", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft 365 Apps for Enterprise", "added_date": "2023-02-14T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.12011, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96012, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21715", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b4c3f92d-d989-4fbb-baa5-e7998f0efaa9", "vulnerability": {"vulnId": "CVE-2015-2291", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "b4c3f92d-d989-4fbb-baa5-e7998f0efaa9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-10T00:00:00+00:00"}, "scope": {"notes": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a... | Affected: Intel / Ethernet diagnostics driver for Windows | CVSS: 7.8 (HIGH) | EPSS: 0.09011 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2291", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2291"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2291"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a...", "cve_id": "CVE-2015-2291", "vendor": "Intel", "ghsa_id": null, "product": "Ethernet diagnostics driver for Windows", "added_date": "2023-02-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09011, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95126, "used_in_malware": "yes", "vulnerability_id": "CVE-2015-2291", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "83569e05-a9a6-4819-8124-c25ad75864e1", "vulnerability": {"vulnId": "CVE-2023-0669", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "83569e05-a9a6-4819-8124-c25ad75864e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-10T00:00:00+00:00"}, "scope": {"notes": "Fortra GoAnywhere MFT License Response Servlet Command Injection | Affected: Fortra / Goanywhere MFT | CVSS: 7.2 (HIGH) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-0669", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0669"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0669"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fortra GoAnywhere MFT License Response Servlet Command Injection", "cve_id": "CVE-2023-0669", "vendor": "Fortra", "ghsa_id": null, "product": "Goanywhere MFT", "added_date": "2023-02-10T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99996, "used_in_malware": "yes", "vulnerability_id": "CVE-2023-0669", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b0e5d70-e0f6-4801-80b1-b9c2c1b84772", "vulnerability": {"vulnId": "CVE-2022-24990", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "9b0e5d70-e0f6-4801-80b1-b9c2c1b84772", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-10T00:00:00+00:00"}, "scope": {"notes": "TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending \"User-Agent: TNAS\" to... | Affected: TerraMaster / NAS | CVSS: 7.5 (HIGH) | EPSS: 0.83043 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24990", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24990"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24990"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending \"User-Agent: TNAS\" to...", "cve_id": "CVE-2022-24990", "vendor": "TerraMaster", "ghsa_id": null, "product": "NAS", "added_date": "2023-02-10T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.83043, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99666, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-24990", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0f0370a-b39e-40b0-a944-89ed5b281e67", "vulnerability": {"vulnId": "CVE-2022-21587", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-02T01:00:00+01:00"}, "gcve": {"object_uuid": "f0f0370a-b39e-40b0-a944-89ed5b281e67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-02T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are... | Affected: Oracle / Web Applications Desktop Integrator | CVSS: 9.8 (CRITICAL) | EPSS: 0.98342 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-21587", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21587"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21587"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are...", "cve_id": "CVE-2022-21587", "vendor": "Oracle", "ghsa_id": null, "product": "Web Applications Desktop Integrator", "added_date": "2023-02-02T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98342, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99916, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-21587", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "251c4f60-a278-431e-a9d4-f6aa78def778", "vulnerability": {"vulnId": "CVE-2023-22952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-02T01:00:00+01:00"}, "gcve": {"object_uuid": "251c4f60-a278-431e-a9d4-f6aa78def778", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-02T00:00:00+00:00"}, "scope": {"notes": "In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. | Affected: SugarCRM / SugarCRM | CVSS: 8.8 (HIGH) | EPSS: 0.80139 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-22952", "url": "https://www.cve.org/CVERecord?id=CVE-2023-22952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-22952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.", "cve_id": "CVE-2023-22952", "vendor": "SugarCRM", "ghsa_id": null, "product": "SugarCRM", "added_date": "2023-02-02T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.80139, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99608, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-22952", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c10cdd3c-929b-492c-8bc3-8cb1345d6f4e", "vulnerability": {"vulnId": "CVE-2023-0611", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-02-01T14:24:46+01:00"}, "gcve": {"object_uuid": "c10cdd3c-929b-492c-8bc3-8cb1345d6f4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-02-01T13:24:46+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-02-01T13:24:46+00:00"}, "scope": {"notes": "TRENDnet TEW-652BRP Web Management Interface get_set.ccp command injection | Affected: TRENDnet / TEW-652BRP | CVSS: 8.8 (HIGH) | EPSS: 0.03853 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-0611", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0611"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0611"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TRENDnet TEW-652BRP Web Management Interface get_set.ccp command injection", "cve_id": "CVE-2023-0611", "vendor": "TRENDnet", "ghsa_id": null, "product": "TEW-652BRP", "added_date": "2023-02-01T13:24:46.000Z", "cvss_score": 8.8, "epss_score": 0.03853, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0611", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "74fd16be-1288-46df-87b0-ce281f498101", "vulnerability": {"vulnId": "CVE-2017-11357", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-26T01:00:00+01:00"}, "gcve": {"object_uuid": "74fd16be-1288-46df-87b0-ce281f498101", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-26T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-26T00:00:00+00:00"}, "scope": {"notes": "Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to... | Affected: Progress Software / Telerik UI for ASP.NET AJAX | CVSS: 9.8 (CRITICAL) | EPSS: 0.77679 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-11357", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11357"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11357"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to...", "cve_id": "CVE-2017-11357", "vendor": "Progress Software", "ghsa_id": null, "product": "Telerik UI for ASP.NET AJAX", "added_date": "2023-01-26T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.77679, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99554, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-11357", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f35f1c4-95c8-4db3-9144-108e9ec0cd7d", "vulnerability": {"vulnId": "CVE-2022-47615", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-24T10:05:26+01:00"}, "gcve": {"object_uuid": "2f35f1c4-95c8-4db3-9144-108e9ec0cd7d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-24T09:05:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-24T09:05:26+00:00"}, "scope": {"notes": "WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion | Affected: ThimPress / LearnPress \u2013 WordPress LMS Plugin | CVSS: 9.3 (CRITICAL) | EPSS: 0.05063 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-47615", "url": "https://www.cve.org/CVERecord?id=CVE-2022-47615"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-47615"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion", "cve_id": "CVE-2022-47615", "vendor": "ThimPress", "ghsa_id": null, "product": "LearnPress \u2013 WordPress LMS Plugin", "added_date": "2023-01-24T09:05:26.000Z", "cvss_score": 9.3, "epss_score": 0.05063, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92052, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-47615", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a5bc1bcc-aad9-4f8d-ba3a-8de37c77d326", "vulnerability": {"vulnId": "CVE-2022-47966", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-23T01:00:00+01:00"}, "gcve": {"object_uuid": "a5bc1bcc-aad9-4f8d-ba3a-8de37c77d326", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-23T00:00:00+00:00"}, "scope": {"notes": "Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario... | Affected: Zoho / ManageEngine | CVSS: 9.8 (CRITICAL) | EPSS: 0.99753 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-47966", "url": "https://www.cve.org/CVERecord?id=CVE-2022-47966"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-47966"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario...", "cve_id": "CVE-2022-47966", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine", "added_date": "2023-01-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99753, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99954, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-47966", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76942755-be15-4951-898a-650f02bffe14", "vulnerability": {"vulnId": "CVE-2022-44877", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-17T01:00:00+01:00"}, "gcve": {"object_uuid": "76942755-be15-4951-898a-650f02bffe14", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-17T00:00:00+00:00"}, "scope": {"notes": "login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via... | Affected: CWP (Control Web Panel) / Control Web Panel | CVSS: 9.8 (CRITICAL) | EPSS: 0.99995 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-44877", "url": "https://www.cve.org/CVERecord?id=CVE-2022-44877"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-44877"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via...", "cve_id": "CVE-2022-44877", "vendor": "CWP (Control Web Panel)", "ghsa_id": null, "product": "Control Web Panel", "added_date": "2023-01-17T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99995, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-44877", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f1e9f034-fed1-4d6d-bac0-1795b20c7c20", "vulnerability": {"vulnId": "CVE-2023-0297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-14T01:00:00+01:00"}, "gcve": {"object_uuid": "f1e9f034-fed1-4d6d-bac0-1795b20c7c20", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-14T00:00:00+00:00"}, "scope": {"notes": " Code Injection in pyload/pyload | Affected: Pyload / pyload/pyload | CVSS: 9.8 (CRITICAL) | EPSS: 0.95915 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2023-0297", "url": "https://www.cve.org/CVERecord?id=CVE-2023-0297"}, {"id": "GHSA-PF38-5P22-X6H6", "url": "https://github.com/advisories/GHSA-PF38-5P22-X6H6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-0297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": " Code Injection in pyload/pyload", "cve_id": "CVE-2023-0297", "vendor": "Pyload", "ghsa_id": "GHSA-PF38-5P22-X6H6", "product": "pyload/pyload", "added_date": "2023-01-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95915, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99873, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-0297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e527c09c-b580-40ca-bb44-fd6c24299f37", "vulnerability": {"vulnId": "CVE-2022-41080", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e527c09c-b580-40ca-bb44-fd6c24299f37", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-10T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12 | CVSS: 8.8 (HIGH) | EPSS: 0.77326 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41080", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41080"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41080"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-41080", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12", "added_date": "2023-01-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.77326, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99544, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-41080", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e330824f-950a-4d52-a3b7-f55178d51286", "vulnerability": {"vulnId": "CVE-2023-21674", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e330824f-950a-4d52-a3b7-f55178d51286", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-10T00:00:00+00:00"}, "scope": {"notes": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.40987 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2023-21674", "url": "https://www.cve.org/CVERecord?id=CVE-2023-21674"}, {"id": "previdian", "url": "https://previdian.com/CVE-2023-21674"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability", "cve_id": "CVE-2023-21674", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2023-01-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.40987, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9862, "used_in_malware": "unknown", "vulnerability_id": "CVE-2023-21674", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c7366923-9b46-45cb-9197-0e39e971cd5e", "vulnerability": {"vulnId": "CVE-2022-44149", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2023-01-06T01:00:00+01:00"}, "gcve": {"object_uuid": "c7366923-9b46-45cb-9197-0e39e971cd5e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2023-01-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2023-01-06T00:00:00+00:00"}, "scope": {"notes": "The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the... | Affected: Nexxt / Amp300 ARN02304U8 | CVSS: 8.8 (HIGH) | EPSS: 0.64354 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-44149", "url": "https://www.cve.org/CVERecord?id=CVE-2022-44149"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-44149"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the...", "cve_id": "CVE-2022-44149", "vendor": "Nexxt", "ghsa_id": null, "product": "Amp300 ARN02304U8", "added_date": "2023-01-06T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.64354, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9921, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-44149", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "638aef16-4452-4b50-90b6-a847783132aa", "vulnerability": {"vulnId": "CVE-2018-5430", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-29T01:00:00+01:00"}, "gcve": {"object_uuid": "638aef16-4452-4b50-90b6-a847783132aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-29T00:00:00+00:00"}, "scope": {"notes": "TIBCO JasperReports Server Information Disclosure Vulnerability | Affected: TIBCO / TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS | CVSS: 7.7 (HIGH) | EPSS: 0.48986 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-5430", "url": "https://www.cve.org/CVERecord?id=CVE-2018-5430"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-5430"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TIBCO JasperReports Server Information Disclosure Vulnerability", "cve_id": "CVE-2018-5430", "vendor": "TIBCO", "ghsa_id": null, "product": "TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS", "added_date": "2022-12-29T00:00:00.000Z", "cvss_score": 7.7, "epss_score": 0.48986, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98847, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-5430", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "545b07a1-dc0c-4b67-812d-30d265575483", "vulnerability": {"vulnId": "CVE-2018-18809", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-29T01:00:00+01:00"}, "gcve": {"object_uuid": "545b07a1-dc0c-4b67-812d-30d265575483", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-29T00:00:00+00:00"}, "scope": {"notes": "TIBCO JasperReports Library Directory Traversal Vulnerability | Affected: TIBCO / TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS | CVSS: 6.5 (MEDIUM) | EPSS: 0.79064 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-18809", "url": "https://www.cve.org/CVERecord?id=CVE-2018-18809"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-18809"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TIBCO JasperReports Library Directory Traversal Vulnerability", "cve_id": "CVE-2018-18809", "vendor": "TIBCO", "ghsa_id": null, "product": "TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS", "added_date": "2022-12-29T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.79064, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99588, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-18809", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6707e6dd-9501-4ac6-b491-24a4ef49c20c", "vulnerability": {"vulnId": "CVE-2022-42953", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-25T01:00:00+01:00"}, "gcve": {"object_uuid": "6707e6dd-9501-4ac6-b491-24a4ef49c20c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-25T00:00:00+00:00"}, "scope": {"notes": "Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the... | Affected: ZKTeco / ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM | CVSS: 7.5 (HIGH) | EPSS: 0.04834 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-42953", "url": "https://www.cve.org/CVERecord?id=CVE-2022-42953"}, {"id": "GHSA-54R9-6X6G-2VFV", "url": "https://github.com/advisories/GHSA-54R9-6X6G-2VFV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-42953"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the...", "cve_id": "CVE-2022-42953", "vendor": "ZKTeco", "ghsa_id": "GHSA-54R9-6X6G-2VFV", "product": "ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM", "added_date": "2022-12-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.04834, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91717, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-42953", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3da43090-cd59-452f-ad9f-454b4e4fa3ea", "vulnerability": {"vulnId": "CVE-2022-45359", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-22T10:23:55+01:00"}, "gcve": {"object_uuid": "3da43090-cd59-452f-ad9f-454b4e4fa3ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-22T09:23:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-22T09:23:55+00:00"}, "scope": {"notes": "WordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File Upload | Affected: YITH / YITH WooCommerce Gift Cards | CVSS: 9.8 (CRITICAL) | EPSS: 0.13514 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-45359", "url": "https://www.cve.org/CVERecord?id=CVE-2022-45359"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-45359"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File Upload", "cve_id": "CVE-2022-45359", "vendor": "YITH", "ghsa_id": null, "product": "YITH WooCommerce Gift Cards", "added_date": "2022-12-22T09:23:55.000Z", "cvss_score": 9.8, "epss_score": 0.13514, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96336, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-45359", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9a8c8e8f-aa2a-48eb-b2d5-3f15cd721c0f", "vulnerability": {"vulnId": "CVE-2022-42856", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-14T01:00:00+01:00"}, "gcve": {"object_uuid": "9a8c8e8f-aa2a-48eb-b2d5-3f15cd721c0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-14T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2... | Affected: Apple / tvOS | CVSS: 8.8 (HIGH) | EPSS: 0.08523 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-42856", "url": "https://www.cve.org/CVERecord?id=CVE-2022-42856"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-42856"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2...", "cve_id": "CVE-2022-42856", "vendor": "Apple", "ghsa_id": null, "product": "tvOS", "added_date": "2022-12-14T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.08523, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-42856", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "25ff5bf2-60e1-489a-8d66-d9ef4fe2bd25", "vulnerability": {"vulnId": "CVE-2022-44698", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-13T01:00:00+01:00"}, "gcve": {"object_uuid": "25ff5bf2-60e1-489a-8d66-d9ef4fe2bd25", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-13T00:00:00+00:00"}, "scope": {"notes": "Windows SmartScreen Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016 | CVSS: 5.4 (MEDIUM) | EPSS: 0.76267 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-44698", "url": "https://www.cve.org/CVERecord?id=CVE-2022-44698"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-44698"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows SmartScreen Security Feature Bypass Vulnerability", "cve_id": "CVE-2022-44698", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2016", "added_date": "2022-12-13T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.76267, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99523, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-44698", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4dc8bb98-33b2-4205-9ecf-f7fae0ef788c", "vulnerability": {"vulnId": "CVE-2022-27518", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-13T01:00:00+01:00"}, "gcve": {"object_uuid": "4dc8bb98-33b2-4205-9ecf-f7fae0ef788c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-13T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated remote arbitrary code execution | Affected: Citrix / Citrix Gateway, Citrix ADC | CVSS: 9.8 (CRITICAL) | EPSS: 0.06683 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-27518", "url": "https://www.cve.org/CVERecord?id=CVE-2022-27518"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-27518"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated remote arbitrary code execution", "cve_id": "CVE-2022-27518", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix Gateway, Citrix ADC", "added_date": "2022-12-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06683, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93697, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-27518", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a0d88f8f-6cfe-494d-9fe0-ea0927c31945", "vulnerability": {"vulnId": "CVE-2022-26501", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-13T01:00:00+01:00"}, "gcve": {"object_uuid": "a0d88f8f-6cfe-494d-9fe0-ea0927c31945", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-13T00:00:00+00:00"}, "scope": {"notes": "Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). | Affected: Veeam / Backup & Replication | CVSS: 9.8 (CRITICAL) | EPSS: 0.04104 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26501", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26501"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26501"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).", "cve_id": "CVE-2022-26501", "vendor": "Veeam", "ghsa_id": null, "product": "Backup & Replication", "added_date": "2022-12-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04104, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90441, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-26501", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7f3c9f21-76cd-4359-a9ef-afe413593b7c", "vulnerability": {"vulnId": "CVE-2022-26500", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-13T01:00:00+01:00"}, "gcve": {"object_uuid": "7f3c9f21-76cd-4359-a9ef-afe413593b7c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-13T00:00:00+00:00"}, "scope": {"notes": "Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to... | Affected: Veeam / Backup & Replication | CVSS: 8.8 (HIGH) | EPSS: 0.05828 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26500", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26500"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26500"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to...", "cve_id": "CVE-2022-26500", "vendor": "Veeam", "ghsa_id": null, "product": "Backup & Replication", "added_date": "2022-12-13T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.05828, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92932, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-26500", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "61550ae3-9418-43e1-a993-0b96ba39631f", "vulnerability": {"vulnId": "CVE-2022-42475", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-13T01:00:00+01:00"}, "gcve": {"object_uuid": "61550ae3-9418-43e1-a993-0b96ba39631f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-13T00:00:00+00:00"}, "scope": {"notes": "A heap-based buffer overflow vulnerability [CWE-122]\u00a0in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0... | Affected: Fortinet / FortiProxy, FortiOS | CVSS: 9.3 (CRITICAL) | EPSS: 0.99474 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-42475", "url": "https://www.cve.org/CVERecord?id=CVE-2022-42475"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-42475"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A heap-based buffer overflow vulnerability [CWE-122]\u00a0in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0...", "cve_id": "CVE-2022-42475", "vendor": "Fortinet", "ghsa_id": null, "product": "FortiProxy, FortiOS", "added_date": "2022-12-13T00:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.99474, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99943, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-42475", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dbc41db4-23db-4619-8a13-4712ecdd8f68", "vulnerability": {"vulnId": "CVE-2022-3982", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-12T18:54:47+01:00"}, "gcve": {"object_uuid": "dbc41db4-23db-4619-8a13-4712ecdd8f68", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-12T17:54:47+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-12T17:54:47+00:00"}, "scope": {"notes": "Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload | Affected: Wpbookingcalendar / Booking Calendar | CVSS: 9.8 (CRITICAL) | EPSS: 0.0454 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-3982", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3982"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3982"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2022-3982", "vendor": "Wpbookingcalendar", "ghsa_id": null, "product": "Booking Calendar", "added_date": "2022-12-12T17:54:47.000Z", "cvss_score": 9.8, "epss_score": 0.0454, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91259, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3982", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "85ca3836-f2ac-48b1-b612-4ee4858df47f", "vulnerability": {"vulnId": "CVE-2022-41800", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-07T04:12:17+01:00"}, "gcve": {"object_uuid": "85ca3836-f2ac-48b1-b612-4ee4858df47f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-07T03:12:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-07T03:12:17+00:00"}, "scope": {"notes": "Appliance mode iControl REST vulnerability | Affected: F5 / BIG-IP | CVSS: 8.7 (HIGH) | EPSS: 0.76866 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-41800", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41800"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41800"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Appliance mode iControl REST vulnerability", "cve_id": "CVE-2022-41800", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2022-12-07T03:12:17.000Z", "cvss_score": 8.7, "epss_score": 0.76866, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99535, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41800", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a68e7ded-615d-4787-9437-9d445c5a3832", "vulnerability": {"vulnId": "CVE-2022-4262", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-05T01:00:00+01:00"}, "gcve": {"object_uuid": "a68e7ded-615d-4787-9437-9d445c5a3832", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-05T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.2351 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-4262", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4262"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4262"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2022-4262", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-12-05T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.2351, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97734, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4262", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c5a3b5f1-d76a-49b0-bf86-c1c98f721176", "vulnerability": {"vulnId": "CVE-2022-4257", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "c5a3b5f1-d76a-49b0-bf86-c1c98f721176", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-12-01T00:00:00+00:00"}, "scope": {"notes": "C-DATA Web Management System GET Parameter jumpto.php argument injection | Affected: C-DATA / Web Management System | CVSS: 6.3 (MEDIUM) | EPSS: 0.4393 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-4257", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4257"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4257"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "C-DATA Web Management System GET Parameter jumpto.php argument injection", "cve_id": "CVE-2022-4257", "vendor": "C-DATA", "ghsa_id": null, "product": "Web Management System", "added_date": "2022-12-01T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.4393, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98711, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4257", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7cd4b06b-5869-4021-859a-6ead4d075711", "vulnerability": {"vulnId": "CVE-2022-41412", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-30T01:00:00+01:00"}, "gcve": {"object_uuid": "7cd4b06b-5869-4021-859a-6ead4d075711", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-30T00:00:00+00:00"}, "scope": {"notes": "An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request... | Affected: perfSONAR / perfSONAR | CVSS: 8.6 (HIGH) | EPSS: 0.04454 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-41412", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41412"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41412"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request...", "cve_id": "CVE-2022-41412", "vendor": "perfSONAR", "ghsa_id": null, "product": "perfSONAR", "added_date": "2022-11-30T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.04454, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91119, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41412", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "13223642-728d-4ad4-81db-15b96ec66865", "vulnerability": {"vulnId": "CVE-2021-35587", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-28T01:00:00+01:00"}, "gcve": {"object_uuid": "13223642-728d-4ad4-81db-15b96ec66865", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-28T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are... | Affected: Oracle / Access Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.96284 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-35587", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35587"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35587"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are...", "cve_id": "CVE-2021-35587", "vendor": "Oracle", "ghsa_id": null, "product": "Access Manager", "added_date": "2022-11-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96284, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99879, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35587", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "77a7d6c7-7446-485f-afd7-50efb08b3c90", "vulnerability": {"vulnId": "CVE-2022-4135", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-28T01:00:00+01:00"}, "gcve": {"object_uuid": "77a7d6c7-7446-485f-afd7-50efb08b3c90", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-28T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.31864 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-4135", "url": "https://www.cve.org/CVERecord?id=CVE-2022-4135"}, {"id": "GHSA-995F-9X5R-2RCJ", "url": "https://github.com/advisories/GHSA-995F-9X5R-2RCJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-4135"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to...", "cve_id": "CVE-2022-4135", "vendor": "Google", "ghsa_id": "GHSA-995F-9X5R-2RCJ", "product": "Chrome", "added_date": "2022-11-28T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.31864, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98254, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-4135", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d8541fe-4b32-4ded-b454-1e8120861b4c", "vulnerability": {"vulnId": "CVE-2022-41049", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-14T01:00:00+01:00"}, "gcve": {"object_uuid": "9d8541fe-4b32-4ded-b454-1e8120861b4c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-14T00:00:00+00:00"}, "scope": {"notes": "Windows Mark of the Web Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 5.4 (MEDIUM) | EPSS: 0.02491 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41049", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41049"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41049"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Mark of the Web Security Feature Bypass Vulnerability", "cve_id": "CVE-2022-41049", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2022-11-14T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.02491, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8408, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41049", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dfe727a0-03e0-448c-97e6-8f1b4c0e7b10", "vulnerability": {"vulnId": "CVE-2022-41091", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "dfe727a0-03e0-448c-97e6-8f1b4c0e7b10", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "Windows Mark of the Web Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 5.4 (MEDIUM) | EPSS: 0.01806 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41091", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41091"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41091"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Mark of the Web Security Feature Bypass Vulnerability", "cve_id": "CVE-2022-41091", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.01806, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77777, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-41091", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "47d801bb-0d6f-494a-ab3f-7144010ec1a0", "vulnerability": {"vulnId": "CVE-2022-41073", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "47d801bb-0d6f-494a-ab3f-7144010ec1a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "Windows Print Spooler Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 7.8 (HIGH) | EPSS: 0.02278 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41073", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41073"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41073"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Print Spooler Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-41073", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02278, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82501, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-41073", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "11ac122d-b00b-4f2f-b551-dca2258e93e7", "vulnerability": {"vulnId": "CVE-2021-25370", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "11ac122d-b00b-4f2f-b551-dca2258e93e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 6.1 (MEDIUM) | EPSS: 0.0089 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25370", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25370"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25370"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel...", "cve_id": "CVE-2021-25370", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.0089, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5789, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25370", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c264bf35-6166-4fdc-a5a9-2630c7ef8846", "vulnerability": {"vulnId": "CVE-2022-41125", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "c264bf35-6166-4fdc-a5a9-2630c7ef8846", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 8.1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022 | CVSS: 7.8 (HIGH) | EPSS: 0.03046 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41125", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41125"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41125"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-41125", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 8.1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03046, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87075, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41125", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "76f5323b-4cef-49e2-a0a4-467beca7277e", "vulnerability": {"vulnId": "CVE-2022-41128", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "76f5323b-4cef-49e2-a0a4-467beca7277e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "Windows Scripting Languages Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022 | CVSS: 8.8 (HIGH) | EPSS: 0.24623 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41128", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41128"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41128"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Scripting Languages Remote Code Execution Vulnerability", "cve_id": "CVE-2022-41128", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.24623, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97823, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41128", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b5f83064-8997-433c-b2bf-1ab6c0083451", "vulnerability": {"vulnId": "CVE-2021-25369", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "b5f83064-8997-433c-b2bf-1ab6c0083451", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 6.2 (MEDIUM) | EPSS: 0.01079 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25369", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25369"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25369"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.", "cve_id": "CVE-2021-25369", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 6.2, "epss_score": 0.01079, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.6381, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25369", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "79aa68bd-152a-47d8-a6ba-42e7864f1728", "vulnerability": {"vulnId": "CVE-2021-25337", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-11-08T01:00:00+01:00"}, "gcve": {"object_uuid": "79aa68bd-152a-47d8-a6ba-42e7864f1728", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-11-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-11-08T00:00:00+00:00"}, "scope": {"notes": "Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or... | Affected: Samsung Mobile / Samsung Mobile Devices | CVSS: 4.4 (MEDIUM) | EPSS: 0.02807 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25337", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25337"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25337"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or...", "cve_id": "CVE-2021-25337", "vendor": "Samsung Mobile", "ghsa_id": null, "product": "Samsung Mobile Devices", "added_date": "2022-11-08T00:00:00.000Z", "cvss_score": 4.4, "epss_score": 0.02807, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86005, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25337", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0b911961-011b-4518-993c-3cedd2b1a032", "vulnerability": {"vulnId": "CVE-2022-3723", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0b911961-011b-4518-993c-3cedd2b1a032", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-28T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.07921 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-3723", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3723"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3723"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2022-3723", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-10-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.07921, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94553, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3723", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3149228c-4f1f-4aac-b16f-86ec9be0f521", "vulnerability": {"vulnId": "CVE-2022-42827", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-25T02:00:00+02:00"}, "gcve": {"object_uuid": "3149228c-4f1f-4aac-b16f-86ec9be0f521", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-25T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS... | Affected: Apple / iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.01048 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-42827", "url": "https://www.cve.org/CVERecord?id=CVE-2022-42827"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-42827"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS...", "cve_id": "CVE-2022-42827", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS", "added_date": "2022-10-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01048, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62931, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-42827", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "944d44c0-801c-4ba7-933a-e7776793cc36", "vulnerability": {"vulnId": "CVE-2020-3153", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "944d44c0-801c-4ba7-933a-e7776793cc36", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-24T00:00:00+00:00"}, "scope": {"notes": "Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability | Affected: Cisco / Cisco AnyConnect Secure Mobility Client | CVSS: 6.5 (MEDIUM) | EPSS: 0.28307 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3153", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3153"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3153"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability", "cve_id": "CVE-2020-3153", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco AnyConnect Secure Mobility Client", "added_date": "2022-10-24T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.28307, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98066, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-3153", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a7991eb-2416-4bf9-8e18-ce1c6d11e1de", "vulnerability": {"vulnId": "CVE-2018-19322", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "6a7991eb-2416-4bf9-8e18-ce1c6d11e1de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-24T00:00:00+00:00"}, "scope": {"notes": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before... | Affected: GIGABYTE / APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II | CVSS: 7.8 (HIGH) | EPSS: 0.01801 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19322", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19322"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19322"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before...", "cve_id": "CVE-2018-19322", "vendor": "GIGABYTE", "ghsa_id": null, "product": "APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II", "added_date": "2022-10-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01801, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77709, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19322", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a0a01c35-47ac-41ab-9ca5-c4ab5c96b033", "vulnerability": {"vulnId": "CVE-2018-19323", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "a0a01c35-47ac-41ab-9ca5-c4ab5c96b033", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-24T00:00:00+00:00"}, "scope": {"notes": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC... | Affected: GIGABYTE / APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II | CVSS: 9.8 (CRITICAL) | EPSS: 0.07828 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19323", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19323"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19323"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC...", "cve_id": "CVE-2018-19323", "vendor": "GIGABYTE", "ghsa_id": null, "product": "APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II", "added_date": "2022-10-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07828, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94499, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19323", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8bf3f714-c915-4332-9bd7-875d93355bba", "vulnerability": {"vulnId": "CVE-2018-19320", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "8bf3f714-c915-4332-9bd7-875d93355bba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-24T00:00:00+00:00"}, "scope": {"notes": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC... | Affected: GIGABYTE / APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II | CVSS: 7.8 (HIGH) | EPSS: 0.03597 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19320", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19320"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19320"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC...", "cve_id": "CVE-2018-19320", "vendor": "GIGABYTE", "ghsa_id": null, "product": "APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II", "added_date": "2022-10-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03597, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8908, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19320", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a121bbef-30b3-42fe-889b-24bd419f499d", "vulnerability": {"vulnId": "CVE-2018-19321", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "a121bbef-30b3-42fe-889b-24bd419f499d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-24T00:00:00+00:00"}, "scope": {"notes": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before... | Affected: GIGABYTE / APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II | CVSS: 7.8 (HIGH) | EPSS: 0.03671 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19321", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19321"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19321"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before...", "cve_id": "CVE-2018-19321", "vendor": "GIGABYTE", "ghsa_id": null, "product": "APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II", "added_date": "2022-10-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03671, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89296, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19321", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b4322b94-d78b-477a-8119-ecf32d7caf0b", "vulnerability": {"vulnId": "CVE-2020-3433", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-24T02:00:00+02:00"}, "gcve": {"object_uuid": "b4322b94-d78b-477a-8119-ecf32d7caf0b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-24T00:00:00+00:00"}, "scope": {"notes": "Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability | Affected: Cisco / Cisco AnyConnect Secure Mobility Client | CVSS: 7.8 (HIGH) | EPSS: 0.10049 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3433", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3433"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3433"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability", "cve_id": "CVE-2020-3433", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco AnyConnect Secure Mobility Client", "added_date": "2022-10-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10049, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95487, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-3433", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6fc35b9a-6e0c-4965-868e-9e138c891031", "vulnerability": {"vulnId": "CVE-2022-42889", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-20T13:40:50+02:00"}, "gcve": {"object_uuid": "6fc35b9a-6e0c-4965-868e-9e138c891031", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-20T11:40:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-20T11:40:50+00:00"}, "scope": {"notes": "Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults | Affected: Apache / Apache Commons Text | CVSS: 9.8 (CRITICAL) | EPSS: 0.99931 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-42889", "url": "https://www.cve.org/CVERecord?id=CVE-2022-42889"}, {"id": "GHSA-599F-7C49-W659", "url": "https://github.com/advisories/GHSA-599F-7C49-W659"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-42889"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults", "cve_id": "CVE-2022-42889", "vendor": "Apache", "ghsa_id": "GHSA-599F-7C49-W659", "product": "Apache Commons Text", "added_date": "2022-10-20T11:40:50.000Z", "cvss_score": 9.8, "epss_score": 0.99931, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-42889", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dd5dcca1-876d-4a1d-a270-9da9f10fa3a5", "vulnerability": {"vulnId": "CVE-2021-3493", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-20T02:00:00+02:00"}, "gcve": {"object_uuid": "dd5dcca1-876d-4a1d-a270-9da9f10fa3a5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-20T00:00:00+00:00"}, "scope": {"notes": "The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on... | Affected: Ubuntu / linux kernel | CVSS: 8.8 (HIGH) | EPSS: 0.49166 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-3493", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3493"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3493"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on...", "cve_id": "CVE-2021-3493", "vendor": "Ubuntu", "ghsa_id": null, "product": "linux kernel", "added_date": "2022-10-20T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.49166, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98851, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3493", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "160f2c5e-fc83-4684-8cec-60fcb2d722e2", "vulnerability": {"vulnId": "CVE-2022-41352", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-20T02:00:00+02:00"}, "gcve": {"object_uuid": "160f2c5e-fc83-4684-8cec-60fcb2d722e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-20T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-20T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole... | Affected: Zimbra / Collaboration | CVSS: 9.8 (CRITICAL) | EPSS: 0.95478 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41352", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41352"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41352"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole...", "cve_id": "CVE-2022-41352", "vendor": "Zimbra", "ghsa_id": null, "product": "Collaboration", "added_date": "2022-10-20T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95478, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99869, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41352", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b4ca056-1cd8-4b9a-87a3-441c0f24da21", "vulnerability": {"vulnId": "CVE-2017-20149", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-15T02:00:00+02:00"}, "gcve": {"object_uuid": "8b4ca056-1cd8-4b9a-87a3-441c0f24da21", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-15T00:00:00+00:00"}, "scope": {"notes": "The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and... | Affected: Mikrotik / RouterOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.01999 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-20149", "url": "https://www.cve.org/CVERecord?id=CVE-2017-20149"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-20149"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and...", "cve_id": "CVE-2017-20149", "vendor": "Mikrotik", "ghsa_id": null, "product": "RouterOS", "added_date": "2022-10-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.01999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79981, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-20149", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0428f201-571d-4f67-b711-7922213adad1", "vulnerability": {"vulnId": "CVE-2022-41033", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-11T02:00:00+02:00"}, "gcve": {"object_uuid": "0428f201-571d-4f67-b711-7922213adad1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-11T00:00:00+00:00"}, "scope": {"notes": "Windows COM+ Event System Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01696 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41033", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41033"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41033"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows COM+ Event System Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-41033", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-10-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01696, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-41033", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1dadbb92-5dba-4739-bcbc-7645f5f4a2af", "vulnerability": {"vulnId": "CVE-2022-40684", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-10-11T02:00:00+02:00"}, "gcve": {"object_uuid": "1dadbb92-5dba-4739-bcbc-7645f5f4a2af", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-10-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-10-11T00:00:00+00:00"}, "scope": {"notes": "An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,... | Affected: Fortinet / Fortinet FortiOS, FortiProxy, FortiSwitchManager | CVSS: 9.8 (CRITICAL) | EPSS: 0.99984 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-40684", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40684"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40684"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6,...", "cve_id": "CVE-2022-40684", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS, FortiProxy, FortiSwitchManager", "added_date": "2022-10-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99984, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99983, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-40684", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3095c80a-a436-4209-b3d2-c9588b34c315", "vulnerability": {"vulnId": "CVE-2022-41040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-30T02:00:00+02:00"}, "gcve": {"object_uuid": "3095c80a-a436-4209-b3d2-c9588b34c315", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-30T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23 | CVSS: 8.8 (HIGH) | EPSS: 0.99956 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41040", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-41040", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23", "added_date": "2022-09-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99956, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99974, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-41040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a4206ac-3401-42c2-b287-18456307e407", "vulnerability": {"vulnId": "CVE-2022-36804", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-30T02:00:00+02:00"}, "gcve": {"object_uuid": "6a4206ac-3401-42c2-b287-18456307e407", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-30T00:00:00+00:00"}, "scope": {"notes": "Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from... | Affected: Atlassian / Bitbucket Server, Bitbucket Data Center | CVSS: 8.8 (HIGH) | EPSS: 0.99174 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-36804", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36804"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36804"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from...", "cve_id": "CVE-2022-36804", "vendor": "Atlassian", "ghsa_id": null, "product": "Bitbucket Server, Bitbucket Data Center", "added_date": "2022-09-30T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99174, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99934, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36804", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5d5f8339-a578-40c1-87b6-0fa902bbc434", "vulnerability": {"vulnId": "CVE-2022-41082", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-30T02:00:00+02:00"}, "gcve": {"object_uuid": "5d5f8339-a578-40c1-87b6-0fa902bbc434", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-30T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-30T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23 | CVSS: 8.0 (HIGH) | EPSS: 0.9997 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-41082", "url": "https://www.cve.org/CVERecord?id=CVE-2022-41082"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-41082"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2022-41082", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 11, Microsoft Exchange Server 2019 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 23", "added_date": "2022-09-30T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.9997, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99977, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-41082", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b1d0999-4727-446a-9e5a-5b977a357363", "vulnerability": {"vulnId": "CVE-2022-3236", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-23T02:00:00+02:00"}, "gcve": {"object_uuid": "3b1d0999-4727-446a-9e5a-5b977a357363", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-23T00:00:00+00:00"}, "scope": {"notes": "A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and... | Affected: Sophos / Sophos Firewall | CVSS: 9.8 (CRITICAL) | EPSS: 0.98905 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-3236", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3236"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3236"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and...", "cve_id": "CVE-2022-3236", "vendor": "Sophos", "ghsa_id": null, "product": "Sophos Firewall", "added_date": "2022-09-23T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98905, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3236", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a82309f6-ef10-4102-85fa-20b20cb4c13e", "vulnerability": {"vulnId": "CVE-2022-35405", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-22T02:00:00+02:00"}, "gcve": {"object_uuid": "a82309f6-ef10-4102-85fa-20b20cb4c13e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-22T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also... | Affected: Zoho / ManageEngine Password Manager Pro, PAM360, Access Manager Plus | CVSS: 9.8 (CRITICAL) | EPSS: 0.99927 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-35405", "url": "https://www.cve.org/CVERecord?id=CVE-2022-35405"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-35405"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also...", "cve_id": "CVE-2022-35405", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine Password Manager Pro, PAM360, Access Manager Plus", "added_date": "2022-09-22T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99927, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-35405", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5a5b4c14-c9a0-4845-ad35-03e36e428fc3", "vulnerability": {"vulnId": "CVE-2022-40139", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "5a5b4c14-c9a0-4845-ad35-03e36e428fc3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-15T00:00:00+00:00"}, "scope": {"notes": "Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could... | Affected: Trend Micro / Trend Micro Apex One | CVSS: 7.2 (HIGH) | EPSS: 0.03291 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-40139", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40139"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40139"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could...", "cve_id": "CVE-2022-40139", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex One", "added_date": "2022-09-15T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.03291, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88079, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40139", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb8338d9-4cc5-43c9-84e4-43f54b7e253c", "vulnerability": {"vulnId": "CVE-2013-6282", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "fb8338d9-4cc5-43c9-84e4-43f54b7e253c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-15T00:00:00+00:00"}, "scope": {"notes": "The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses,... | Affected: Linux / Linux Kernel | CVSS: 8.8 (HIGH) | EPSS: 0.39711 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-6282", "url": "https://www.cve.org/CVERecord?id=CVE-2013-6282"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-6282"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses,...", "cve_id": "CVE-2013-6282", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2022-09-15T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.39711, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98579, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-6282", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9caf0c50-9bb2-44f2-8f95-890bcbf95207", "vulnerability": {"vulnId": "CVE-2013-2597", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "9caf0c50-9bb2-44f2-8f95-890bcbf95207", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-15T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in... | Affected: Qualcomm / Linux Kernel | CVSS: 8.4 (HIGH) | EPSS: 0.01503 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2597", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2597"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2597"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in...", "cve_id": "CVE-2013-2597", "vendor": "Qualcomm", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2022-09-15T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.01503, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7338, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2597", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "24dc7d09-12a9-4d88-ad8f-00ca9367c10d", "vulnerability": {"vulnId": "CVE-2013-2596", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "24dc7d09-12a9-4d88-ad8f-00ca9367c10d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-15T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android... | Affected: Linux / Linux Kernel | CVSS: 7.8 (HIGH) | EPSS: 0.03212 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2596", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2596"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2596"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android...", "cve_id": "CVE-2013-2596", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2022-09-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03212, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87744, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2596", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b61058ce-f32a-451a-bd67-b03e1b41ee8d", "vulnerability": {"vulnId": "CVE-2010-2568", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "b61058ce-f32a-451a-bd67-b03e1b41ee8d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-15T00:00:00+00:00"}, "scope": {"notes": "Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.91324 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-2568", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2568"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-2568"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote...", "cve_id": "CVE-2010-2568", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-09-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.91324, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9981, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-2568", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2cb08788-b4a4-4cd7-a263-37e600a5a649", "vulnerability": {"vulnId": "CVE-2013-2094", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-15T02:00:00+02:00"}, "gcve": {"object_uuid": "2cb08788-b4a4-4cd7-a263-37e600a5a649", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-15T00:00:00+00:00"}, "scope": {"notes": "The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local... | Affected: Linux / Linux Kernel | CVSS: 8.4 (HIGH) | EPSS: 0.47709 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2094", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2094"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2094"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local...", "cve_id": "CVE-2013-2094", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2022-09-15T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.47709, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98814, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2094", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d9b804a-c0f5-40d1-9d17-ea768c290afa", "vulnerability": {"vulnId": "CVE-2022-37969", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "3d9b804a-c0f5-40d1-9d17-ea768c290afa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-14T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.28275 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-37969", "url": "https://www.cve.org/CVERecord?id=CVE-2022-37969"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-37969"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-37969", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-09-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.28275, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98065, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-37969", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "37013855-eeda-452c-8c6e-0b7add7f01bd", "vulnerability": {"vulnId": "CVE-2022-40734", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "37013855-eeda-452c-8c6e-0b7add7f01bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-14T00:00:00+00:00"}, "scope": {"notes": "UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files,... | Affected: UniSharp / laravel-filemanager | CVSS: 6.5 (MEDIUM) | EPSS: 0.05183 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-40734", "url": "https://www.cve.org/CVERecord?id=CVE-2022-40734"}, {"id": "GHSA-5M2H-7RF2-RPX6", "url": "https://github.com/advisories/GHSA-5M2H-7RF2-RPX6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-40734"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files,...", "cve_id": "CVE-2022-40734", "vendor": "UniSharp", "ghsa_id": "GHSA-5M2H-7RF2-RPX6", "product": "laravel-filemanager", "added_date": "2022-09-14T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.05183, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92199, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-40734", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e56bdb73-e489-4b13-a4b7-e1f71284ec92", "vulnerability": {"vulnId": "CVE-2022-32917", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-14T02:00:00+02:00"}, "gcve": {"object_uuid": "e56bdb73-e489-4b13-a4b7-e1f71284ec92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-14T00:00:00+00:00"}, "scope": {"notes": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur... | Affected: Apple / iOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.05603 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-32917", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32917"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32917"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur...", "cve_id": "CVE-2022-32917", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS", "added_date": "2022-09-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05603, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92667, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32917", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5ee463b2-fd40-480d-9162-914210fbddc3", "vulnerability": {"vulnId": "CVE-2022-3180", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-13T10:50:53+02:00"}, "gcve": {"object_uuid": "5ee463b2-fd40-480d-9162-914210fbddc3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-13T08:50:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-13T08:50:53+00:00"}, "scope": {"notes": "WPGateway <= 3.5 - Unauthenticated Privilege Escalation | Affected: Jack Hopman / WPGateway | CVSS: 9.8 (CRITICAL) | EPSS: 0.0921 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-3180", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3180"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3180"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WPGateway <= 3.5 - Unauthenticated Privilege Escalation", "cve_id": "CVE-2022-3180", "vendor": "Jack Hopman", "ghsa_id": null, "product": "WPGateway", "added_date": "2022-09-13T08:50:53.000Z", "cvss_score": 9.8, "epss_score": 0.0921, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95195, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3180", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "264e4d1e-f25f-4884-822e-920fbc327eab", "vulnerability": {"vulnId": "CVE-2018-2628", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "264e4d1e-f25f-4884-822e-920fbc327eab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99958 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-2628", "url": "https://www.cve.org/CVERecord?id=CVE-2018-2628"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-2628"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...", "cve_id": "CVE-2018-2628", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99958, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99975, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-2628", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "281d9945-6903-446c-a16e-21798aa96b2e", "vulnerability": {"vulnId": "CVE-2022-3075", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "281d9945-6903-446c-a16e-21798aa96b2e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.05806 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-3075", "url": "https://www.cve.org/CVERecord?id=CVE-2022-3075"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-3075"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to...", "cve_id": "CVE-2022-3075", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.05806, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92903, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-3075", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c98519dd-169e-4f1c-9fda-c1d7adff9f58", "vulnerability": {"vulnId": "CVE-2022-26258", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "c98519dd-169e-4f1c-9fda-c1d7adff9f58", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | Affected: D-Link / DIR-820L | CVSS: 9.8 (CRITICAL) | EPSS: 0.91981 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26258", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26258"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26258"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.", "cve_id": "CVE-2022-26258", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-820L", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91981, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99818, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26258", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20e88f34-9547-4765-8f71-b3273ff3bce7", "vulnerability": {"vulnId": "CVE-2020-9934", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "20e88f34-9547-4765-8f71-b3273ff3bce7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and... | Affected: Apple / iOS, macOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.03208 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9934", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9934"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9934"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and...", "cve_id": "CVE-2020-9934", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.03208, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9934", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cac77fbf-b121-41a8-8729-7e0e3a8f4be2", "vulnerability": {"vulnId": "CVE-2018-6530", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "cac77fbf-b121-41a8-8729-7e0e3a8f4be2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous... | Affected: D-Link / DIR-880L, DIR-868L, DIR-865L, DIR-860L | CVSS: 9.8 (CRITICAL) | EPSS: 0.96682 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-6530", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6530"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-6530"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous...", "cve_id": "CVE-2018-6530", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-880L, DIR-868L, DIR-865L, DIR-860L", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96682, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99884, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-6530", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ee546371-7948-4a99-9b19-52e902df513a", "vulnerability": {"vulnId": "CVE-2018-13374", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "ee546371-7948-4a99-9b19-52e902df513a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the... | Affected: Fortinet / Fortinet FortiOS, fortiADC | CVSS: 4.3 (MEDIUM) | EPSS: 0.37832 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-13374", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13374"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13374"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the...", "cve_id": "CVE-2018-13374", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS, fortiADC", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.37832, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98503, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-13374", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "80167e9c-165f-4976-ad4e-07301ae75434", "vulnerability": {"vulnId": "CVE-2022-27593", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "80167e9c-165f-4976-ad4e-07301ae75434", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "DeadBolt Ransomware | Affected: QNAP / Photo Station | CVSS: 10.0 (CRITICAL) | EPSS: 0.87908 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-27593", "url": "https://www.cve.org/CVERecord?id=CVE-2022-27593"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-27593"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DeadBolt Ransomware", "cve_id": "CVE-2022-27593", "vendor": "QNAP", "ghsa_id": null, "product": "Photo Station", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.87908, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9976, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-27593", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eec03762-fbdf-4f10-a742-13d06aa5d713", "vulnerability": {"vulnId": "CVE-2017-5521", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "eec03762-fbdf-4f10-a742-13d06aa5d713", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000... | Affected: NETGEAR / Routers | CVSS: 8.1 (HIGH) | EPSS: 0.89245 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-5521", "url": "https://www.cve.org/CVERecord?id=CVE-2017-5521"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-5521"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000...", "cve_id": "CVE-2017-5521", "vendor": "NETGEAR", "ghsa_id": null, "product": "Routers", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.89245, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99779, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-5521", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dfb7d8f1-b485-4250-bc8f-72f5b432d4bc", "vulnerability": {"vulnId": "CVE-2018-7445", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "dfb7d8f1-b485-4250-bc8f-72f5b432d4bc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to... | Affected: MikroTik / RouterOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.60809 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-7445", "url": "https://www.cve.org/CVERecord?id=CVE-2018-7445"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-7445"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to...", "cve_id": "CVE-2018-7445", "vendor": "MikroTik", "ghsa_id": null, "product": "RouterOS", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.60809, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99127, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-7445", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7d7ea20f-9e08-4691-9ede-04f34049134b", "vulnerability": {"vulnId": "CVE-2011-1823", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "7d7ea20f-9e08-4691-9ede-04f34049134b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.41367 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-1823", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1823"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1823"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local...", "cve_id": "CVE-2011-1823", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.41367, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98633, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1823", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8c3bbf55-0dfe-4e85-aff7-0f6cd1c77e1e", "vulnerability": {"vulnId": "CVE-2011-4723", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-08T02:00:00+02:00"}, "gcve": {"object_uuid": "8c3bbf55-0dfe-4e85-aff7-0f6cd1c77e1e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-08T00:00:00+00:00"}, "scope": {"notes": "The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified... | Affected: D-Link / DIR-300 | CVSS: 5.7 (MEDIUM) | EPSS: 0.03064 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-4723", "url": "https://www.cve.org/CVERecord?id=CVE-2011-4723"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-4723"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified...", "cve_id": "CVE-2011-4723", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-300", "added_date": "2022-09-08T00:00:00.000Z", "cvss_score": 5.7, "epss_score": 0.03064, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87158, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-4723", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4d0a6f69-aa62-4f06-948b-9ccfe6ab8e73", "vulnerability": {"vulnId": "CVE-2022-31474", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-07T09:56:11+02:00"}, "gcve": {"object_uuid": "4d0a6f69-aa62-4f06-948b-9ccfe6ab8e73", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-07T07:56:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-07T07:56:11+00:00"}, "scope": {"notes": "WordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversal | Affected: iThemes / BackupBuddy | CVSS: 7.5 (HIGH) | EPSS: 0.63761 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31474", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31474"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31474"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress BackupBuddy Plugin 8.5.8.0-8.7.4.1 is vulnerable to Directory Traversal", "cve_id": "CVE-2022-31474", "vendor": "iThemes", "ghsa_id": null, "product": "BackupBuddy", "added_date": "2022-09-07T07:56:11.000Z", "cvss_score": 7.5, "epss_score": 0.63761, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99198, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31474", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c8d7b2ef-b023-4d53-80a7-bae52dbfdcf7", "vulnerability": {"vulnId": "CVE-2022-36642", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-09-02T23:23:28+02:00"}, "gcve": {"object_uuid": "c8d7b2ef-b023-4d53-80a7-bae52dbfdcf7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-09-02T21:23:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-09-02T21:23:28+00:00"}, "scope": {"notes": "A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access... | Affected: Telos Alliance / Omnia MPX Node | CVSS: 9.8 (CRITICAL) | EPSS: 0.1288 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-36642", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36642"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36642"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access...", "cve_id": "CVE-2022-36642", "vendor": "Telos Alliance", "ghsa_id": null, "product": "Omnia MPX Node", "added_date": "2022-09-02T21:23:28.000Z", "cvss_score": 9.8, "epss_score": 0.1288, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9619, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36642", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a19902aa-192c-4472-a415-6801042d29b4", "vulnerability": {"vulnId": "CVE-2022-36559", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-30T00:46:21+02:00"}, "gcve": {"object_uuid": "a19902aa-192c-4472-a415-6801042d29b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-29T22:46:21+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-29T22:46:21+00:00"}, "scope": {"notes": "Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. | Affected: Seiko / SkyBridge MB-A200 | CVSS: 9.8 (CRITICAL) | EPSS: 0.01762 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-36559", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36559"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36559"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.", "cve_id": "CVE-2022-36559", "vendor": "Seiko", "ghsa_id": null, "product": "SkyBridge MB-A200", "added_date": "2022-08-29T22:46:21.000Z", "cvss_score": 9.8, "epss_score": 0.01762, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77193, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36559", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "64267a68-bd46-49bf-910c-318fb26d7868", "vulnerability": {"vulnId": "CVE-2022-36553", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-30T00:46:17+02:00"}, "gcve": {"object_uuid": "64267a68-bd46-49bf-910c-318fb26d7868", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-29T22:46:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-29T22:46:17+00:00"}, "scope": {"notes": "Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi. | Affected: Hytec Inter / HWL-2511-SS | CVSS: 9.8 (CRITICAL) | EPSS: 0.90902 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-36553", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36553"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36553"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.", "cve_id": "CVE-2022-36553", "vendor": "Hytec Inter", "ghsa_id": null, "product": "HWL-2511-SS", "added_date": "2022-08-29T22:46:17.000Z", "cvss_score": 9.8, "epss_score": 0.90902, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99804, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36553", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "42dd5272-659e-4ec8-871b-c724f9ea3410", "vulnerability": {"vulnId": "CVE-2022-26352", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "42dd5272-659e-4ec8-871b-c724f9ea3410", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose... | Affected: dotCMS / dotCMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.91553 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26352", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26352"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26352"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose...", "cve_id": "CVE-2022-26352", "vendor": "dotCMS", "ghsa_id": null, "product": "dotCMS", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91553, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99812, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-26352", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "df6cff44-9caf-47a1-a550-5035d4a2994d", "vulnerability": {"vulnId": "CVE-2020-36193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "df6cff44-9caf-47a1-a550-5035d4a2994d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related... | Affected: Pear / Archive_Tar | CVSS: 7.5 (HIGH) | EPSS: 0.70595 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-36193", "url": "https://www.cve.org/CVERecord?id=CVE-2020-36193"}, {"id": "GHSA-RPW6-9XFX-JVCX", "url": "https://github.com/advisories/GHSA-RPW6-9XFX-JVCX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-36193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related...", "cve_id": "CVE-2020-36193", "vendor": "Pear", "ghsa_id": "GHSA-RPW6-9XFX-JVCX", "product": "Archive_Tar", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.70595, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99375, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-36193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2b885591-0651-48ab-b6fe-530cc6420ee5", "vulnerability": {"vulnId": "CVE-2021-31010", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "2b885591-0651-48ab-b6fe-530cc6420ee5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8... | Affected: Apple / macOS, watchOS | CVSS: 7.5 (HIGH) | EPSS: 0.03673 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31010", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31010"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31010"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8...", "cve_id": "CVE-2021-31010", "vendor": "Apple", "ghsa_id": null, "product": "macOS, watchOS", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.03673, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31010", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cab9e33a-34e6-4e7d-bac8-bbeea5d8321a", "vulnerability": {"vulnId": "CVE-2022-24112", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "cab9e33a-34e6-4e7d-bac8-bbeea5d8321a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "apisix/batch-requests plugin allows overwriting the X-REAL-IP header | Affected: Apache / Apache APISIX | CVSS: 9.8 (CRITICAL) | EPSS: 0.96069 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24112", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24112"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24112"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "apisix/batch-requests plugin allows overwriting the X-REAL-IP header", "cve_id": "CVE-2022-24112", "vendor": "Apache", "ghsa_id": null, "product": "Apache APISIX", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96069, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99876, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24112", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ebdbd527-edcb-4265-9d26-465244976ff1", "vulnerability": {"vulnId": "CVE-2020-28949", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "ebdbd527-edcb-4265-9d26-465244976ff1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to... | Affected: Pear / Archive_Tar | CVSS: 7.8 (HIGH) | EPSS: 0.84554 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-28949", "url": "https://www.cve.org/CVERecord?id=CVE-2020-28949"}, {"id": "GHSA-75C5-F4GW-38R9", "url": "https://github.com/advisories/GHSA-75C5-F4GW-38R9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-28949"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to...", "cve_id": "CVE-2020-28949", "vendor": "Pear", "ghsa_id": "GHSA-75C5-F4GW-38R9", "product": "Archive_Tar", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.84554, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99696, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-28949", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "309e09f4-de76-4265-b21e-2fbe13c84f55", "vulnerability": {"vulnId": "CVE-2022-22963", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "309e09f4-de76-4265-b21e-2fbe13c84f55", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to... | Affected: VMware / Spring Cloud Function | CVSS: 9.8 (CRITICAL) | EPSS: 0.99938 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22963", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22963"}, {"id": "GHSA-6V73-FGF6-W5J7", "url": "https://github.com/advisories/GHSA-6V73-FGF6-W5J7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22963"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to...", "cve_id": "CVE-2022-22963", "vendor": "VMware", "ghsa_id": "GHSA-6V73-FGF6-W5J7", "product": "Spring Cloud Function", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99938, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99971, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22963", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "024ca50e-2afa-4ed2-9cb9-afa56e1867c2", "vulnerability": {"vulnId": "CVE-2022-24706", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "024ca50e-2afa-4ed2-9cb9-afa56e1867c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution Vulnerability in Packaging | Affected: Apache / Apache CouchDB | CVSS: 9.8 (CRITICAL) | EPSS: 0.9251 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24706", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24706"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24706"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution Vulnerability in Packaging", "cve_id": "CVE-2022-24706", "vendor": "Apache", "ghsa_id": null, "product": "Apache CouchDB", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9251, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99825, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24706", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6511de0-bfc4-4d90-8b14-b2963f942512", "vulnerability": {"vulnId": "CVE-2021-38406", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "a6511de0-bfc4-4d90-8b14-b2963f942512", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "Delta Electronics DOPSoft 2 Out-of-Bounds Write | Affected: Delta Electronics / DOPSoft 2 | CVSS: 7.8 (HIGH) | EPSS: 0.76428 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38406", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38406"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38406"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Delta Electronics DOPSoft 2 Out-of-Bounds Write", "cve_id": "CVE-2021-38406", "vendor": "Delta Electronics", "ghsa_id": null, "product": "DOPSoft 2", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.76428, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99526, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38406", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "23c3d462-fb78-4856-860e-0aafbf85f968", "vulnerability": {"vulnId": "CVE-2022-2294", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "23c3d462-fb78-4856-860e-0aafbf85f968", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.70461 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-2294", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2294"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2294"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2022-2294", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.70461, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99373, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-2294", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f526768-4956-4fbc-80ca-3452d891e452", "vulnerability": {"vulnId": "CVE-2021-39226", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-25T02:00:00+02:00"}, "gcve": {"object_uuid": "6f526768-4956-4fbc-80ca-3452d891e452", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-25T00:00:00+00:00"}, "scope": {"notes": "Snapshot authentication bypass in grafana | Affected: Grafana / grafana | CVSS: 9.8 (CRITICAL) | EPSS: 0.99933 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-39226", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39226"}, {"id": "GHSA-69J6-29VR-P3J9", "url": "https://github.com/advisories/GHSA-69J6-29VR-P3J9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39226"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Snapshot authentication bypass in grafana", "cve_id": "CVE-2021-39226", "vendor": "Grafana", "ghsa_id": "GHSA-69J6-29VR-P3J9", "product": "grafana", "added_date": "2022-08-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99933, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9997, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39226", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a11dd943-38fb-4901-90d5-44cf54cc707f", "vulnerability": {"vulnId": "CVE-2022-0028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-22T02:00:00+02:00"}, "gcve": {"object_uuid": "a11dd943-38fb-4901-90d5-44cf54cc707f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-22T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering | Affected: Palo Alto Networks / Cloud NGFW, PAN-OS, Prisma Access | CVSS: 8.6 (HIGH) | EPSS: 0.02383 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0028", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Reflected Amplification Denial-of-Service (DoS) Vulnerability in URL Filtering", "cve_id": "CVE-2022-0028", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Cloud NGFW, PAN-OS, Prisma Access", "added_date": "2022-08-22T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.02383, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83296, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e310f546-bcc0-41d7-8875-1513be76bf3b", "vulnerability": {"vulnId": "CVE-2022-21971", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "e310f546-bcc0-41d7-8875-1513be76bf3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "Windows Runtime Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2 | CVSS: 7.8 (HIGH) | EPSS: 0.53934 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-21971", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21971"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21971"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Runtime Remote Code Execution Vulnerability", "cve_id": "CVE-2022-21971", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.53934, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98971, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21971", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "250ed461-9f8e-4edd-a342-50edc6b7200c", "vulnerability": {"vulnId": "CVE-2022-37061", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "250ed461-9f8e-4edd-a342-50edc6b7200c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject... | Affected: FLIR / AX8 thermal sensor camera | CVSS: 9.8 (CRITICAL) | EPSS: 0.99607 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-37061", "url": "https://www.cve.org/CVERecord?id=CVE-2022-37061"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-37061"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject...", "cve_id": "CVE-2022-37061", "vendor": "FLIR", "ghsa_id": null, "product": "AX8 thermal sensor camera", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99607, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99947, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-37061", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c52ea4d1-438c-4078-96bc-873ad274e014", "vulnerability": {"vulnId": "CVE-2022-26923", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "c52ea4d1-438c-4078-96bc-873ad274e014", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "Active Directory Domain Services Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.835 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26923", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26923"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26923"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Active Directory Domain Services Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-26923", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.835, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99677, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26923", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "580fc390-0234-4a3a-ad9f-07643d0e37b2", "vulnerability": {"vulnId": "CVE-2022-32894", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "580fc390-0234-4a3a-ad9f-07643d0e37b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.03286 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-32894", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32894"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32894"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey...", "cve_id": "CVE-2022-32894", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03286, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88055, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32894", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eb56a10a-8564-4f0c-b01a-24a11a5f9bf4", "vulnerability": {"vulnId": "CVE-2022-22536", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "eb56a10a-8564-4f0c-b01a-24a11a5f9bf4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are... | Affected: SAP SE / SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server | CVSS: 10.0 (CRITICAL) | EPSS: 0.97945 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22536", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22536"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22536"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are...", "cve_id": "CVE-2022-22536", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP NetWeaver and ABAP Platform, SAP Web Dispatcher, SAP Content Server", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.97945, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99909, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22536", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "167973c3-254c-4137-9a55-42af93350774", "vulnerability": {"vulnId": "CVE-2022-32893", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "167973c3-254c-4137-9a55-42af93350774", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey... | Affected: Apple / Safari, iOS and iPadOS, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.09931 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-32893", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32893"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32893"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey...", "cve_id": "CVE-2022-32893", "vendor": "Apple", "ghsa_id": null, "product": "Safari, iOS and iPadOS, macOS", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.09931, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95454, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32893", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cdc69371-4417-490e-a70f-0c869b2d599b", "vulnerability": {"vulnId": "CVE-2022-2856", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "cdc69371-4417-490e-a70f-0c869b2d599b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily... | Affected: Google / Chrome | CVSS: 6.5 (MEDIUM) | EPSS: 0.0453 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-2856", "url": "https://www.cve.org/CVERecord?id=CVE-2022-2856"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-2856"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily...", "cve_id": "CVE-2022-2856", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.0453, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91246, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-2856", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5e4d6032-ae66-4adb-a696-df7b4e0629df", "vulnerability": {"vulnId": "CVE-2017-15944", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-18T02:00:00+02:00"}, "gcve": {"object_uuid": "5e4d6032-ae66-4adb-a696-df7b4e0629df", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-18T00:00:00+00:00"}, "scope": {"notes": "Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute... | Affected: Palo Alto Networks / PAN-OS | CVSS: 9.8 (CRITICAL) | EPSS: 0.98303 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-15944", "url": "https://www.cve.org/CVERecord?id=CVE-2017-15944"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-15944"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute...", "cve_id": "CVE-2017-15944", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "PAN-OS", "added_date": "2022-08-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98303, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-15944", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ec0e1aa2-06a2-4178-b68b-99c34ffbd959", "vulnerability": {"vulnId": "CVE-2022-37042", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-11T02:00:00+02:00"}, "gcve": {"object_uuid": "ec0e1aa2-06a2-4178-b68b-99c34ffbd959", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-11T00:00:00+00:00"}, "scope": {"notes": "Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing... | Affected: Zimbra / Collaboration Suite | CVSS: 9.8 (CRITICAL) | EPSS: 0.91893 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-37042", "url": "https://www.cve.org/CVERecord?id=CVE-2022-37042"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-37042"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing...", "cve_id": "CVE-2022-37042", "vendor": "Zimbra", "ghsa_id": null, "product": "Collaboration Suite", "added_date": "2022-08-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91893, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99816, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-37042", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "75545a27-bc4a-45e2-8819-71b4ef079807", "vulnerability": {"vulnId": "CVE-2022-27925", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-11T02:00:00+02:00"}, "gcve": {"object_uuid": "75545a27-bc4a-45e2-8819-71b4ef079807", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-11T00:00:00+00:00"}, "scope": {"notes": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated... | Affected: Zimbra / Collaboration | CVSS: 7.2 (HIGH) | EPSS: 0.98676 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-27925", "url": "https://www.cve.org/CVERecord?id=CVE-2022-27925"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-27925"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated...", "cve_id": "CVE-2022-27925", "vendor": "Zimbra", "ghsa_id": null, "product": "Collaboration", "added_date": "2022-08-11T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.98676, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99923, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-27925", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "83e4a44e-7d7e-4901-843f-0bfb0a7be2a6", "vulnerability": {"vulnId": "CVE-2022-30333", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-09T02:00:00+02:00"}, "gcve": {"object_uuid": "83e4a44e-7d7e-4901-843f-0bfb0a7be2a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-09T00:00:00+00:00"}, "scope": {"notes": "RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated... | Affected: RARLAB / UnRAR | CVSS: 9.8 (CRITICAL) | EPSS: 0.99107 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-30333", "url": "https://www.cve.org/CVERecord?id=CVE-2022-30333"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-30333"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated...", "cve_id": "CVE-2022-30333", "vendor": "RARLAB", "ghsa_id": null, "product": "UnRAR", "added_date": "2022-08-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99107, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99933, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-30333", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b6d9b5fb-1f41-43da-89af-aa25859ef17a", "vulnerability": {"vulnId": "CVE-2022-34713", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-09T02:00:00+02:00"}, "gcve": {"object_uuid": "b6d9b5fb-1f41-43da-89af-aa25859ef17a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-09T00:00:00+00:00"}, "scope": {"notes": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.67757 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-34713", "url": "https://www.cve.org/CVERecord?id=CVE-2022-34713"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-34713"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability", "cve_id": "CVE-2022-34713", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-08-09T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.67757, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99299, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-34713", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6288e486-e042-4847-a804-c9074e2dc28e", "vulnerability": {"vulnId": "CVE-2022-36267", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-08T16:34:15+02:00"}, "gcve": {"object_uuid": "6288e486-e042-4847-a804-c9074e2dc28e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-08T14:34:15+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-08T14:34:15+00:00"}, "scope": {"notes": "In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality... | Affected: Airspan / AirSpot 5410 | CVSS: 9.8 (CRITICAL) | EPSS: 0.54546 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-36267", "url": "https://www.cve.org/CVERecord?id=CVE-2022-36267"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-36267"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality...", "cve_id": "CVE-2022-36267", "vendor": "Airspan", "ghsa_id": null, "product": "AirSpot 5410", "added_date": "2022-08-08T14:34:15.000Z", "cvss_score": 9.8, "epss_score": 0.54546, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-36267", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b8f308bd-70be-41c8-9286-fef879d0f658", "vulnerability": {"vulnId": "CVE-2022-31793", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-04T23:55:05+02:00"}, "gcve": {"object_uuid": "b8f308bd-70be-41c8-9286-fef879d0f658", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-04T21:55:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-04T21:55:05+00:00"}, "scope": {"notes": "do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character... | Affected: Arris / muhttpd | CVSS: 7.5 (HIGH) | EPSS: 0.16856 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31793", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31793"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31793"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character...", "cve_id": "CVE-2022-31793", "vendor": "Arris", "ghsa_id": null, "product": "muhttpd", "added_date": "2022-08-04T21:55:05.000Z", "cvss_score": 7.5, "epss_score": 0.16856, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31793", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "da485d7c-ce88-445d-804d-e17a558de1da", "vulnerability": {"vulnId": "CVE-2022-27924", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-04T02:00:00+02:00"}, "gcve": {"object_uuid": "da485d7c-ce88-445d-804d-e17a558de1da", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-04T00:00:00+00:00"}, "scope": {"notes": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance.... | Affected: Zimbra / Zimbra Collaboration | CVSS: 9.8 (CRITICAL) | EPSS: 0.85398 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-27924", "url": "https://www.cve.org/CVERecord?id=CVE-2022-27924"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-27924"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance....", "cve_id": "CVE-2022-27924", "vendor": "Zimbra", "ghsa_id": null, "product": "Zimbra Collaboration", "added_date": "2022-08-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.85398, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99714, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-27924", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b024bbda-4c5a-4d15-a506-8188e7bd296b", "vulnerability": {"vulnId": "CVE-2022-1950", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-08-01T14:49:04+02:00"}, "gcve": {"object_uuid": "b024bbda-4c5a-4d15-a506-8188e7bd296b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-08-01T12:49:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-08-01T12:49:04+00:00"}, "scope": {"notes": "Youzify < 1.2.0 - Unauthenticated SQLi | Affected: Youzify / Youzify | CVSS: 9.8 (CRITICAL) | EPSS: 0.05878 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1950", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1950"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1950"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Youzify < 1.2.0 - Unauthenticated SQLi", "cve_id": "CVE-2022-1950", "vendor": "Youzify", "ghsa_id": null, "product": "Youzify", "added_date": "2022-08-01T12:49:04.000Z", "cvss_score": 9.8, "epss_score": 0.05878, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1950", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "74999b07-839c-48ac-80d3-5093af9449ae", "vulnerability": {"vulnId": "CVE-2022-26138", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-29T02:00:00+02:00"}, "gcve": {"object_uuid": "74999b07-839c-48ac-80d3-5093af9449ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-29T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-29T00:00:00+00:00"}, "scope": {"notes": "The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group... | Affected: Atlassian / Questions For Confluence | CVSS: 9.8 (CRITICAL) | EPSS: 0.9817 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26138", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26138"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26138"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group...", "cve_id": "CVE-2022-26138", "vendor": "Atlassian", "ghsa_id": null, "product": "Questions For Confluence", "added_date": "2022-07-29T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9817, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99914, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26138", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b73ed313-9452-4d45-ae62-5b3f5c1e577c", "vulnerability": {"vulnId": "CVE-2022-35653", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-25T17:33:11+02:00"}, "gcve": {"object_uuid": "b73ed313-9452-4d45-ae62-5b3f5c1e577c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-25T15:33:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-25T15:33:11+00:00"}, "scope": {"notes": "A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data... | Affected: Moodle / Moodle | CVSS: 6.1 (MEDIUM) | EPSS: 0.04754 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-35653", "url": "https://www.cve.org/CVERecord?id=CVE-2022-35653"}, {"id": "GHSA-62WH-M4JR-233R", "url": "https://github.com/advisories/GHSA-62WH-M4JR-233R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-35653"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data...", "cve_id": "CVE-2022-35653", "vendor": "Moodle", "ghsa_id": "GHSA-62WH-M4JR-233R", "product": "Moodle", "added_date": "2022-07-25T15:33:11.000Z", "cvss_score": 6.1, "epss_score": 0.04754, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-35653", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "300fcbc2-5c59-402e-9f67-1b248d7986fa", "vulnerability": {"vulnId": "CVE-2022-34538", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-19T21:03:57+02:00"}, "gcve": {"object_uuid": "300fcbc2-5c59-402e-9f67-1b248d7986fa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-19T19:03:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-19T19:03:57+00:00"}, "scope": {"notes": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component... | Affected: Digital Watchdog / DW MEGApix IP cameras | CVSS: 8.8 (HIGH) | EPSS: 0.02727 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-34538", "url": "https://www.cve.org/CVERecord?id=CVE-2022-34538"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-34538"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component...", "cve_id": "CVE-2022-34538", "vendor": "Digital Watchdog", "ghsa_id": null, "product": "DW MEGApix IP cameras", "added_date": "2022-07-19T19:03:57.000Z", "cvss_score": 8.8, "epss_score": 0.02727, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85551, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-34538", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "48904cbf-b842-42ff-9622-6ab46229a3f7", "vulnerability": {"vulnId": "CVE-2022-31208", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-18T00:36:18+02:00"}, "gcve": {"object_uuid": "48904cbf-b842-42ff-9622-6ab46229a3f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-17T22:36:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-17T22:36:18+00:00"}, "scope": {"notes": "An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the... | Affected: Infiray / IRAY-A8Z3 | CVSS: 8.8 (HIGH) | EPSS: 0.01464 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-31208", "url": "https://www.cve.org/CVERecord?id=CVE-2022-31208"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-31208"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the...", "cve_id": "CVE-2022-31208", "vendor": "Infiray", "ghsa_id": null, "product": "IRAY-A8Z3", "added_date": "2022-07-17T22:36:18.000Z", "cvss_score": 8.8, "epss_score": 0.01464, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-31208", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "62d9df37-08b2-46a7-915f-8d9d45e1dfa8", "vulnerability": {"vulnId": "CVE-2022-32409", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-14T23:24:22+02:00"}, "gcve": {"object_uuid": "62d9df37-08b2-46a7-915f-8d9d45e1dfa8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-14T21:24:22+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-14T21:24:22+00:00"}, "scope": {"notes": "A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers... | Affected: Portal do Software Publico Brasileiro / i3geo | CVSS: 9.8 (CRITICAL) | EPSS: 0.13599 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-32409", "url": "https://www.cve.org/CVERecord?id=CVE-2022-32409"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-32409"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers...", "cve_id": "CVE-2022-32409", "vendor": "Portal do Software Publico Brasileiro", "ghsa_id": null, "product": "i3geo", "added_date": "2022-07-14T21:24:22.000Z", "cvss_score": 9.8, "epss_score": 0.13599, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96355, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-32409", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "21276c35-d518-4013-bb1c-4fb13ae0265a", "vulnerability": {"vulnId": "CVE-2021-24284", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-13T12:52:06+02:00"}, "gcve": {"object_uuid": "21276c35-d518-4013-bb1c-4fb13ae0265a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-13T10:52:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-13T10:52:06+00:00"}, "scope": {"notes": "Kaswara Modern VC Addons <= 3.0.1 - Unauthenticated Arbitrary File Upload | Affected: SayenThemes / Kaswara Modern VC Addons | CVSS: 9.8 (CRITICAL) | EPSS: 0.4214 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24284", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24284"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24284"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kaswara Modern VC Addons <= 3.0.1 - Unauthenticated Arbitrary File Upload", "cve_id": "CVE-2021-24284", "vendor": "SayenThemes", "ghsa_id": null, "product": "Kaswara Modern VC Addons", "added_date": "2022-07-13T10:52:06.000Z", "cvss_score": 9.8, "epss_score": 0.4214, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98655, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24284", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "439a17bb-e456-425d-a2de-763761f223d7", "vulnerability": {"vulnId": "CVE-2022-22047", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-12T02:00:00+02:00"}, "gcve": {"object_uuid": "439a17bb-e456-425d-a2de-763761f223d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-12T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-12T00:00:00+00:00"}, "scope": {"notes": "Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.18765 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22047", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22047"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22047"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-22047", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-07-12T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.18765, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97198, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22047", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b7a2aedd-d2d6-454f-9e78-2c03025b494a", "vulnerability": {"vulnId": "CVE-2022-26925", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-07-01T02:00:00+02:00"}, "gcve": {"object_uuid": "b7a2aedd-d2d6-454f-9e78-2c03025b494a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-07-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-07-01T00:00:00+00:00"}, "scope": {"notes": "Windows LSA Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 8.1 (HIGH) | EPSS: 0.10476 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26925", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26925"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26925"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows LSA Spoofing Vulnerability", "cve_id": "CVE-2022-26925", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-07-01T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.10476, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9562, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26925", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18b283c2-0164-4e08-a723-624772f91941", "vulnerability": {"vulnId": "CVE-2022-1916", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T10:58:38+02:00"}, "gcve": {"object_uuid": "18b283c2-0164-4e08-a723-624772f91941", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T08:58:38+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T08:58:38+00:00"}, "scope": {"notes": "Active Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-Scripting | Affected: Active Products Tables / Active Products Tables for WooCommerce | CVSS: 6.1 (MEDIUM) | EPSS: 0.01949 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1916", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1916"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1916"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Active Products Tables for WooCommerce < 1.0.5 - Reflected Cross-Site-Scripting", "cve_id": "CVE-2022-1916", "vendor": "Active Products Tables", "ghsa_id": null, "product": "Active Products Tables for WooCommerce", "added_date": "2022-06-27T08:58:38.000Z", "cvss_score": 6.1, "epss_score": 0.01949, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.7949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1916", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "eeaf4b2d-9ba7-4e1e-bcfe-2c37a79229f2", "vulnerability": {"vulnId": "CVE-2021-30533", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "eeaf4b2d-9ba7-4e1e-bcfe-2c37a79229f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions... | Affected: Google / Chrome | CVSS: 6.5 (MEDIUM) | EPSS: 0.16611 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30533", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30533"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30533"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions...", "cve_id": "CVE-2021-30533", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.16611, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30533", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1f5f7ae2-1e4e-4334-93c4-a8ef1d71e4f0", "vulnerability": {"vulnId": "CVE-2020-3837", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "1f5f7ae2-1e4e-4334-93c4-a8ef1d71e4f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3,... | Affected: Apple / iOS, macOS, tvOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.14722 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3837", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3837"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3837"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3,...", "cve_id": "CVE-2020-3837", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS, tvOS, watchOS", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.14722, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3837", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "14eb2d4c-cd6b-47a6-9357-4ce3e5e3f99d", "vulnerability": {"vulnId": "CVE-2020-9907", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "14eb2d4c-cd6b-47a6-9357-4ce3e5e3f99d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An... | Affected: Apple / iOS, tvOS | CVSS: 7.8 (HIGH) | EPSS: 0.03199 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9907", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9907"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9907"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An...", "cve_id": "CVE-2020-9907", "vendor": "Apple", "ghsa_id": null, "product": "iOS, tvOS", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03199, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87685, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9907", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ed85198e-dd6b-47f5-9bb7-8b0cde065516", "vulnerability": {"vulnId": "CVE-2018-4344", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "ed85198e-dd6b-47f5-9bb7-8b0cde065516", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12,... | Affected: Apple / iOS, macOS, tvOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.02374 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-4344", "url": "https://www.cve.org/CVERecord?id=CVE-2018-4344"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-4344"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12,...", "cve_id": "CVE-2018-4344", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS, tvOS, watchOS", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02374, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83232, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-4344", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "901351be-dff3-494e-bec1-dca35e557ff5", "vulnerability": {"vulnId": "CVE-2021-30983", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "901351be-dff3-494e-bec1-dca35e557ff5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to... | Affected: Apple / iOS and iPadOS | CVSS: 7.8 (HIGH) | EPSS: 0.02923 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30983", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30983"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30983"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to...", "cve_id": "CVE-2021-30983", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02923, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86568, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30983", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2daa637c-3e5e-4dbc-b406-2b398f5d7bab", "vulnerability": {"vulnId": "CVE-2021-4034", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "2daa637c-3e5e-4dbc-b406-2b398f5d7bab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow... | Affected: Freedesktop.org / polkit | CVSS: 7.8 (HIGH) | EPSS: 0.94345 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-4034", "url": "https://www.cve.org/CVERecord?id=CVE-2021-4034"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-4034"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow...", "cve_id": "CVE-2021-4034", "vendor": "Freedesktop.org", "ghsa_id": null, "product": "polkit", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.94345, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9985, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-4034", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cc838497-cfb7-4408-8c02-45e63b01be07", "vulnerability": {"vulnId": "CVE-2022-29499", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "cc838497-cfb7-4408-8c02-45e63b01be07", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The... | Affected: Mitel / MiVoice Connect | CVSS: 9.8 (CRITICAL) | EPSS: 0.55242 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-29499", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29499"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29499"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The...", "cve_id": "CVE-2022-29499", "vendor": "Mitel", "ghsa_id": null, "product": "MiVoice Connect", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.55242, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99003, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-29499", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8593b506-570c-44ed-8ec6-34d84d8f242b", "vulnerability": {"vulnId": "CVE-2019-8605", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-27T02:00:00+02:00"}, "gcve": {"object_uuid": "8593b506-570c-44ed-8ec6-34d84d8f242b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-27T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-27T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS... | Affected: Apple / iOS, macOS, tvOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.17609 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-8605", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8605"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8605"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS...", "cve_id": "CVE-2019-8605", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS, tvOS, watchOS", "added_date": "2022-06-27T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.17609, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97063, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8605", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1e6e496a-8e63-4135-915a-abb4b59d49b6", "vulnerability": {"vulnId": "CVE-2022-30190", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-14T02:00:00+02:00"}, "gcve": {"object_uuid": "1e6e496a-8e63-4135-915a-abb4b59d49b6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-14T00:00:00+00:00"}, "scope": {"notes": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.99163 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-30190", "url": "https://www.cve.org/CVERecord?id=CVE-2022-30190"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-30190"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability", "cve_id": "CVE-2022-30190", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-06-14T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.99163, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99933, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-30190", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f2ec45d4-74a9-4a3a-8de1-c37de7532d38", "vulnerability": {"vulnId": "CVE-2016-2388", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-09T02:00:00+02:00"}, "gcve": {"object_uuid": "f2ec45d4-74a9-4a3a-8de1-c37de7532d38", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-09T00:00:00+00:00"}, "scope": {"notes": "The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP... | Affected: SAP / NetWeaver AS JAVA | CVSS: 5.3 (MEDIUM) | EPSS: 0.52206 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-2388", "url": "https://www.cve.org/CVERecord?id=CVE-2016-2388"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-2388"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP...", "cve_id": "CVE-2016-2388", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver AS JAVA", "added_date": "2022-06-09T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.52206, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-2388", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3983928d-99c6-45f6-b94c-7c02b8be2560", "vulnerability": {"vulnId": "CVE-2016-2386", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-09T02:00:00+02:00"}, "gcve": {"object_uuid": "3983928d-99c6-45f6-b94c-7c02b8be2560", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-09T00:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via... | Affected: SAP / NetWeaver J2EE Engine | CVSS: 9.8 (CRITICAL) | EPSS: 0.71522 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-2386", "url": "https://www.cve.org/CVERecord?id=CVE-2016-2386"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-2386"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via...", "cve_id": "CVE-2016-2386", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver J2EE Engine", "added_date": "2022-06-09T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.71522, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99401, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-2386", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a37fe7e-4c70-40bf-8412-3d6555fedff1", "vulnerability": {"vulnId": "CVE-2021-38163", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-09T02:00:00+02:00"}, "gcve": {"object_uuid": "6a37fe7e-4c70-40bf-8412-3d6555fedff1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-09T00:00:00+00:00"}, "scope": {"notes": "SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative... | Affected: SAP SE / SAP NetWeaver (Visual Composer 7.0 RT) | CVSS: 9.9 (CRITICAL) | EPSS: 0.36018 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38163", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38163"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38163"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative...", "cve_id": "CVE-2021-38163", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP NetWeaver (Visual Composer 7.0 RT)", "added_date": "2022-06-09T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.36018, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98431, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38163", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ea16268d-0071-4076-9850-02f8baff7bbe", "vulnerability": {"vulnId": "CVE-2022-29013", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-09T01:28:57+02:00"}, "gcve": {"object_uuid": "ea16268d-0071-4076-9850-02f8baff7bbe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T23:28:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T23:28:57+00:00"}, "scope": {"notes": "A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a... | Affected: Razer / Sila Gaming Router | CVSS: 9.8 (CRITICAL) | EPSS: 0.76905 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29013", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29013"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29013"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a...", "cve_id": "CVE-2022-29013", "vendor": "Razer", "ghsa_id": null, "product": "Sila Gaming Router", "added_date": "2022-06-08T23:28:57.000Z", "cvss_score": 9.8, "epss_score": 0.76905, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99536, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29013", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a8aa4203-c088-4b97-82b6-cf58c4f04d44", "vulnerability": {"vulnId": "CVE-2009-0563", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "a8aa4203-c088-4b97-82b6-cf58c4f04d44", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.62828 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-0563", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0563"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0563"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML...", "cve_id": "CVE-2009-0563", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.62828, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99174, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0563", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ed0e944-71fd-4617-9021-c3569bf7d2aa", "vulnerability": {"vulnId": "CVE-2017-5070", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "2ed0e944-71fd-4617-9021-c3569bf7d2aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to... | Affected: Google / Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android | CVSS: 8.8 (HIGH) | EPSS: 0.32071 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-5070", "url": "https://www.cve.org/CVERecord?id=CVE-2017-5070"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-5070"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to...", "cve_id": "CVE-2017-5070", "vendor": "Google", "ghsa_id": null, "product": "Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.32071, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98265, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-5070", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ee0add9d-03e6-4014-a134-fce2a8f02950", "vulnerability": {"vulnId": "CVE-2012-0767", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "ee0add9d-03e6-4014-a134-fce2a8f02950", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and... | Affected: Adobe / Flash Player | CVSS: 6.1 (MEDIUM) | EPSS: 0.06417 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0767", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0767"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0767"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and...", "cve_id": "CVE-2012-0767", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.06417, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93485, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0767", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "66108b14-93e8-4df5-84df-8747ee188521", "vulnerability": {"vulnId": "CVE-2019-7193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "66108b14-93e8-4df5-84df-8747ee188521", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP... | Affected: QNAP / QNAP NAS devices | CVSS: 9.8 (CRITICAL) | EPSS: 0.14367 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7193", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP...", "cve_id": "CVE-2019-7193", "vendor": "QNAP", "ghsa_id": null, "product": "QNAP NAS devices", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14367, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96514, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-7193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "321fa14f-d399-478f-a710-413c0d7b1993", "vulnerability": {"vulnId": "CVE-2018-6065", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "321fa14f-d399-478f-a710-413c0d7b1993", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.60304 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-6065", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6065"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-6065"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146...", "cve_id": "CVE-2018-6065", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.60304, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99115, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-6065", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8404cf18-d8d1-4af9-9e7c-0883d5f62772", "vulnerability": {"vulnId": "CVE-2013-1331", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "8404cf18-d8d1-4af9-9e7c-0883d5f62772", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.79822 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-1331", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1331"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1331"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an...", "cve_id": "CVE-2013-1331", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.79822, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1331", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e1327a20-fde0-4874-a462-beb1ee5da4bb", "vulnerability": {"vulnId": "CVE-2011-0609", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "e1327a20-fde0-4874-a462-beb1ee5da4bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on... | Affected: Adobe / Flash Player | CVSS: 7.8 (HIGH) | EPSS: 0.63507 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-0609", "url": "https://www.cve.org/CVERecord?id=CVE-2011-0609"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-0609"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on...", "cve_id": "CVE-2011-0609", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.63507, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9919, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-0609", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a30bf36b-8ed6-4b22-8e3e-0c3201562356", "vulnerability": {"vulnId": "CVE-2010-2883", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "a30bf36b-8ed6-4b22-8e3e-0c3201562356", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote... | Affected: Adobe / Reader and Acrobat | CVSS: 7.3 (HIGH) | EPSS: 0.81376 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-2883", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2883"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-2883"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote...", "cve_id": "CVE-2010-2883", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.81376, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9963, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-2883", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d899902e-91fb-4d82-bcb3-b365d4e53ba9", "vulnerability": {"vulnId": "CVE-2012-5054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "d899902e-91fb-4d82-bcb3-b365d4e53ba9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.21194 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-5054", "url": "https://www.cve.org/CVERecord?id=CVE-2012-5054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-5054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute...", "cve_id": "CVE-2012-5054", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.21194, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97521, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-5054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4d3cbe18-03b3-4b49-8f8a-bb77ae06079b", "vulnerability": {"vulnId": "CVE-2009-3953", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "4d3cbe18-03b3-4b49-8f8a-bb77ae06079b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote... | Affected: Adobe / Reader and Acrobat | CVSS: 8.8 (HIGH) | EPSS: 0.83219 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-3953", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3953"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-3953"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote...", "cve_id": "CVE-2009-3953", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.83219, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99671, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-3953", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "65e22124-a254-4e63-8ccb-ea3ff2d84dc1", "vulnerability": {"vulnId": "CVE-2009-0557", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "65e22124-a254-4e63-8ccb-ea3ff2d84dc1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.53 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-0557", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0557"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0557"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and...", "cve_id": "CVE-2009-0557", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.53, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0557", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "30503a8e-7d12-412d-a3f6-7ef58603d66e", "vulnerability": {"vulnId": "CVE-2007-5659", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "30503a8e-7d12-412d-a3f6-7ef58603d66e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long... | Affected: Adobe / Reader and Acrobat | CVSS: 7.8 (HIGH) | EPSS: 0.87423 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2007-5659", "url": "https://www.cve.org/CVERecord?id=CVE-2007-5659"}, {"id": "previdian", "url": "https://previdian.com/CVE-2007-5659"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long...", "cve_id": "CVE-2007-5659", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.87423, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99753, "used_in_malware": "unknown", "vulnerability_id": "CVE-2007-5659", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b9969f41-fd2a-474a-980d-01cb1c26c0e2", "vulnerability": {"vulnId": "CVE-2006-2492", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "b9969f41-fd2a-474a-980d-01cb1c26c0e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows... | Affected: Microsoft / Word | CVSS: 8.8 (HIGH) | EPSS: 0.48107 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2006-2492", "url": "https://www.cve.org/CVERecord?id=CVE-2006-2492"}, {"id": "previdian", "url": "https://previdian.com/CVE-2006-2492"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows...", "cve_id": "CVE-2006-2492", "vendor": "Microsoft", "ghsa_id": null, "product": "Word", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.48107, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98822, "used_in_malware": "unknown", "vulnerability_id": "CVE-2006-2492", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e60e93bc-c0ee-4786-98b7-dc4ce6f15270", "vulnerability": {"vulnId": "CVE-2016-1646", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "e60e93bc-c0ee-4786-98b7-dc4ce6f15270", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.4811 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-1646", "url": "https://www.cve.org/CVERecord?id=CVE-2016-1646"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-1646"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider...", "cve_id": "CVE-2016-1646", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.4811, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98822, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-1646", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "92bac42a-9e8e-414e-8845-05cfdb2271bd", "vulnerability": {"vulnId": "CVE-2012-0754", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "92bac42a-9e8e-414e-8845-05cfdb2271bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and... | Affected: Adobe / Flash Player | CVSS: 8.1 (HIGH) | EPSS: 0.91244 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0754", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0754"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0754"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and...", "cve_id": "CVE-2012-0754", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.91244, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99807, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0754", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d57beab9-43e8-48b5-8320-8c01623f5203", "vulnerability": {"vulnId": "CVE-2009-1862", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "d57beab9-43e8-48b5-8320-8c01623f5203", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87,... | Affected: Adobe / [\"Reader\", \"Acrobat\", \"Flash Player\"] | CVSS: 7.8 (HIGH) | EPSS: 0.21198 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-1862", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1862"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1862"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87,...", "cve_id": "CVE-2009-1862", "vendor": "Adobe", "ghsa_id": null, "product": "[\"Reader\", \"Acrobat\", \"Flash Player\"]", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.21198, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97521, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1862", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6791c2c8-bebf-47cb-81a8-c9daa68abf30", "vulnerability": {"vulnId": "CVE-2008-0655", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "6791c2c8-bebf-47cb-81a8-c9daa68abf30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. | Affected: Adobe / Reader and Acrobat | CVSS: 8.8 (HIGH) | EPSS: 0.37871 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2008-0655", "url": "https://www.cve.org/CVERecord?id=CVE-2008-0655"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-0655"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.", "cve_id": "CVE-2008-0655", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.37871, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98505, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-0655", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c5ece0c0-540b-4590-b5ba-a11d1c35c210", "vulnerability": {"vulnId": "CVE-2019-7195", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "c5ece0c0-540b-4590-b5ba-a11d1c35c210", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP... | Affected: QNAP / QNAP NAS devices running Photo Station | CVSS: 9.8 (CRITICAL) | EPSS: 0.89681 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7195", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7195"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7195"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP...", "cve_id": "CVE-2019-7195", "vendor": "QNAP", "ghsa_id": null, "product": "QNAP NAS devices running Photo Station", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.89681, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99786, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-7195", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f437829d-5ddb-4bfd-9eab-e791cca179d0", "vulnerability": {"vulnId": "CVE-2018-17480", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "f437829d-5ddb-4bfd-9eab-e791cca179d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.3564 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-17480", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17480"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17480"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80...", "cve_id": "CVE-2018-17480", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.3564, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98415, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17480", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ad5899c4-f05b-458e-822f-90c27303b93e", "vulnerability": {"vulnId": "CVE-2012-1889", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "ad5899c4-f05b-458e-822f-90c27303b93e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code... | Affected: Microsoft / XML Core Services | CVSS: 8.8 (HIGH) | EPSS: 0.83516 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1889", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1889"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1889"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code...", "cve_id": "CVE-2012-1889", "vendor": "Microsoft", "ghsa_id": null, "product": "XML Core Services", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.83516, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99677, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1889", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "781ab392-1590-4c26-a4ba-62ce4c42a7dd", "vulnerability": {"vulnId": "CVE-2009-4324", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "781ab392-1590-4c26-a4ba-62ce4c42a7dd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on... | Affected: Adobe / Reader and Acrobat | CVSS: 7.8 (HIGH) | EPSS: 0.8188 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-4324", "url": "https://www.cve.org/CVERecord?id=CVE-2009-4324"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-4324"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on...", "cve_id": "CVE-2009-4324", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.8188, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9964, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-4324", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb0cbf9d-71eb-4f62-866b-f7da7d2c8aa5", "vulnerability": {"vulnId": "CVE-2019-7194", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "fb0cbf9d-71eb-4f62-866b-f7da7d2c8aa5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP... | Affected: QNAP / QNAP NAS devices running Photo Station | CVSS: 9.8 (CRITICAL) | EPSS: 0.83124 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7194", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7194"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7194"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP...", "cve_id": "CVE-2019-7194", "vendor": "QNAP", "ghsa_id": null, "product": "QNAP NAS devices running Photo Station", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83124, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99667, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-7194", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e4f9c207-f815-4896-9b7a-a1c58b99973f", "vulnerability": {"vulnId": "CVE-2019-15271", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "e4f9c207-f815-4896-9b7a-a1c58b99973f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 8.8 (HIGH) | EPSS: 0.05488 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-15271", "url": "https://www.cve.org/CVERecord?id=CVE-2019-15271"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-15271"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability", "cve_id": "CVE-2019-15271", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.05488, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92524, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-15271", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "03e9be38-4417-449f-9aca-77d41b359647", "vulnerability": {"vulnId": "CVE-2017-6862", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "03e9be38-4417-449f-9aca-77d41b359647", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and... | Affected: NETGEAR / NETGEAR All versions prior to WNR2000v3 1.1.2.14, WNR2000v4 1.0.0.66, WNR2000v5 1.0.0.42 | CVSS: 9.8 (CRITICAL) | EPSS: 0.45748 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6862", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6862"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6862"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and...", "cve_id": "CVE-2017-6862", "vendor": "NETGEAR", "ghsa_id": null, "product": "NETGEAR All versions prior to WNR2000v3 1.1.2.14, WNR2000v4 1.0.0.66, WNR2000v5 1.0.0.42", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.45748, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98764, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6862", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5601e0ed-83a6-4da1-80eb-25a71a44ef2a", "vulnerability": {"vulnId": "CVE-2017-5030", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "5601e0ed-83a6-4da1-80eb-25a71a44ef2a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android... | Affected: Google / Google Chrome prior to 57.0.2987.98 for Linux, Windows and Mac, and 57.0.2987.108 for Android | CVSS: 8.8 (HIGH) | EPSS: 0.40635 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-5030", "url": "https://www.cve.org/CVERecord?id=CVE-2017-5030"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-5030"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android...", "cve_id": "CVE-2017-5030", "vendor": "Google", "ghsa_id": null, "product": "Google Chrome prior to 57.0.2987.98 for Linux, Windows and Mac, and 57.0.2987.108 for Android", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.40635, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98611, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-5030", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "01ad742c-310a-483b-9763-13ffd46d30c7", "vulnerability": {"vulnId": "CVE-2012-0151", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "01ad742c-310a-483b-9763-13ffd46d30c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.87719 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0151", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0151"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0151"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server...", "cve_id": "CVE-2012-0151", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.87719, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99758, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0151", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dab88e4d-d2e2-40b7-8698-6feaa829762e", "vulnerability": {"vulnId": "CVE-2011-2462", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "dab88e4d-d2e2-40b7-8698-6feaa829762e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through... | Affected: Adobe / Reader and Acrobat | CVSS: 9.8 (CRITICAL) | EPSS: 0.88516 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-2462", "url": "https://www.cve.org/CVERecord?id=CVE-2011-2462"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-2462"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through...", "cve_id": "CVE-2011-2462", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88516, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-2462", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "600a3687-8240-4ee1-aeab-1e1a8b0dc868", "vulnerability": {"vulnId": "CVE-2019-5825", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "600a3687-8240-4ee1-aeab-1e1a8b0dc868", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 6.5 (MEDIUM) | EPSS: 0.55925 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-5825", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5825"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5825"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2019-5825", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.55925, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9902, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5825", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5060131c-a5ab-488b-8157-c3bc015d6fa2", "vulnerability": {"vulnId": "CVE-2018-4990", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "5060131c-a5ab-488b-8157-c3bc015d6fa2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free... | Affected: Adobe / Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions | CVSS: 8.8 (HIGH) | EPSS: 0.36228 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-4990", "url": "https://www.cve.org/CVERecord?id=CVE-2018-4990"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-4990"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free...", "cve_id": "CVE-2018-4990", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Acrobat and Reader 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier versions", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.36228, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98436, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-4990", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "01d927ce-9bad-484b-9a85-3abc7e454ed0", "vulnerability": {"vulnId": "CVE-2018-17463", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "01d927ce-9bad-484b-9a85-3abc7e454ed0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.84564 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-17463", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17463"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17463"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox...", "cve_id": "CVE-2018-17463", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.84564, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99697, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17463", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a4460890-d8f7-4e73-9a75-5de724f1dd37", "vulnerability": {"vulnId": "CVE-2016-5198", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "a4460890-d8f7-4e73-9a75-5de724f1dd37", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect... | Affected: Google / Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac | CVSS: 8.8 (HIGH) | EPSS: 0.34164 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-5198", "url": "https://www.cve.org/CVERecord?id=CVE-2016-5198"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-5198"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect...", "cve_id": "CVE-2016-5198", "vendor": "Google", "ghsa_id": null, "product": "Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.34164, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98359, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-5198", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "548d6f01-d00c-47f9-a7e8-697fa68301ae", "vulnerability": {"vulnId": "CVE-2012-4969", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "548d6f01-d00c-47f9-a7e8-697fa68301ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to... | Affected: Microsoft / Internet Explorer | CVSS: 8.1 (HIGH) | EPSS: 0.8025 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-4969", "url": "https://www.cve.org/CVERecord?id=CVE-2012-4969"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-4969"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to...", "cve_id": "CVE-2012-4969", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.8025, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-4969", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "361985ef-26a8-4c9a-a205-489d204b747e", "vulnerability": {"vulnId": "CVE-2010-1297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "361985ef-26a8-4c9a-a205-489d204b747e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and... | Affected: Adobe / Flash Player, AIR, Reader, Acrobat | CVSS: 7.8 (HIGH) | EPSS: 0.82531 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-1297", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-1297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and...", "cve_id": "CVE-2010-1297", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player, AIR, Reader, Acrobat", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.82531, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99657, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-1297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0647b5af-fbc0-4715-b04e-1f2db301b4de", "vulnerability": {"vulnId": "CVE-2010-2572", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "0647b5af-fbc0-4715-b04e-1f2db301b4de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95... | Affected: Microsoft / PowerPoint | CVSS: 7.8 (HIGH) | EPSS: 0.58646 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-2572", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2572"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-2572"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95...", "cve_id": "CVE-2010-2572", "vendor": "Microsoft", "ghsa_id": null, "product": "PowerPoint", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.58646, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99078, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-2572", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "70291daf-cc50-4419-9b0e-30cdae6bb4fb", "vulnerability": {"vulnId": "CVE-2019-7192", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-08T02:00:00+02:00"}, "gcve": {"object_uuid": "70291daf-cc50-4419-9b0e-30cdae6bb4fb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-08T00:00:00+00:00"}, "scope": {"notes": "This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP... | Affected: QNAP / QNAP NAS devices running Photo Station | CVSS: 9.8 (CRITICAL) | EPSS: 0.88102 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7192", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7192"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7192"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP...", "cve_id": "CVE-2019-7192", "vendor": "QNAP", "ghsa_id": null, "product": "QNAP NAS devices running Photo Station", "added_date": "2022-06-08T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88102, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99764, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-7192", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cc681920-3658-465a-973f-c132a8aae037", "vulnerability": {"vulnId": "CVE-2022-26134", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-06-02T02:00:00+02:00"}, "gcve": {"object_uuid": "cc681920-3658-465a-973f-c132a8aae037", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-06-02T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-06-02T00:00:00+00:00"}, "scope": {"notes": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to... | Affected: Atlassian / Confluence Data Center, Confluence Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26134", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26134"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26134"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to...", "cve_id": "CVE-2022-26134", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Data Center, Confluence Server", "added_date": "2022-06-02T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99994, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-26134", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c1ad25a9-f747-4d60-be0b-a555e4d6ce75", "vulnerability": {"vulnId": "CVE-2022-1883", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T10:20:11+02:00"}, "gcve": {"object_uuid": "c1ad25a9-f747-4d60-be0b-a555e4d6ce75", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T08:20:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T08:20:11+00:00"}, "scope": {"notes": "SQL Injection in camptocamp/terraboard | Affected: Camptocamp / camptocamp/terraboard | CVSS: 9.6 (CRITICAL) | EPSS: 0.0676 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1883", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1883"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1883"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL Injection in camptocamp/terraboard", "cve_id": "CVE-2022-1883", "vendor": "Camptocamp", "ghsa_id": null, "product": "camptocamp/terraboard", "added_date": "2022-05-25T08:20:11.000Z", "cvss_score": 9.6, "epss_score": 0.0676, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93773, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1883", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9fd6e86e-2f51-498c-8b3e-21fa045a704b", "vulnerability": {"vulnId": "CVE-2015-2360", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "9fd6e86e-2f51-498c-8b3e-21fa045a704b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.1484 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2360", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2360"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2360"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,...", "cve_id": "CVE-2015-2360", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.1484, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96596, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2360", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d413e8b4-38b0-484e-84fb-e177e943e604", "vulnerability": {"vulnId": "CVE-2013-2423", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "d413e8b4-38b0-484e-84fb-e177e943e604", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote... | Affected: Oracle / Java SE | CVSS: 3.7 (LOW) | EPSS: 0.85215 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2423", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2423"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2423"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote...", "cve_id": "CVE-2013-2423", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 3.7, "epss_score": 0.85215, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9971, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2423", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3c303cee-db35-4bf0-ab20-94e2d5c5e463", "vulnerability": {"vulnId": "CVE-2014-2817", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "3c303cee-db35-4bf0-ab20-94e2d5c5e463", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.26349 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-2817", "url": "https://www.cve.org/CVERecord?id=CVE-2014-2817"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-2817"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of...", "cve_id": "CVE-2014-2817", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.26349, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97947, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-2817", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e5de5573-96b7-47a3-a20a-69fe943bc94c", "vulnerability": {"vulnId": "CVE-2010-0840", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "e5de5573-96b7-47a3-a20a-69fe943bc94c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.96319 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-0840", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0840"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0840"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and...", "cve_id": "CVE-2010-0840", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96319, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99879, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-0840", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "854ea15a-4fdf-4184-8f82-570e36c5d2f2", "vulnerability": {"vulnId": "CVE-2010-1428", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "854ea15a-4fdf-4184-8f82-570e36c5d2f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and... | Affected: Red Hat / JBoss Enterprise Application Platform | CVSS: 5.9 (MEDIUM) | EPSS: 0.62052 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-1428", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1428"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-1428"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and...", "cve_id": "CVE-2010-1428", "vendor": "Red Hat", "ghsa_id": null, "product": "JBoss Enterprise Application Platform", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.62052, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99156, "used_in_malware": "yes", "vulnerability_id": "CVE-2010-1428", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d42ef40-38c2-4ede-9058-690174f00bd1", "vulnerability": {"vulnId": "CVE-2013-0422", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "9d42ef40-38c2-4ede-9058-690174f00bd1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public... | Affected: Oracle / Java | CVSS: 9.8 (CRITICAL) | EPSS: 0.97024 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0422", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0422"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0422"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public...", "cve_id": "CVE-2013-0422", "vendor": "Oracle", "ghsa_id": null, "product": "Java", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97024, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9989, "used_in_malware": "yes", "vulnerability_id": "CVE-2013-0422", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b64a62f-5ce1-4aa3-800a-12d75b82fbc9", "vulnerability": {"vulnId": "CVE-2014-4077", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "9b64a62f-5ce1-4aa3-800a-12d75b82fbc9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.54577 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-4077", "url": "https://www.cve.org/CVERecord?id=CVE-2014-4077"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-4077"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka...", "cve_id": "CVE-2014-4077", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.54577, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-4077", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "711871e0-0fca-4094-80a4-fa2eee730521", "vulnerability": {"vulnId": "CVE-2015-1769", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "711871e0-0fca-4094-80a4-fa2eee730521", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold... | Affected: Microsoft / Windows | CVSS: 6.6 (MEDIUM) | EPSS: 0.04078 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1769", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1769"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1769"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold...", "cve_id": "CVE-2015-1769", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.04078, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90382, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1769", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "64ad38ff-cea1-4bbf-a35a-3cc4003ac0b5", "vulnerability": {"vulnId": "CVE-2015-0016", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "64ad38ff-cea1-4bbf-a35a-3cc4003ac0b5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.75777 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-0016", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0016"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-0016"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2...", "cve_id": "CVE-2015-0016", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.75777, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9951, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-0016", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cbf56416-8eb7-4245-b998-1e097731667e", "vulnerability": {"vulnId": "CVE-2014-4148", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "cbf56416-8eb7-4245-b998-1e097731667e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.5985 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-4148", "url": "https://www.cve.org/CVERecord?id=CVE-2014-4148"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-4148"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...", "cve_id": "CVE-2014-4148", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.5985, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99107, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-4148", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9dc5db90-56e8-4739-ac4e-5bc4015d2fc5", "vulnerability": {"vulnId": "CVE-2016-7256", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "9dc5db90-56e8-4739-ac4e-5bc4015d2fc5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.64591 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7256", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7256"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7256"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows...", "cve_id": "CVE-2016-7256", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.64591, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99218, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7256", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "123e1d3c-a5a0-49c7-afb0-f5deb40187e9", "vulnerability": {"vulnId": "CVE-2016-0034", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "123e1d3c-a5a0-49c7-afb0-f5deb40187e9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or... | Affected: Microsoft / Silverlight | CVSS: 8.8 (HIGH) | EPSS: 0.69397 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0034", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0034"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0034"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or...", "cve_id": "CVE-2016-0034", "vendor": "Microsoft", "ghsa_id": null, "product": "Silverlight", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.69397, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99342, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-0034", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d9a20cb5-3797-45fc-9f0d-aa820b5f1cf0", "vulnerability": {"vulnId": "CVE-2015-2425", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "d9a20cb5-3797-45fc-9f0d-aa820b5f1cf0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.44727 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2425", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2425"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2425"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web...", "cve_id": "CVE-2015-2425", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.44727, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98734, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2425", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2954170a-ca25-4a1d-9742-016a5eeba521", "vulnerability": {"vulnId": "CVE-2015-8651", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "2954170a-ca25-4a1d-9742-016a5eeba521", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.67698 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-8651", "url": "https://www.cve.org/CVERecord?id=CVE-2015-8651"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-8651"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,...", "cve_id": "CVE-2015-8651", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.67698, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99297, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-8651", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "46d52d0e-c8e6-4907-91df-8648631754d7", "vulnerability": {"vulnId": "CVE-2013-7331", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "46d52d0e-c8e6-4907-91df-8648631754d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames,... | Affected: Microsoft / Windows | CVSS: 6.5 (MEDIUM) | EPSS: 0.5021 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-7331", "url": "https://www.cve.org/CVERecord?id=CVE-2013-7331"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-7331"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames,...", "cve_id": "CVE-2013-7331", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.5021, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98874, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-7331", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06a37d63-2419-4d70-96f3-7df914adc648", "vulnerability": {"vulnId": "CVE-2010-0738", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "06a37d63-2419-4d70-96f3-7df914adc648", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3... | Affected: Red Hat / JBoss Enterprise Application Platform | CVSS: 3.7 (LOW) | EPSS: 0.79415 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-0738", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0738"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0738"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3...", "cve_id": "CVE-2010-0738", "vendor": "Red Hat", "ghsa_id": null, "product": "JBoss Enterprise Application Platform", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 3.7, "epss_score": 0.79415, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99593, "used_in_malware": "yes", "vulnerability_id": "CVE-2010-0738", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20424bda-3edf-48af-ae54-526abafdd5aa", "vulnerability": {"vulnId": "CVE-2014-4123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "20424bda-3edf-48af-ae54-526abafdd5aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.47133 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-4123", "url": "https://www.cve.org/CVERecord?id=CVE-2014-4123"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-4123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka \"Internet Explorer Elevation of...", "cve_id": "CVE-2014-4123", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.47133, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-4123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9d8d5c09-4535-4824-9a83-5e9dbdbf645d", "vulnerability": {"vulnId": "CVE-2013-3896", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "9d8d5c09-4535-4824-9a83-5e9dbdbf645d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers... | Affected: Microsoft / Silverlight | CVSS: 5.5 (MEDIUM) | EPSS: 0.67959 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3896", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3896"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3896"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers...", "cve_id": "CVE-2013-3896", "vendor": "Microsoft", "ghsa_id": null, "product": "Silverlight", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.67959, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99303, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3896", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dd479ac3-c91d-4c3e-9257-6c91e55f5fd5", "vulnerability": {"vulnId": "CVE-2013-0074", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "dd479ac3-c91d-4c3e-9257-6c91e55f5fd5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows... | Affected: Microsoft / Silverlight | CVSS: 7.8 (HIGH) | EPSS: 0.78885 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0074", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0074"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0074"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows...", "cve_id": "CVE-2013-0074", "vendor": "Microsoft", "ghsa_id": null, "product": "Silverlight", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.78885, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99584, "used_in_malware": "yes", "vulnerability_id": "CVE-2013-0074", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bb26d9a5-7fd7-4877-a855-c6b199057a29", "vulnerability": {"vulnId": "CVE-2014-3153", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "bb26d9a5-7fd7-4877-a855-c6b199057a29", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses,... | Affected: Linux / Linux Kernel | CVSS: 7.8 (HIGH) | EPSS: 0.37233 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-3153", "url": "https://www.cve.org/CVERecord?id=CVE-2014-3153"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-3153"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses,...", "cve_id": "CVE-2014-3153", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.37233, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98481, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-3153", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "294564a2-4bad-4f7f-bae8-638059fbd4d8", "vulnerability": {"vulnId": "CVE-2014-8439", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "294564a2-4bad-4f7f-bae8-638059fbd4d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.20369 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-8439", "url": "https://www.cve.org/CVERecord?id=CVE-2014-8439"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-8439"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before...", "cve_id": "CVE-2014-8439", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.20369, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97415, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-8439", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b26a75a4-2226-428c-90a1-ef5db5a78088", "vulnerability": {"vulnId": "CVE-2013-0431", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "b26a75a4-2226-428c-90a1-ef5db5a78088", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows... | Affected: Oracle / Java SE | CVSS: 3.7 (LOW) | EPSS: 0.90237 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0431", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0431"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0431"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows...", "cve_id": "CVE-2013-0431", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 3.7, "epss_score": 0.90237, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99796, "used_in_malware": "yes", "vulnerability_id": "CVE-2013-0431", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e7ceb56a-4814-4e97-9f6d-37bd02af92c5", "vulnerability": {"vulnId": "CVE-2015-0071", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "e7ceb56a-4814-4e97-9f6d-37bd02af92c5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka \"Internet... | Affected: Microsoft / Internet Explorer | CVSS: 6.5 (MEDIUM) | EPSS: 0.33581 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-0071", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0071"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-0071"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka \"Internet...", "cve_id": "CVE-2015-0071", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.33581, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98338, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-0071", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "86461229-b82d-4934-bcc3-6e9226a05425", "vulnerability": {"vulnId": "CVE-2014-0546", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "86461229-b82d-4934-bcc3-6e9226a05425", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and... | Affected: Adobe / Reader and Acrobat | CVSS: 9.8 (CRITICAL) | EPSS: 0.2233 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0546", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0546"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0546"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and...", "cve_id": "CVE-2014-0546", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.2233, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97622, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0546", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8191e087-8789-4c19-af7c-fbe78dc9d166", "vulnerability": {"vulnId": "CVE-2015-0310", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "8191e087-8789-4c19-af7c-fbe78dc9d166", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly... | Affected: Adobe / Flash Player | CVSS: 7.8 (HIGH) | EPSS: 0.15097 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-0310", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0310"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-0310"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly...", "cve_id": "CVE-2015-0310", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.15097, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96636, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-0310", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7d1a7aab-7b4e-4b77-b180-fec2936645a5", "vulnerability": {"vulnId": "CVE-2019-3010", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "7d1a7aab-7b4e-4b77-b180-fec2936645a5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily... | Affected: Oracle / Solaris Operating System | CVSS: 8.8 (HIGH) | EPSS: 0.13399 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-3010", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3010"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3010"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily...", "cve_id": "CVE-2019-3010", "vendor": "Oracle", "ghsa_id": null, "product": "Solaris Operating System", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.13399, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9631, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-3010", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac1f61c1-3278-49d5-9069-32829656328e", "vulnerability": {"vulnId": "CVE-2016-0984", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "ac1f61c1-3278-49d5-9069-32829656328e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.54544 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0984", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0984"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0984"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before...", "cve_id": "CVE-2016-0984", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.54544, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0984", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "52b80418-62c4-4e31-b0e2-2774e78a104e", "vulnerability": {"vulnId": "CVE-2013-3993", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "52b80418-62c4-4e31-b0e2-2774e78a104e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted... | Affected: IBM / InfoSphere BigInsights | CVSS: 6.5 (MEDIUM) | EPSS: 0.04766 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3993", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3993"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3993"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted...", "cve_id": "CVE-2013-3993", "vendor": "IBM", "ghsa_id": null, "product": "InfoSphere BigInsights", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.04766, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91622, "used_in_malware": "yes", "vulnerability_id": "CVE-2013-3993", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "057dbeb2-aa79-4b37-804c-072a85569f32", "vulnerability": {"vulnId": "CVE-2015-6175", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "057dbeb2-aa79-4b37-804c-072a85569f32", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka \"Windows Kernel Memory Elevation of... | Affected: Microsoft / Windows 10 | CVSS: 7.8 (HIGH) | EPSS: 0.05127 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-6175", "url": "https://www.cve.org/CVERecord?id=CVE-2015-6175"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-6175"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka \"Windows Kernel Memory Elevation of...", "cve_id": "CVE-2015-6175", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05127, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92129, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-6175", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c2259c09-e76f-4332-a60c-c44d03d83027", "vulnerability": {"vulnId": "CVE-2012-1710", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "c2259c09-e76f-4332-a60c-c44d03d83027", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to... | Affected: Oracle / Fusion Middleware | CVSS: 9.8 (CRITICAL) | EPSS: 0.07826 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1710", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1710"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1710"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to...", "cve_id": "CVE-2012-1710", "vendor": "Oracle", "ghsa_id": null, "product": "Fusion Middleware", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07826, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94497, "used_in_malware": "yes", "vulnerability_id": "CVE-2012-1710", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72822d48-cb95-4674-8f01-c1c6e8145b3a", "vulnerability": {"vulnId": "CVE-2015-1671", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "72822d48-cb95-4674-8f01-c1c6e8145b3a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2;... | Affected: Microsoft / Windows DirectWrite | CVSS: 7.8 (HIGH) | EPSS: 0.48986 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1671", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1671"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1671"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2;...", "cve_id": "CVE-2015-1671", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows DirectWrite", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.48986, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98847, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1671", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20f68033-b2df-4a4e-a738-d25cb3f7fd10", "vulnerability": {"vulnId": "CVE-2016-3393", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "20f68033-b2df-4a4e-a738-d25cb3f7fd10", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.68465 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3393", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3393"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3393"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...", "cve_id": "CVE-2016-3393", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.68465, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99317, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3393", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e6d0240-6e7b-4ba0-9867-1b1413da0025", "vulnerability": {"vulnId": "CVE-2015-4495", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "8e6d0240-6e7b-4ba0-9867-1b1413da0025", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the... | Affected: Mozilla / Firefox | CVSS: 8.8 (HIGH) | EPSS: 0.68558 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-4495", "url": "https://www.cve.org/CVERecord?id=CVE-2015-4495"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-4495"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the...", "cve_id": "CVE-2015-4495", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.68558, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-4495", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5d0e16c7-94bb-4847-a30a-72bb9aac3cf3", "vulnerability": {"vulnId": "CVE-2016-1010", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-25T02:00:00+02:00"}, "gcve": {"object_uuid": "5d0e16c7-94bb-4847-a30a-72bb9aac3cf3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-25T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.19333 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-1010", "url": "https://www.cve.org/CVERecord?id=CVE-2016-1010"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-1010"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on...", "cve_id": "CVE-2016-1010", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-05-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.19333, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97269, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-1010", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c39261c9-3b68-466a-8ca5-d62a84dafd84", "vulnerability": {"vulnId": "CVE-2018-19949", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "c39261c9-3b68-466a-8ca5-d62a84dafd84", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the... | Affected: QNAP / QTS | CVSS: 9.8 (CRITICAL) | EPSS: 0.28421 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19949", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19949"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19949"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the...", "cve_id": "CVE-2018-19949", "vendor": "QNAP", "ghsa_id": null, "product": "QTS", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.28421, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98073, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19949", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "857bc986-0ca7-4880-9fea-9bbb73255da9", "vulnerability": {"vulnId": "CVE-2017-0210", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "857bc986-0ca7-4880-9fea-9bbb73255da9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.22334 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0210", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0210"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0210"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an...", "cve_id": "CVE-2017-0210", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.22334, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97623, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0210", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bab49324-da46-432f-9492-be072e223954", "vulnerability": {"vulnId": "CVE-2017-8291", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "bab49324-da46-432f-9492-be072e223954", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a \"/OutputFile... | Affected: Artifex / Ghostscript | CVSS: 7.8 (HIGH) | EPSS: 0.96968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-8291", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8291"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8291"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a \"/OutputFile...", "cve_id": "CVE-2017-8291", "vendor": "Artifex", "ghsa_id": null, "product": "Ghostscript", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.96968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8291", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e9469a84-d3ca-4674-8c5d-e6ca3135fd1f", "vulnerability": {"vulnId": "CVE-2017-0022", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "e9469a84-d3ca-4674-8c5d-e6ca3135fd1f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2... | Affected: Microsoft / XML Core Services | CVSS: 6.5 (MEDIUM) | EPSS: 0.18069 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0022", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0022"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0022"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2...", "cve_id": "CVE-2017-0022", "vendor": "Microsoft", "ghsa_id": null, "product": "XML Core Services", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.18069, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97111, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0022", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d891d537-7a63-4c05-a6ce-14bcfa6c0ec7", "vulnerability": {"vulnId": "CVE-2017-18362", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "d891d537-7a63-4c05-a6ce-14bcfa6c0ec7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to... | Affected: ConnectWise / ManagedITSync integration for Kaseya VSA | CVSS: 9.8 (CRITICAL) | EPSS: 0.8682 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-18362", "url": "https://www.cve.org/CVERecord?id=CVE-2017-18362"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-18362"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to...", "cve_id": "CVE-2017-18362", "vendor": "ConnectWise", "ghsa_id": null, "product": "ManagedITSync integration for Kaseya VSA", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.8682, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9974, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-18362", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e43de5cb-4287-4d39-a309-d68b82fedcae", "vulnerability": {"vulnId": "CVE-2016-0162", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "e43de5cb-4287-4d39-a309-d68b82fedcae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka \"Internet... | Affected: Microsoft / Internet Explorer | CVSS: 4.3 (MEDIUM) | EPSS: 0.22012 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0162", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0162"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0162"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka \"Internet...", "cve_id": "CVE-2016-0162", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.22012, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97596, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0162", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9abb71ea-f31f-4a7e-8541-b5e6bde7ba89", "vulnerability": {"vulnId": "CVE-2016-3351", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "9abb71ea-f31f-4a7e-8541-b5e6bde7ba89", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka... | Affected: Microsoft / Internet Explorer, Edge | CVSS: 6.5 (MEDIUM) | EPSS: 0.26286 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3351", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3351"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3351"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka...", "cve_id": "CVE-2016-3351", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer, Edge", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.26286, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97944, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-3351", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eca17e59-1a26-426b-bfcb-f963650d7570", "vulnerability": {"vulnId": "CVE-2016-4656", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "eca17e59-1a26-426b-bfcb-f963650d7570", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory... | Affected: Apple / iOS | CVSS: 7.8 (HIGH) | EPSS: 0.23626 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4656", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4656"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4656"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory...", "cve_id": "CVE-2016-4656", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.23626, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97744, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4656", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e555d905-96e8-4471-a284-59ede00de397", "vulnerability": {"vulnId": "CVE-2018-8611", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "e555d905-96e8-4471-a284-59ede00de397", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka \"Windows Kernel Elevation of... | Affected: Microsoft / Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | CVSS: 7.8 (HIGH) | EPSS: 0.04196 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8611", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8611"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8611"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka \"Windows Kernel Elevation of...", "cve_id": "CVE-2018-8611", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04196, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90635, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8611", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "948fe3c6-70e4-44d5-8d87-a2e754a3f63b", "vulnerability": {"vulnId": "CVE-2018-19953", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "948fe3c6-70e4-44d5-8d87-a2e754a3f63b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in... | Affected: QNAP / QTS | CVSS: 6.1 (MEDIUM) | EPSS: 0.28771 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19953", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19953"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19953"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in...", "cve_id": "CVE-2018-19953", "vendor": "QNAP", "ghsa_id": null, "product": "QTS", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.28771, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98095, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19953", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b9cccbf6-8884-4d58-9b05-18206c451024", "vulnerability": {"vulnId": "CVE-2018-19943", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "b9cccbf6-8884-4d58-9b05-18206c451024", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in... | Affected: QNAP / QTS | CVSS: 8.0 (HIGH) | EPSS: 0.21476 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-19943", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19943"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19943"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in...", "cve_id": "CVE-2018-19943", "vendor": "QNAP", "ghsa_id": null, "product": "QTS", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.21476, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97547, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-19943", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "62de747d-43dc-4304-8202-629afdf7f527", "vulnerability": {"vulnId": "CVE-2016-4657", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "62de747d-43dc-4304-8202-629afdf7f527", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted... | Affected: Apple / iOS | CVSS: 8.8 (HIGH) | EPSS: 0.66788 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4657", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4657"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4657"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted...", "cve_id": "CVE-2016-4657", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.66788, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99271, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4657", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d9432f3d-1c8f-4a3a-8558-5ea8b1eeb901", "vulnerability": {"vulnId": "CVE-2017-0149", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "d9432f3d-1c8f-4a3a-8558-5ea8b1eeb901", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.29178 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0149", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0149"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0149"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...", "cve_id": "CVE-2017-0149", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.29178, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9812, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0149", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aa6c3f9c-72e9-4ee4-8ba4-5b892da08c53", "vulnerability": {"vulnId": "CVE-2017-0147", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "aa6c3f9c-72e9-4ee4-8ba4-5b892da08c53", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... | Affected: Microsoft / Windows SMB | CVSS: 7.5 (HIGH) | EPSS: 0.99693 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0147", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0147"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0147"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...", "cve_id": "CVE-2017-0147", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows SMB", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99693, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9995, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0147", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eb75650f-b3c1-46ac-a531-fddd1764baae", "vulnerability": {"vulnId": "CVE-2016-4655", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "eb75650f-b3c1-46ac-a531-fddd1764baae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app. | Affected: Apple / iOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.33353 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4655", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4655"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4655"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.", "cve_id": "CVE-2016-4655", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.33353, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98328, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4655", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b9ca5e56-31cd-42bd-a96d-831329c4724b", "vulnerability": {"vulnId": "CVE-2016-6366", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "b9ca5e56-31cd-42bd-a96d-831329c4724b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv,... | Affected: Cisco / Adaptive Security Appliance (ASA) Software | CVSS: 8.8 (HIGH) | EPSS: 0.87565 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-6366", "url": "https://www.cve.org/CVERecord?id=CVE-2016-6366"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-6366"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv,...", "cve_id": "CVE-2016-6366", "vendor": "Cisco", "ghsa_id": null, "product": "Adaptive Security Appliance (ASA) Software", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.87565, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99756, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-6366", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c4c3a59a-c5d8-4ef8-b5d7-0cfc3441fa2a", "vulnerability": {"vulnId": "CVE-2017-8543", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "c4c3a59a-c5d8-4ef8-b5d7-0cfc3441fa2a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8,... | Affected: Microsoft / Microsoft Windows | CVSS: 9.8 (CRITICAL) | EPSS: 0.74164 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-8543", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8543"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8543"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8,...", "cve_id": "CVE-2017-8543", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Windows", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74164, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99474, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8543", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0462e263-1e35-4a5c-a240-44312176250d", "vulnerability": {"vulnId": "CVE-2016-6367", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "0462e263-1e35-4a5c-a240-44312176250d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges... | Affected: Cisco / Adaptive Security Appliance (ASA) Software | CVSS: 7.8 (HIGH) | EPSS: 0.22583 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-6367", "url": "https://www.cve.org/CVERecord?id=CVE-2016-6367"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-6367"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges...", "cve_id": "CVE-2016-6367", "vendor": "Cisco", "ghsa_id": null, "product": "Adaptive Security Appliance (ASA) Software", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.22583, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97652, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-6367", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "92d5b229-58f7-4b88-996c-76e4a320e1a6", "vulnerability": {"vulnId": "CVE-2016-3298", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "92d5b229-58f7-4b88-996c-76e4a320e1a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1... | Affected: Microsoft / Internet Explorer | CVSS: 6.5 (MEDIUM) | EPSS: 0.33332 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3298", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3298"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3298"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1...", "cve_id": "CVE-2016-3298", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.33332, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98326, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3298", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0894061-0c32-42bb-8166-00cc1ce42bf6", "vulnerability": {"vulnId": "CVE-2017-0005", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-24T02:00:00+02:00"}, "gcve": {"object_uuid": "b0894061-0c32-42bb-8166-00cc1ce42bf6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-24T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-24T00:00:00+00:00"}, "scope": {"notes": "The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... | Affected: Microsoft / Windows GDI | CVSS: 7.8 (HIGH) | EPSS: 0.11022 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0005", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0005"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0005"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server...", "cve_id": "CVE-2017-0005", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows GDI", "added_date": "2022-05-24T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.11022, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95782, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0005", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c326f3f-4b37-4953-9e72-6b408d68a38a", "vulnerability": {"vulnId": "CVE-2019-8720", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "4c326f3f-4b37-4953-9e72-6b408d68a38a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code... | Affected: Apple / webkitgtk | CVSS: 8.8 (HIGH) | EPSS: 0.01556 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-8720", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8720"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8720"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code...", "cve_id": "CVE-2019-8720", "vendor": "Apple", "ghsa_id": null, "product": "webkitgtk", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.01556, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74263, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8720", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5ea98c4b-338e-445a-8746-b1b2b218fe07", "vulnerability": {"vulnId": "CVE-2019-0676", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "5ea98c4b-338e-445a-8746-b1b2b218fe07", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited... | Affected: Microsoft / Internet Explorer 11, Internet Explorer 10 | CVSS: 6.5 (MEDIUM) | EPSS: 0.0811 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0676", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0676"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0676"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited...", "cve_id": "CVE-2019-0676", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 11, Internet Explorer 10", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.0811, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9466, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0676", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a2ac05a5-85ce-4cca-828d-ae47f1545833", "vulnerability": {"vulnId": "CVE-2019-5786", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "a2ac05a5-85ce-4cca-828d-ae47f1545833", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access... | Affected: Google / Chrome | CVSS: 6.5 (MEDIUM) | EPSS: 0.61085 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-5786", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5786"}, {"id": "GHSA-C2GP-86P4-5935", "url": "https://github.com/advisories/GHSA-C2GP-86P4-5935"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5786"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access...", "cve_id": "CVE-2019-5786", "vendor": "Google", "ghsa_id": "GHSA-C2GP-86P4-5935", "product": "Chrome", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.61085, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99135, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5786", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "08feb941-075b-43f5-be78-0e1d95978a97", "vulnerability": {"vulnId": "CVE-2022-20821", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "08feb941-075b-43f5-be78-0e1d95978a97", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS XR Software Health Check Open Port Vulnerability | Affected: Cisco / Cisco IOS XR Software | CVSS: 6.5 (MEDIUM) | EPSS: 0.11471 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20821", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20821"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20821"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS XR Software Health Check Open Port Vulnerability", "cve_id": "CVE-2022-20821", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XR Software", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.11471, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95893, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20821", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b5105eb1-d4b8-431d-8e58-bc4945f9d8f2", "vulnerability": {"vulnId": "CVE-2020-0638", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "b5105eb1-d4b8-431d-8e58-bc4945f9d8f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker... | Affected: Microsoft / Windows, Windows 10 Version 1903 for ARM64-based Systems, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows Server, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1909 for ARM64-based Systems | CVSS: 7.8 (HIGH) | EPSS: 0.02351 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0638", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0638"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0638"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker...", "cve_id": "CVE-2020-0638", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows 10 Version 1903 for ARM64-based Systems, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows Server, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1909 for ARM64-based Systems", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02351, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83074, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-0638", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f9b9d09-a876-419e-835d-eeac152f45e8", "vulnerability": {"vulnId": "CVE-2019-0703", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "5f9b9d09-a876-419e-835d-eeac152f45e8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information... | Affected: Microsoft / Windows, Windows Server | CVSS: 6.5 (MEDIUM) | EPSS: 0.0964 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0703", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0703"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0703"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information...", "cve_id": "CVE-2019-0703", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.0964, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95348, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0703", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "670d8999-b4a1-4e13-be0a-9a705cb6be37", "vulnerability": {"vulnId": "CVE-2019-0880", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "670d8999-b4a1-4e13-be0a-9a705cb6be37", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege... | Affected: Microsoft / Windows Server, Windows, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.02289 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0880", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0880"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0880"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege...", "cve_id": "CVE-2019-0880", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server, Windows, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02289, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82585, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0880", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b23504f-be60-4a8e-bf03-8e873183ebc8", "vulnerability": {"vulnId": "CVE-2019-13720", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "8b23504f-be60-4a8e-bf03-8e873183ebc8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.4914 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-13720", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13720"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13720"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted...", "cve_id": "CVE-2019-13720", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.4914, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98851, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-13720", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "643392b4-103b-45d6-b327-188c4ffa29d5", "vulnerability": {"vulnId": "CVE-2019-11708", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "643392b4-103b-45d6-b327-188c4ffa29d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed... | Affected: Mozilla / Firefox ESR, Firefox, Thunderbird | CVSS: 10.0 (CRITICAL) | EPSS: 0.55874 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11708", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11708"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11708"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed...", "cve_id": "CVE-2019-11708", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox ESR, Firefox, Thunderbird", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.55874, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99017, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-11708", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3d55027a-4b96-4e3c-afe9-621acfa92eee", "vulnerability": {"vulnId": "CVE-2019-1385", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "3d55027a-4b96-4e3c-afe9-621acfa92eee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.03604 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1385", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1385"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1385"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in...", "cve_id": "CVE-2019-1385", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03604, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.891, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1385", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9f5c0c9b-acff-49d6-9f85-39894c154c91", "vulnerability": {"vulnId": "CVE-2019-1130", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "9f5c0c9b-acff-49d6-9f85-39894c154c91", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation... | Affected: Microsoft / Windows Server, Windows, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01705 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1130", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1130"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1130"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...", "cve_id": "CVE-2019-1130", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server, Windows, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01705, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76441, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1130", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6eb47fa2-b2a9-4526-8c5b-256888164f2a", "vulnerability": {"vulnId": "CVE-2018-5002", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "6eb47fa2-b2a9-4526-8c5b-256888164f2a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to... | Affected: Adobe / Adobe Flash Player 29.0.0.171 and earlier versions | CVSS: 7.8 (HIGH) | EPSS: 0.25059 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-5002", "url": "https://www.cve.org/CVERecord?id=CVE-2018-5002"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-5002"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to...", "cve_id": "CVE-2018-5002", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Flash Player 29.0.0.171 and earlier versions", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.25059, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97862, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-5002", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a20fadfb-c7a5-4ceb-b91f-f13be2067a05", "vulnerability": {"vulnId": "CVE-2020-1027", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "a20fadfb-c7a5-4ceb-b91f-f13be2067a05", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.04547 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1027", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1027"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1027"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of...", "cve_id": "CVE-2020-1027", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04547, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91285, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1027", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f2eb7dd-61d0-4e66-b0c6-1566f92412c1", "vulnerability": {"vulnId": "CVE-2019-7287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "6f2eb7dd-61d0-4e66-b0c6-1566f92412c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute... | Affected: Apple / iOS | CVSS: 7.8 (HIGH) | EPSS: 0.04579 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7287", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute...", "cve_id": "CVE-2019-7287", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04579, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91336, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e56e8242-3b15-456c-9814-d19b8d791e57", "vulnerability": {"vulnId": "CVE-2021-0920", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "e56e8242-3b15-456c-9814-d19b8d791e57", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege... | Affected: Google / Android | CVSS: 6.4 (MEDIUM) | EPSS: 0.0082 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-0920", "url": "https://www.cve.org/CVERecord?id=CVE-2021-0920"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-0920"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege...", "cve_id": "CVE-2021-0920", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 6.4, "epss_score": 0.0082, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55688, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-0920", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8069a5c0-3d84-4942-a83e-b6ad474cde99", "vulnerability": {"vulnId": "CVE-2021-30883", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "8069a5c0-3d84-4942-a83e-b6ad474cde99", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1,... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.14721 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30883", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30883"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30883"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1,...", "cve_id": "CVE-2021-30883", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.14721, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96575, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30883", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9a746836-0d7b-4ee4-9b45-bdfb5c2b81d4", "vulnerability": {"vulnId": "CVE-2019-11707", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "9a746836-0d7b-4ee4-9b45-bdfb5c2b81d4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash.... | Affected: Mozilla / Firefox ESR, Firefox, Thunderbird | CVSS: 8.8 (HIGH) | EPSS: 0.37696 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11707", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11707"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11707"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash....", "cve_id": "CVE-2019-11707", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox ESR, Firefox, Thunderbird", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.37696, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98498, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-11707", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb540fbe-b072-4044-ace3-7ecdaa7c944f", "vulnerability": {"vulnId": "CVE-2019-18426", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "fb540fbe-b072-4044-ace3-7ecdaa7c944f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site... | Affected: Facebook / WhatsApp Desktop | CVSS: 8.2 (HIGH) | EPSS: 0.67859 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-18426", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18426"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18426"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site...", "cve_id": "CVE-2019-18426", "vendor": "Facebook", "ghsa_id": null, "product": "WhatsApp Desktop", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.67859, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99301, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18426", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "648a713e-a2ce-4f0e-855a-16e76d98db73", "vulnerability": {"vulnId": "CVE-2018-8589", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "648a713e-a2ce-4f0e-855a-16e76d98db73", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka \"Windows Win32k Elevation of Privilege... | Affected: Microsoft / Windows Server 2008, Windows 7, Windows Server 2008 R2 | CVSS: 7.8 (HIGH) | EPSS: 0.03023 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8589", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8589"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8589"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka \"Windows Win32k Elevation of Privilege...", "cve_id": "CVE-2018-8589", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2008, Windows 7, Windows Server 2008 R2", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03023, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8699, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8589", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "66111bfb-8329-491c-942d-06c4f6be1277", "vulnerability": {"vulnId": "CVE-2021-1048", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "66111bfb-8329-491c-942d-06c4f6be1277", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.01 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1048", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1048"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1048"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of...", "cve_id": "CVE-2021-1048", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.61462, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1048", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5c3e819b-350d-4588-8d9a-6fc92ad59fe9", "vulnerability": {"vulnId": "CVE-2019-7286", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-23T02:00:00+02:00"}, "gcve": {"object_uuid": "5c3e819b-350d-4588-8d9a-6fc92ad59fe9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-23T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-23T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental... | Affected: Apple / iOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.15939 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7286", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7286"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7286"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental...", "cve_id": "CVE-2019-7286", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS", "added_date": "2022-05-23T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.15939, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96799, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7286", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c74e9538-4726-45d1-8694-1e45405e898d", "vulnerability": {"vulnId": "CVE-2022-22947", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-16T02:00:00+02:00"}, "gcve": {"object_uuid": "c74e9538-4726-45d1-8694-1e45405e898d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-16T00:00:00+00:00"}, "scope": {"notes": "In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator... | Affected: VMware / Spring Cloud Gateway | CVSS: 10.0 (CRITICAL) | EPSS: 0.98253 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22947", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22947"}, {"id": "GHSA-3GX9-37WW-9QW6", "url": "https://github.com/advisories/GHSA-3GX9-37WW-9QW6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22947"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator...", "cve_id": "CVE-2022-22947", "vendor": "VMware", "ghsa_id": "GHSA-3GX9-37WW-9QW6", "product": "Spring Cloud Gateway", "added_date": "2022-05-16T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.98253, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99914, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22947", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "300a55c2-7ffe-4646-8718-6d72eb139eec", "vulnerability": {"vulnId": "CVE-2022-30525", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-16T02:00:00+02:00"}, "gcve": {"object_uuid": "300a55c2-7ffe-4646-8718-6d72eb139eec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-16T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-16T00:00:00+00:00"}, "scope": {"notes": "A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware... | Affected: Zyxel / USG FLEX 100(W) firmware, USG FLEX 200 firmware, USG FLEX 500 firmware, USG FLEX 700 firmware, ATP series firmware, VPN series firmware, USG FLEX 50(W) firmware, USG 20(W)-VPN firmware | CVSS: 9.8 (CRITICAL) | EPSS: 0.99944 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-30525", "url": "https://www.cve.org/CVERecord?id=CVE-2022-30525"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-30525"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware...", "cve_id": "CVE-2022-30525", "vendor": "Zyxel", "ghsa_id": null, "product": "USG FLEX 100(W) firmware, USG FLEX 200 firmware, USG FLEX 500 firmware, USG FLEX 700 firmware, ATP series firmware, VPN series firmware, USG FLEX 50(W) firmware, USG 20(W)-VPN firmware", "added_date": "2022-05-16T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99944, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99973, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-30525", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "520dcfcd-67ad-41a7-ab0d-fe0448f87997", "vulnerability": {"vulnId": "CVE-2022-28912", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-10T15:17:02+02:00"}, "gcve": {"object_uuid": "520dcfcd-67ad-41a7-ab0d-fe0448f87997", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-10T13:17:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-10T13:17:02+00:00"}, "scope": {"notes": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW. | Affected: TOTOLink / N600R | CVSS: 9.8 (CRITICAL) | EPSS: 0.02541 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28912", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28912"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28912"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.", "cve_id": "CVE-2022-28912", "vendor": "TOTOLink", "ghsa_id": null, "product": "N600R", "added_date": "2022-05-10T13:17:02.000Z", "cvss_score": 9.8, "epss_score": 0.02541, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28912", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d866d7b1-55ff-4513-90c0-284a7cde4f86", "vulnerability": {"vulnId": "CVE-2022-28907", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-10T15:16:59+02:00"}, "gcve": {"object_uuid": "d866d7b1-55ff-4513-90c0-284a7cde4f86", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-10T13:16:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-10T13:16:59+00:00"}, "scope": {"notes": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost. | Affected: TOTOLink / N600R | CVSS: 9.8 (CRITICAL) | EPSS: 0.02541 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28907", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28907"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28907"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.", "cve_id": "CVE-2022-28907", "vendor": "TOTOLink", "ghsa_id": null, "product": "N600R", "added_date": "2022-05-10T13:16:59.000Z", "cvss_score": 9.8, "epss_score": 0.02541, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84415, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28907", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e245c9d3-67aa-4710-960f-253555e84dac", "vulnerability": {"vulnId": "CVE-2022-28908", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-10T15:16:59+02:00"}, "gcve": {"object_uuid": "e245c9d3-67aa-4710-960f-253555e84dac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-10T13:16:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-10T13:16:59+00:00"}, "scope": {"notes": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in... | Affected: TOTOLink / N600R | CVSS: 9.8 (CRITICAL) | EPSS: 0.02541 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28908", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28908"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28908"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in...", "cve_id": "CVE-2022-28908", "vendor": "TOTOLink", "ghsa_id": null, "product": "N600R", "added_date": "2022-05-10T13:16:59.000Z", "cvss_score": 9.8, "epss_score": 0.02541, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28908", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e6d9d7d1-1b9f-4cf6-8fb8-d6b5ba55fbde", "vulnerability": {"vulnId": "CVE-2022-28906", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-10T15:16:58+02:00"}, "gcve": {"object_uuid": "e6d9d7d1-1b9f-4cf6-8fb8-d6b5ba55fbde", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-10T13:16:58+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-10T13:16:58+00:00"}, "scope": {"notes": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg. | Affected: TOTOLink / N600R | CVSS: 9.8 (CRITICAL) | EPSS: 0.02849 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28906", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28906"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28906"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.", "cve_id": "CVE-2022-28906", "vendor": "TOTOLink", "ghsa_id": null, "product": "N600R", "added_date": "2022-05-10T13:16:58.000Z", "cvss_score": 9.8, "epss_score": 0.02849, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86216, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28906", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bde9d72c-8f46-44fe-84a4-7ec948e7a9b0", "vulnerability": {"vulnId": "CVE-2022-1388", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-10T02:00:00+02:00"}, "gcve": {"object_uuid": "bde9d72c-8f46-44fe-84a4-7ec948e7a9b0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-10T00:00:00+00:00"}, "scope": {"notes": "On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to... | Affected: F5 / BIG-IP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99954 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-1388", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1388"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1388"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to...", "cve_id": "CVE-2022-1388", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2022-05-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99954, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99974, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-1388", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "242aa9f4-a681-4902-843b-53ef25420186", "vulnerability": {"vulnId": "CVE-2022-28079", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-05T17:31:57+02:00"}, "gcve": {"object_uuid": "242aa9f4-a681-4902-843b-53ef25420186", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-05T15:31:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-05T15:31:57+00:00"}, "scope": {"notes": "College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. | Affected: College Management System / College Management System v1.0 | CVSS: 8.8 (HIGH) | EPSS: 0.28512 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28079", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28079"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28079"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.", "cve_id": "CVE-2022-28079", "vendor": "College Management System", "ghsa_id": null, "product": "College Management System v1.0", "added_date": "2022-05-05T15:31:57.000Z", "cvss_score": 8.8, "epss_score": 0.28512, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98078, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28079", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0138bcef-e618-419a-96c3-c5fc15dc02eb", "vulnerability": {"vulnId": "CVE-2021-43163", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-04T02:08:24+02:00"}, "gcve": {"object_uuid": "0138bcef-e618-419a-96c3-c5fc15dc02eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-04T00:08:24+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-04T00:08:24+00:00"}, "scope": {"notes": "A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the... | Affected: Ruijie / Ruijie RG-EW Series Routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.02135 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-43163", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43163"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43163"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the...", "cve_id": "CVE-2021-43163", "vendor": "Ruijie", "ghsa_id": null, "product": "Ruijie RG-EW Series Routers", "added_date": "2022-05-04T00:08:24.000Z", "cvss_score": 9.8, "epss_score": 0.02135, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81335, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-43163", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "74d11c78-4c25-48e4-81e9-8c7551372ee6", "vulnerability": {"vulnId": "CVE-2021-1789", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-04T02:00:00+02:00"}, "gcve": {"object_uuid": "74d11c78-4c25-48e4-81e9-8c7551372ee6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-04T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina,... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.13975 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1789", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1789"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1789"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina,...", "cve_id": "CVE-2021-1789", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2022-05-04T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.13975, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9644, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1789", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c0479338-9436-425b-857c-124d6a344eb1", "vulnerability": {"vulnId": "CVE-2014-0160", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-04T02:00:00+02:00"}, "gcve": {"object_uuid": "c0479338-9436-425b-857c-124d6a344eb1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-04T00:00:00+00:00"}, "scope": {"notes": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote... | Affected: OpenSSL / OpenSSL | CVSS: 7.5 (HIGH) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0160", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0160"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0160"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote...", "cve_id": "CVE-2014-0160", "vendor": "OpenSSL", "ghsa_id": null, "product": "OpenSSL", "added_date": "2022-05-04T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99997, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0160", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9adf43ae-5cde-4bd0-9f75-927750718913", "vulnerability": {"vulnId": "CVE-2019-8506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-04T02:00:00+02:00"}, "gcve": {"object_uuid": "9adf43ae-5cde-4bd0-9f75-927750718913", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-04T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes... | Affected: Apple / iOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows | CVSS: 8.8 (HIGH) | EPSS: 0.16159 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-8506", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes...", "cve_id": "CVE-2019-8506", "vendor": "Apple", "ghsa_id": null, "product": "iOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows", "added_date": "2022-05-04T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.16159, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96839, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e429319e-7970-4c6f-9821-a78aba76cc58", "vulnerability": {"vulnId": "CVE-2014-4113", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-04T02:00:00+02:00"}, "gcve": {"object_uuid": "e429319e-7970-4c6f-9821-a78aba76cc58", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-04T00:00:00+00:00"}, "scope": {"notes": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.86928 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-4113", "url": "https://www.cve.org/CVERecord?id=CVE-2014-4113"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-4113"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...", "cve_id": "CVE-2014-4113", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-05-04T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.86928, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99743, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-4113", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c393c61a-c091-461f-b807-eebb651f4982", "vulnerability": {"vulnId": "CVE-2014-0322", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-05-04T02:00:00+02:00"}, "gcve": {"object_uuid": "c393c61a-c091-461f-b807-eebb651f4982", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-05-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-05-04T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.85122 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0322", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0322"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0322"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving...", "cve_id": "CVE-2014-0322", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-05-04T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.85122, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99709, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0322", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0ab263d2-11fd-4195-a7da-2d6315ddd1ff", "vulnerability": {"vulnId": "CVE-2021-46442", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-27T12:10:37+02:00"}, "gcve": {"object_uuid": "0ab263d2-11fd-4195-a7da-2d6315ddd1ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-27T10:10:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-27T10:10:37+00:00"}, "scope": {"notes": "In the \"webupg\" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters \"autoupgrade.asp\", and perform functions such... | Affected: D-Link / DIR-825 G1 | CVSS: 9.8 (CRITICAL) | EPSS: 0.5606 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-46442", "url": "https://www.cve.org/CVERecord?id=CVE-2021-46442"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-46442"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In the \"webupg\" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters \"autoupgrade.asp\", and perform functions such...", "cve_id": "CVE-2021-46442", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-825 G1", "added_date": "2022-04-27T10:10:37.000Z", "cvss_score": 9.8, "epss_score": 0.5606, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99021, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-46442", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "78bb5d7c-0d7d-4e36-b8a0-1b50903af3ac", "vulnerability": {"vulnId": "CVE-2022-28290", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T18:31:01+02:00"}, "gcve": {"object_uuid": "78bb5d7c-0d7d-4e36-b8a0-1b50903af3ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T16:31:01+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T16:31:01+00:00"}, "scope": {"notes": "Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries... | Affected: Welaunch / Country Selector Plugin | CVSS: 6.1 (MEDIUM) | EPSS: 0.01399 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28290", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28290"}, {"id": "GHSA-WMQQ-3WJJ-MG5P", "url": "https://github.com/advisories/GHSA-WMQQ-3WJJ-MG5P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28290"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries...", "cve_id": "CVE-2022-28290", "vendor": "Welaunch", "ghsa_id": "GHSA-WMQQ-3WJJ-MG5P", "product": "Country Selector Plugin", "added_date": "2022-04-25T16:31:01.000Z", "cvss_score": 6.1, "epss_score": 0.01399, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71476, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28290", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f63d5f4e-0013-45c3-9c5d-ceae3f2857dc", "vulnerability": {"vulnId": "CVE-2022-0847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "f63d5f4e-0013-45c3-9c5d-ceae3f2857dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "A flaw was found in the way the \"flags\" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and... | Affected: Linux / kernel | CVSS: 7.8 (HIGH) | EPSS: 0.92795 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0847", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A flaw was found in the way the \"flags\" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and...", "cve_id": "CVE-2022-0847", "vendor": "Linux", "ghsa_id": null, "product": "kernel", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.92795, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99828, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0847", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1365cfa9-30b2-44fa-a2b0-ab5ea7d7e5ec", "vulnerability": {"vulnId": "CVE-2019-1003029", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "1365cfa9-30b2-44fa-a2b0-ab5ea7d7e5ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in... | Affected: Jenkins project / Jenkins Script Security Plugin | CVSS: 9.9 (CRITICAL) | EPSS: 0.7444 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1003029", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1003029"}, {"id": "GHSA-XVXQ-HQ48-XPHM", "url": "https://github.com/advisories/GHSA-XVXQ-HQ48-XPHM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1003029"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in...", "cve_id": "CVE-2019-1003029", "vendor": "Jenkins project", "ghsa_id": "GHSA-XVXQ-HQ48-XPHM", "product": "Jenkins Script Security Plugin", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.7444, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99481, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1003029", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a732b548-e594-4910-b084-0de866fffe92", "vulnerability": {"vulnId": "CVE-2021-40450", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "a732b548-e594-4910-b084-0de866fffe92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2 | CVSS: 7.8 (HIGH) | EPSS: 0.01582 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40450", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40450"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40450"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-40450", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01582, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74643, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40450", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "96114196-5d31-48ec-8e5a-d653d68517a4", "vulnerability": {"vulnId": "CVE-2021-41357", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "96114196-5d31-48ec-8e5a-d653d68517a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2 | CVSS: 7.8 (HIGH) | EPSS: 0.01582 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-41357", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41357"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41357"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-41357", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01582, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74643, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-41357", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d86f5487-d0bb-46a9-bac8-878ef3441cd4", "vulnerability": {"vulnId": "CVE-2022-21919", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "d86f5487-d0bb-46a9-bac8-878ef3441cd4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "Windows User Profile Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.02434 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-21919", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21919"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21919"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows User Profile Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-21919", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.02434, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21919", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4ee799bb-a15b-42c8-a763-28a2ad11bcf3", "vulnerability": {"vulnId": "CVE-2022-26904", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "4ee799bb-a15b-42c8-a763-28a2ad11bcf3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "Windows User Profile Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.16948 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26904", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26904"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26904"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows User Profile Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-26904", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.16948, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96975, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26904", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a9b39b83-6791-4a6d-af63-dcb29aaf1f28", "vulnerability": {"vulnId": "CVE-2022-29464", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-25T02:00:00+02:00"}, "gcve": {"object_uuid": "a9b39b83-6791-4a6d-af63-dcb29aaf1f28", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-25T00:00:00+00:00"}, "scope": {"notes": "Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a... | Affected: WSO2 / WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Open Banking AM, WSO2 Open Banking KM | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-29464", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29464"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29464"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a...", "cve_id": "CVE-2022-29464", "vendor": "WSO2", "ghsa_id": null, "product": "WSO2 API Manager, WSO2 Identity Server, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Open Banking AM, WSO2 Open Banking KM", "added_date": "2022-04-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99992, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-29464", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9c26e2ec-c15c-4643-b9dc-c27cdaa51eff", "vulnerability": {"vulnId": "CVE-2022-1439", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-22T18:30:14+02:00"}, "gcve": {"object_uuid": "9c26e2ec-c15c-4643-b9dc-c27cdaa51eff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-22T16:30:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-22T16:30:14+00:00"}, "scope": {"notes": "Reflected XSS on demo.microweber.org/demo/module/ in microweber/microweber | Affected: Microweber / microweber/microweber | CVSS: 6.3 (MEDIUM) | EPSS: 0.03258 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-1439", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1439"}, {"id": "GHSA-9W7H-3WWH-6M5Q", "url": "https://github.com/advisories/GHSA-9W7H-3WWH-6M5Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1439"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Reflected XSS on demo.microweber.org/demo/module/ in microweber/microweber", "cve_id": "CVE-2022-1439", "vendor": "Microweber", "ghsa_id": "GHSA-9W7H-3WWH-6M5Q", "product": "microweber/microweber", "added_date": "2022-04-22T16:30:14.000Z", "cvss_score": 6.3, "epss_score": 0.03258, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87955, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1439", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3fbe7adb-1451-4422-81c8-63b96940d6b2", "vulnerability": {"vulnId": "CVE-2018-6882", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-19T02:00:00+02:00"}, "gcve": {"object_uuid": "3fbe7adb-1451-4422-81c8-63b96940d6b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-19T00:00:00+00:00"}, "scope": {"notes": "Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1... | Affected: Zimbra / Collaboration Suite | CVSS: 6.1 (MEDIUM) | EPSS: 0.29761 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-6882", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6882"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-6882"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1...", "cve_id": "CVE-2018-6882", "vendor": "Zimbra", "ghsa_id": null, "product": "Collaboration Suite", "added_date": "2022-04-19T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.29761, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98148, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-6882", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "78301547-703d-49fa-a0a9-248a03ce448e", "vulnerability": {"vulnId": "CVE-2022-22718", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-19T02:00:00+02:00"}, "gcve": {"object_uuid": "78301547-703d-49fa-a0a9-248a03ce448e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-19T00:00:00+00:00"}, "scope": {"notes": "Windows Print Spooler Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.18464 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22718", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22718"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22718"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Print Spooler Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-22718", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-04-19T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.18464, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97162, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22718", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ebaa4ca5-1364-4776-8ab5-fc6a10bbe074", "vulnerability": {"vulnId": "CVE-2019-3568", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-19T02:00:00+02:00"}, "gcve": {"object_uuid": "ebaa4ca5-1364-4776-8ab5-fc6a10bbe074", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-19T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target... | Affected: Facebook / WhatsApp for Android, WhatsApp Business for Android, WhatsApp for iOS, WhatsApp Business for iOS, WhatsApp for Windows Phone, WhatsApp for Tizen | CVSS: 9.8 (CRITICAL) | EPSS: 0.30076 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-3568", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3568"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3568"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target...", "cve_id": "CVE-2019-3568", "vendor": "Facebook", "ghsa_id": null, "product": "WhatsApp for Android, WhatsApp Business for Android, WhatsApp for iOS, WhatsApp Business for iOS, WhatsApp for Windows Phone, WhatsApp for Tizen", "added_date": "2022-04-19T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.30076, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98164, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-3568", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f1129d4-47c6-4799-8ba8-e9fd3000ef0d", "vulnerability": {"vulnId": "CVE-2022-29153", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-19T02:00:00+02:00"}, "gcve": {"object_uuid": "2f1129d4-47c6-4799-8ba8-e9fd3000ef0d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-19T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-19T00:00:00+00:00"}, "scope": {"notes": "HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows... | Affected: Hashi / Consul | CVSS: 7.5 (HIGH) | EPSS: 0.08676 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-29153", "url": "https://www.cve.org/CVERecord?id=CVE-2022-29153"}, {"id": "GHSA-Q6H7-4QGW-2J9P", "url": "https://github.com/advisories/GHSA-Q6H7-4QGW-2J9P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-29153"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows...", "cve_id": "CVE-2022-29153", "vendor": "Hashi", "ghsa_id": "GHSA-Q6H7-4QGW-2J9P", "product": "Consul", "added_date": "2022-04-19T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.08676, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94971, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-29153", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c4514147-0865-4968-8873-23a8bacc309f", "vulnerability": {"vulnId": "CVE-2019-3929", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "c4514147-0865-4968-8873-23a8bacc309f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W... | Affected: Crestron / Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4. | CVSS: 9.8 (CRITICAL) | EPSS: 0.98952 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-3929", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3929"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3929"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W...", "cve_id": "CVE-2019-3929", "vendor": "Crestron", "ghsa_id": null, "product": "Crestron AirMedia, Barco WePresent, Extron ShareLink, Teq AV IT WIPS710, SHARP PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow3, and InFocus LiteShow4.", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98952, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99929, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-3929", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "14593fe0-2d43-4dec-8728-ae369ca34a01", "vulnerability": {"vulnId": "CVE-2018-7841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "14593fe0-2d43-4dec-8728-ae369ca34a01", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper... | Affected: U.motion / U.motion Builder software version 1.3.4 | CVSS: 9.8 (CRITICAL) | EPSS: 0.72675 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-7841", "url": "https://www.cve.org/CVERecord?id=CVE-2018-7841"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-7841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper...", "cve_id": "CVE-2018-7841", "vendor": "U.motion", "ghsa_id": null, "product": "U.motion Builder software version 1.3.4", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.72675, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99431, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-7841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "67028b1f-aae1-4f20-aa78-0ceaf98a35be", "vulnerability": {"vulnId": "CVE-2014-0780", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "67028b1f-aae1-4f20-aa78-0ceaf98a35be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "InduSoft Web Studio Path Traversal | Affected: InduSoft / Web Studio | CVSS: 9.8 (CRITICAL) | EPSS: 0.74679 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0780", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0780"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0780"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "InduSoft Web Studio Path Traversal", "cve_id": "CVE-2014-0780", "vendor": "InduSoft", "ghsa_id": null, "product": "Web Studio", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74679, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0780", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "899a9d79-d310-47a8-a743-14242419aae9", "vulnerability": {"vulnId": "CVE-2007-3010", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "899a9d79-d310-47a8-a743-14242419aae9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute... | Affected: Alcatel / OmniPCX Enterprise Communication Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.97385 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2007-3010", "url": "https://www.cve.org/CVERecord?id=CVE-2007-3010"}, {"id": "previdian", "url": "https://previdian.com/CVE-2007-3010"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute...", "cve_id": "CVE-2007-3010", "vendor": "Alcatel", "ghsa_id": null, "product": "OmniPCX Enterprise Communication Server", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97385, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99898, "used_in_malware": "unknown", "vulnerability_id": "CVE-2007-3010", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5882026-f563-4d85-9724-af329da70f3c", "vulnerability": {"vulnId": "CVE-2022-1364", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "a5882026-f563-4d85-9724-af329da70f3c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.1372 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-1364", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1364"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1364"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2022-1364", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.1372, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96393, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1364", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1bf1c663-70ec-44de-abce-0e01c62dd974", "vulnerability": {"vulnId": "CVE-2022-22960", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "1bf1c663-70ec-44de-abce-0e01c62dd974", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in... | Affected: VMware / VMware Workspace ONE Access, Identity Manager and vRealize Automation | CVSS: 7.8 (HIGH) | EPSS: 0.35519 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22960", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22960"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22960"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in...", "cve_id": "CVE-2022-22960", "vendor": "VMware", "ghsa_id": null, "product": "VMware Workspace ONE Access, Identity Manager and vRealize Automation", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.35519, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9841, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22960", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5b95fa06-083f-44a8-bda6-a8deedd0fb31", "vulnerability": {"vulnId": "CVE-2016-4523", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "5b95fa06-083f-44a8-bda6-a8deedd0fb31", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service... | Affected: Trihedral / VTScada | CVSS: 7.5 (HIGH) | EPSS: 0.31167 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4523", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4523"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4523"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service...", "cve_id": "CVE-2016-4523", "vendor": "Trihedral", "ghsa_id": null, "product": "VTScada", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.31167, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98222, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4523", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f274fe9f-4223-42ca-a4ed-dffb4886fa56", "vulnerability": {"vulnId": "CVE-2019-16057", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "f274fe9f-4223-42ca-a4ed-dffb4886fa56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. | Affected: D-Link / DNS-320 | CVSS: 9.8 (CRITICAL) | EPSS: 0.86491 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-16057", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16057"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16057"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.", "cve_id": "CVE-2019-16057", "vendor": "D-Link", "ghsa_id": null, "product": "DNS-320", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86491, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99733, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-16057", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "514aaa22-eb5c-4148-ad13-36824ea6a2d7", "vulnerability": {"vulnId": "CVE-2010-5330", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-15T02:00:00+02:00"}, "gcve": {"object_uuid": "514aaa22-eb5c-4148-ad13-36824ea6a2d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-15T00:00:00+00:00"}, "scope": {"notes": "On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not... | Affected: Ubiquiti / AirOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.39362 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-5330", "url": "https://www.cve.org/CVERecord?id=CVE-2010-5330"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-5330"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not...", "cve_id": "CVE-2010-5330", "vendor": "Ubiquiti", "ghsa_id": null, "product": "AirOS", "added_date": "2022-04-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39362, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98564, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-5330", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b8b857d0-d443-496b-8157-4f840346c732", "vulnerability": {"vulnId": "CVE-2022-22954", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-14T02:00:00+02:00"}, "gcve": {"object_uuid": "b8b857d0-d443-496b-8157-4f840346c732", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-14T00:00:00+00:00"}, "scope": {"notes": "VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious... | Affected: VMware / VMware Workspace ONE Access and Identity Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.99998 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22954", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22954"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22954"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious...", "cve_id": "CVE-2022-22954", "vendor": "VMware", "ghsa_id": null, "product": "VMware Workspace ONE Access and Identity Manager", "added_date": "2022-04-14T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99989, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-22954", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cd2c1681-3c87-48fc-930c-8eb4ea17bf1c", "vulnerability": {"vulnId": "CVE-2014-9163", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "cd2c1681-3c87-48fc-930c-8eb4ea17bf1c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425... | Affected: Adobe / Flash Player | CVSS: 7.8 (HIGH) | EPSS: 0.20724 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-9163", "url": "https://www.cve.org/CVERecord?id=CVE-2014-9163"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-9163"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425...", "cve_id": "CVE-2014-9163", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.20724, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97468, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-9163", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "03ed6219-606b-4039-a459-001fa1214bbf", "vulnerability": {"vulnId": "CVE-2015-0313", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "03ed6219-606b-4039-a459-001fa1214bbf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.95266 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-0313", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0313"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-0313"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before...", "cve_id": "CVE-2015-0313", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95266, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99865, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-0313", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e47264be-5640-42d5-9ab2-428900c455ae", "vulnerability": {"vulnId": "CVE-2015-5123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "e47264be-5640-42d5-9ab2-428900c455ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.1883 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-5123", "url": "https://www.cve.org/CVERecord?id=CVE-2015-5123"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-5123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...", "cve_id": "CVE-2015-5123", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.1883, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97204, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-5123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d9b678c1-1f47-4d07-8ae4-ac3cac396a19", "vulnerability": {"vulnId": "CVE-2018-20753", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "d9b678c1-1f47-4d07-8ae4-ac3cac396a19", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell... | Affected: Kaseya / VSA RMM | CVSS: 9.8 (CRITICAL) | EPSS: 0.29336 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-20753", "url": "https://www.cve.org/CVERecord?id=CVE-2018-20753"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-20753"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell...", "cve_id": "CVE-2018-20753", "vendor": "Kaseya", "ghsa_id": null, "product": "VSA RMM", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.29336, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98127, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-20753", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d68bd3e-6c8e-4043-954c-762862bf9f47", "vulnerability": {"vulnId": "CVE-2015-2502", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "6d68bd3e-6c8e-4043-954c-762862bf9f47", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.51001 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2502", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2502"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2502"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...", "cve_id": "CVE-2015-2502", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.51001, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98898, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2502", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0b81a6a-73aa-4e52-8460-e006703bb69b", "vulnerability": {"vulnId": "CVE-2018-7602", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "f0b81a6a-73aa-4e52-8460-e006703bb69b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004 | Affected: Drupal / core | CVSS: 8.1 (HIGH) | EPSS: 0.99205 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-7602", "url": "https://www.cve.org/CVERecord?id=CVE-2018-7602"}, {"id": "GHSA-297X-J9PM-XJGG", "url": "https://github.com/advisories/GHSA-297X-J9PM-XJGG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-7602"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004", "cve_id": "CVE-2018-7602", "vendor": "Drupal", "ghsa_id": "GHSA-297X-J9PM-XJGG", "product": "core", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.99205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99934, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-7602", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "df06f0a6-c505-4105-b65c-c301010a12b4", "vulnerability": {"vulnId": "CVE-2015-3113", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "df06f0a6-c505-4105-b65c-c301010a12b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.99944 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-3113", "url": "https://www.cve.org/CVERecord?id=CVE-2015-3113"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-3113"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before...", "cve_id": "CVE-2015-3113", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99944, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99972, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-3113", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eaed209d-c55b-4bf3-910a-b1f2fe85cbd0", "vulnerability": {"vulnId": "CVE-2015-0311", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "eaed209d-c55b-4bf3-910a-b1f2fe85cbd0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.85589 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-0311", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0311"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-0311"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through...", "cve_id": "CVE-2015-0311", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.85589, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99718, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-0311", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1cd6491c-7f0a-4b2c-a6fa-c925cbb6c8f2", "vulnerability": {"vulnId": "CVE-2022-24521", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "1cd6491c-7f0a-4b2c-a6fa-c925cbb6c8f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.07076 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24521", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24521"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24521"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-24521", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07076, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94025, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-24521", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "187b2379-b34a-4470-83dc-64bf86998c98", "vulnerability": {"vulnId": "CVE-2015-5122", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-13T02:00:00+02:00"}, "gcve": {"object_uuid": "187b2379-b34a-4470-83dc-64bf86998c98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-13T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-13T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.93978 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-5122", "url": "https://www.cve.org/CVERecord?id=CVE-2015-5122"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-5122"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...", "cve_id": "CVE-2015-5122", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-04-13T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93978, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-5122", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c20ee3fa-fff0-4f8e-903a-ebf27439a4de", "vulnerability": {"vulnId": "CVE-2022-0142", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-12T13:15:23+02:00"}, "gcve": {"object_uuid": "c20ee3fa-fff0-4f8e-903a-ebf27439a4de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-12T11:15:23+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-12T11:15:23+00:00"}, "scope": {"notes": "Visual Form Builder < 3.0.6 - CSV Injection | Affected: Visual Form Builder / Visual Form Builder | CVSS: 9.8 (CRITICAL) | EPSS: 0.02872 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0142", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0142"}, {"id": "GHSA-G4V7-HFRX-HQF3", "url": "https://github.com/advisories/GHSA-G4V7-HFRX-HQF3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0142"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Visual Form Builder < 3.0.6 - CSV Injection", "cve_id": "CVE-2022-0142", "vendor": "Visual Form Builder", "ghsa_id": "GHSA-G4V7-HFRX-HQF3", "product": "Visual Form Builder", "added_date": "2022-04-12T11:15:23.000Z", "cvss_score": 9.8, "epss_score": 0.02872, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86321, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0142", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "88dbac2d-0b6a-463f-a068-89326b516d38", "vulnerability": {"vulnId": "CVE-2020-2509", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "88dbac2d-0b6a-463f-a068-89326b516d38", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "Command Injection Vulnerability in QTS and QuTS hero | Affected: QNAP / QTS, QuTS hero | CVSS: 9.8 (CRITICAL) | EPSS: 0.33987 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-2509", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2509"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2509"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection Vulnerability in QTS and QuTS hero", "cve_id": "CVE-2020-2509", "vendor": "QNAP", "ghsa_id": null, "product": "QTS, QuTS hero", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.33987, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98353, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-2509", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "77da63f4-58f4-463f-89fb-2385d72f8f5e", "vulnerability": {"vulnId": "CVE-2021-22600", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "77da63f4-58f4-463f-89fb-2385d72f8f5e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "Double Free in net/packet/af_packet.c leading to priviledge escalation | Affected: Linux Kernel / Kernel | CVSS: 6.6 (MEDIUM) | EPSS: 0.06586 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22600", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22600"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22600"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Double Free in net/packet/af_packet.c leading to priviledge escalation", "cve_id": "CVE-2021-22600", "vendor": "Linux Kernel", "ghsa_id": null, "product": "Kernel", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.06586, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93633, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22600", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f35a75bd-afe9-492f-9758-95e77251ceeb", "vulnerability": {"vulnId": "CVE-2022-23176", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "f35a75bd-afe9-492f-9758-95e77251ceeb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management... | Affected: WatchGuard / Firebox and XTM appliances | CVSS: 8.8 (HIGH) | EPSS: 0.10805 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-23176", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23176"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23176"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management...", "cve_id": "CVE-2022-23176", "vendor": "WatchGuard", "ghsa_id": null, "product": "Firebox and XTM appliances", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10805, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95718, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23176", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cc6d1289-d9de-47fb-b90c-d6a67215f8aa", "vulnerability": {"vulnId": "CVE-2021-27852", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "cc6d1289-d9de-47fb-b90c-d6a67215f8aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute... | Affected: Checkbox / Survey | CVSS: 9.8 (CRITICAL) | EPSS: 0.30258 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27852", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27852"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27852"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute...", "cve_id": "CVE-2021-27852", "vendor": "Checkbox", "ghsa_id": null, "product": "Survey", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.30258, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98174, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27852", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f2f1152-7990-419c-8552-9998c35d021c", "vulnerability": {"vulnId": "CVE-2017-11317", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "5f2f1152-7990-419c-8552-9998c35d021c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows... | Affected: Progress Software / Telerik UI for ASP.NET AJAX | CVSS: 9.8 (CRITICAL) | EPSS: 0.84175 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-11317", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11317"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11317"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows...", "cve_id": "CVE-2017-11317", "vendor": "Progress Software", "ghsa_id": null, "product": "Telerik UI for ASP.NET AJAX", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84175, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99689, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-11317", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dfe29cf1-fc1f-44b8-8d13-90a52084737f", "vulnerability": {"vulnId": "CVE-2021-42278", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "dfe29cf1-fc1f-44b8-8d13-90a52084737f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "Active Directory Domain Services Elevation of Privilege Vulnerability | Affected: Microsoft / Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.5 (HIGH) | EPSS: 0.73297 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42278", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42278"}, {"id": "GHSA-CHP6-C7F5-H9W9", "url": "https://github.com/advisories/GHSA-CHP6-C7F5-H9W9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42278"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Active Directory Domain Services Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-42278", "vendor": "Microsoft", "ghsa_id": "GHSA-CHP6-C7F5-H9W9", "product": "Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.73297, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99448, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-42278", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a7fdcc9f-5aa8-4247-a1bd-c109d0918c1a", "vulnerability": {"vulnId": "CVE-2021-42287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "a7fdcc9f-5aa8-4247-a1bd-c109d0918c1a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "Active Directory Domain Services Elevation of Privilege Vulnerability | Affected: Microsoft / Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.5 (HIGH) | EPSS: 0.7717 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42287", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42287"}, {"id": "GHSA-737R-5J68-97HH", "url": "https://github.com/advisories/GHSA-737R-5J68-97HH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Active Directory Domain Services Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-42287", "vendor": "Microsoft", "ghsa_id": "GHSA-737R-5J68-97HH", "product": "Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.7717, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9954, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-42287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "339686b0-7a78-480d-ae75-dbd02185f2ec", "vulnerability": {"vulnId": "CVE-2021-39793", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-11T02:00:00+02:00"}, "gcve": {"object_uuid": "339686b0-7a78-480d-ae75-dbd02185f2ec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-11T00:00:00+00:00"}, "scope": {"notes": "In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.00685 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-39793", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39793"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39793"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to...", "cve_id": "CVE-2021-39793", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2022-04-11T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00685, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.50845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39793", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "93522bf1-b38a-495a-ab4d-75c8c8801bfe", "vulnerability": {"vulnId": "CVE-2022-28363", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-09T18:26:45+02:00"}, "gcve": {"object_uuid": "93522bf1-b38a-495a-ab4d-75c8c8801bfe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-09T16:26:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-09T16:26:45+00:00"}, "scope": {"notes": "Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter... | Affected: Reprise / Reprise License Manager | CVSS: 6.1 (MEDIUM) | EPSS: 0.04901 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28363", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28363"}, {"id": "GHSA-RPVC-QGRM-R54F", "url": "https://github.com/advisories/GHSA-RPVC-QGRM-R54F"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28363"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter...", "cve_id": "CVE-2022-28363", "vendor": "Reprise", "ghsa_id": "GHSA-RPVC-QGRM-R54F", "product": "Reprise License Manager", "added_date": "2022-04-09T16:26:45.000Z", "cvss_score": 6.1, "epss_score": 0.04901, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91819, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28363", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c7d7871c-d57a-40df-8f61-e99ca52dc102", "vulnerability": {"vulnId": "CVE-2022-28365", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-09T02:00:00+02:00"}, "gcve": {"object_uuid": "c7d7871c-d57a-40df-8f61-e99ca52dc102", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-09T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-09T00:00:00+00:00"}, "scope": {"notes": "Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is... | Affected: Reprise / Reprise License Manager | CVSS: 5.3 (MEDIUM) | EPSS: 0.09322 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28365", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28365"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28365"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is...", "cve_id": "CVE-2022-28365", "vendor": "Reprise", "ghsa_id": null, "product": "Reprise License Manager", "added_date": "2022-04-09T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.09322, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95236, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28365", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b8c46853-1bff-4e8d-92c7-70f19d83b6e4", "vulnerability": {"vulnId": "CVE-2021-46417", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-07T12:55:09+02:00"}, "gcve": {"object_uuid": "b8c46853-1bff-4e8d-92c7-70f19d83b6e4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-07T10:55:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-07T10:55:09+00:00"}, "scope": {"notes": "Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling... | Affected: Franklin Fueling Systems / Colibri Controller Module | CVSS: 7.5 (HIGH) | EPSS: 0.59753 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-46417", "url": "https://www.cve.org/CVERecord?id=CVE-2021-46417"}, {"id": "GHSA-WCQR-93W9-8G64", "url": "https://github.com/advisories/GHSA-WCQR-93W9-8G64"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-46417"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling...", "cve_id": "CVE-2021-46417", "vendor": "Franklin Fueling Systems", "ghsa_id": "GHSA-WCQR-93W9-8G64", "product": "Colibri Controller Module", "added_date": "2022-04-07T10:55:09.000Z", "cvss_score": 7.5, "epss_score": 0.59753, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99104, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-46417", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cf60e4d5-29b4-4d78-a7b8-ecd56b87b1f1", "vulnerability": {"vulnId": "CVE-2022-23900", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-07T12:19:14+02:00"}, "gcve": {"object_uuid": "cf60e4d5-29b4-4d78-a7b8-ecd56b87b1f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-07T10:19:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-07T10:19:14+00:00"}, "scope": {"notes": "A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve... | Affected: Wavlink / WL-WN531P3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.03521 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-23900", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23900"}, {"id": "GHSA-5JM7-X4MP-X3XJ", "url": "https://github.com/advisories/GHSA-5JM7-X4MP-X3XJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23900"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve...", "cve_id": "CVE-2022-23900", "vendor": "Wavlink", "ghsa_id": "GHSA-5JM7-X4MP-X3XJ", "product": "WL-WN531P3", "added_date": "2022-04-07T10:19:14.000Z", "cvss_score": 9.8, "epss_score": 0.03521, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88843, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23900", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a585bf88-e9de-4757-8517-e230a52d88d1", "vulnerability": {"vulnId": "CVE-2017-0148", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-06T02:00:00+02:00"}, "gcve": {"object_uuid": "a585bf88-e9de-4757-8517-e230a52d88d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-06T00:00:00+00:00"}, "scope": {"notes": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... | Affected: Microsoft / Windows SMB | CVSS: 8.1 (HIGH) | EPSS: 0.99356 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0148", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0148"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0148"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...", "cve_id": "CVE-2017-0148", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows SMB", "added_date": "2022-04-06T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.99356, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99939, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0148", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "326c4c28-8981-4b07-bac3-8bb3b062f45b", "vulnerability": {"vulnId": "CVE-2021-31166", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-06T02:00:00+02:00"}, "gcve": {"object_uuid": "326c4c28-8981-4b07-bac3-8bb3b062f45b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-06T00:00:00+00:00"}, "scope": {"notes": "HTTP Protocol Stack Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99867 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31166", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31166"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31166"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HTTP Protocol Stack Remote Code Execution Vulnerability", "cve_id": "CVE-2021-31166", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2", "added_date": "2022-04-06T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99867, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99962, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31166", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0bdbf2f5-2eba-4aa7-bc71-e77b857669d7", "vulnerability": {"vulnId": "CVE-2021-3156", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-06T02:00:00+02:00"}, "gcve": {"object_uuid": "0bdbf2f5-2eba-4aa7-bc71-e77b857669d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-06T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-06T00:00:00+00:00"}, "scope": {"notes": "Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via... | Affected: Sudo Project / Sudo | CVSS: 7.8 (HIGH) | EPSS: 0.99962 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-3156", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3156"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3156"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via...", "cve_id": "CVE-2021-3156", "vendor": "Sudo Project", "ghsa_id": null, "product": "Sudo", "added_date": "2022-04-06T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.99962, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99976, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3156", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7386de54-7870-4160-8b86-9cd1621506ef", "vulnerability": {"vulnId": "CVE-2022-22675", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "7386de54-7870-4160-8b86-9cd1621506ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-04T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6,... | Affected: Apple / iOS and iPadOS, macOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.12492 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22675", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22675"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22675"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6,...", "cve_id": "CVE-2022-22675", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS, watchOS", "added_date": "2022-04-04T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.12492, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96104, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22675", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b64463a7-e388-4518-b4cf-bd5ba74dbdf8", "vulnerability": {"vulnId": "CVE-2022-22965", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "b64463a7-e388-4518-b4cf-bd5ba74dbdf8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-04T00:00:00+00:00"}, "scope": {"notes": "A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific... | Affected: VMware / Spring Framework | CVSS: 9.8 (CRITICAL) | EPSS: 0.99638 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22965", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22965"}, {"id": "GHSA-36P3-WJMG-H94X", "url": "https://github.com/advisories/GHSA-36P3-WJMG-H94X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22965"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...", "cve_id": "CVE-2022-22965", "vendor": "VMware", "ghsa_id": "GHSA-36P3-WJMG-H94X", "product": "Spring Framework", "added_date": "2022-04-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99638, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99949, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22965", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "336912bb-1a0e-41bd-b333-a945d75cc089", "vulnerability": {"vulnId": "CVE-2022-22674", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "336912bb-1a0e-41bd-b333-a945d75cc089", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-04T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is... | Affected: Apple / macOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.01133 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22674", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22674"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22674"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is...", "cve_id": "CVE-2022-22674", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2022-04-04T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.01133, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.65249, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22674", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8d8ae27c-fc43-46bd-ae5b-4909dfa34498", "vulnerability": {"vulnId": "CVE-2021-45382", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-04-04T02:00:00+02:00"}, "gcve": {"object_uuid": "8d8ae27c-fc43-46bd-ae5b-4909dfa34498", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-04-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-04-04T00:00:00+00:00"}, "scope": {"notes": "A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L... | Affected: D-link / DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, DIR-836L routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.97836 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-45382", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45382"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45382"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L...", "cve_id": "CVE-2021-45382", "vendor": "D-link", "ghsa_id": null, "product": "DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, DIR-836L routers", "added_date": "2022-04-04T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97836, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99906, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-45382", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e581dcdb-cfb6-4466-892a-ef465f3a12c0", "vulnerability": {"vulnId": "CVE-2022-1040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "e581dcdb-cfb6-4466-892a-ef465f3a12c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5... | Affected: Sophos / Sophos Firewall | CVSS: 9.8 (CRITICAL) | EPSS: 0.99796 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-1040", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5...", "cve_id": "CVE-2022-1040", "vendor": "Sophos", "ghsa_id": null, "product": "Sophos Firewall", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99796, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e030dfa0-5547-49b5-8643-70d4bf846391", "vulnerability": {"vulnId": "CVE-2022-26871", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "e030dfa0-5547-49b5-8643-70d4bf846391", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which... | Affected: Trend Micro / Trend Micro Apex Central | CVSS: 9.8 (CRITICAL) | EPSS: 0.19481 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26871", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26871"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26871"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which...", "cve_id": "CVE-2022-26871", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex Central", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.19481, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97298, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26871", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3ed4f544-7e85-4e9a-b684-fc4cf7759721", "vulnerability": {"vulnId": "CVE-2021-28799", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "3ed4f544-7e85-4e9a-b684-fc4cf7759721", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync) | Affected: QNAP / HBS 3, HBS 2, HBS 1.3 | CVSS: 10.0 (CRITICAL) | EPSS: 0.7825 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-28799", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28799"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28799"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)", "cve_id": "CVE-2021-28799", "vendor": "QNAP", "ghsa_id": null, "product": "HBS 3, HBS 2, HBS 1.3", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.7825, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99567, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-28799", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6491f447-e657-48a6-8a52-9ecb1a1b80e5", "vulnerability": {"vulnId": "CVE-2021-21551", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "6491f447-e657-48a6-8a52-9ecb1a1b80e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or... | Affected: Dell / dbutil | CVSS: 8.8 (HIGH) | EPSS: 0.79249 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21551", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21551"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21551"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or...", "cve_id": "CVE-2021-21551", "vendor": "Dell", "ghsa_id": null, "product": "dbutil", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.79249, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9959, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21551", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "22b277e9-d078-467e-a3d9-b21eb510a2d2", "vulnerability": {"vulnId": "CVE-2021-34484", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "22b277e9-d078-467e-a3d9-b21eb510a2d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "Windows User Profile Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.21827 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-34484", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34484"}, {"id": "GHSA-MP6H-CXP8-82J6", "url": "https://github.com/advisories/GHSA-MP6H-CXP8-82J6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34484"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows User Profile Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-34484", "vendor": "Microsoft", "ghsa_id": "GHSA-MP6H-CXP8-82J6", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.21827, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34484", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4e9b2282-ace7-4d67-a9d9-807c6c19fd15", "vulnerability": {"vulnId": "CVE-2018-10561", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "4e9b2282-ace7-4d67-a9d9-807c6c19fd15", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending \"?images\" to any URL of the device... | Affected: Dasan / GPON home routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.92893 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-10561", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10561"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10561"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending \"?images\" to any URL of the device...", "cve_id": "CVE-2018-10561", "vendor": "Dasan", "ghsa_id": null, "product": "GPON home routers", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.92893, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99829, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10561", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0bc0fb42-cd54-4a24-805e-c2ea57b6dc2d", "vulnerability": {"vulnId": "CVE-2018-10562", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-31T02:00:00+02:00"}, "gcve": {"object_uuid": "0bc0fb42-cd54-4a24-805e-c2ea57b6dc2d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-31T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-31T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a... | Affected: Dasan / GPON home routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.99949 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-10562", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10562"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10562"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a...", "cve_id": "CVE-2018-10562", "vendor": "Dasan", "ghsa_id": null, "product": "GPON home routers", "added_date": "2022-03-31T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99949, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99973, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-10562", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4a57fb8a-efc9-48fb-a4fc-62167d88d1a8", "vulnerability": {"vulnId": "CVE-2022-28221", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-30T08:11:19+02:00"}, "gcve": {"object_uuid": "4a57fb8a-efc9-48fb-a4fc-62167d88d1a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-30T06:11:19+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-30T06:11:19+00:00"}, "scope": {"notes": "CleanTalk AntiSpam <= 5.173 Reflected XSS | Affected: CleanTalk / CleanTalk AntiSpam | CVSS: 6.1 (MEDIUM) | EPSS: 0.02396 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-28221", "url": "https://www.cve.org/CVERecord?id=CVE-2022-28221"}, {"id": "GHSA-VRXH-FR4W-J852", "url": "https://github.com/advisories/GHSA-VRXH-FR4W-J852"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-28221"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CleanTalk AntiSpam <= 5.173 Reflected XSS", "cve_id": "CVE-2022-28221", "vendor": "CleanTalk", "ghsa_id": "GHSA-VRXH-FR4W-J852", "product": "CleanTalk AntiSpam", "added_date": "2022-03-30T06:11:19.000Z", "cvss_score": 6.1, "epss_score": 0.02396, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83401, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-28221", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8f71fa9d-3163-4dca-8612-4b5942b10609", "vulnerability": {"vulnId": "CVE-2012-5076", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "8f71fa9d-3163-4dca-8612-4b5942b10609", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.9125 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-5076", "url": "https://www.cve.org/CVERecord?id=CVE-2012-5076"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-5076"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to...", "cve_id": "CVE-2012-5076", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9125, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99808, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-5076", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "366978ed-6a4e-4ca0-bf7f-6bbb066efb9c", "vulnerability": {"vulnId": "CVE-2021-26085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "366978ed-6a4e-4ca0-bf7f-6bbb066efb9c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read... | Affected: Atlassian / Confluence Server, Confluence Data Center | CVSS: 5.3 (MEDIUM) | EPSS: 0.99937 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26085", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read...", "cve_id": "CVE-2021-26085", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Server, Confluence Data Center", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.99937, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99971, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-26085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c6bab5dc-7bbd-4b30-8e63-5fbe6c9f45d2", "vulnerability": {"vulnId": "CVE-2022-0543", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "c6bab5dc-7bbd-4b30-8e63-5fbe6c9f45d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which... | Affected: Debian / redis | CVSS: 10.0 (CRITICAL) | EPSS: 0.99351 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0543", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0543"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0543"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which...", "cve_id": "CVE-2022-0543", "vendor": "Debian", "ghsa_id": null, "product": "redis", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99351, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0543", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c3ccbda-430f-477a-9607-6e9dc913ccbc", "vulnerability": {"vulnId": "CVE-2016-0189", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "4c3ccbda-430f-477a-9607-6e9dc913ccbc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote... | Affected: Microsoft / Internet Explorer | CVSS: 7.5 (HIGH) | EPSS: 0.94062 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0189", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0189"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0189"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote...", "cve_id": "CVE-2016-0189", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.94062, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99846, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0189", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0d8d0367-4941-49c2-b225-41c2f8b7aa18", "vulnerability": {"vulnId": "CVE-2019-7483", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0d8d0367-4941-49c2-b225-41c2f8b7aa18", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of... | Affected: SonicWall / SMA100 | CVSS: 7.5 (HIGH) | EPSS: 0.0401 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7483", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7483"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7483"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of...", "cve_id": "CVE-2019-7483", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA100", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0401, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90236, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7483", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "09c97cba-03e7-4997-a29e-3eb788356e4c", "vulnerability": {"vulnId": "CVE-2015-2426", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "09c97cba-03e7-4997-a29e-3eb788356e4c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.86576 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2426", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2426"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2426"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows...", "cve_id": "CVE-2015-2426", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.86576, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99734, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2426", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d5204f6b-55b8-488d-8432-0642b4ab4daf", "vulnerability": {"vulnId": "CVE-2016-7201", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "d5204f6b-55b8-488d-8432-0642b4ab4daf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory... | Affected: Microsoft / Edge | CVSS: 8.8 (HIGH) | EPSS: 0.80004 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7201", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7201"}, {"id": "GHSA-4F5G-J7WG-7W8J", "url": "https://github.com/advisories/GHSA-4F5G-J7WG-7W8J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7201"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory...", "cve_id": "CVE-2016-7201", "vendor": "Microsoft", "ghsa_id": "GHSA-4F5G-J7WG-7W8J", "product": "Edge", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.80004, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99605, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7201", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c38c1c12-0c92-4ec0-9ac9-dd67eb88dd56", "vulnerability": {"vulnId": "CVE-2015-1770", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "c38c1c12-0c92-4ec0-9ac9-dd67eb88dd56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office... | Affected: Microsoft / Office 2013 | CVSS: 8.8 (HIGH) | EPSS: 0.34995 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1770", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1770"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1770"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka \"Microsoft Office...", "cve_id": "CVE-2015-1770", "vendor": "Microsoft", "ghsa_id": null, "product": "Office 2013", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.34995, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98392, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1770", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "713f0840-fd1d-49de-827e-001536fe1953", "vulnerability": {"vulnId": "CVE-2013-3660", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "713f0840-fd1d-49de-827e-001536fe1953", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.39318 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3660", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3660"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3660"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows...", "cve_id": "CVE-2013-3660", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.39318, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98562, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3660", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "45d25704-316c-47de-b62b-e60a05a85a34", "vulnerability": {"vulnId": "CVE-2011-2005", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "45d25704-316c-47de-b62b-e60a05a85a34", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.31534 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-2005", "url": "https://www.cve.org/CVERecord?id=CVE-2011-2005"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-2005"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed...", "cve_id": "CVE-2011-2005", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.31534, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98237, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-2005", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0f5db85e-bc10-4b4d-a0b9-ad2811f26667", "vulnerability": {"vulnId": "CVE-2017-0213", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0f5db85e-bc10-4b4d-a0b9-ad2811f26667", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,... | Affected: Microsoft / Windows COM | CVSS: 7.3 (HIGH) | EPSS: 0.84138 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0213", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0213"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0213"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,...", "cve_id": "CVE-2017-0213", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows COM", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.84138, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99688, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0213", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e7940fb7-f340-418e-b821-4c50c5c2b196", "vulnerability": {"vulnId": "CVE-2017-0037", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "e7940fb7-f340-418e-b821-4c50c5c2b196", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the... | Affected: Microsoft / Internet Browser | CVSS: 8.1 (HIGH) | EPSS: 0.80386 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0037", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0037"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0037"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the...", "cve_id": "CVE-2017-0037", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Browser", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.80386, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99612, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0037", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0bbda3a4-3e78-4d2c-acb9-bf41c64ed099", "vulnerability": {"vulnId": "CVE-2012-2034", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "0bbda3a4-3e78-4d2c-acb9-bf41c64ed099", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on... | Affected: Adobe / Flash Player | CVSS: 7.5 (HIGH) | EPSS: 0.078 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-2034", "url": "https://www.cve.org/CVERecord?id=CVE-2012-2034"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-2034"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on...", "cve_id": "CVE-2012-2034", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.078, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94485, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-2034", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ca23f621-8c26-4b0e-be48-147e662e1c57", "vulnerability": {"vulnId": "CVE-2013-2465", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "ca23f621-8c26-4b0e-be48-147e662e1c57", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.98802 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2465", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2465"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2465"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and...", "cve_id": "CVE-2013-2465", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98802, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99926, "used_in_malware": "yes", "vulnerability_id": "CVE-2013-2465", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a93ec6f3-d833-4c8a-8209-6956dc6b36f5", "vulnerability": {"vulnId": "CVE-2022-1096", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "a93ec6f3-d833-4c8a-8209-6956dc6b36f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.24205 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-1096", "url": "https://www.cve.org/CVERecord?id=CVE-2022-1096"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-1096"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2022-1096", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.24205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97789, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-1096", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "11f1cac0-a1f9-4ca9-ab23-b8861e93a6e2", "vulnerability": {"vulnId": "CVE-2016-0151", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "11f1cac0-a1f9-4ca9-ab23-b8861e93a6e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.62943 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0151", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0151"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0151"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and...", "cve_id": "CVE-2016-0151", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.62943, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99177, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-0151", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3f7905b4-0f68-40a1-9cbb-bdafd91cff71", "vulnerability": {"vulnId": "CVE-2021-38646", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "3f7905b4-0f68-40a1-9cbb-bdafd91cff71", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016, Microsoft Office 2019 | CVSS: 7.8 (HIGH) | EPSS: 0.07987 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38646", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38646"}, {"id": "GHSA-846X-H43V-68X9", "url": "https://github.com/advisories/GHSA-846X-H43V-68X9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38646"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability", "cve_id": "CVE-2021-38646", "vendor": "Microsoft", "ghsa_id": "GHSA-846X-H43V-68X9", "product": "Microsoft 365 Apps for Enterprise, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016, Microsoft Office 2019", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07987, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94587, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-38646", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bc8fe3a6-bd88-4aa3-9dd1-07c0a1e113d0", "vulnerability": {"vulnId": "CVE-2018-8440", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "bc8fe3a6-bd88-4aa3-9dd1-07c0a1e113d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka \"Windows ALPC... | Affected: Microsoft / Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | CVSS: 7.8 (HIGH) | EPSS: 0.18386 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8440", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8440"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8440"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka \"Windows ALPC...", "cve_id": "CVE-2018-8440", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.18386, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97149, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8440", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c2617850-810d-4f86-97f8-b28557684366", "vulnerability": {"vulnId": "CVE-2016-7200", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "c2617850-810d-4f86-97f8-b28557684366", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory... | Affected: Microsoft / Edge | CVSS: 8.8 (HIGH) | EPSS: 0.82779 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7200", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7200"}, {"id": "GHSA-5WHG-J5FV-XCM2", "url": "https://github.com/advisories/GHSA-5WHG-J5FV-XCM2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7200"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory...", "cve_id": "CVE-2016-7200", "vendor": "Microsoft", "ghsa_id": "GHSA-5WHG-J5FV-XCM2", "product": "Edge", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.82779, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99661, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7200", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e4af460-cac1-4ee6-9619-4fb2ed323cfc", "vulnerability": {"vulnId": "CVE-2013-2729", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "8e4af460-cac1-4ee6-9619-4fb2ed323cfc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary... | Affected: Adobe / Reader and Acrobat | CVSS: 9.8 (CRITICAL) | EPSS: 0.66555 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2729", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2729"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2729"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary...", "cve_id": "CVE-2013-2729", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.66555, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99266, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2729", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d091c8cf-03da-4d4e-b8fd-968b6131d6cd", "vulnerability": {"vulnId": "CVE-2018-8406", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "d091c8cf-03da-4d4e-b8fd-968b6131d6cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka \"DirectX... | Affected: Microsoft / Windows Server 2016, Windows 10, Windows 10 Servers | CVSS: 7.8 (HIGH) | EPSS: 0.03444 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8406", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8406"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8406"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka \"DirectX...", "cve_id": "CVE-2018-8406", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2016, Windows 10, Windows 10 Servers", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03444, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88601, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8406", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "104c0c04-070a-455f-b7b1-f178fbb6917f", "vulnerability": {"vulnId": "CVE-2016-0040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "104c0c04-070a-455f-b7b1-f178fbb6917f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.24467 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0040", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a...", "cve_id": "CVE-2016-0040", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.24467, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97812, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ae76f893-6ccf-40bc-8535-155938ca7b1d", "vulnerability": {"vulnId": "CVE-2013-1690", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "ae76f893-6ccf-40bc-8535-155938ca7b1d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly... | Affected: Mozilla / Firefox, Firefox ESR, Thunderbird, Thunderbird ESR | CVSS: 8.8 (HIGH) | EPSS: 0.69021 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-1690", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1690"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1690"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly...", "cve_id": "CVE-2013-1690", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Firefox ESR, Thunderbird, Thunderbird ESR", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.69021, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99334, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1690", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "55fcb755-97d6-4a94-8746-e417741bf39d", "vulnerability": {"vulnId": "CVE-2012-2539", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "55fcb755-97d6-4a94-8746-e417741bf39d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow... | Affected: Microsoft / Word | CVSS: 7.8 (HIGH) | EPSS: 0.53033 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-2539", "url": "https://www.cve.org/CVERecord?id=CVE-2012-2539"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-2539"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow...", "cve_id": "CVE-2012-2539", "vendor": "Microsoft", "ghsa_id": null, "product": "Word", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.53033, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98947, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-2539", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "358e85cc-73c8-4bca-8e98-872903a1a724", "vulnerability": {"vulnId": "CVE-2018-8405", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "358e85cc-73c8-4bca-8e98-872903a1a724", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka \"DirectX... | Affected: Microsoft / Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers | CVSS: 7.8 (HIGH) | EPSS: 0.03444 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8405", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8405"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8405"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka \"DirectX...", "cve_id": "CVE-2018-8405", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03444, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88601, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8405", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b2c6eb3-b09a-4338-a85c-24b89d575bdf", "vulnerability": {"vulnId": "CVE-2021-34486", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "3b2c6eb3-b09a-4338-a85c-24b89d575bdf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Windows Event Tracing Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.09253 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-34486", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34486"}, {"id": "GHSA-793M-WQ3J-WHVR", "url": "https://github.com/advisories/GHSA-793M-WQ3J-WHVR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34486"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Event Tracing Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-34486", "vendor": "Microsoft", "ghsa_id": "GHSA-793M-WQ3J-WHVR", "product": "Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09253, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95212, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34486", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1ef06302-fe67-4d17-98a4-ea7e0e11b6ad", "vulnerability": {"vulnId": "CVE-2015-2419", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "1ef06302-fe67-4d17-98a4-ea7e0e11b6ad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.53127 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2419", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2419"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2419"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory...", "cve_id": "CVE-2015-2419", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.53127, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9895, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2419", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "67829d8e-0bb7-4830-858c-17ce80614585", "vulnerability": {"vulnId": "CVE-2013-2551", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "67829d8e-0bb7-4830-858c-17ce80614585", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.74096 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2551", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2551"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2551"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site...", "cve_id": "CVE-2013-2551", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.74096, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99473, "used_in_malware": "yes", "vulnerability_id": "CVE-2013-2551", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e223265b-fa08-4744-8303-fe82a4518e19", "vulnerability": {"vulnId": "CVE-2021-20028", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "e223265b-fa08-4744-8303-fe82a4518e19", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products,... | Affected: SonicWall / SonicWall SRA/SMA100 | CVSS: 9.8 (CRITICAL) | EPSS: 0.30084 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20028", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20028"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20028"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products,...", "cve_id": "CVE-2021-20028", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicWall SRA/SMA100", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.30084, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98166, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-20028", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8d44323e-f3a1-438e-baa8-39223a837903", "vulnerability": {"vulnId": "CVE-2017-0059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "8d44323e-f3a1-438e-baa8-39223a837903", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka... | Affected: Microsoft / Internet Explorer | CVSS: 4.3 (MEDIUM) | EPSS: 0.61968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0059", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0059"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka...", "cve_id": "CVE-2017-0059", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.61968, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99154, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6b46ba2f-b136-46c6-9425-1482d3595196", "vulnerability": {"vulnId": "CVE-2012-0518", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "6b46ba2f-b136-46c6-9425-1482d3595196", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers... | Affected: Oracle / Fusion Middleware | CVSS: 4.7 (MEDIUM) | EPSS: 0.04685 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0518", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0518"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0518"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers...", "cve_id": "CVE-2012-0518", "vendor": "Oracle", "ghsa_id": null, "product": "Fusion Middleware", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 4.7, "epss_score": 0.04685, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91498, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0518", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2c0ca827-2653-4d72-b4c2-4df81bba2b7d", "vulnerability": {"vulnId": "CVE-2010-4398", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-28T02:00:00+02:00"}, "gcve": {"object_uuid": "2c0ca827-2653-4d72-b4c2-4df81bba2b7d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-28T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.08661 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-4398", "url": "https://www.cve.org/CVERecord?id=CVE-2010-4398"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-4398"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,...", "cve_id": "CVE-2010-4398", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.08661, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94964, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-4398", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "50bcb11a-1c31-487a-8374-20bab73e213d", "vulnerability": {"vulnId": "CVE-2020-2506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "50bcb11a-1c31-487a-8374-20bab73e213d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "improper access control vulnerability in Helpdesk | Affected: QNAP / Helpdesk | CVSS: 7.3 (HIGH) | EPSS: 0.01982 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-2506", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "improper access control vulnerability in Helpdesk", "cve_id": "CVE-2020-2506", "vendor": "QNAP", "ghsa_id": null, "product": "Helpdesk", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.01982, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79809, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-2506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3ab23086-93fd-4f10-85ab-8174b0b5d74b", "vulnerability": {"vulnId": "CVE-2013-5223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "3ab23086-93fd-4f10-85ab-8174b0b5d74b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web... | Affected: D-Link / DSL-2760U Gateway | CVSS: 5.4 (MEDIUM) | EPSS: 0.50833 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-5223", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5223"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web...", "cve_id": "CVE-2013-5223", "vendor": "D-Link", "ghsa_id": null, "product": "DSL-2760U Gateway", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.50833, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98893, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5223", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0d06f8c6-61ca-40c3-b115-221ce9900fe6", "vulnerability": {"vulnId": "CVE-2019-6340", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "0d06f8c6-61ca-40c3-b115-221ce9900fe6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Drupal core - Highly critical - Remote Code Execution | Affected: Drupal / Drupal Core | CVSS: 8.1 (HIGH) | EPSS: 0.92017 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-6340", "url": "https://www.cve.org/CVERecord?id=CVE-2019-6340"}, {"id": "GHSA-3GX6-H57H-RM27", "url": "https://github.com/advisories/GHSA-3GX6-H57H-RM27"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-6340"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Drupal core - Highly critical - Remote Code Execution", "cve_id": "CVE-2019-6340", "vendor": "Drupal", "ghsa_id": "GHSA-3GX6-H57H-RM27", "product": "Drupal Core", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.92017, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99819, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-6340", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5aa964d4-6dce-4307-b19a-7241ec5b3406", "vulnerability": {"vulnId": "CVE-2020-9054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "5aa964d4-6dce-4307-b19a-7241ec5b3406", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi | Affected: ZyXEL / NAS326, NAS520, NAS540, NAS542, NSA210, NSA220, NSA220+, NSA221, NSA310, NSA320, NSA320S, NSA325, NSA325v2 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99988 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9054", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi", "cve_id": "CVE-2020-9054", "vendor": "ZyXEL", "ghsa_id": null, "product": "NAS326, NAS520, NAS540, NAS542, NSA210, NSA220, NSA220+, NSA221, NSA310, NSA320, NSA320S, NSA325, NSA325v2", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99988, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99985, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "040792c4-a182-4f63-b925-3e8900bcdba2", "vulnerability": {"vulnId": "CVE-2021-22941", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "040792c4-a182-4f63-b925-3e8900bcdba2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise... | Affected: Citrix / Citrix ShareFile storage zones controller | CVSS: 9.8 (CRITICAL) | EPSS: 0.53585 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22941", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22941"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22941"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise...", "cve_id": "CVE-2021-22941", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ShareFile storage zones controller", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.53585, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98963, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-22941", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a83a4ea5-fe82-41a4-b261-3e5bb880ac46", "vulnerability": {"vulnId": "CVE-2013-2251", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "a83a4ea5-fe82-41a4-b261-3e5bb880ac46", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)... | Affected: Apache / Struts | CVSS: 9.8 (CRITICAL) | EPSS: 0.99998 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-2251", "url": "https://www.cve.org/CVERecord?id=CVE-2013-2251"}, {"id": "GHSA-47QP-8V9G-39HP", "url": "https://github.com/advisories/GHSA-47QP-8V9G-39HP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-2251"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)...", "cve_id": "CVE-2013-2251", "vendor": "Apache", "ghsa_id": "GHSA-47QP-8V9G-39HP", "product": "Struts", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9999, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-2251", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "840dba5b-8d2b-4f74-a89e-b3c0970a65b8", "vulnerability": {"vulnId": "CVE-2019-10068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "840dba5b-8d2b-4f74-a89e-b3c0970a65b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to... | Affected: Kentico / Kentico CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.95074 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-10068", "url": "https://www.cve.org/CVERecord?id=CVE-2019-10068"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-10068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to...", "cve_id": "CVE-2019-10068", "vendor": "Kentico", "ghsa_id": null, "product": "Kentico CMS", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95074, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99862, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-10068", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f25f0076-b33f-4fe7-8899-9f24ba0ce4bf", "vulnerability": {"vulnId": "CVE-2020-2021", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "f25f0076-b33f-4fe7-8899-9f24ba0ce4bf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "PAN-OS: Authentication Bypass in SAML Authentication | Affected: Palo Alto Networks / PAN-OS | CVSS: 10.0 (CRITICAL) | EPSS: 0.04362 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-2021", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2021"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2021"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PAN-OS: Authentication Bypass in SAML Authentication", "cve_id": "CVE-2020-2021", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "PAN-OS", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.04362, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90945, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-2021", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "072fbd36-2c2b-4cd7-b3ca-7f753678ab13", "vulnerability": {"vulnId": "CVE-2018-0147", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "072fbd36-2c2b-4cd7-b3ca-7f753678ab13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an... | Affected: Cisco / Cisco Secure Access Control System | CVSS: 9.8 (CRITICAL) | EPSS: 0.18212 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0147", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0147"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0147"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an...", "cve_id": "CVE-2018-0147", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Secure Access Control System", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.18212, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97129, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0147", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8eb80e77-5fda-4623-8441-9086cc8b9475", "vulnerability": {"vulnId": "CVE-2015-1187", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "8eb80e77-5fda-4623-8441-9086cc8b9475", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. | Affected: D-Link / multiple devices | CVSS: 9.8 (CRITICAL) | EPSS: 0.82863 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1187", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1187"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1187"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.", "cve_id": "CVE-2015-1187", "vendor": "D-Link", "ghsa_id": null, "product": "multiple devices", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82863, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99663, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1187", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b832ac12-395f-419a-a79e-23c06ee7a036", "vulnerability": {"vulnId": "CVE-2010-3035", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "b832ac12-395f-419a-a79e-23c06ee7a036", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers... | Affected: Cisco / IOS XR | CVSS: 7.5 (HIGH) | EPSS: 0.05668 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-3035", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3035"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3035"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers...", "cve_id": "CVE-2010-3035", "vendor": "Cisco", "ghsa_id": null, "product": "IOS XR", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.05668, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92743, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3035", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8ea5d888-acf5-4e31-a4a3-794a98b965b2", "vulnerability": {"vulnId": "CVE-2016-11021", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "8ea5d888-acf5-4e31-a4a3-794a98b965b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. | Affected: D-Link / DCS-930L | CVSS: 7.2 (HIGH) | EPSS: 0.6887 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-11021", "url": "https://www.cve.org/CVERecord?id=CVE-2016-11021"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-11021"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.", "cve_id": "CVE-2016-11021", "vendor": "D-Link", "ghsa_id": null, "product": "DCS-930L", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.6887, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9933, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-11021", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d4a13553-9f26-478b-b8a1-17d3d82574d7", "vulnerability": {"vulnId": "CVE-2005-2773", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "d4a13553-9f26-478b-b8a1-17d3d82574d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node... | Affected: HP / OpenView Network Node Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.74592 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2005-2773", "url": "https://www.cve.org/CVERecord?id=CVE-2005-2773"}, {"id": "previdian", "url": "https://previdian.com/CVE-2005-2773"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node...", "cve_id": "CVE-2005-2773", "vendor": "HP", "ghsa_id": null, "product": "OpenView Network Node Manager", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74592, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99486, "used_in_malware": "unknown", "vulnerability_id": "CVE-2005-2773", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5ab0e068-dcc0-4279-a97d-67e35cdc6351", "vulnerability": {"vulnId": "CVE-2020-9377", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "5ab0e068-dcc0-4279-a97d-67e35cdc6351", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are... | Affected: D-Link / DIR-610 | CVSS: 8.8 (HIGH) | EPSS: 0.21338 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9377", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9377"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9377"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are...", "cve_id": "CVE-2020-9377", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-610", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.21338, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97535, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9377", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1bbaf59f-4d4b-444b-b475-3a253f11f904", "vulnerability": {"vulnId": "CVE-2015-4068", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "1bbaf59f-4d4b-444b-b475-3a253f11f904", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of... | Affected: Arcserve / UDP | CVSS: 9.1 (CRITICAL) | EPSS: 0.63643 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-4068", "url": "https://www.cve.org/CVERecord?id=CVE-2015-4068"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-4068"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of...", "cve_id": "CVE-2015-4068", "vendor": "Arcserve", "ghsa_id": null, "product": "UDP", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.63643, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99194, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-4068", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cdb636a6-1927-45b5-8ce9-2df3a351002c", "vulnerability": {"vulnId": "CVE-2013-4810", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "cdb636a6-1927-45b5-8ce9-2df3a351002c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote... | Affected: HP / ProCurve Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.79468 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-4810", "url": "https://www.cve.org/CVERecord?id=CVE-2013-4810"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-4810"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote...", "cve_id": "CVE-2013-4810", "vendor": "HP", "ghsa_id": null, "product": "ProCurve Manager", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.79468, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-4810", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2860d167-68ab-49d3-8334-b00c8ce94917", "vulnerability": {"vulnId": "CVE-2010-2861", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "2860d167-68ab-49d3-8334-b00c8ce94917", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read... | Affected: Adobe / ColdFusion | CVSS: 7.5 (HIGH) | EPSS: 0.99721 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-2861", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2861"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-2861"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read...", "cve_id": "CVE-2010-2861", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99721, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99952, "used_in_malware": "yes", "vulnerability_id": "CVE-2010-2861", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "adc7bf5e-3e69-4d80-91d7-86b7d60a4dd9", "vulnerability": {"vulnId": "CVE-2018-14839", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "adc7bf5e-3e69-4d80-91d7-86b7d60a4dd9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with... | Affected: LG / N1A1 NAS | CVSS: 9.8 (CRITICAL) | EPSS: 0.89354 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-14839", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14839"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14839"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with...", "cve_id": "CVE-2018-14839", "vendor": "LG", "ghsa_id": null, "product": "N1A1 NAS", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.89354, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99781, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14839", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d0b598fb-48a4-4775-82d2-ebef38914078", "vulnerability": {"vulnId": "CVE-2014-6324", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "d0b598fb-48a4-4775-82d2-ebef38914078", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.87335 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-6324", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6324"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6324"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7...", "cve_id": "CVE-2014-6324", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.87335, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6324", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3f2cc764-d57f-4d81-9c9a-487ff8d53936", "vulnerability": {"vulnId": "CVE-2014-3120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "3f2cc764-d57f-4d81-9c9a-487ff8d53936", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL... | Affected: Elastic / Elasticsearch | CVSS: 8.1 (HIGH) | EPSS: 0.88559 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-3120", "url": "https://www.cve.org/CVERecord?id=CVE-2014-3120"}, {"id": "GHSA-MRFM-JXGF-2H6V", "url": "https://github.com/advisories/GHSA-MRFM-JXGF-2H6V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-3120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL...", "cve_id": "CVE-2014-3120", "vendor": "Elastic", "ghsa_id": "GHSA-MRFM-JXGF-2H6V", "product": "Elasticsearch", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.88559, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99772, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-3120", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bc749325-a2ed-47da-9472-12c435db4ec1", "vulnerability": {"vulnId": "CVE-2015-0666", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "bc749325-a2ed-47da-9472-12c435db4ec1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers... | Affected: Cisco / Prime Data Center Network Manager | CVSS: 7.5 (HIGH) | EPSS: 0.40379 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-0666", "url": "https://www.cve.org/CVERecord?id=CVE-2015-0666"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-0666"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers...", "cve_id": "CVE-2015-0666", "vendor": "Cisco", "ghsa_id": null, "product": "Prime Data Center Network Manager", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.40379, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98603, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-0666", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "23534f47-a68f-43a9-aa41-cb42929bf9e2", "vulnerability": {"vulnId": "CVE-2015-3035", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "23534f47-a68f-43a9-aa41-cb42929bf9e2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with... | Affected: TP-LINK / Archer C5, Archer C7, Archer C8, Archer C9, TL-WDR3500, TL-WDR3600, TL-WDR4300, TL-WR740N, TL-WR741ND, TL-WR841N, TL-WR841ND | CVSS: 7.5 (HIGH) | EPSS: 0.83948 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-3035", "url": "https://www.cve.org/CVERecord?id=CVE-2015-3035"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-3035"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with...", "cve_id": "CVE-2015-3035", "vendor": "TP-LINK", "ghsa_id": null, "product": "Archer C5, Archer C7, Archer C8, Archer C9, TL-WDR3500, TL-WDR3600, TL-WDR4300, TL-WR740N, TL-WR741ND, TL-WR841N, TL-WR841ND", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.83948, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-3035", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "28512708-ab11-43a6-8908-9d20cfdd4d0e", "vulnerability": {"vulnId": "CVE-2017-6334", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "28512708-ab11-43a6-8908-9d20cfdd4d0e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via... | Affected: NETGEAR / DGN2200 | CVSS: 8.8 (HIGH) | EPSS: 0.7264 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6334", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6334"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6334"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via...", "cve_id": "CVE-2017-6334", "vendor": "NETGEAR", "ghsa_id": null, "product": "DGN2200", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.7264, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9943, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6334", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ed73101-6b8f-4bbb-ade5-dde5fdec9eac", "vulnerability": {"vulnId": "CVE-2019-16920", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "2ed73101-6b8f-4bbb-ade5-dde5fdec9eac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the... | Affected: D-Link / DIR-655C, DIR-866L, DIR-652, DHP-1565, DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, DIR-825 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99996 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-16920", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16920"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16920"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the...", "cve_id": "CVE-2019-16920", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-655C, DIR-866L, DIR-652, DHP-1565, DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, DIR-825", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99996, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16920", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "97ba480c-2c41-419f-a24a-b20b6ce6ef63", "vulnerability": {"vulnId": "CVE-2017-12617", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "97ba480c-2c41-419f-a24a-b20b6ce6ef63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via... | Affected: Apache / Apache Tomcat | CVSS: 8.1 (HIGH) | EPSS: 0.99968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12617", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12617"}, {"id": "GHSA-XJGH-84HX-56C5", "url": "https://github.com/advisories/GHSA-XJGH-84HX-56C5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12617"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via...", "cve_id": "CVE-2017-12617", "vendor": "Apache", "ghsa_id": "GHSA-XJGH-84HX-56C5", "product": "Apache Tomcat", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.99968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12617", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8a519b2e-16d8-4674-9fd0-6bf38f8c83d8", "vulnerability": {"vulnId": "CVE-2012-1823", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "8a519b2e-16d8-4674-9fd0-6bf38f8c83d8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query... | Affected: PHP / PHP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99998 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1823", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1823"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1823"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query...", "cve_id": "CVE-2012-1823", "vendor": "PHP", "ghsa_id": null, "product": "PHP", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9999, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1823", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9815dd81-45d8-4d68-b77e-23875367dcdb", "vulnerability": {"vulnId": "CVE-2009-2055", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "9815dd81-45d8-4d68-b77e-23875367dcdb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid... | Affected: Cisco / IOS XR | CVSS: 5.9 (MEDIUM) | EPSS: 0.03314 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-2055", "url": "https://www.cve.org/CVERecord?id=CVE-2009-2055"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-2055"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid...", "cve_id": "CVE-2009-2055", "vendor": "Cisco", "ghsa_id": null, "product": "IOS XR", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.03314, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88166, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-2055", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dcc063f8-ac41-415e-9953-0893915bf9b3", "vulnerability": {"vulnId": "CVE-2022-21999", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "dcc063f8-ac41-415e-9953-0893915bf9b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Windows Print Spooler Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.41007 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-21999", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21999"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21999"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Print Spooler Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-21999", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.41007, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98621, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-21999", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5b92c577-2b52-47f8-9d06-1de1ed8c4232", "vulnerability": {"vulnId": "CVE-2016-0752", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "5b92c577-2b52-47f8-9d06-1de1ed8c4232", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x... | Affected: Ruby on Rails / Action View | CVSS: 7.5 (HIGH) | EPSS: 0.95537 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0752", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0752"}, {"id": "GHSA-XRR4-P6FQ-HJG7", "url": "https://github.com/advisories/GHSA-XRR4-P6FQ-HJG7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0752"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...", "cve_id": "CVE-2016-0752", "vendor": "Ruby on Rails", "ghsa_id": "GHSA-XRR4-P6FQ-HJG7", "product": "Action View", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.95537, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99869, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0752", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "da9d1947-96d8-4c92-9523-31d1d36341e7", "vulnerability": {"vulnId": "CVE-2021-42237", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "da9d1947-96d8-4c92-9523-31d1d36341e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve... | Affected: Sitecore / Sitecore XP | CVSS: 9.8 (CRITICAL) | EPSS: 0.97566 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42237", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42237"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42237"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve...", "cve_id": "CVE-2021-42237", "vendor": "Sitecore", "ghsa_id": null, "product": "Sitecore XP", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97566, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99901, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-42237", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f89ca72-9abf-479e-b8a0-2f67acce0a55", "vulnerability": {"vulnId": "CVE-2020-1631", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "6f89ca72-9abf-479e-b8a0-2f67acce0a55", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services | Affected: Juniper Networks / Junos OS | CVSS: 8.8 (HIGH) | EPSS: 0.04843 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1631", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1631"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1631"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services", "cve_id": "CVE-2020-1631", "vendor": "Juniper Networks", "ghsa_id": null, "product": "Junos OS", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.04843, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1631", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "334efb88-6c03-4b78-968d-d683dddccc22", "vulnerability": {"vulnId": "CVE-2019-0903", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "334efb88-6c03-4b78-968d-d683dddccc22", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.21713 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0903", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0903"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0903"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+...", "cve_id": "CVE-2019-0903", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.21713, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97568, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0903", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a14c9b72-f91c-4eaa-8ded-f954ae3904b2", "vulnerability": {"vulnId": "CVE-2016-1555", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "a14c9b72-f91c-4eaa-8ded-f954ae3904b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and... | Affected: Netgear / WN604, WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, WNDAP660 | CVSS: 9.8 (CRITICAL) | EPSS: 0.98288 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-1555", "url": "https://www.cve.org/CVERecord?id=CVE-2016-1555"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-1555"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and...", "cve_id": "CVE-2016-1555", "vendor": "Netgear", "ghsa_id": null, "product": "WN604, WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, WNDAP660", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98288, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-1555", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "935560b8-402a-47bb-848d-5b8ea246a1f0", "vulnerability": {"vulnId": "CVE-2014-6287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "935560b8-402a-47bb-848d-5b8ea246a1f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to... | Affected: Rejetto / HTTP File Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99323 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-6287", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to...", "cve_id": "CVE-2014-6287", "vendor": "Rejetto", "ghsa_id": null, "product": "HTTP File Server", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99323, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99938, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d0e5382d-c470-4dce-8560-57560714515a", "vulnerability": {"vulnId": "CVE-2014-0130", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "d0e5382d-c470-4dce-8560-57560714515a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before... | Affected: Ruby on Rails / Ruby on Rails | CVSS: 7.5 (HIGH) | EPSS: 0.53703 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0130", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0130"}, {"id": "GHSA-6X85-J5J2-27JX", "url": "https://github.com/advisories/GHSA-6X85-J5J2-27JX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0130"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before...", "cve_id": "CVE-2014-0130", "vendor": "Ruby on Rails", "ghsa_id": "GHSA-6X85-J5J2-27JX", "product": "Ruby on Rails", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.53703, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98966, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0130", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1805f9a2-dc8e-44af-b6d4-ed30887a90e6", "vulnerability": {"vulnId": "CVE-2018-8414", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "1805f9a2-dc8e-44af-b6d4-ed30887a90e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka \"Windows Shell Remote Code Execution... | Affected: Microsoft / Windows 10 Servers, Windows 10 | CVSS: 8.8 (HIGH) | EPSS: 0.72912 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8414", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8414"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8414"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka \"Windows Shell Remote Code Execution...", "cve_id": "CVE-2018-8414", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Servers, Windows 10", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.72912, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99438, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8414", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "014278f0-efd0-45e2-ba9d-0514e19e7dcb", "vulnerability": {"vulnId": "CVE-2019-2616", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "014278f0-efd0-45e2-ba9d-0514e19e7dcb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... | Affected: Oracle / BI Publisher (formerly XML Publisher) | CVSS: 7.2 (HIGH) | EPSS: 0.92183 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-2616", "url": "https://www.cve.org/CVERecord?id=CVE-2019-2616"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-2616"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...", "cve_id": "CVE-2019-2616", "vendor": "Oracle", "ghsa_id": null, "product": "BI Publisher (formerly XML Publisher)", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.92183, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-2616", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06faa8fc-2d5c-4cd9-9b89-5af95f70cc20", "vulnerability": {"vulnId": "CVE-2020-1956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "06faa8fc-2d5c-4cd9-9b89-5af95f70cc20", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user... | Affected: Apache / Kylin | CVSS: 8.8 (HIGH) | EPSS: 0.97337 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1956", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1956"}, {"id": "GHSA-GPRM-XQRC-C2J3", "url": "https://github.com/advisories/GHSA-GPRM-XQRC-C2J3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user...", "cve_id": "CVE-2020-1956", "vendor": "Apache", "ghsa_id": "GHSA-GPRM-XQRC-C2J3", "product": "Kylin", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.97337, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99896, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f7b65249-b1ff-4bbe-9b54-219a2b3bb189", "vulnerability": {"vulnId": "CVE-2018-11138", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "f7b65249-b1ff-4bbe-9b54-219a2b3bb189", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be... | Affected: Quest / KACE System Management Appliance | CVSS: 9.8 (CRITICAL) | EPSS: 0.91778 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-11138", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11138"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11138"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be...", "cve_id": "CVE-2018-11138", "vendor": "Quest", "ghsa_id": null, "product": "KACE System Management Appliance", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91778, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99814, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-11138", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d74034df-8f46-4f2c-a401-673d42b0e595", "vulnerability": {"vulnId": "CVE-2017-3881", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "d74034df-8f46-4f2c-a401-673d42b0e595", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an... | Affected: Cisco / Cisco IOS and IOS XE Software | CVSS: 9.8 (CRITICAL) | EPSS: 0.9895 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-3881", "url": "https://www.cve.org/CVERecord?id=CVE-2017-3881"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-3881"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an...", "cve_id": "CVE-2017-3881", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE Software", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9895, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99928, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-3881", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "982e9d48-564c-4538-8724-b2a571d05caf", "vulnerability": {"vulnId": "CVE-2010-4344", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "982e9d48-564c-4538-8724-b2a571d05caf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an... | Affected: Exim / Exim | CVSS: 9.8 (CRITICAL) | EPSS: 0.71706 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-4344", "url": "https://www.cve.org/CVERecord?id=CVE-2010-4344"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-4344"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an...", "cve_id": "CVE-2010-4344", "vendor": "Exim", "ghsa_id": null, "product": "Exim", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.71706, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99406, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-4344", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8fb47478-3c48-4f56-b11b-4d2da0249c3d", "vulnerability": {"vulnId": "CVE-2020-7247", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "8fb47478-3c48-4f56-b11b-4d2da0249c3d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands... | Affected: OpenBSD / OpenSMTPD | CVSS: 9.8 (CRITICAL) | EPSS: 0.98972 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-7247", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7247"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-7247"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands...", "cve_id": "CVE-2020-7247", "vendor": "OpenBSD", "ghsa_id": null, "product": "OpenSMTPD", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98972, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99929, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-7247", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8fefdb3c-16b7-4468-8afe-b183fdadfa57", "vulnerability": {"vulnId": "CVE-2019-12989", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "8fefdb3c-16b7-4468-8afe-b183fdadfa57", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. | Affected: Citrix / SD-WAN | CVSS: 9.8 (CRITICAL) | EPSS: 0.94957 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-12989", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12989"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12989"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.", "cve_id": "CVE-2019-12989", "vendor": "Citrix", "ghsa_id": null, "product": "SD-WAN", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94957, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.9986, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12989", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f02e847b-2a1f-4c29-bbe9-10c99e969c99", "vulnerability": {"vulnId": "CVE-2017-6316", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "f02e847b-2a1f-4c29-bbe9-10c99e969c99", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie.... | Affected: Citrix / NetScaler SD-WAN | CVSS: 9.8 (CRITICAL) | EPSS: 0.7303 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6316", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6316"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6316"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie....", "cve_id": "CVE-2017-6316", "vendor": "Citrix", "ghsa_id": null, "product": "NetScaler SD-WAN", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7303, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99442, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6316", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7f1953b5-9340-4c9b-9ab8-71058bfbd913", "vulnerability": {"vulnId": "CVE-2017-0146", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "7f1953b5-9340-4c9b-9ab8-71058bfbd913", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... | Affected: Microsoft / Windows SMB | CVSS: 8.8 (HIGH) | EPSS: 0.89862 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0146", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0146"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0146"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...", "cve_id": "CVE-2017-0146", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows SMB", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.89862, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9979, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0146", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ff7b9dda-379d-4d3f-9789-0cf84aee2670", "vulnerability": {"vulnId": "CVE-2016-7892", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "ff7b9dda-379d-4d3f-9789-0cf84aee2670", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField... | Affected: Adobe / Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier | CVSS: 8.8 (HIGH) | EPSS: 0.18786 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7892", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7892"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7892"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField...", "cve_id": "CVE-2016-7892", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.18786, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97201, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7892", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a4493d9a-8b22-451b-ab91-4df007481065", "vulnerability": {"vulnId": "CVE-2014-6332", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "a4493d9a-8b22-451b-ab91-4df007481065", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.94996 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-6332", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6332"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6332"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows...", "cve_id": "CVE-2014-6332", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.94996, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99861, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6332", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c301c846-6e8f-447b-a6da-dd3230269edf", "vulnerability": {"vulnId": "CVE-2010-4345", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "c301c846-6e8f-447b-a6da-dd3230269edf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate... | Affected: Exim / Exim | CVSS: 7.8 (HIGH) | EPSS: 0.17965 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-4345", "url": "https://www.cve.org/CVERecord?id=CVE-2010-4345"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-4345"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate...", "cve_id": "CVE-2010-4345", "vendor": "Exim", "ghsa_id": null, "product": "Exim", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.17965, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97101, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-4345", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "944449b1-d242-4da6-b8f4-7037d8f7b6f0", "vulnerability": {"vulnId": "CVE-2009-0927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "944449b1-d242-4da6-b8f4-7037d8f7b6f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute... | Affected: Adobe / Reader and Acrobat | CVSS: 8.8 (HIGH) | EPSS: 0.96632 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-0927", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0927"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute...", "cve_id": "CVE-2009-0927", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.96632, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99883, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0927", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cf13768e-4a6e-48be-86f3-e81dd834fde8", "vulnerability": {"vulnId": "CVE-2020-25223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "cf13768e-4a6e-48be-86f3-e81dd834fde8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 | Affected: Sophos / SG UTM | CVSS: 9.8 (CRITICAL) | EPSS: 0.96753 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-25223", "url": "https://www.cve.org/CVERecord?id=CVE-2020-25223"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-25223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11", "cve_id": "CVE-2020-25223", "vendor": "Sophos", "ghsa_id": null, "product": "SG UTM", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96753, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-25223", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4df9bbbb-ae3a-4ff4-aa59-0abb7e7f84fb", "vulnerability": {"vulnId": "CVE-2018-8373", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "4df9bbbb-ae3a-4ff4-aa59-0abb7e7f84fb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting... | Affected: Microsoft / Internet Explorer 9, Internet Explorer 11, Internet Explorer 10 | CVSS: 7.5 (HIGH) | EPSS: 0.61912 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8373", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8373"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8373"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting...", "cve_id": "CVE-2018-8373", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 9, Internet Explorer 11, Internet Explorer 10", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.61912, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99152, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8373", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0b41592-60dc-46a6-b0e4-ad811ad0339f", "vulnerability": {"vulnId": "CVE-2018-6961", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "b0b41592-60dc-46a6-b0e4-ad811ad0339f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component... | Affected: VMware / NSX SD-WAN by VeloCloud | CVSS: 8.1 (HIGH) | EPSS: 0.86252 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-6961", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6961"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-6961"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component...", "cve_id": "CVE-2018-6961", "vendor": "VMware", "ghsa_id": null, "product": "NSX SD-WAN by VeloCloud", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.86252, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99728, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-6961", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "71bfb529-061b-4de5-9b4d-52d42121fdc5", "vulnerability": {"vulnId": "CVE-2019-12991", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "71bfb529-061b-4de5-9b4d-52d42121fdc5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | Affected: Citrix / SD-WAN | CVSS: 8.8 (HIGH) | EPSS: 0.74052 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-12991", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12991"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12991"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).", "cve_id": "CVE-2019-12991", "vendor": "Citrix", "ghsa_id": null, "product": "SD-WAN", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.74052, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99472, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12991", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e72a76bd-92ad-450d-b69c-8cb7d33132cb", "vulnerability": {"vulnId": "CVE-2017-12615", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "e72a76bd-92ad-450d-b69c-8cb7d33132cb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default... | Affected: Apache / Apache Tomcat | CVSS: 8.1 (HIGH) | EPSS: 0.99641 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12615", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12615"}, {"id": "GHSA-PJFR-QF3P-3Q25", "url": "https://github.com/advisories/GHSA-PJFR-QF3P-3Q25"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12615"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default...", "cve_id": "CVE-2017-12615", "vendor": "Apache", "ghsa_id": "GHSA-PJFR-QF3P-3Q25", "product": "Apache Tomcat", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.99641, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99949, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-12615", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e6436b53-3d9a-4970-9c65-4358aaf9098e", "vulnerability": {"vulnId": "CVE-2015-1427", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "e6436b53-3d9a-4970-9c65-4358aaf9098e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism... | Affected: Elastic / Elasticsearch | CVSS: 9.8 (CRITICAL) | EPSS: 0.99906 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1427", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1427"}, {"id": "GHSA-W94P-6MHW-4QXW", "url": "https://github.com/advisories/GHSA-W94P-6MHW-4QXW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1427"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism...", "cve_id": "CVE-2015-1427", "vendor": "Elastic", "ghsa_id": "GHSA-W94P-6MHW-4QXW", "product": "Elasticsearch", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99906, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99965, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1427", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "61671826-5687-4f47-a6f1-5ecf2e61ec8f", "vulnerability": {"vulnId": "CVE-2016-4171", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "61671826-5687-4f47-a6f1-5ecf2e61ec8f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.20055 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4171", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4171"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4171"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as...", "cve_id": "CVE-2016-4171", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.20055, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97374, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4171", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b89403df-b6af-48cc-9191-b55b2a2bce79", "vulnerability": {"vulnId": "CVE-2022-26318", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "b89403df-b6af-48cc-9191-b55b2a2bce79", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS... | Affected: WatchGuard / Firebox and XTM appliances | CVSS: 9.8 (CRITICAL) | EPSS: 0.78157 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26318", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26318"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26318"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS...", "cve_id": "CVE-2022-26318", "vendor": "WatchGuard", "ghsa_id": null, "product": "Firebox and XTM appliances", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.78157, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99566, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26318", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "49cab759-d09a-4d38-b463-5afb2fa21472", "vulnerability": {"vulnId": "CVE-2022-26143", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "49cab759-d09a-4d38-b463-5afb2fa21472", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain... | Affected: Mitel / MiCollab, MiVoice Business Express | CVSS: 9.8 (CRITICAL) | EPSS: 0.87325 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26143", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26143"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26143"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain...", "cve_id": "CVE-2022-26143", "vendor": "Mitel", "ghsa_id": null, "product": "MiCollab, MiVoice Business Express", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.87325, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26143", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0663707-00a9-4afe-9651-ff3d400db2f5", "vulnerability": {"vulnId": "CVE-2019-11043", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "f0663707-00a9-4afe-9651-ff3d400db2f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Underflow in PHP-FPM can lead to RCE | Affected: PHP / PHP | CVSS: 8.7 (HIGH) | EPSS: 0.9978 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11043", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11043"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11043"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Underflow in PHP-FPM can lead to RCE", "cve_id": "CVE-2019-11043", "vendor": "PHP", "ghsa_id": null, "product": "PHP", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 8.7, "epss_score": 0.9978, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99955, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-11043", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2d2f2b63-7fdf-4b70-840a-1fd1eb2b54f2", "vulnerability": {"vulnId": "CVE-2018-0125", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "2d2f2b63-7fdf-4b70-840a-1fd1eb2b54f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an... | Affected: Cisco / Cisco RV132W and RV134W | CVSS: 9.8 (CRITICAL) | EPSS: 0.55186 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0125", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0125"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0125"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an...", "cve_id": "CVE-2018-0125", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco RV132W and RV134W", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.55186, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99002, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0125", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a161313f-586e-4042-970d-1e5fc9f1e02b", "vulnerability": {"vulnId": "CVE-2016-10174", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "a161313f-586e-4042-970d-1e5fc9f1e02b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This... | Affected: NETGEAR / WNR2000v5 router | CVSS: 9.8 (CRITICAL) | EPSS: 0.83328 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-10174", "url": "https://www.cve.org/CVERecord?id=CVE-2016-10174"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-10174"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This...", "cve_id": "CVE-2016-10174", "vendor": "NETGEAR", "ghsa_id": null, "product": "WNR2000v5 router", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83328, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99672, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-10174", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e751f155-80e3-40c4-9a8c-43333808c520", "vulnerability": {"vulnId": "CVE-2009-1151", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "e751f155-80e3-40c4-9a8c-43333808c520", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject... | Affected: phpMyAdmin / phpMyAdmin | CVSS: 9.8 (CRITICAL) | EPSS: 0.96565 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-1151", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1151"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1151"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject...", "cve_id": "CVE-2009-1151", "vendor": "phpMyAdmin", "ghsa_id": null, "product": "phpMyAdmin", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96565, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99881, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1151", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72fcb789-ec1c-4c44-bddd-e0a9a2471597", "vulnerability": {"vulnId": "CVE-2019-1003030", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "72fcb789-ec1c-4c44-bddd-e0a9a2471597", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml,... | Affected: Jenkins project / Jenkins Pipeline: Groovy Plugin | CVSS: 9.9 (CRITICAL) | EPSS: 0.97058 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1003030", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1003030"}, {"id": "GHSA-R6MC-MRVR-23CR", "url": "https://github.com/advisories/GHSA-R6MC-MRVR-23CR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1003030"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml,...", "cve_id": "CVE-2019-1003030", "vendor": "Jenkins project", "ghsa_id": "GHSA-R6MC-MRVR-23CR", "product": "Jenkins Pipeline: Groovy Plugin", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.97058, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99891, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1003030", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ed20e9ab-1795-42d4-b948-e7e741b72c93", "vulnerability": {"vulnId": "CVE-2020-5410", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "ed20e9ab-1795-42d4-b948-e7e741b72c93", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Directory Traversal with spring-cloud-config-server | Affected: Spring by VMware / Spring Cloud Config | CVSS: 7.5 (HIGH) | EPSS: 0.95586 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5410", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5410"}, {"id": "GHSA-32XF-JWMV-9HF3", "url": "https://github.com/advisories/GHSA-32XF-JWMV-9HF3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5410"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory Traversal with spring-cloud-config-server", "cve_id": "CVE-2020-5410", "vendor": "Spring by VMware", "ghsa_id": "GHSA-32XF-JWMV-9HF3", "product": "Spring Cloud Config", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.95586, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5410", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "70698ef1-e998-492c-a9dc-1e51b5026ea1", "vulnerability": {"vulnId": "CVE-2019-15107", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "70698ef1-e998-492c-a9dc-1e51b5026ea1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. | Affected: Webmin / Webmin | CVSS: 9.8 (CRITICAL) | EPSS: 0.9971 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-15107", "url": "https://www.cve.org/CVERecord?id=CVE-2019-15107"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-15107"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.", "cve_id": "CVE-2019-15107", "vendor": "Webmin", "ghsa_id": null, "product": "Webmin", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9971, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99951, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-15107", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cb06f014-732e-4739-8650-0e4ccfb9a65f", "vulnerability": {"vulnId": "CVE-2018-1273", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-25T01:00:00+01:00"}, "gcve": {"object_uuid": "cb06f014-732e-4739-8650-0e4ccfb9a65f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-25T00:00:00+00:00"}, "scope": {"notes": "Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability... | Affected: Spring by Pivotal / Spring Framework | CVSS: 9.8 (CRITICAL) | EPSS: 0.96956 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-1273", "url": "https://www.cve.org/CVERecord?id=CVE-2018-1273"}, {"id": "GHSA-4FQ3-MR56-CG6R", "url": "https://github.com/advisories/GHSA-4FQ3-MR56-CG6R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-1273"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability...", "cve_id": "CVE-2018-1273", "vendor": "Spring by Pivotal", "ghsa_id": "GHSA-4FQ3-MR56-CG6R", "product": "Spring Framework", "added_date": "2022-03-25T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96956, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99889, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-1273", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0f840f9-3061-4e2f-bec2-b1c77bcfc76c", "vulnerability": {"vulnId": "CVE-2022-26186", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-22T21:13:16+01:00"}, "gcve": {"object_uuid": "e0f840f9-3061-4e2f-bec2-b1c77bcfc76c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-22T20:13:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-22T20:13:16+00:00"}, "scope": {"notes": "TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi. | Affected: TOTOLINK / N600R | CVSS: 9.8 (CRITICAL) | EPSS: 0.03947 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-26186", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26186"}, {"id": "GHSA-PM89-XMVF-HR23", "url": "https://github.com/advisories/GHSA-PM89-XMVF-HR23"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26186"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.", "cve_id": "CVE-2022-26186", "vendor": "TOTOLINK", "ghsa_id": "GHSA-PM89-XMVF-HR23", "product": "N600R", "added_date": "2022-03-22T20:13:16.000Z", "cvss_score": 9.8, "epss_score": 0.03947, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90081, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26186", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d50ddb2a-cb74-4adb-84cc-bbb237dd2b25", "vulnerability": {"vulnId": "CVE-2022-0591", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-21T19:55:48+01:00"}, "gcve": {"object_uuid": "d50ddb2a-cb74-4adb-84cc-bbb237dd2b25", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-21T18:55:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-21T18:55:48+00:00"}, "scope": {"notes": "Formcraft3 < 3.8.28 - Unauthenticated SSRF | Affected: FormCraft / FormCraft | CVSS: 9.1 (CRITICAL) | EPSS: 0.20249 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0591", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0591"}, {"id": "GHSA-X9WP-HPRC-2GVQ", "url": "https://github.com/advisories/GHSA-X9WP-HPRC-2GVQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0591"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Formcraft3 < 3.8.28 - Unauthenticated SSRF", "cve_id": "CVE-2022-0591", "vendor": "FormCraft", "ghsa_id": "GHSA-X9WP-HPRC-2GVQ", "product": "FormCraft", "added_date": "2022-03-21T18:55:48.000Z", "cvss_score": 9.1, "epss_score": 0.20249, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.974, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0591", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9857dc4c-af8b-403b-a4e7-04d3a36d16aa", "vulnerability": {"vulnId": "CVE-2021-45967", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-18T06:00:35+01:00"}, "gcve": {"object_uuid": "9857dc4c-af8b-403b-a4e7-04d3a36d16aa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-18T05:00:35+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-18T05:00:35+00:00"}, "scope": {"notes": "An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path... | Affected: Pascom / Cloud Phone System | CVSS: 9.8 (CRITICAL) | EPSS: 0.208 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-45967", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45967"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45967"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path...", "cve_id": "CVE-2021-45967", "vendor": "Pascom", "ghsa_id": null, "product": "Cloud Phone System", "added_date": "2022-03-18T05:00:35.000Z", "cvss_score": 9.8, "epss_score": 0.208, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9748, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-45967", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c11f4ae7-24f5-46b3-8a73-4a1e4181ad40", "vulnerability": {"vulnId": "CVE-2016-3309", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "c11f4ae7-24f5-46b3-8a73-4a1e4181ad40", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.20467 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3309", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3309"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3309"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold...", "cve_id": "CVE-2016-3309", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.20467, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97437, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-3309", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d9ea85b-b472-45c0-859e-1b31a74f0eeb", "vulnerability": {"vulnId": "CVE-2018-8120", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "6d9ea85b-b472-45c0-859e-1b31a74f0eeb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k... | Affected: Microsoft / Windows Server 2008, Windows 7, Windows Server 2008 R2 | CVSS: 7.0 (HIGH) | EPSS: 0.73434 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8120", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8120"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8120"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k...", "cve_id": "CVE-2018-8120", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server 2008, Windows 7, Windows Server 2008 R2", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.73434, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99453, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8120", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "127f4a15-d85b-42fd-ab9a-7e9d201efb64", "vulnerability": {"vulnId": "CVE-2019-1405", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "127f4a15-d85b-42fd-ab9a-7e9d201efb64", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.2995 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1405", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1405"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1405"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka...", "cve_id": "CVE-2019-1405", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.2995, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98157, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1405", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac3ffae4-9abe-46b1-8897-e0539cb6aad0", "vulnerability": {"vulnId": "CVE-2015-2546", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "ac3ffae4-9abe-46b1-8897-e0539cb6aad0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server... | Affected: Microsoft / Windows | CVSS: 8.2 (HIGH) | EPSS: 0.10107 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2546", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2546"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2546"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server...", "cve_id": "CVE-2015-2546", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.10107, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95509, "used_in_malware": "yes", "vulnerability_id": "CVE-2015-2546", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "41ffa2d4-2693-42fc-ade9-fc391d747368", "vulnerability": {"vulnId": "CVE-2019-1315", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "41ffa2d4-2693-42fc-ade9-fc391d747368", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.03478 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1315", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1315"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1315"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting...", "cve_id": "CVE-2019-1315", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03478, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88709, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1315", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "97275809-3710-4a08-b416-5a3f726a45a3", "vulnerability": {"vulnId": "CVE-2017-0101", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "97275809-3710-4a08-b416-5a3f726a45a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.57482 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0101", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0101"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0101"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows...", "cve_id": "CVE-2017-0101", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.57482, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99055, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0101", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "33fe0ca9-f06a-497a-afe6-1619099a4300", "vulnerability": {"vulnId": "CVE-2019-1064", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "33fe0ca9-f06a-497a-afe6-1619099a4300", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "Windows Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1703, Windows 10 Version 1803, Windows Server, version 1803  (Server Core Installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.06886 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1064", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1064"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1064"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Elevation of Privilege Vulnerability", "cve_id": "CVE-2019-1064", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1703, Windows 10 Version 1803, Windows Server, version 1803  (Server Core Installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.06886, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93868, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1064", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c482598f-f4c5-44a6-bed5-7b6cd0b08e25", "vulnerability": {"vulnId": "CVE-2019-1129", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "c482598f-f4c5-44a6-bed5-7b6cd0b08e25", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01782 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1129", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1129"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1129"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...", "cve_id": "CVE-2019-1129", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01782, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77465, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1129", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0ae2faca-f459-48d9-8fff-2b9de8a8acec", "vulnerability": {"vulnId": "CVE-2019-1322", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "0ae2faca-f459-48d9-8fff-2b9de8a8acec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.19205 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1322", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1322"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1322"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of...", "cve_id": "CVE-2019-1322", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.19205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97255, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1322", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "56e68cf2-c67c-4443-8c58-de4e4bb85b15", "vulnerability": {"vulnId": "CVE-2019-0543", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "56e68cf2-c67c-4443-8c58-de4e4bb85b15", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka \"Microsoft Windows Elevation of... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.04718 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0543", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0543"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0543"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka \"Microsoft Windows Elevation of...", "cve_id": "CVE-2019-0543", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04718, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91545, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-0543", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c78efb0a-3d9b-45b6-ad99-cecb81483037", "vulnerability": {"vulnId": "CVE-2019-1253", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "c78efb0a-3d9b-45b6-ad99-cecb81483037", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability,... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.11616 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1253", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1253"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1253"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability,...", "cve_id": "CVE-2019-1253", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.11616, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95923, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1253", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "050d3f72-40e3-4fc2-84e3-81dde1688cae", "vulnerability": {"vulnId": "CVE-2019-1069", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "050d3f72-40e3-4fc2-84e3-81dde1688cae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "Task Scheduler Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1703, Windows 10 Version 1803, Windows Server, version 1803  (Server Core Installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.06117 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1069", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1069"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1069"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Task Scheduler Elevation of Privilege Vulnerability", "cve_id": "CVE-2019-1069", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1703, Windows 10 Version 1803, Windows Server, version 1803  (Server Core Installation), Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation)", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.06117, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93217, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1069", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5741440c-1ce2-4853-9eb2-c5facf1982bb", "vulnerability": {"vulnId": "CVE-2019-1132", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "5741440c-1ce2-4853-9eb2-c5facf1982bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... | Affected: Microsoft / Windows, Windows Server | CVSS: 7.8 (HIGH) | EPSS: 0.09788 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1132", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1132"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1132"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...", "cve_id": "CVE-2019-1132", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09788, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1132", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "be969866-a8a0-4bac-b666-3ca3f5b6290e", "vulnerability": {"vulnId": "CVE-2020-5135", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "be969866-a8a0-4bac-b666-3ca3f5b6290e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by... | Affected: SonicWall / SonicOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.26869 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5135", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5135"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5135"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by...", "cve_id": "CVE-2020-5135", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicOS", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.26869, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97978, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5135", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7ebaa640-d799-4b0c-aa96-44c4f1018af6", "vulnerability": {"vulnId": "CVE-2019-0841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-15T01:00:00+01:00"}, "gcve": {"object_uuid": "7ebaa640-d799-4b0c-aa96-44c4f1018af6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-15T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation... | Affected: Microsoft / Windows, Windows Server | CVSS: 7.8 (HIGH) | EPSS: 0.414 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0841", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0841"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...", "cve_id": "CVE-2019-0841", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2022-03-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.414, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98636, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-0841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8a9fb02b-4f73-4934-9b34-671783c56650", "vulnerability": {"vulnId": "CVE-2021-20083", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-11T09:00:34+01:00"}, "gcve": {"object_uuid": "8a9fb02b-4f73-4934-9b34-671783c56650", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-11T08:00:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-11T08:00:34+00:00"}, "scope": {"notes": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious... | Affected: jQuery / jquery-plugin-query-object | CVSS: 8.8 (HIGH) | EPSS: 0.04186 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-20083", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20083"}, {"id": "GHSA-Q9XG-H756-8689", "url": "https://github.com/advisories/GHSA-Q9XG-H756-8689"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20083"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious...", "cve_id": "CVE-2021-20083", "vendor": "jQuery", "ghsa_id": "GHSA-Q9XG-H756-8689", "product": "jquery-plugin-query-object", "added_date": "2022-03-11T08:00:34.000Z", "cvss_score": 8.8, "epss_score": 0.04186, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90614, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20083", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2bf29ba7-ac23-4413-ac4a-a5144c5fccb9", "vulnerability": {"vulnId": "CVE-2022-0482", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-09T11:20:10+01:00"}, "gcve": {"object_uuid": "2bf29ba7-ac23-4413-ac4a-a5144c5fccb9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-09T10:20:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-09T10:20:10+00:00"}, "scope": {"notes": "Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments | Affected: Alex Tselegidis / alextselegidis/easyappointments | CVSS: 9.1 (CRITICAL) | EPSS: 0.43746 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-0482", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0482"}, {"id": "GHSA-R6CM-WG48-RH2R", "url": "https://github.com/advisories/GHSA-R6CM-WG48-RH2R"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0482"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments", "cve_id": "CVE-2022-0482", "vendor": "Alex Tselegidis", "ghsa_id": "GHSA-R6CM-WG48-RH2R", "product": "alextselegidis/easyappointments", "added_date": "2022-03-09T10:20:10.000Z", "cvss_score": 9.1, "epss_score": 0.43746, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98704, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0482", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b6889fbe-fef3-475a-92f0-0f855410adba", "vulnerability": {"vulnId": "CVE-2013-0631", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "b6889fbe-fef3-475a-92f0-0f855410adba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in... | Affected: Adobe / ColdFusion | CVSS: 7.5 (HIGH) | EPSS: 0.66413 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0631", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0631"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0631"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in...", "cve_id": "CVE-2013-0631", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.66413, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99263, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0631", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9c7066f1-a2d4-4c39-bf13-725f71dd834b", "vulnerability": {"vulnId": "CVE-2020-8218", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "9c7066f1-a2d4-4c39-bf13-725f71dd834b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code... | Affected: Pulse Secure / Pulse Connect Secure | CVSS: 7.2 (HIGH) | EPSS: 0.3225 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8218", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8218"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8218"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code...", "cve_id": "CVE-2020-8218", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.3225, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98276, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8218", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "32008df6-6e99-4f99-84d1-68fc3173181d", "vulnerability": {"vulnId": "CVE-2017-6077", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "32008df6-6e99-4f99-84d1-68fc3173181d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell... | Affected: NETGEAR / DGN2200 | CVSS: 9.8 (CRITICAL) | EPSS: 0.68712 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6077", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6077"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6077"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell...", "cve_id": "CVE-2017-6077", "vendor": "NETGEAR", "ghsa_id": null, "product": "DGN2200", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68712, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99324, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6077", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1e1427dd-154a-4119-826a-769552cbdc84", "vulnerability": {"vulnId": "CVE-2022-26485", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "1e1427dd-154a-4119-826a-769552cbdc84", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing... | Affected: Mozilla / Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus | CVSS: 8.8 (HIGH) | EPSS: 0.14261 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26485", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26485"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26485"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing...", "cve_id": "CVE-2022-26485", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.14261, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96492, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26485", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e6d50cf3-32ab-45a5-999e-10156ff17253", "vulnerability": {"vulnId": "CVE-2021-21973", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "e6d50cf3-32ab-45a5-999e-10156ff17253", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server... | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation | CVSS: 5.3 (MEDIUM) | EPSS: 0.8764 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21973", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21973"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21973"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server...", "cve_id": "CVE-2021-21973", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.8764, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99757, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21973", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8fb067f6-96f6-49a6-b96f-70efb105364e", "vulnerability": {"vulnId": "CVE-2009-3960", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "8fb067f6-96f6-49a6-b96f-70efb105364e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0,... | Affected: Adobe / BlazeDS | CVSS: 6.5 (MEDIUM) | EPSS: 0.90118 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-3960", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3960"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-3960"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0,...", "cve_id": "CVE-2009-3960", "vendor": "Adobe", "ghsa_id": null, "product": "BlazeDS", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.90118, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99794, "used_in_malware": "yes", "vulnerability_id": "CVE-2009-3960", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2340fd53-331a-4195-b758-f19fd6663619", "vulnerability": {"vulnId": "CVE-2013-0625", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "2340fd53-331a-4195-b758-f19fd6663619", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute... | Affected: Adobe / ColdFusion | CVSS: 9.8 (CRITICAL) | EPSS: 0.93758 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0625", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0625"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0625"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute...", "cve_id": "CVE-2013-0625", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93758, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99843, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0625", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "50c0d236-787a-43c9-a0f6-db2fd0661ab7", "vulnerability": {"vulnId": "CVE-2016-6277", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "50c0d236-787a-43c9-a0f6-db2fd0661ab7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before... | Affected: NETGEAR / Routers | CVSS: 8.8 (HIGH) | EPSS: 0.99803 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-6277", "url": "https://www.cve.org/CVERecord?id=CVE-2016-6277"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-6277"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before...", "cve_id": "CVE-2016-6277", "vendor": "NETGEAR", "ghsa_id": null, "product": "Routers", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99803, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99957, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-6277", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "302eca7a-e8f0-4a27-8366-9a40a9f840ab", "vulnerability": {"vulnId": "CVE-2013-0629", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "302eca7a-e8f0-4a27-8366-9a40a9f840ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified... | Affected: Adobe / ColdFusion | CVSS: 7.5 (HIGH) | EPSS: 0.65795 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0629", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0629"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0629"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified...", "cve_id": "CVE-2013-0629", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.65795, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99249, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0629", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cb4388de-c952-496f-884c-931a2dfefb07", "vulnerability": {"vulnId": "CVE-2019-11581", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "cb4388de-c952-496f-884c-931a2dfefb07", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions.... | Affected: Atlassian / Jira Server and Data Center | CVSS: 9.8 (CRITICAL) | EPSS: 0.84621 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11581", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11581"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11581"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions....", "cve_id": "CVE-2019-11581", "vendor": "Atlassian", "ghsa_id": null, "product": "Jira Server and Data Center", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84621, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99698, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-11581", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "11c6c08e-ae73-4436-bbc3-39532219b262", "vulnerability": {"vulnId": "CVE-2022-26486", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-07T01:00:00+01:00"}, "gcve": {"object_uuid": "11c6c08e-ae73-4436-bbc3-39532219b262", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-07T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-07T00:00:00+00:00"}, "scope": {"notes": "An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in... | Affected: Mozilla / Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus | CVSS: 9.6 (CRITICAL) | EPSS: 0.02349 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-26486", "url": "https://www.cve.org/CVERecord?id=CVE-2022-26486"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-26486"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in...", "cve_id": "CVE-2022-26486", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Firefox ESR, Firefox for Android, Thunderbird, Focus", "added_date": "2022-03-07T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.02349, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83062, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-26486", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "074ee0c8-b152-4865-b447-7542cf0b444a", "vulnerability": {"vulnId": "CVE-2021-46379", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-04T16:02:26+01:00"}, "gcve": {"object_uuid": "074ee0c8-b152-4865-b447-7542cf0b444a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-04T15:02:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-04T15:02:26+00:00"}, "scope": {"notes": "DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. | Affected: D-Link / DIR850 | CVSS: 6.1 (MEDIUM) | EPSS: 0.15769 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-46379", "url": "https://www.cve.org/CVERecord?id=CVE-2021-46379"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-46379"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.", "cve_id": "CVE-2021-46379", "vendor": "D-Link", "ghsa_id": null, "product": "DIR850", "added_date": "2022-03-04T15:02:26.000Z", "cvss_score": 6.1, "epss_score": 0.15769, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96772, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-46379", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3200bb78-5061-4175-9d8a-2fe2feb4c8b7", "vulnerability": {"vulnId": "CVE-2016-5195", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3200bb78-5061-4175-9d8a-2fe2feb4c8b7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling... | Affected: Linux / Linux Kernel | CVSS: 7.0 (HIGH) | EPSS: 0.83524 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-5195", "url": "https://www.cve.org/CVERecord?id=CVE-2016-5195"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-5195"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling...", "cve_id": "CVE-2016-5195", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.83524, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99678, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-5195", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e81cfab5-c98f-48fa-869a-e705284e712e", "vulnerability": {"vulnId": "CVE-2011-0611", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e81cfab5-c98f-48fa-869a-e705284e712e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;... | Affected: Adobe / Flash Player, AIR, Reader, Acrobat | CVSS: 8.8 (HIGH) | EPSS: 0.9941 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-0611", "url": "https://www.cve.org/CVERecord?id=CVE-2011-0611"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-0611"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140;...", "cve_id": "CVE-2011-0611", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player, AIR, Reader, Acrobat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.9941, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99941, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-0611", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "62bec2d0-8e19-454b-880d-ce30e8590f4d", "vulnerability": {"vulnId": "CVE-2008-2992", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "62bec2d0-8e19-454b-880d-ce30e8590f4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that... | Affected: Adobe / Acrobat and Reader | CVSS: 7.8 (HIGH) | EPSS: 0.98482 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2008-2992", "url": "https://www.cve.org/CVERecord?id=CVE-2008-2992"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-2992"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that...", "cve_id": "CVE-2008-2992", "vendor": "Adobe", "ghsa_id": null, "product": "Acrobat and Reader", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.98482, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99919, "used_in_malware": "yes", "vulnerability_id": "CVE-2008-2992", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5e272951-bd18-4ccc-a32c-37fe1e77d1a5", "vulnerability": {"vulnId": "CVE-2011-3544", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5e272951-bd18-4ccc-a32c-37fe1e77d1a5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.96714 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-3544", "url": "https://www.cve.org/CVERecord?id=CVE-2011-3544"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-3544"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote...", "cve_id": "CVE-2011-3544", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96714, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99885, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-3544", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0968c60c-21a6-4d77-b89b-898a36d19f22", "vulnerability": {"vulnId": "CVE-2015-2387", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0968c60c-21a6-4d77-b89b-898a36d19f22", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.34878 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2387", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2387"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2387"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,...", "cve_id": "CVE-2015-2387", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.34878, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98389, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2387", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f910af9-5f1b-4262-89df-5e319308deeb", "vulnerability": {"vulnId": "CVE-2013-0641", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6f910af9-5f1b-4262-89df-5e319308deeb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute... | Affected: Adobe / Reader and Acrobat | CVSS: 7.8 (HIGH) | EPSS: 0.32346 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0641", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0641"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0641"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute...", "cve_id": "CVE-2013-0641", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.32346, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9828, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0641", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3051a7c6-0de0-4aaa-b314-cd24a680775d", "vulnerability": {"vulnId": "CVE-2015-2424", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3051a7c6-0de0-4aaa-b314-cd24a680775d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1... | Affected: Microsoft / Office | CVSS: 8.8 (HIGH) | EPSS: 0.40388 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2424", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2424"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2424"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1...", "cve_id": "CVE-2015-2424", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.40388, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98603, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2424", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f7334b93-a816-4e11-a36f-6843f0e59de8", "vulnerability": {"vulnId": "CVE-2017-11292", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f7334b93-a816-4e11-a36f-6843f0e59de8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in... | Affected: Adobe / Adobe Flash Player version 27.0.0.159 and earlier | CVSS: 8.8 (HIGH) | EPSS: 0.11885 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-11292", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11292"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11292"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in...", "cve_id": "CVE-2017-11292", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Flash Player version 27.0.0.159 and earlier", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.11885, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-11292", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4fdb09a4-8846-4205-a8af-cf34bc59f41b", "vulnerability": {"vulnId": "CVE-2012-1856", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4fdb09a4-8846-4205-a8af-cf34bc59f41b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2... | Affected: Microsoft / Office | CVSS: 8.8 (HIGH) | EPSS: 0.72032 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1856", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1856"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1856"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2...", "cve_id": "CVE-2012-1856", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.72032, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1856", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0ec4b42e-486a-4918-aa1c-e35a79436eb7", "vulnerability": {"vulnId": "CVE-2015-1642", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0ec4b42e-486a-4918-aa1c-e35a79436eb7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka \"Microsoft Office... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.53087 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1642", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1642"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1642"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka \"Microsoft Office...", "cve_id": "CVE-2015-1642", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.53087, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98948, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1642", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9dd82a13-f357-4bb8-86d2-acbce255ccf6", "vulnerability": {"vulnId": "CVE-2016-1019", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9dd82a13-f357-4bb8-86d2-acbce255ccf6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.22316 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-1019", "url": "https://www.cve.org/CVERecord?id=CVE-2016-1019"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-1019"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary...", "cve_id": "CVE-2016-1019", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.22316, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97621, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-1019", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dd905fd9-2cfa-4ba3-9ad8-77cbabcbf15f", "vulnerability": {"vulnId": "CVE-2018-0154", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "dd905fd9-2cfa-4ba3-9ad8-77cbabcbf15f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an... | Affected: Cisco / Cisco IOS | CVSS: 7.5 (HIGH) | EPSS: 0.0707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0154", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0154"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0154"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an...", "cve_id": "CVE-2018-0154", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94019, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0154", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "927ace12-a936-4855-85fc-7a8a6836e22d", "vulnerability": {"vulnId": "CVE-2002-0367", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "927ace12-a936-4855-85fc-7a8a6836e22d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.04919 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2002-0367", "url": "https://www.cve.org/CVERecord?id=CVE-2002-0367"}, {"id": "previdian", "url": "https://previdian.com/CVE-2002-0367"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows...", "cve_id": "CVE-2002-0367", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04919, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91844, "used_in_malware": "unknown", "vulnerability_id": "CVE-2002-0367", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ab7642ae-6fe3-4383-9adb-a1da02948e48", "vulnerability": {"vulnId": "CVE-2004-0210", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ab7642ae-6fe3-4383-9adb-a1da02948e48", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by... | Affected: Microsoft / Windows NT, Windows 2000 | CVSS: 7.8 (HIGH) | EPSS: 0.07214 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2004-0210", "url": "https://www.cve.org/CVERecord?id=CVE-2004-0210"}, {"id": "previdian", "url": "https://previdian.com/CVE-2004-0210"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by...", "cve_id": "CVE-2004-0210", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows NT, Windows 2000", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07214, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94131, "used_in_malware": "unknown", "vulnerability_id": "CVE-2004-0210", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5515d3d1-4170-4694-a3dd-a83fa5d8190e", "vulnerability": {"vulnId": "CVE-2010-3333", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5515d3d1-4170-4694-a3dd-a83fa5d8190e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.89497 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-3333", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3333"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3333"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac...", "cve_id": "CVE-2010-3333", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.89497, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99783, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3333", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d114a6a2-d5d6-4acb-aead-50fa05872b9a", "vulnerability": {"vulnId": "CVE-2010-0232", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d114a6a2-d5d6-4acb-aead-50fa05872b9a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.28735 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-0232", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0232"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0232"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows...", "cve_id": "CVE-2010-0232", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.28735, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98091, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-0232", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "885f197b-4131-4899-943c-8f30710947d7", "vulnerability": {"vulnId": "CVE-2017-0261", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "885f197b-4131-4899-943c-8f30710947d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle... | Affected: Microsoft / Microsoft Office | CVSS: 7.8 (HIGH) | EPSS: 0.7813 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0261", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0261"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0261"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...", "cve_id": "CVE-2017-0261", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.7813, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99565, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0261", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5dcf640-444e-42eb-b540-3f4a9080d025", "vulnerability": {"vulnId": "CVE-2008-3431", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a5dcf640-444e-42eb-b540-3f4a9080d025", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and... | Affected: Sun / xVM VirtualBox | CVSS: 8.8 (HIGH) | EPSS: 0.06876 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2008-3431", "url": "https://www.cve.org/CVERecord?id=CVE-2008-3431"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-3431"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and...", "cve_id": "CVE-2008-3431", "vendor": "Sun", "ghsa_id": null, "product": "xVM VirtualBox", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.06876, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93858, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-3431", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20392fc9-5a5c-4994-89fa-3945f81780e3", "vulnerability": {"vulnId": "CVE-2013-3346", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "20392fc9-5a5c-4994-89fa-3945f81780e3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial... | Affected: Adobe / Reader and Acrobat | CVSS: 9.8 (CRITICAL) | EPSS: 0.78913 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3346", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3346"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3346"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial...", "cve_id": "CVE-2013-3346", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.78913, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99584, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3346", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c17ca9e2-2237-4f44-9c57-fc53b498a5fa", "vulnerability": {"vulnId": "CVE-2017-12232", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c17ca9e2-2237-4f44-9c57-fc53b498a5fa", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0... | Affected: Cisco / Cisco IOS | CVSS: 6.5 (MEDIUM) | EPSS: 0.02153 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12232", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12232"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12232"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0...", "cve_id": "CVE-2017-12232", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.02153, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81484, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12232", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "22bf0afb-b983-4295-9044-4cb03b5987ed", "vulnerability": {"vulnId": "CVE-2018-0155", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "22bf0afb-b983-4295-9044-4cb03b5987ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 8.6 (HIGH) | EPSS: 0.07742 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0155", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0155"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0155"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst...", "cve_id": "CVE-2018-0155", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.07742, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94451, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0155", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cee8c4d4-262d-444d-b7a3-c7b8dfa15333", "vulnerability": {"vulnId": "CVE-2018-0175", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cee8c4d4-262d-444d-b7a3-c7b8dfa15333", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR... | Affected: Cisco / Cisco IOS, IOS XE, and IOS XR | CVSS: 8.0 (HIGH) | EPSS: 0.03478 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0175", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0175"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0175"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR...", "cve_id": "CVE-2018-0175", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS, IOS XE, and IOS XR", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.03478, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8871, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0175", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aee4bd55-ad2b-4abc-8711-6024a6cfbc42", "vulnerability": {"vulnId": "CVE-2019-1297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "aee4bd55-ad2b-4abc-8711-6024a6cfbc42", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka... | Affected: Microsoft / Microsoft Excel, Microsoft Office, Office 365 ProPlus | CVSS: 8.8 (HIGH) | EPSS: 0.21805 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1297", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka...", "cve_id": "CVE-2019-1297", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Excel, Microsoft Office, Office 365 ProPlus", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.21805, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97573, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cf5b7bc5-877a-47af-a80c-b3e4461be412", "vulnerability": {"vulnId": "CVE-2012-1723", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cf5b7bc5-877a-47af-a80c-b3e4461be412", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.93688 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1723", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1723"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1723"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5...", "cve_id": "CVE-2012-1723", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93688, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99842, "used_in_malware": "yes", "vulnerability_id": "CVE-2012-1723", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bf069efb-833c-48e5-b51f-a149c79e9aef", "vulnerability": {"vulnId": "CVE-2013-1347", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bf069efb-833c-48e5-b51f-a149c79e9aef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an... | Affected: Microsoft / Internet Explorer 8 | CVSS: 8.8 (HIGH) | EPSS: 0.7774 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-1347", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1347"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1347"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an...", "cve_id": "CVE-2013-1347", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 8", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.7774, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99556, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1347", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3c297933-f760-4f4c-a94c-d47dc0e94e07", "vulnerability": {"vulnId": "CVE-2015-7645", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3c297933-f760-4f4c-a94c-d47dc0e94e07", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote... | Affected: Adobe / Flash Player | CVSS: 7.8 (HIGH) | EPSS: 0.65339 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-7645", "url": "https://www.cve.org/CVERecord?id=CVE-2015-7645"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-7645"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote...", "cve_id": "CVE-2015-7645", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.65339, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99239, "used_in_malware": "yes", "vulnerability_id": "CVE-2015-7645", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0ad7e4f-0f67-4b7c-95a9-9a7c1c7ff38e", "vulnerability": {"vulnId": "CVE-2016-7193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e0ad7e4f-0f67-4b7c-95a9-9a7c1c7ff38e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility... | Affected: Microsoft / Word | CVSS: 7.8 (HIGH) | EPSS: 0.57582 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7193", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility...", "cve_id": "CVE-2016-7193", "vendor": "Microsoft", "ghsa_id": null, "product": "Word", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.57582, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99057, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e21afa21-3961-490b-9237-1329c608d184", "vulnerability": {"vulnId": "CVE-2018-0156", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e21afa21-3961-490b-9237-1329c608d184", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 7.5 (HIGH) | EPSS: 0.0936 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0156", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0156"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0156"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to...", "cve_id": "CVE-2018-0156", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0936, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95248, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0156", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ec0500fe-b65a-40fb-a029-e5261904b7d9", "vulnerability": {"vulnId": "CVE-2022-20701", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ec0500fe-b65a-40fb-a029-e5261904b7d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 10.0 (CRITICAL) | EPSS: 0.09747 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20701", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20701"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20701"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV Series Routers Vulnerabilities", "cve_id": "CVE-2022-20701", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.09747, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95386, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20701", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "db7d05ee-861b-4073-8a98-858e169d1e9f", "vulnerability": {"vulnId": "CVE-2013-3897", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "db7d05ee-861b-4073-8a98-858e169d1e9f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.7731 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3897", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3897"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3897"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to...", "cve_id": "CVE-2013-3897", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.7731, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99544, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3897", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "213079bd-6582-4d56-990d-82f9e929e2f0", "vulnerability": {"vulnId": "CVE-2015-5119", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "213079bd-6582-4d56-990d-82f9e929e2f0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.99326 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-5119", "url": "https://www.cve.org/CVERecord?id=CVE-2015-5119"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-5119"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and...", "cve_id": "CVE-2015-5119", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99326, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-5119", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8a05653b-0267-4162-9b59-6bdcb534267d", "vulnerability": {"vulnId": "CVE-2018-0174", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8a05653b-0267-4162-9b59-6bdcb534267d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 8.6 (HIGH) | EPSS: 0.07608 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0174", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0174"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0174"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...", "cve_id": "CVE-2018-0174", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.07608, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9437, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0174", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c544ed10-bf7e-46f1-ae34-2a55235971ba", "vulnerability": {"vulnId": "CVE-2012-0507", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c544ed10-bf7e-46f1-ae34-2a55235971ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.98113 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0507", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0507"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0507"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and...", "cve_id": "CVE-2012-0507", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98113, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99912, "used_in_malware": "yes", "vulnerability_id": "CVE-2012-0507", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "90208db2-15ad-4894-8475-3cbe817b2516", "vulnerability": {"vulnId": "CVE-2016-8562", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "90208db2-15ad-4894-8475-3cbe817b2516", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under... | Affected: Siemens / SIMATIC CP 1543-1, SIPLUS NET CP 1543-1 | CVSS: 7.5 (HIGH) | EPSS: 0.0361 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-8562", "url": "https://www.cve.org/CVERecord?id=CVE-2016-8562"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-8562"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under...", "cve_id": "CVE-2016-8562", "vendor": "Siemens", "ghsa_id": null, "product": "SIMATIC CP 1543-1, SIPLUS NET CP 1543-1", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0361, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89117, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-8562", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "434e21f5-0b1d-4d9e-8e41-1d36d8c03d92", "vulnerability": {"vulnId": "CVE-2017-6743", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "434e21f5-0b1d-4d9e-8e41-1d36d8c03d92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... | Affected: Cisco, IntelliShield / IOS, Universal Product | CVSS: 8.8 (HIGH) | EPSS: 0.10855 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6743", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6743"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6743"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...", "cve_id": "CVE-2017-6743", "vendor": "Cisco, IntelliShield", "ghsa_id": null, "product": "IOS, Universal Product", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10855, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95732, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6743", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ba9bdd68-929e-4af0-8656-48f62140d1f5", "vulnerability": {"vulnId": "CVE-2018-0167", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ba9bdd68-929e-4af0-8656-48f62140d1f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and... | Affected: Cisco / Cisco IOS, IOS XE, and IOS XR | CVSS: 8.8 (HIGH) | EPSS: 0.03354 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0167", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0167"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0167"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and...", "cve_id": "CVE-2018-0167", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS, IOS XE, and IOS XR", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03354, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88297, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0167", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "97ad545b-309e-4362-9b6b-b5b2ae5c8179", "vulnerability": {"vulnId": "CVE-2018-8298", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "97ad545b-309e-4362-9b6b-b5b2ae5c8179", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka \"Scripting Engine... | Affected: Microsoft / ChakraCore | CVSS: 7.5 (HIGH) | EPSS: 0.74521 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8298", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8298"}, {"id": "GHSA-WGW2-WWQ8-C7WF", "url": "https://github.com/advisories/GHSA-WGW2-WWQ8-C7WF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8298"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka \"Scripting Engine...", "cve_id": "CVE-2018-8298", "vendor": "Microsoft", "ghsa_id": "GHSA-WGW2-WWQ8-C7WF", "product": "ChakraCore", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.74521, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99485, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8298", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0cd9491e-b9ef-4db4-9834-ad7b33401662", "vulnerability": {"vulnId": "CVE-2009-3129", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0cd9491e-b9ef-4db4-9834-ad7b33401662", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel... | Affected: Microsoft / Office Excel | CVSS: 7.8 (HIGH) | EPSS: 0.84034 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-3129", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3129"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-3129"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel...", "cve_id": "CVE-2009-3129", "vendor": "Microsoft", "ghsa_id": null, "product": "Office Excel", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.84034, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99687, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-3129", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c4836ded-e9ac-453f-98d9-b9ebc2e904f7", "vulnerability": {"vulnId": "CVE-2015-2590", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c4836ded-e9ac-453f-98d9-b9ebc2e904f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.25469 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2590", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2590"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2590"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect...", "cve_id": "CVE-2015-2590", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.25469, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97892, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2590", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5024e965-22e1-4d7a-a2d6-3f5f2a100e44", "vulnerability": {"vulnId": "CVE-2016-0099", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5024e965-22e1-4d7a-a2d6-3f5f2a100e44", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.37045 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0099", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0099"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0099"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012...", "cve_id": "CVE-2016-0099", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.37045, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98473, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-0099", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e2382c7b-47cd-4cdc-a805-47f3d0e7e35a", "vulnerability": {"vulnId": "CVE-2016-4117", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e2382c7b-47cd-4cdc-a805-47f3d0e7e35a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.94354 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4117", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4117"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4117"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in...", "cve_id": "CVE-2016-4117", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94354, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9985, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4117", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c454b3ae-3d67-42ff-b89c-831f24b3f458", "vulnerability": {"vulnId": "CVE-2017-12234", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c454b3ae-3d67-42ff-b89c-831f24b3f458", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an... | Affected: Cisco / Cisco IOS | CVSS: 7.5 (HIGH) | EPSS: 0.0707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12234", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12234"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12234"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an...", "cve_id": "CVE-2017-12234", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12234", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0e4ac81-ffc9-4c7c-a55b-2b10030292ad", "vulnerability": {"vulnId": "CVE-2017-12235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b0e4ac81-ffc9-4c7c-a55b-2b10030292ad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an... | Affected: Cisco / Cisco IOS | CVSS: 7.5 (HIGH) | EPSS: 0.0707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12235", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12235"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an...", "cve_id": "CVE-2017-12235", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "64d0a8da-1ab8-45c5-9a8b-f3c2657e78d0", "vulnerability": {"vulnId": "CVE-2011-1889", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "64d0a8da-1ab8-45c5-9a8b-f3c2657e78d0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute... | Affected: Microsoft / Forefront Threat Management Gateway 2010 | CVSS: 9.8 (CRITICAL) | EPSS: 0.4902 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-1889", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1889"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1889"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute...", "cve_id": "CVE-2011-1889", "vendor": "Microsoft", "ghsa_id": null, "product": "Forefront Threat Management Gateway 2010", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.4902, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98848, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1889", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f6d09e6-911e-4d2c-baf3-3678b0a6fb50", "vulnerability": {"vulnId": "CVE-2014-4114", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5f6d09e6-911e-4d2c-baf3-3678b0a6fb50", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.81628 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-4114", "url": "https://www.cve.org/CVERecord?id=CVE-2014-4114"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-4114"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and...", "cve_id": "CVE-2014-4114", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.81628, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-4114", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9ec1686b-d5ae-474d-9dad-0d79dc4eb74f", "vulnerability": {"vulnId": "CVE-2016-7855", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9ec1686b-d5ae-474d-9dad-0d79dc4eb74f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers... | Affected: Adobe / Flash Player | CVSS: 8.8 (HIGH) | EPSS: 0.25198 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7855", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7855"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7855"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers...", "cve_id": "CVE-2016-7855", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.25198, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97875, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7855", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aabf6730-81e1-4e63-87c5-4bd20edf78e9", "vulnerability": {"vulnId": "CVE-2022-20700", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "aabf6730-81e1-4e63-87c5-4bd20edf78e9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 10.0 (CRITICAL) | EPSS: 0.05655 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20700", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20700"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20700"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV Series Routers Vulnerabilities", "cve_id": "CVE-2022-20700", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.05655, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20700", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "52f7cd2b-bd89-4872-a8aa-f085fb6dfa5e", "vulnerability": {"vulnId": "CVE-2012-1535", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "52f7cd2b-bd89-4872-a8aa-f085fb6dfa5e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote... | Affected: Adobe / Flash Player | CVSS: 7.8 (HIGH) | EPSS: 0.70384 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1535", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1535"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1535"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote...", "cve_id": "CVE-2012-1535", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.70384, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99369, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1535", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3e8a7068-8ef3-4e2a-9a04-ac3ddd84ab42", "vulnerability": {"vulnId": "CVE-2015-2545", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3e8a7068-8ef3-4e2a-9a04-ac3ddd84ab42", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.85937 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2545", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2545"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2545"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka...", "cve_id": "CVE-2015-2545", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.85937, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99724, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2545", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9a5004f8-e2bb-4db5-835c-687d589aa014", "vulnerability": {"vulnId": "CVE-2017-0001", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9a5004f8-e2bb-4db5-835c-687d589aa014", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server... | Affected: Microsoft / Windows GDI | CVSS: 7.8 (HIGH) | EPSS: 0.03114 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0001", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0001"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0001"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server...", "cve_id": "CVE-2017-0001", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows GDI", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03114, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87348, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0001", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "37c8a6c8-28f7-45ad-90ee-f1c5173260f8", "vulnerability": {"vulnId": "CVE-2017-12240", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "37c8a6c8-28f7-45ad-90ee-f1c5173260f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated,... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 9.8 (CRITICAL) | EPSS: 0.13773 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12240", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12240"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12240"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated,...", "cve_id": "CVE-2017-12240", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.13773, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96403, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12240", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6f879ed3-eb29-4fb9-98a0-f9dadfa155f7", "vulnerability": {"vulnId": "CVE-2018-0161", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6f879ed3-eb29-4fb9-98a0-f9dadfa155f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst... | Affected: Cisco / Cisco IOS | CVSS: 6.3 (MEDIUM) | EPSS: 0.04116 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0161", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0161"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0161"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst...", "cve_id": "CVE-2018-0161", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 6.3, "epss_score": 0.04116, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90465, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0161", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bd4b5a8a-fe8d-4d63-b279-b2a140e47650", "vulnerability": {"vulnId": "CVE-2018-0180", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bd4b5a8a-fe8d-4d63-b279-b2a140e47650", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to... | Affected: Cisco / Cisco IOS | CVSS: 5.9 (MEDIUM) | EPSS: 0.04935 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0180", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0180"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0180"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...", "cve_id": "CVE-2018-0180", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.04935, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91869, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0180", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ba234185-ed84-479e-9d63-e21b97499d74", "vulnerability": {"vulnId": "CVE-2019-1652", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ba234185-ed84-479e-9d63-e21b97499d74", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 7.2 (HIGH) | EPSS: 0.95923 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1652", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1652"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1652"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability", "cve_id": "CVE-2019-1652", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.95923, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99873, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1652", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b8cfbea-72eb-427a-9cac-36caeeeb9c57", "vulnerability": {"vulnId": "CVE-2012-4681", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9b8cfbea-72eb-427a-9cac-36caeeeb9c57", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute... | Affected: Oracle / Java SE | CVSS: 9.8 (CRITICAL) | EPSS: 0.98536 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-4681", "url": "https://www.cve.org/CVERecord?id=CVE-2012-4681"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-4681"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute...", "cve_id": "CVE-2012-4681", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98536, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9992, "used_in_malware": "yes", "vulnerability_id": "CVE-2012-4681", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e6bd9610-7bf9-4f46-84f1-181ef7c6e453", "vulnerability": {"vulnId": "CVE-2013-1675", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e6bd9610-7bf9-4f46-84f1-181ef7c6e453", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly... | Affected: Mozilla / Firefox, Firefox ESR, Thunderbird, Thunderbird ESR | CVSS: 6.5 (MEDIUM) | EPSS: 0.06696 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-1675", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1675"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1675"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly...", "cve_id": "CVE-2013-1675", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Firefox ESR, Thunderbird, Thunderbird ESR", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.06696, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93708, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1675", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6816dc7c-2a97-4274-aed6-74e2d362bb26", "vulnerability": {"vulnId": "CVE-2014-0496", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6816dc7c-2a97-4274-aed6-74e2d362bb26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to... | Affected: Adobe / Reader and Acrobat | CVSS: 8.8 (HIGH) | EPSS: 0.3998 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-0496", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0496"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0496"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to...", "cve_id": "CVE-2014-0496", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.3998, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98588, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0496", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e8804e67-4c41-4c16-a348-00e891d4f4cd", "vulnerability": {"vulnId": "CVE-2015-3043", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e8804e67-4c41-4c16-a348-00e891d4f4cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers... | Affected: Adobe / Flash Player | CVSS: 9.8 (CRITICAL) | EPSS: 0.73862 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-3043", "url": "https://www.cve.org/CVERecord?id=CVE-2015-3043"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-3043"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers...", "cve_id": "CVE-2015-3043", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.73862, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99467, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-3043", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a88a345-01fb-4ba5-8731-d55f5db77fe7", "vulnerability": {"vulnId": "CVE-2017-11826", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6a88a345-01fb-4ba5-8731-d55f5db77fe7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word... | Affected: Microsoft / Microsoft Office | CVSS: 7.8 (HIGH) | EPSS: 0.81158 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-11826", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11826"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11826"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word...", "cve_id": "CVE-2017-11826", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.81158, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99626, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-11826", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bbdf41f1-1518-4456-9551-396218d45d56", "vulnerability": {"vulnId": "CVE-2017-12319", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bbdf41f1-1518-4456-9551-396218d45d56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an... | Affected: Cisco / Cisco IOS XE | CVSS: 5.9 (MEDIUM) | EPSS: 0.05243 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12319", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12319"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12319"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an...", "cve_id": "CVE-2017-12319", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.05243, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92272, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12319", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f9c76466-1475-4d1a-b861-deb05c8a9a5d", "vulnerability": {"vulnId": "CVE-2017-6627", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f9c76466-1475-4d1a-b861-deb05c8a9a5d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote... | Affected: Cisco / Cisco IOS and Cisco IOS XE | CVSS: 7.5 (HIGH) | EPSS: 0.06158 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6627", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6627"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6627"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote...", "cve_id": "CVE-2017-6627", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and Cisco IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.06158, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9326, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6627", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a54e41ef-a95c-4ad8-be60-77174a0e64c9", "vulnerability": {"vulnId": "CVE-2018-0151", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a54e41ef-a95c-4ad8-be60-77174a0e64c9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 9.8 (CRITICAL) | EPSS: 0.14197 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0151", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0151"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0151"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote...", "cve_id": "CVE-2018-0151", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14197, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96478, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0151", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6faaaa8c-4e2c-4e86-9868-d7d129a8b22b", "vulnerability": {"vulnId": "CVE-2013-5065", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6faaaa8c-4e2c-4e86-9868-d7d129a8b22b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application,... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.34651 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-5065", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5065"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5065"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application,...", "cve_id": "CVE-2013-5065", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.34651, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98378, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5065", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "68b8b150-c051-4977-a9f6-34677c84a123", "vulnerability": {"vulnId": "CVE-2017-12233", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "68b8b150-c051-4977-a9f6-34677c84a123", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an... | Affected: Cisco / Cisco IOS | CVSS: 7.5 (HIGH) | EPSS: 0.0707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12233", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12233"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12233"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an...", "cve_id": "CVE-2017-12233", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12233", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d6331a3d-ac59-4953-be12-d6afff27fc7c", "vulnerability": {"vulnId": "CVE-2017-12237", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d6331a3d-ac59-4953-be12-d6afff27fc7c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 7.5 (HIGH) | EPSS: 0.0707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12237", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12237"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12237"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow...", "cve_id": "CVE-2017-12237", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94019, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12237", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a8bc5d8f-7448-462a-9e34-08eeebd8b675", "vulnerability": {"vulnId": "CVE-2017-8540", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a8bc5d8f-7448-462a-9e34-08eeebd8b675", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1,... | Affected: Microsoft / Malware Protection Engine | CVSS: 7.8 (HIGH) | EPSS: 0.71874 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-8540", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8540"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8540"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1,...", "cve_id": "CVE-2017-8540", "vendor": "Microsoft", "ghsa_id": null, "product": "Malware Protection Engine", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.71874, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99411, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8540", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "698820e2-7fcd-4806-a187-3d69a3786514", "vulnerability": {"vulnId": "CVE-2018-0159", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "698820e2-7fcd-4806-a187-3d69a3786514", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 7.5 (HIGH) | EPSS: 0.0687 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0159", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0159"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0159"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software...", "cve_id": "CVE-2018-0159", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0687, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93854, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0159", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4a9b2aba-c48a-4b20-aab7-361de322b6d7", "vulnerability": {"vulnId": "CVE-2015-4902", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4a9b2aba-c48a-4b20-aab7-361de322b6d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to... | Affected: Oracle / Java SE | CVSS: 5.3 (MEDIUM) | EPSS: 0.13603 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-4902", "url": "https://www.cve.org/CVERecord?id=CVE-2015-4902"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-4902"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to...", "cve_id": "CVE-2015-4902", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.13603, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96357, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-4902", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06aaf789-c395-41c2-a1ee-f185375c8fea", "vulnerability": {"vulnId": "CVE-2017-12231", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "06aaf789-c395-41c2-a1ee-f185375c8fea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an... | Affected: Cisco / Cisco IOS | CVSS: 7.5 (HIGH) | EPSS: 0.0707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12231", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12231"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12231"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an...", "cve_id": "CVE-2017-12231", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94019, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12231", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b1ded60a-658b-4e76-a4d7-f3c5a67b5ab8", "vulnerability": {"vulnId": "CVE-2017-6737", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b1ded60a-658b-4e76-a4d7-f3c5a67b5ab8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely... | Affected: Cisco / IOS | CVSS: 8.8 (HIGH) | EPSS: 0.4524 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6737", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6737"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6737"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...", "cve_id": "CVE-2017-6737", "vendor": "Cisco", "ghsa_id": null, "product": "IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.4524, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98751, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6737", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b6e1bac0-0a9f-4d79-a18f-727df92f67c1", "vulnerability": {"vulnId": "CVE-2018-0158", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b6e1bac0-0a9f-4d79-a18f-727df92f67c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 8.6 (HIGH) | EPSS: 0.0719 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0158", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0158"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0158"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an...", "cve_id": "CVE-2018-0158", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.0719, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94116, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0158", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "56b75799-8d80-4b3a-b2f0-8dd15b90b063", "vulnerability": {"vulnId": "CVE-2019-16928", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "56b75799-8d80-4b3a-b2f0-8dd15b90b063", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in... | Affected: Exim / Exim | CVSS: 9.8 (CRITICAL) | EPSS: 0.41638 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-16928", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16928"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16928"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in...", "cve_id": "CVE-2019-16928", "vendor": "Exim", "ghsa_id": null, "product": "Exim", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.41638, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98643, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16928", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5da2c556-893d-4b87-8e16-389a29cbd08c", "vulnerability": {"vulnId": "CVE-2016-7262", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5da2c556-893d-4b87-8e16-389a29cbd08c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow... | Affected: Microsoft / Excel | CVSS: 7.8 (HIGH) | EPSS: 0.57733 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7262", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7262"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7262"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow...", "cve_id": "CVE-2016-7262", "vendor": "Microsoft", "ghsa_id": null, "product": "Excel", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.57733, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9906, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7262", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d0f023b8-589e-4c4e-98e5-fffb0193fada", "vulnerability": {"vulnId": "CVE-2017-12238", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d0f023b8-589e-4c4e-98e5-fffb0193fada", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow... | Affected: Cisco / Cisco IOS | CVSS: 6.5 (MEDIUM) | EPSS: 0.02017 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12238", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12238"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12238"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow...", "cve_id": "CVE-2017-12238", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.02017, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.802, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-12238", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "85e407dd-44f0-4afa-b8d8-08e2a06f2691", "vulnerability": {"vulnId": "CVE-2017-6738", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "85e407dd-44f0-4afa-b8d8-08e2a06f2691", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... | Affected: Cisco / IOS, Cisco IOS XE Software | CVSS: 8.8 (HIGH) | EPSS: 0.10855 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6738", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6738"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6738"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...", "cve_id": "CVE-2017-6738", "vendor": "Cisco", "ghsa_id": null, "product": "IOS, Cisco IOS XE Software", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10855, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6738", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f6d27170-38ab-4d39-ae68-124f7b206d4e", "vulnerability": {"vulnId": "CVE-2018-0173", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f6d27170-38ab-4d39-ae68-124f7b206d4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 8.6 (HIGH) | EPSS: 0.07608 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0173", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0173"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0173"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4...", "cve_id": "CVE-2018-0173", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.07608, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9437, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0173", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5dec83ba-b63e-45ca-874e-fe770e28c92a", "vulnerability": {"vulnId": "CVE-2018-8581", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5dec83ba-b63e-45ca-874e-fe770e28c92a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka \"Microsoft Exchange Server Elevation of Privilege Vulnerability.\"... | Affected: Microsoft / Microsoft Exchange Server | CVSS: 7.4 (HIGH) | EPSS: 0.27355 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8581", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8581"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8581"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka \"Microsoft Exchange Server Elevation of Privilege Vulnerability.\"...", "cve_id": "CVE-2018-8581", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.4, "epss_score": 0.27355, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98005, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8581", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aa16d39f-0d94-47c9-83e3-2f899a3567e3", "vulnerability": {"vulnId": "CVE-2017-6663", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "aa16d39f-0d94-47c9-83e3-2f899a3567e3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 6.5 (MEDIUM) | EPSS: 0.02117 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6663", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6663"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6663"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent...", "cve_id": "CVE-2017-6663", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.02117, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81167, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6663", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "25631695-f312-4d2f-ae12-332343829f44", "vulnerability": {"vulnId": "CVE-2017-6744", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "25631695-f312-4d2f-ae12-332343829f44", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... | Affected: Cisco, IntelliShield / IOS, Universal Product | CVSS: 8.8 (HIGH) | EPSS: 0.07292 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6744", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6744"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6744"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...", "cve_id": "CVE-2017-6744", "vendor": "Cisco, IntelliShield", "ghsa_id": null, "product": "IOS, Universal Product", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.07292, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94178, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6744", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "59f692d7-68a0-44b9-87aa-34c977d17b70", "vulnerability": {"vulnId": "CVE-2020-1938", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "59f692d7-68a0-44b9-87aa-34c977d17b70", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections... | Affected: Apache / Apache Tomcat | CVSS: 9.8 (CRITICAL) | EPSS: 0.9927 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1938", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1938"}, {"id": "GHSA-C9HW-WF7X-JP9J", "url": "https://github.com/advisories/GHSA-C9HW-WF7X-JP9J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1938"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections...", "cve_id": "CVE-2020-1938", "vendor": "Apache", "ghsa_id": "GHSA-C9HW-WF7X-JP9J", "product": "Apache Tomcat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9927, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99937, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1938", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3f7265fe-4091-4be3-8e49-b417c99c5ba3", "vulnerability": {"vulnId": "CVE-2021-41379", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3f7265fe-4091-4be3-8e49-b417c99c5ba3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Windows Installer Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 11 version 21H2, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 | CVSS: 5.5 (MEDIUM) | EPSS: 0.19452 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-41379", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41379"}, {"id": "GHSA-HXF7-QH53-96J5", "url": "https://github.com/advisories/GHSA-HXF7-QH53-96J5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41379"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Installer Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-41379", "vendor": "Microsoft", "ghsa_id": "GHSA-HXF7-QH53-96J5", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 11 version 21H2, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.19452, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97295, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-41379", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ea956a08-9843-4e53-8ec3-077dd2d7d1b8", "vulnerability": {"vulnId": "CVE-2022-20699", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ea956a08-9843-4e53-8ec3-077dd2d7d1b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 10.0 (CRITICAL) | EPSS: 0.72458 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20699", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20699"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20699"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV Series Routers Vulnerabilities", "cve_id": "CVE-2022-20699", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.72458, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99426, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20699", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4b10cf1a-b4c8-4b0d-80fe-5e50b7b6c0f8", "vulnerability": {"vulnId": "CVE-2017-6736", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4b10cf1a-b4c8-4b0d-80fe-5e50b7b6c0f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... | Affected: Cisco, IntelliShield / IOS, Universal Product | CVSS: 8.8 (HIGH) | EPSS: 0.70354 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6736", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6736"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6736"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...", "cve_id": "CVE-2017-6736", "vendor": "Cisco, IntelliShield", "ghsa_id": null, "product": "IOS, Universal Product", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.70354, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99369, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6736", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d6caced5-2d67-402d-8659-3af5153504ba", "vulnerability": {"vulnId": "CVE-2017-6739", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d6caced5-2d67-402d-8659-3af5153504ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely... | Affected: IntelliShield / Universal Product | CVSS: 8.8 (HIGH) | EPSS: 0.10855 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6739", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6739"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6739"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...", "cve_id": "CVE-2017-6739", "vendor": "IntelliShield", "ghsa_id": null, "product": "Universal Product", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10855, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6739", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "14756526-ce80-4141-a18a-a7f8d799f61f", "vulnerability": {"vulnId": "CVE-2018-0179", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "14756526-ce80-4141-a18a-a7f8d799f61f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to... | Affected: Cisco / Cisco IOS | CVSS: 5.9 (MEDIUM) | EPSS: 0.04935 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0179", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0179"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0179"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...", "cve_id": "CVE-2018-0179", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 5.9, "epss_score": 0.04935, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91869, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0179", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "254c10e5-8e78-4bff-89dd-cba913ec9aa9", "vulnerability": {"vulnId": "CVE-2022-20703", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "254c10e5-8e78-4bff-89dd-cba913ec9aa9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 10.0 (CRITICAL) | EPSS: 0.09203 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20703", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20703"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20703"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV Series Routers Vulnerabilities", "cve_id": "CVE-2022-20703", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.09203, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95191, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20703", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7e5743d7-86d7-4375-afae-9774f7352362", "vulnerability": {"vulnId": "CVE-2017-6740", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7e5743d7-86d7-4375-afae-9774f7352362", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... | Affected: Cisco, IntelliShield / IOS, Universal Product | CVSS: 8.8 (HIGH) | EPSS: 0.111 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6740", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6740"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6740"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...", "cve_id": "CVE-2017-6740", "vendor": "Cisco, IntelliShield", "ghsa_id": null, "product": "IOS, Universal Product", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.111, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95804, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6740", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "655ec0fa-b2bc-48f5-9c31-19d47811b7b8", "vulnerability": {"vulnId": "CVE-2020-11899", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "655ec0fa-b2bc-48f5-9c31-19d47811b7b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | Affected: Treck / TCP/IP stack | CVSS: 5.4 (MEDIUM) | EPSS: 0.18564 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11899", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11899"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11899"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.", "cve_id": "CVE-2020-11899", "vendor": "Treck", "ghsa_id": null, "product": "TCP/IP stack", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 5.4, "epss_score": 0.18564, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97175, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11899", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0c2d778-6cdc-448e-b966-3f9a05df7590", "vulnerability": {"vulnId": "CVE-2018-0172", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b0c2d778-6cdc-448e-b966-3f9a05df7590", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 8.6 (HIGH) | EPSS: 0.0782 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0172", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0172"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0172"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...", "cve_id": "CVE-2018-0172", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.0782, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94495, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0172", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fa5c1ee5-a8f3-43c4-aaac-e7587b522831", "vulnerability": {"vulnId": "CVE-2022-20708", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fa5c1ee5-a8f3-43c4-aaac-e7587b522831", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV Series Routers Vulnerabilities | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 10.0 (CRITICAL) | EPSS: 0.14863 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-20708", "url": "https://www.cve.org/CVERecord?id=CVE-2022-20708"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-20708"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV Series Routers Vulnerabilities", "cve_id": "CVE-2022-20708", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.14863, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96599, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-20708", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8a4ef864-dbb4-4dbe-8644-78190951b91f", "vulnerability": {"vulnId": "CVE-2015-1701", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8a4ef864-dbb4-4dbe-8644-78190951b91f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.55923 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1701", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1701"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1701"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges...", "cve_id": "CVE-2015-1701", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.55923, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99019, "used_in_malware": "yes", "vulnerability_id": "CVE-2015-1701", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7677c0fa-05b3-48c3-8a80-065ffb010832", "vulnerability": {"vulnId": "CVE-2010-0188", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7677c0fa-05b3-48c3-8a80-065ffb010832", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service... | Affected: Adobe / Reader and Acrobat | CVSS: 7.8 (HIGH) | EPSS: 0.88246 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-0188", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0188"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0188"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service...", "cve_id": "CVE-2010-0188", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.88246, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99767, "used_in_malware": "yes", "vulnerability_id": "CVE-2010-0188", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f007451-b12c-461a-b83e-7f636c259bb8", "vulnerability": {"vulnId": "CVE-2013-0640", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2f007451-b12c-461a-b83e-7f636c259bb8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a... | Affected: Adobe / Reader and Acrobat | CVSS: 7.8 (HIGH) | EPSS: 0.86927 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0640", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0640"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0640"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a...", "cve_id": "CVE-2013-0640", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.86927, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99743, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0640", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6367cb29-7bad-4e7b-9d0c-93052f6ce01d", "vulnerability": {"vulnId": "CVE-2013-0632", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6367cb29-7bad-4e7b-9d0c-93052f6ce01d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary... | Affected: Adobe / ColdFusion | CVSS: 9.8 (CRITICAL) | EPSS: 0.93603 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-0632", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0632"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0632"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary...", "cve_id": "CVE-2013-0632", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93603, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99841, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0632", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "63e9bdfc-995a-468a-b4a4-f5585ca0d974", "vulnerability": {"vulnId": "CVE-2009-1123", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-03-03T01:00:00+01:00"}, "gcve": {"object_uuid": "63e9bdfc-995a-468a-b4a4-f5585ca0d974", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-03-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-03-03T00:00:00+00:00"}, "scope": {"notes": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.04878 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-1123", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1123"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1123"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate...", "cve_id": "CVE-2009-1123", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-03-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04878, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91784, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1123", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a25ce444-a430-4733-9f4e-20cca6923dd6", "vulnerability": {"vulnId": "CVE-2022-24288", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-25T09:30:16+01:00"}, "gcve": {"object_uuid": "a25ce444-a430-4733-9f4e-20cca6923dd6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-25T08:30:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-25T08:30:16+00:00"}, "scope": {"notes": "Apache Airflow: RCE in example DAGs | Affected: Apache / Apache Airflow | CVSS: 8.8 (HIGH) | EPSS: 0.7788 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-24288", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24288"}, {"id": "GHSA-3V7G-4PG3-7R6J", "url": "https://github.com/advisories/GHSA-3V7G-4PG3-7R6J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24288"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Airflow: RCE in example DAGs", "cve_id": "CVE-2022-24288", "vendor": "Apache", "ghsa_id": "GHSA-3V7G-4PG3-7R6J", "product": "Apache Airflow", "added_date": "2022-02-25T08:30:16.000Z", "cvss_score": 8.8, "epss_score": 0.7788, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9956, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24288", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a4704201-76f0-4712-b193-2c20c72b4f06", "vulnerability": {"vulnId": "CVE-2014-6352", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-25T01:00:00+01:00"}, "gcve": {"object_uuid": "a4704201-76f0-4712-b193-2c20c72b4f06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.77485 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-6352", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6352"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6352"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and...", "cve_id": "CVE-2014-6352", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-02-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.77485, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99549, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6352", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "830a5437-6910-462d-a693-b4ab6cdf102a", "vulnerability": {"vulnId": "CVE-2022-24682", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-25T01:00:00+01:00"}, "gcve": {"object_uuid": "830a5437-6910-462d-a693-b4ab6cdf102a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-25T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild... | Affected: Zimbra / Collaboration Suite | CVSS: 6.1 (MEDIUM) | EPSS: 0.30931 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24682", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24682"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24682"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild...", "cve_id": "CVE-2022-24682", "vendor": "Zimbra", "ghsa_id": null, "product": "Collaboration Suite", "added_date": "2022-02-25T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.30931, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9821, "used_in_malware": "yes", "vulnerability_id": "CVE-2022-24682", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a49080c2-ec78-4845-b822-8faa4e7f91dc", "vulnerability": {"vulnId": "CVE-2017-0222", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-25T01:00:00+01:00"}, "gcve": {"object_uuid": "a49080c2-ec78-4845-b822-8faa4e7f91dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-25T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka \"Internet Explorer Memory Corruption... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.29645 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0222", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0222"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0222"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka \"Internet Explorer Memory Corruption...", "cve_id": "CVE-2017-0222", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-02-25T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.29645, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98143, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0222", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ddbdc2e2-3248-4bc5-981b-936ed6b28fbf", "vulnerability": {"vulnId": "CVE-2017-8570", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-25T01:00:00+01:00"}, "gcve": {"object_uuid": "ddbdc2e2-3248-4bc5-981b-936ed6b28fbf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-25T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-25T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka \"Microsoft Office Remote Code... | Affected: Microsoft / Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016. | CVSS: 7.8 (HIGH) | EPSS: 0.89889 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-8570", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8570"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8570"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka \"Microsoft Office Remote Code...", "cve_id": "CVE-2017-8570", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, and Microsoft Office 2016.", "added_date": "2022-02-25T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.89889, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8570", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2b465482-7d41-47ee-a9a4-e37ae1269a71", "vulnerability": {"vulnId": "CVE-2022-25075", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-22T23:44:07+01:00"}, "gcve": {"object_uuid": "2b465482-7d41-47ee-a9a4-e37ae1269a71", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-22T22:44:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-22T22:44:07+00:00"}, "scope": {"notes": "TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the \"Main\" function. This vulnerability allows... | Affected: TOTOLink / A3000RU | CVSS: 9.8 (CRITICAL) | EPSS: 0.56248 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-25075", "url": "https://www.cve.org/CVERecord?id=CVE-2022-25075"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-25075"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the \"Main\" function. This vulnerability allows...", "cve_id": "CVE-2022-25075", "vendor": "TOTOLink", "ghsa_id": null, "product": "A3000RU", "added_date": "2022-02-22T22:44:07.000Z", "cvss_score": 9.8, "epss_score": 0.56248, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99025, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-25075", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "35858339-abab-4ab8-900a-a20114ac0338", "vulnerability": {"vulnId": "CVE-2022-23131", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-22T01:00:00+01:00"}, "gcve": {"object_uuid": "35858339-abab-4ab8-900a-a20114ac0338", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-22T00:00:00+00:00"}, "scope": {"notes": "Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML | Affected: Zabbix / Frontend | CVSS: 9.1 (CRITICAL) | EPSS: 0.95683 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-23131", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23131"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23131"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML", "cve_id": "CVE-2022-23131", "vendor": "Zabbix", "ghsa_id": null, "product": "Frontend", "added_date": "2022-02-22T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.95683, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99871, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23131", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b27c74af-1bd5-4703-9c32-898ad813ec7a", "vulnerability": {"vulnId": "CVE-2022-23134", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-22T01:00:00+01:00"}, "gcve": {"object_uuid": "b27c74af-1bd5-4703-9c32-898ad813ec7a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-22T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-22T00:00:00+00:00"}, "scope": {"notes": "Possible view of the setup pages by unauthenticated users if config file already exists | Affected: Zabbix / Frontend | CVSS: 3.7 (LOW) | EPSS: 0.9526 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-23134", "url": "https://www.cve.org/CVERecord?id=CVE-2022-23134"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-23134"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Possible view of the setup pages by unauthenticated users if config file already exists", "cve_id": "CVE-2022-23134", "vendor": "Zabbix", "ghsa_id": null, "product": "Frontend", "added_date": "2022-02-22T00:00:00.000Z", "cvss_score": 3.7, "epss_score": 0.9526, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99865, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-23134", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8b00328a-cd7e-4e23-8649-81611b8a1697", "vulnerability": {"vulnId": "CVE-2013-3906", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "8b00328a-cd7e-4e23-8649-81611b8a1697", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync... | Affected: Microsoft / Windows, Office, Office Compatibility Pack, Lync | CVSS: 7.8 (HIGH) | EPSS: 0.84853 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3906", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3906"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3906"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync...", "cve_id": "CVE-2013-3906", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Office, Office Compatibility Pack, Lync", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.84853, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99705, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3906", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "83a3bf0a-8c5c-4f7c-8f44-74f79e3fe207", "vulnerability": {"vulnId": "CVE-2018-15982", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "83a3bf0a-8c5c-4f7c-8f44-74f79e3fe207", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to... | Affected: Adobe / Flash Player | CVSS: 7.8 (HIGH) | EPSS: 0.89581 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-15982", "url": "https://www.cve.org/CVERecord?id=CVE-2018-15982"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-15982"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to...", "cve_id": "CVE-2018-15982", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.89581, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99785, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-15982", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d248a23b-e0d8-418b-b881-a1c16d935e33", "vulnerability": {"vulnId": "CVE-2018-8174", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "d248a23b-e0d8-418b-b881-a1c16d935e33", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka \"Windows VBScript Engine Remote... | Affected: Microsoft / Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | CVSS: 7.5 (HIGH) | EPSS: 0.88332 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8174", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8174"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8174"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka \"Windows VBScript Engine Remote...", "cve_id": "CVE-2018-8174", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.88332, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99768, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8174", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1fc9b189-7dac-4d15-abdd-bc029f7b51b8", "vulnerability": {"vulnId": "CVE-2019-0752", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "1fc9b189-7dac-4d15-abdd-bc029f7b51b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... | Affected: Microsoft / Internet Explorer 11, Internet Explorer 10 | CVSS: 7.5 (HIGH) | EPSS: 0.81551 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0752", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0752"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0752"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...", "cve_id": "CVE-2019-0752", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 11, Internet Explorer 10", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.81551, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99633, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-0752", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2bad94b2-0bb0-4e24-b09a-a9419342ccd8", "vulnerability": {"vulnId": "CVE-2022-0609", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "2bad94b2-0bb0-4e24-b09a-a9419342ccd8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.22933 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-0609", "url": "https://www.cve.org/CVERecord?id=CVE-2022-0609"}, {"id": "GHSA-VV6J-WW6X-54GX", "url": "https://github.com/advisories/GHSA-VV6J-WW6X-54GX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-0609"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted...", "cve_id": "CVE-2022-0609", "vendor": "Google", "ghsa_id": "GHSA-VV6J-WW6X-54GX", "product": "Chrome", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.22933, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97685, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-0609", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f058340-ad49-48e2-9ca1-86ec1062b069", "vulnerability": {"vulnId": "CVE-2022-24086", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "5f058340-ad49-48e2-9ca1-86ec1062b069", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "Adobe Commerce checkout improper input validation leads to remote code execution | Affected: Adobe / Magento Commerce | CVSS: 9.8 (CRITICAL) | EPSS: 0.99199 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-24086", "url": "https://www.cve.org/CVERecord?id=CVE-2022-24086"}, {"id": "GHSA-F8FV-F786-9933", "url": "https://github.com/advisories/GHSA-F8FV-F786-9933"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-24086"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Commerce checkout improper input validation leads to remote code execution", "cve_id": "CVE-2022-24086", "vendor": "Adobe", "ghsa_id": "GHSA-F8FV-F786-9933", "product": "Magento Commerce", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99199, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99934, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-24086", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bcaf4cf9-d611-453d-a030-168428ba45a6", "vulnerability": {"vulnId": "CVE-2014-1761", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "bcaf4cf9-d611-453d-a030-168428ba45a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word... | Affected: Microsoft / Word | CVSS: 7.8 (HIGH) | EPSS: 0.7746 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-1761", "url": "https://www.cve.org/CVERecord?id=CVE-2014-1761"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-1761"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word...", "cve_id": "CVE-2014-1761", "vendor": "Microsoft", "ghsa_id": null, "product": "Word", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.7746, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99547, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-1761", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a93aa7e9-3930-4016-8b1a-9e7a23e188f6", "vulnerability": {"vulnId": "CVE-2018-20250", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "a93aa7e9-3930-4016-8b1a-9e7a23e188f6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in... | Affected: Check Point Software Technologies / WinRAR | CVSS: 7.8 (HIGH) | EPSS: 0.96004 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-20250", "url": "https://www.cve.org/CVERecord?id=CVE-2018-20250"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-20250"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in...", "cve_id": "CVE-2018-20250", "vendor": "Check Point Software Technologies", "ghsa_id": null, "product": "WinRAR", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.96004, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99875, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-20250", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5a737233-b989-4012-967c-4c20ec41e867", "vulnerability": {"vulnId": "CVE-2017-9841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-15T01:00:00+01:00"}, "gcve": {"object_uuid": "5a737233-b989-4012-967c-4c20ec41e867", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-15T00:00:00+00:00"}, "scope": {"notes": "Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data... | Affected: PHPUnit / PHPUnit | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-9841", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9841"}, {"id": "GHSA-R7C9-C69M-RPH8", "url": "https://github.com/advisories/GHSA-R7C9-C69M-RPH8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data...", "cve_id": "CVE-2017-9841", "vendor": "PHPUnit", "ghsa_id": "GHSA-R7C9-C69M-RPH8", "product": "PHPUnit", "added_date": "2022-02-15T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99994, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e1b6959-d64a-464d-a7f7-14972409296e", "vulnerability": {"vulnId": "CVE-2022-22620", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-11T01:00:00+01:00"}, "gcve": {"object_uuid": "8e1b6959-d64a-464d-a7f7-14972409296e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-11T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1,... | Affected: Apple / Safari (v and ), macOS | CVSS: 8.8 (HIGH) | EPSS: 0.16342 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22620", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22620"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22620"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1,...", "cve_id": "CVE-2022-22620", "vendor": "Apple", "ghsa_id": null, "product": "Safari (v and ), macOS", "added_date": "2022-02-11T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.16342, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96871, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22620", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18f13ab2-3429-4bf7-b464-d69767db0f46", "vulnerability": {"vulnId": "CVE-2021-44892", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T17:05:25+01:00"}, "gcve": {"object_uuid": "18f13ab2-3429-4bf7-b464-d69767db0f46", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T16:05:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T16:05:25+00:00"}, "scope": {"notes": "A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain... | Affected: ThinkPHP / ThinkPHP 3.x.x | CVSS: 8.8 (HIGH) | EPSS: 0.02021 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-44892", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44892"}, {"id": "GHSA-75JP-87W2-C6X2", "url": "https://github.com/advisories/GHSA-75JP-87W2-C6X2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44892"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain...", "cve_id": "CVE-2021-44892", "vendor": "ThinkPHP", "ghsa_id": "GHSA-75JP-87W2-C6X2", "product": "ThinkPHP 3.x.x", "added_date": "2022-02-10T16:05:25.000Z", "cvss_score": 8.8, "epss_score": 0.02021, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80235, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44892", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fc811b9e-e86f-4495-b1aa-051899b8f022", "vulnerability": {"vulnId": "CVE-2020-0796", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "fc811b9e-e86f-4495-b1aa-051899b8f022", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests,... | Affected: Microsoft / Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation) | CVSS: 10.0 (CRITICAL) | EPSS: 0.9981 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0796", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0796"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0796"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests,...", "cve_id": "CVE-2020-0796", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation)", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.9981, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99958, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-0796", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "22726d57-58e8-4ec5-bba3-af6c843b8a09", "vulnerability": {"vulnId": "CVE-2017-10271", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "22726d57-58e8-4ec5-bba3-af6c843b8a09", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are... | Affected: Oracle / WebLogic Server | CVSS: 7.5 (HIGH) | EPSS: 0.9999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-10271", "url": "https://www.cve.org/CVERecord?id=CVE-2017-10271"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-10271"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are...", "cve_id": "CVE-2017-10271", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.9999, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99985, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-10271", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b30b7fb6-93b8-4673-a230-48829bd753bb", "vulnerability": {"vulnId": "CVE-2017-0262", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "b30b7fb6-93b8-4673-a230-48829bd753bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle... | Affected: Microsoft / Microsoft Office | CVSS: 7.8 (HIGH) | EPSS: 0.81005 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0262", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0262"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0262"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...", "cve_id": "CVE-2017-0262", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.81005, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99622, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0262", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e66f6fa7-9e06-423a-a75d-e595fa667d2f", "vulnerability": {"vulnId": "CVE-2017-0144", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e66f6fa7-9e06-423a-a75d-e595fa667d2f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... | Affected: Microsoft / Windows SMB | CVSS: 8.8 (HIGH) | EPSS: 0.9923 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0144", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0144"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0144"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...", "cve_id": "CVE-2017-0144", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows SMB", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.9923, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99936, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0144", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "663d6def-633c-49f1-8603-d3a3e4b06892", "vulnerability": {"vulnId": "CVE-2017-9791", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "663d6def-633c-49f1-8603-d3a3e4b06892", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the... | Affected: Apache / Apache Struts | CVSS: 9.8 (CRITICAL) | EPSS: 0.98908 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-9791", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9791"}, {"id": "GHSA-29RM-6752-GVWV", "url": "https://github.com/advisories/GHSA-29RM-6752-GVWV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9791"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the...", "cve_id": "CVE-2017-9791", "vendor": "Apache", "ghsa_id": "GHSA-29RM-6752-GVWV", "product": "Apache Struts", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98908, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99927, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9791", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d6234707-1851-4400-baab-2cc787ed35ab", "vulnerability": {"vulnId": "CVE-2017-0263", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "d6234707-1851-4400-baab-2cc787ed35ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT... | Affected: Microsoft / Microsoft Windows | CVSS: 7.8 (HIGH) | EPSS: 0.10034 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0263", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0263"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0263"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...", "cve_id": "CVE-2017-0263", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Windows", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10034, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95484, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-0263", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dc2aadb0-7990-46af-b5c4-8b6d588dbddf", "vulnerability": {"vulnId": "CVE-2021-36934", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "dc2aadb0-7990-46af-b5c4-8b6d588dbddf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "Windows Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1 | CVSS: 7.8 (HIGH) | EPSS: 0.67252 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36934", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36934"}, {"id": "GHSA-X4M2-PX5G-5Q55", "url": "https://github.com/advisories/GHSA-X4M2-PX5G-5Q55"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36934"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-36934", "vendor": "Microsoft", "ghsa_id": "GHSA-X4M2-PX5G-5Q55", "product": "Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.67252, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99284, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36934", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "57b76e00-4409-4676-ade3-dee196b22701", "vulnerability": {"vulnId": "CVE-2015-1635", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "57b76e00-4409-4676-ade3-dee196b22701", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote... | Affected: Microsoft / Windows | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1635", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1635"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1635"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote...", "cve_id": "CVE-2015-1635", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99998, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1635", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "75e6417e-5c27-4a8f-b8d8-28ec386da8a2", "vulnerability": {"vulnId": "CVE-2014-4404", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "75e6417e-5c27-4a8f-b8d8-28ec386da8a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged... | Affected: Apple / iOS, Apple TV | CVSS: 7.8 (HIGH) | EPSS: 0.48923 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-4404", "url": "https://www.cve.org/CVERecord?id=CVE-2014-4404"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-4404"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged...", "cve_id": "CVE-2014-4404", "vendor": "Apple", "ghsa_id": null, "product": "iOS, Apple TV", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.48923, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-4404", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "976c4afd-8468-47f1-b867-07a572763729", "vulnerability": {"vulnId": "CVE-2017-0145", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "976c4afd-8468-47f1-b867-07a572763729", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... | Affected: Microsoft / Windows SMB | CVSS: 8.8 (HIGH) | EPSS: 0.8985 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0145", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0145"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0145"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...", "cve_id": "CVE-2017-0145", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows SMB", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.8985, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99789, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0145", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e8be001a-3e4e-4bca-8bd8-4b09de2c24cb", "vulnerability": {"vulnId": "CVE-2017-8464", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e8be001a-3e4e-4bca-8bd8-4b09de2c24cb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT... | Affected: Microsoft / Windows Shell | CVSS: 8.8 (HIGH) | EPSS: 0.8992 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-8464", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8464"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8464"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...", "cve_id": "CVE-2017-8464", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Shell", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.8992, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99791, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8464", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ced12658-c70f-419b-9b3e-4a5de0fdfe8a", "vulnerability": {"vulnId": "CVE-2018-1000861", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "ced12658-c70f-419b-9b3e-4a5de0fdfe8a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in... | Affected: Jenkins / Jenkins | CVSS: 9.8 (CRITICAL) | EPSS: 0.98326 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-1000861", "url": "https://www.cve.org/CVERecord?id=CVE-2018-1000861"}, {"id": "GHSA-HHPM-5CP2-HG4X", "url": "https://github.com/advisories/GHSA-HHPM-5CP2-HG4X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-1000861"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in...", "cve_id": "CVE-2018-1000861", "vendor": "Jenkins", "ghsa_id": "GHSA-HHPM-5CP2-HG4X", "product": "Jenkins", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98326, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99916, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-1000861", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "81a83f56-2b6a-440c-b1f2-a6afa38c44ea", "vulnerability": {"vulnId": "CVE-2015-2051", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "81a83f56-2b6a-440c-b1f2-a6afa38c44ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a... | Affected: D-Link / DIR-645 Wired/Wireless Router | CVSS: 8.8 (HIGH) | EPSS: 0.97101 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-2051", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2051"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2051"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a...", "cve_id": "CVE-2015-2051", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-645 Wired/Wireless Router", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.97101, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99892, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2051", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "535fcb49-c68c-4a9c-949e-4bc9f0d4b54d", "vulnerability": {"vulnId": "CVE-2015-1130", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "535fcb49-c68c-4a9c-949e-4bc9f0d4b54d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via... | Affected: Apple / OS X | CVSS: 7.8 (HIGH) | EPSS: 0.09887 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1130", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1130"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1130"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via...", "cve_id": "CVE-2015-1130", "vendor": "Apple", "ghsa_id": null, "product": "OS X", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.09887, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95436, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1130", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0a35f4df-3fd9-43bd-8af5-92c01ddc3a06", "vulnerability": {"vulnId": "CVE-2016-3088", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-10T01:00:00+01:00"}, "gcve": {"object_uuid": "0a35f4df-3fd9-43bd-8af5-92c01ddc3a06", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-10T00:00:00+00:00"}, "scope": {"notes": "The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT... | Affected: Apache / ActiveMQ | CVSS: 9.8 (CRITICAL) | EPSS: 0.98518 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3088", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3088"}, {"id": "GHSA-RXQH-FC23-GXP2", "url": "https://github.com/advisories/GHSA-RXQH-FC23-GXP2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3088"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT...", "cve_id": "CVE-2016-3088", "vendor": "Apache", "ghsa_id": "GHSA-RXQH-FC23-GXP2", "product": "ActiveMQ", "added_date": "2022-02-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98518, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9992, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3088", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d42b7ca3-0a1a-4278-9c8f-e47ffdc0fcc1", "vulnerability": {"vulnId": "CVE-2022-21882", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-02-04T01:00:00+01:00"}, "gcve": {"object_uuid": "d42b7ca3-0a1a-4278-9c8f-e47ffdc0fcc1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-02-04T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-02-04T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2 | CVSS: 7.0 (HIGH) | EPSS: 0.59205 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-21882", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21882"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21882"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2022-21882", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2", "added_date": "2022-02-04T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.59205, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99091, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21882", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b205576b-2471-4eaa-af88-ffeefe000cb4", "vulnerability": {"vulnId": "CVE-2014-6271", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "b205576b-2471-4eaa-af88-ffeefe000cb4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to... | Affected: GNU / Bash | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-6271", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6271"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6271"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to...", "cve_id": "CVE-2014-6271", "vendor": "GNU", "ghsa_id": null, "product": "Bash", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6271", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "29df5568-247b-44bb-ba0b-e63153d0685b", "vulnerability": {"vulnId": "CVE-2022-22587", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "29df5568-247b-44bb-ba0b-e63153d0685b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3,... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.11638 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2022-22587", "url": "https://www.cve.org/CVERecord?id=CVE-2022-22587"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-22587"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3,...", "cve_id": "CVE-2022-22587", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.11638, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95929, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-22587", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ee22b0f0-ea49-48e1-a970-08127f5eced0", "vulnerability": {"vulnId": "CVE-2020-0787", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "ee22b0f0-ea49-48e1-a970-08127f5eced0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links,... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.42524 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0787", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0787"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0787"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links,...", "cve_id": "CVE-2020-0787", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.42524, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98667, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-0787", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "427dad03-e1c7-4a14-b762-3a6644ef3226", "vulnerability": {"vulnId": "CVE-2014-7169", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "427dad03-e1c7-4a14-b762-3a6644ef3226", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,... | Affected: GNU / Bash | CVSS: 9.8 (CRITICAL) | EPSS: 0.9994 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-7169", "url": "https://www.cve.org/CVERecord?id=CVE-2014-7169"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-7169"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,...", "cve_id": "CVE-2014-7169", "vendor": "GNU", "ghsa_id": null, "product": "Bash", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9994, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99972, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-7169", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0a2dba7-9c37-4744-82b7-94789d2da195", "vulnerability": {"vulnId": "CVE-2017-5689", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "b0a2dba7-9c37-4744-82b7-94789d2da195", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and... | Affected: Intel / Intel Active Mangement Technology, Intel Small Business Technology, Intel Standard Manageability | CVSS: 9.8 (CRITICAL) | EPSS: 0.92189 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-5689", "url": "https://www.cve.org/CVERecord?id=CVE-2017-5689"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-5689"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and...", "cve_id": "CVE-2017-5689", "vendor": "Intel", "ghsa_id": null, "product": "Intel Active Mangement Technology, Intel Small Business Technology, Intel Standard Manageability", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.92189, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99821, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-5689", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "294e5ad5-0005-48f5-8ffb-b3ac3b5693d9", "vulnerability": {"vulnId": "CVE-2021-20038", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "294e5ad5-0005-48f5-8ffb-b3ac3b5693d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated... | Affected: SonicWall / SonicWall SMA100 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99912 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20038", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20038"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20038"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated...", "cve_id": "CVE-2021-20038", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicWall SMA100", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99912, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99966, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-20038", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "68958e0f-bb82-47a7-9968-370bbac75b05", "vulnerability": {"vulnId": "CVE-2020-5722", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "68958e0f-bb82-47a7-9968-370bbac75b05", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker... | Affected: Grandstream / Grandstream UCM6200 Series | CVSS: 9.8 (CRITICAL) | EPSS: 0.84406 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5722", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5722"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5722"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker...", "cve_id": "CVE-2020-5722", "vendor": "Grandstream", "ghsa_id": null, "product": "Grandstream UCM6200 Series", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84406, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99693, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5722", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3a345f52-a572-472e-8414-9ae588fd9b57", "vulnerability": {"vulnId": "CVE-2014-1776", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-28T01:00:00+01:00"}, "gcve": {"object_uuid": "3a345f52-a572-472e-8414-9ae588fd9b57", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-28T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-28T00:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of... | Affected: Microsoft / Internet Explorer | CVSS: 9.8 (CRITICAL) | EPSS: 0.82682 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-1776", "url": "https://www.cve.org/CVERecord?id=CVE-2014-1776"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-1776"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of...", "cve_id": "CVE-2014-1776", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2022-01-28T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82682, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99658, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-1776", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e7d39a6a-3fd2-44c7-aebb-5f67c0ee1641", "vulnerability": {"vulnId": "CVE-2012-0391", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-21T01:00:00+01:00"}, "gcve": {"object_uuid": "e7d39a6a-3fd2-44c7-aebb-5f67c0ee1641", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-21T00:00:00+00:00"}, "scope": {"notes": "The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling... | Affected: Apache / Struts | CVSS: 9.8 (CRITICAL) | EPSS: 0.75599 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0391", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0391"}, {"id": "GHSA-4WRR-9H5R-M92W", "url": "https://github.com/advisories/GHSA-4WRR-9H5R-M92W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0391"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling...", "cve_id": "CVE-2012-0391", "vendor": "Apache", "ghsa_id": "GHSA-4WRR-9H5R-M92W", "product": "Struts", "added_date": "2022-01-21T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.75599, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99506, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0391", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2c3da21b-8a81-49ea-87e6-168adf150fdf", "vulnerability": {"vulnId": "CVE-2006-1547", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-21T01:00:00+01:00"}, "gcve": {"object_uuid": "2c3da21b-8a81-49ea-87e6-168adf150fdf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-21T00:00:00+00:00"}, "scope": {"notes": "ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a... | Affected: Apache / Struts | CVSS: 7.5 (HIGH) | EPSS: 0.54635 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2006-1547", "url": "https://www.cve.org/CVERecord?id=CVE-2006-1547"}, {"id": "GHSA-7QWV-CWGJ-C8RJ", "url": "https://github.com/advisories/GHSA-7QWV-CWGJ-C8RJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2006-1547"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a...", "cve_id": "CVE-2006-1547", "vendor": "Apache", "ghsa_id": "GHSA-7QWV-CWGJ-C8RJ", "product": "Struts", "added_date": "2022-01-21T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.54635, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98991, "used_in_malware": "unknown", "vulnerability_id": "CVE-2006-1547", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e9db8c40-53d0-45f7-8225-14bb9fd52a9b", "vulnerability": {"vulnId": "CVE-2018-8453", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-21T01:00:00+01:00"}, "gcve": {"object_uuid": "e9db8c40-53d0-45f7-8225-14bb9fd52a9b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-21T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k... | Affected: Microsoft / Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers | CVSS: 7.8 (HIGH) | EPSS: 0.70042 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8453", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8453"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8453"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k...", "cve_id": "CVE-2018-8453", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers", "added_date": "2022-01-21T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.70042, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9936, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-8453", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "13a2c183-1b7c-4d66-ae03-69d0e36f19eb", "vulnerability": {"vulnId": "CVE-2021-35247", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-21T01:00:00+01:00"}, "gcve": {"object_uuid": "13a2c183-1b7c-4d66-ae03-69d0e36f19eb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-21T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-21T00:00:00+00:00"}, "scope": {"notes": "Improper Input Validation Vulnerability in Serv-U | Affected: SolarWinds / Serv-U | CVSS: 4.3 (MEDIUM) | EPSS: 0.03453 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-35247", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35247"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35247"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper Input Validation Vulnerability in Serv-U", "cve_id": "CVE-2021-35247", "vendor": "SolarWinds", "ghsa_id": null, "product": "Serv-U", "added_date": "2022-01-21T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.03453, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88624, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35247", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6898e61c-8b3c-4ed8-977e-5750377b6534", "vulnerability": {"vulnId": "CVE-2020-14864", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "6898e61c-8b3c-4ed8-977e-5750377b6534", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported... | Affected: Oracle / Business Intelligence Enterprise Edition | CVSS: 7.5 (HIGH) | EPSS: 0.97233 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-14864", "url": "https://www.cve.org/CVERecord?id=CVE-2020-14864"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-14864"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...", "cve_id": "CVE-2020-14864", "vendor": "Oracle", "ghsa_id": null, "product": "Business Intelligence Enterprise Edition", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.97233, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99895, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-14864", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e62926d4-5b36-4b85-a07e-8bed3aa96935", "vulnerability": {"vulnId": "CVE-2021-25298", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "e62926d4-5b36-4b85-a07e-8bed3aa96935", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file... | Affected: Nagios / Nagios XI | CVSS: 8.8 (HIGH) | EPSS: 0.75148 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25298", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25298"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25298"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...", "cve_id": "CVE-2021-25298", "vendor": "Nagios", "ghsa_id": null, "product": "Nagios XI", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.75148, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99497, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25298", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "83c73aad-3df3-4a70-ab32-c9358a0a0324", "vulnerability": {"vulnId": "CVE-2021-33766", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "83c73aad-3df3-4a70-ab32-c9358a0a0324", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Information Disclosure Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 | CVSS: 7.3 (HIGH) | EPSS: 0.98136 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-33766", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33766"}, {"id": "GHSA-F9F4-96J3-5MVR", "url": "https://github.com/advisories/GHSA-F9F4-96J3-5MVR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33766"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Information Disclosure Vulnerability", "cve_id": "CVE-2021-33766", "vendor": "Microsoft", "ghsa_id": "GHSA-F9F4-96J3-5MVR", "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 7.3, "epss_score": 0.98136, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99913, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33766", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d4f3037-9b8b-4dc0-a690-f89525df519f", "vulnerability": {"vulnId": "CVE-2021-21315", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "6d4f3037-9b8b-4dc0-a690-f89525df519f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Command Injection Vulnerability | Affected: Sebhildebrandt / systeminformation | CVSS: 7.1 (HIGH) | EPSS: 0.90675 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21315", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21315"}, {"id": "GHSA-2M8V-572M-FF2V", "url": "https://github.com/advisories/GHSA-2M8V-572M-FF2V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21315"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection Vulnerability", "cve_id": "CVE-2021-21315", "vendor": "Sebhildebrandt", "ghsa_id": "GHSA-2M8V-572M-FF2V", "product": "systeminformation", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.90675, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99801, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21315", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3742bfd0-7050-4172-bcdd-ca45883b59f1", "vulnerability": {"vulnId": "CVE-2021-25297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "3742bfd0-7050-4172-bcdd-ca45883b59f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file... | Affected: Nagios / Nagios XI | CVSS: 8.8 (HIGH) | EPSS: 0.56659 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25297", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...", "cve_id": "CVE-2021-25297", "vendor": "Nagios", "ghsa_id": null, "product": "Nagios XI", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.56659, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99037, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "78e11389-a701-420d-9b7b-1a200fa2ebf4", "vulnerability": {"vulnId": "CVE-2020-13671", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "78e11389-a701-420d-9b7b-1a200fa2ebf4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension... | Affected: Drupal / Drupal Core | CVSS: 8.8 (HIGH) | EPSS: 0.3535 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-13671", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13671"}, {"id": "GHSA-68JC-V27H-VHMW", "url": "https://github.com/advisories/GHSA-68JC-V27H-VHMW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13671"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension...", "cve_id": "CVE-2020-13671", "vendor": "Drupal", "ghsa_id": "GHSA-68JC-V27H-VHMW", "product": "Drupal Core", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.3535, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98404, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13671", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e7ef3cd7-959e-4dbd-97da-850d4d9565d9", "vulnerability": {"vulnId": "CVE-2020-13927", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "e7ef3cd7-959e-4dbd-97da-850d4d9565d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to... | Affected: Apache / Apache Airflow | CVSS: 9.8 (CRITICAL) | EPSS: 0.99778 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-13927", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13927"}, {"id": "GHSA-HHX9-P69V-CX2J", "url": "https://github.com/advisories/GHSA-HHX9-P69V-CX2J"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13927"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to...", "cve_id": "CVE-2020-13927", "vendor": "Apache", "ghsa_id": "GHSA-HHX9-P69V-CX2J", "product": "Apache Airflow", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99778, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99954, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13927", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "108ea0da-ca20-4f9f-935c-eefc32caaeaf", "vulnerability": {"vulnId": "CVE-2021-40870", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "108ea0da-ca20-4f9f-935c-eefc32caaeaf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which... | Affected: Aviatrix / Controller | CVSS: 9.8 (CRITICAL) | EPSS: 0.93019 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40870", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40870"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40870"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which...", "cve_id": "CVE-2021-40870", "vendor": "Aviatrix", "ghsa_id": null, "product": "Controller", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93019, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99831, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40870", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "563bfa86-6f29-4d59-9504-92469d1037da", "vulnerability": {"vulnId": "CVE-2021-22991", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "563bfa86-6f29-4d59-9504-92469d1037da", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,... | Affected: F5 / BIG-IP | CVSS: 9.8 (CRITICAL) | EPSS: 0.61064 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22991", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22991"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22991"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,...", "cve_id": "CVE-2021-22991", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.61064, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99135, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22991", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e17e7aa-5125-4c33-9b16-bd871dc38b32", "vulnerability": {"vulnId": "CVE-2020-11978", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "6e17e7aa-5125-4c33-9b16-bd871dc38b32", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example... | Affected: Apache / Apache Airflow | CVSS: 8.8 (HIGH) | EPSS: 0.99189 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11978", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11978"}, {"id": "GHSA-RVMQ-4X66-Q7J3", "url": "https://github.com/advisories/GHSA-RVMQ-4X66-Q7J3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11978"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...", "cve_id": "CVE-2020-11978", "vendor": "Apache", "ghsa_id": "GHSA-RVMQ-4X66-Q7J3", "product": "Apache Airflow", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99189, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99934, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11978", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ac99a43a-121e-461a-8000-23b563f99bd3", "vulnerability": {"vulnId": "CVE-2021-25296", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "ac99a43a-121e-461a-8000-23b563f99bd3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file... | Affected: Nagios / Nagios XI | CVSS: 8.8 (HIGH) | EPSS: 0.72182 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-25296", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25296"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25296"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...", "cve_id": "CVE-2021-25296", "vendor": "Nagios", "ghsa_id": null, "product": "Nagios XI", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.72182, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99419, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25296", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b28c28e5-26fa-438a-b037-f444ef37c24e", "vulnerability": {"vulnId": "CVE-2021-21975", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "b28c28e5-26fa-438a-b037-f444ef37c24e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the... | Affected: VMware / VMware vRealize Operations | CVSS: 9.8 (CRITICAL) | EPSS: 0.7829 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21975", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21975"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21975"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...", "cve_id": "CVE-2021-21975", "vendor": "VMware", "ghsa_id": null, "product": "VMware vRealize Operations", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7829, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99569, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-21975", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b4b83e0d-360b-4cb5-a4bf-5d1892f12e97", "vulnerability": {"vulnId": "CVE-2021-32648", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-18T01:00:00+01:00"}, "gcve": {"object_uuid": "b4b83e0d-360b-4cb5-a4bf-5d1892f12e97", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-18T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-18T00:00:00+00:00"}, "scope": {"notes": "Account Takeover in Octobercms | Affected: October CMS / october | CVSS: 8.2 (HIGH) | EPSS: 0.90418 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-32648", "url": "https://www.cve.org/CVERecord?id=CVE-2021-32648"}, {"id": "GHSA-MXR5-MC97-63RC", "url": "https://github.com/advisories/GHSA-MXR5-MC97-63RC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-32648"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Account Takeover in Octobercms", "cve_id": "CVE-2021-32648", "vendor": "October CMS", "ghsa_id": "GHSA-MXR5-MC97-63RC", "product": "october", "added_date": "2022-01-18T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.90418, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99798, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-32648", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "028abab8-3ab4-44e4-8dcd-8ebe6fb2a89d", "vulnerability": {"vulnId": "CVE-2021-45422", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-13T19:15:03+01:00"}, "gcve": {"object_uuid": "028abab8-3ab4-44e4-8dcd-8ebe6fb2a89d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-13T18:15:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-13T18:15:03+00:00"}, "scope": {"notes": "Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process \"count\" parameter via... | Affected: Reprise / Reprise License Manager | CVSS: 6.1 (MEDIUM) | EPSS: 0.03241 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-45422", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45422"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45422"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process \"count\" parameter via...", "cve_id": "CVE-2021-45422", "vendor": "Reprise", "ghsa_id": null, "product": "Reprise License Manager", "added_date": "2022-01-13T18:15:03.000Z", "cvss_score": 6.1, "epss_score": 0.03241, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8786, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-45422", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "963ac5a5-fca7-4b45-bce5-1cdf96b254a7", "vulnerability": {"vulnId": "CVE-2022-21894", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-11T21:22:58+01:00"}, "gcve": {"object_uuid": "963ac5a5-fca7-4b45-bce5-1cdf96b254a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-11T20:22:58+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-11T20:22:58+00:00"}, "scope": {"notes": "Secure Boot Security Feature Bypass Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 4.4 (MEDIUM) | EPSS: 0.06567 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-21894", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21894"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21894"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Secure Boot Security Feature Bypass Vulnerability", "cve_id": "CVE-2022-21894", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 8.1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-01-11T20:22:58.000Z", "cvss_score": 4.4, "epss_score": 0.06567, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93616, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21894", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2f1e53ae-0811-4f75-b3fd-a60b926fa220", "vulnerability": {"vulnId": "CVE-2019-1579", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "2f1e53ae-0811-4f75-b3fd-a60b926fa220", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or... | Affected: Palo Alto Networks / Palo Alto Networks GlobalProtect Portal/Gateway Interface | CVSS: 8.1 (HIGH) | EPSS: 0.46239 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1579", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1579"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1579"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or...", "cve_id": "CVE-2019-1579", "vendor": "Palo Alto Networks", "ghsa_id": null, "product": "Palo Alto Networks GlobalProtect Portal/Gateway Interface", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.46239, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98778, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1579", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b2b6ed24-022c-42a8-828d-774e63e8392b", "vulnerability": {"vulnId": "CVE-2018-13383", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "b2b6ed24-022c-42a8-828d-774e63e8392b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy... | Affected: Fortinet / Fortinet FortiOS and FortiProxy | CVSS: 4.3 (MEDIUM) | EPSS: 0.33647 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-13383", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13383"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13383"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy...", "cve_id": "CVE-2018-13383", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS and FortiProxy", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.33647, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9834, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-13383", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a9e113be-6583-42ae-831b-1aba0eb9b12b", "vulnerability": {"vulnId": "CVE-2019-9670", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "a9e113be-6583-42ae-831b-1aba0eb9b12b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as... | Affected: Synacor / Zimbra Collaboration Suite | CVSS: 9.8 (CRITICAL) | EPSS: 0.99986 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-9670", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9670"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9670"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as...", "cve_id": "CVE-2019-9670", "vendor": "Synacor", "ghsa_id": null, "product": "Zimbra Collaboration Suite", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99986, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99983, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9670", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e29c2365-9711-403f-b7bf-614c8c6d6551", "vulnerability": {"vulnId": "CVE-2020-6572", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e29c2365-9711-403f-b7bf-614c8c6d6551", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.10586 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-6572", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6572"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6572"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.", "cve_id": "CVE-2020-6572", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10586, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95653, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6572", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8fff94e2-b5a5-4069-8c25-4cf102e11525", "vulnerability": {"vulnId": "CVE-2013-3900", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "8fff94e2-b5a5-4069-8c25-4cf102e11525", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "WinVerifyTrust Signature Validation Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 5.5 (MEDIUM) | EPSS: 0.44647 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3900", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3900"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3900"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WinVerifyTrust Signature Validation Vulnerability", "cve_id": "CVE-2013-3900", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows 11 version 21H2, Windows 10 Version 21H2, Windows 11 version 22H2, Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2025, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.44647, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98732, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3900", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72eefba3-38a3-4580-acdf-309dd3a84e88", "vulnerability": {"vulnId": "CVE-2021-22017", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "72eefba3-38a3-4580-acdf-309dd3a84e88", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network... | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation | CVSS: 5.3 (MEDIUM) | EPSS: 0.49177 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22017", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22017"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22017"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network...", "cve_id": "CVE-2021-22017", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.49177, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98851, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22017", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f40c39dd-16c0-4608-ae33-ea39baf1f3dc", "vulnerability": {"vulnId": "CVE-2018-13382", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "f40c39dd-16c0-4608-ae33-ea39baf1f3dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to... | Affected: Fortinet / Fortinet FortiOS, FortiProxy | CVSS: 9.1 (CRITICAL) | EPSS: 0.81691 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-13382", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13382"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13382"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to...", "cve_id": "CVE-2018-13382", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS, FortiProxy", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.81691, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99635, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-13382", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9ed3b5a3-9b75-4dbb-9373-31c7aa7339c7", "vulnerability": {"vulnId": "CVE-2021-36260", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "9ed3b5a3-9b75-4dbb-9373-31c7aa7339c7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the... | Affected: Hikvision / IP Camera | CVSS: 9.8 (CRITICAL) | EPSS: 0.99869 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36260", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36260"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36260"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the...", "cve_id": "CVE-2021-36260", "vendor": "Hikvision", "ghsa_id": null, "product": "IP Camera", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99869, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99962, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36260", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "894a20fd-ab5d-454c-a266-602a30028aa9", "vulnerability": {"vulnId": "CVE-2019-7609", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "894a20fd-ab5d-454c-a266-602a30028aa9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the... | Affected: Elastic / Kibana | CVSS: 10.0 (CRITICAL) | EPSS: 0.95338 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7609", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7609"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7609"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...", "cve_id": "CVE-2019-7609", "vendor": "Elastic", "ghsa_id": null, "product": "Kibana", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.95338, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99866, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7609", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "060544e1-5b4f-4fa0-b8f9-fdcb18637534", "vulnerability": {"vulnId": "CVE-2015-7450", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "060544e1-5b4f-4fa0-b8f9-fdcb18637534", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow... | Affected: IBM / WebSphere | CVSS: 9.8 (CRITICAL) | EPSS: 0.97764 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-7450", "url": "https://www.cve.org/CVERecord?id=CVE-2015-7450"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-7450"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow...", "cve_id": "CVE-2015-7450", "vendor": "IBM", "ghsa_id": null, "product": "WebSphere", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97764, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-7450", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0f576124-6ada-4ec8-8b10-6d621fcd0eef", "vulnerability": {"vulnId": "CVE-2019-2725", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "0f576124-6ada-4ec8-8b10-6d621fcd0eef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are... | Affected: Oracle / Tape Library ACSLS | CVSS: 9.8 (CRITICAL) | EPSS: 0.99964 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-2725", "url": "https://www.cve.org/CVERecord?id=CVE-2019-2725"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-2725"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...", "cve_id": "CVE-2019-2725", "vendor": "Oracle", "ghsa_id": null, "product": "Tape Library ACSLS", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99964, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99976, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-2725", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2baf955c-3d0b-4007-a3b1-ac61c2ef345f", "vulnerability": {"vulnId": "CVE-2017-1000486", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "2baf955c-3d0b-4007-a3b1-ac61c2ef345f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution | Affected: Primetek / Primefaces | CVSS: 9.8 (CRITICAL) | EPSS: 0.94104 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-1000486", "url": "https://www.cve.org/CVERecord?id=CVE-2017-1000486"}, {"id": "GHSA-J239-4GQG-5J54", "url": "https://github.com/advisories/GHSA-J239-4GQG-5J54"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-1000486"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution", "cve_id": "CVE-2017-1000486", "vendor": "Primetek", "ghsa_id": "GHSA-J239-4GQG-5J54", "product": "Primefaces", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.94104, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99846, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-1000486", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0983b07c-0a65-40b8-a5e6-01ebf968694e", "vulnerability": {"vulnId": "CVE-2019-1458", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "0983b07c-0a65-40b8-a5e6-01ebf968694e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... | Affected: Microsoft / Windows, Windows Server | CVSS: 7.8 (HIGH) | EPSS: 0.74263 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1458", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1458"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1458"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...", "cve_id": "CVE-2019-1458", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.74263, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99477, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1458", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4da239c2-bb1e-430b-a3d7-64dc57c9ebcd", "vulnerability": {"vulnId": "CVE-2019-10149", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "4da239c2-bb1e-430b-a3d7-64dc57c9ebcd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in... | Affected: Exim / exim | CVSS: 9.0 (CRITICAL) | EPSS: 0.99961 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-10149", "url": "https://www.cve.org/CVERecord?id=CVE-2019-10149"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-10149"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in...", "cve_id": "CVE-2019-10149", "vendor": "Exim", "ghsa_id": null, "product": "exim", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.99961, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99975, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-10149", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7c982c88-d2e7-4aa2-aa0e-7592399eaa66", "vulnerability": {"vulnId": "CVE-2021-27860", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-10T01:00:00+01:00"}, "gcve": {"object_uuid": "7c982c88-d2e7-4aa2-aa0e-7592399eaa66", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-10T00:00:00+00:00"}, "scope": {"notes": "Arbitrary file upload vulnerability in FatPipe software | Affected: FatPipe / WARP, IPVPN, MPVPN | CVSS: 9.8 (CRITICAL) | EPSS: 0.39824 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27860", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27860"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27860"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Arbitrary file upload vulnerability in FatPipe software", "cve_id": "CVE-2021-27860", "vendor": "FatPipe", "ghsa_id": null, "product": "WARP, IPVPN, MPVPN", "added_date": "2022-01-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.39824, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98582, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27860", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a631a794-fd19-4aec-84be-2fb19c49c1df", "vulnerability": {"vulnId": "CVE-2022-21661", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2022-01-06T23:50:11+01:00"}, "gcve": {"object_uuid": "a631a794-fd19-4aec-84be-2fb19c49c1df", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2022-01-06T22:50:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2022-01-06T22:50:11+00:00"}, "scope": {"notes": "SQL injection in WordPress | Affected: WordPress / wordpress-develop | CVSS: 8.0 (HIGH) | EPSS: 0.97795 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2022-21661", "url": "https://www.cve.org/CVERecord?id=CVE-2022-21661"}, {"id": "previdian", "url": "https://previdian.com/CVE-2022-21661"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection in WordPress", "cve_id": "CVE-2022-21661", "vendor": "WordPress", "ghsa_id": null, "product": "wordpress-develop", "added_date": "2022-01-06T22:50:11.000Z", "cvss_score": 8.0, "epss_score": 0.97795, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2022-21661", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c04930d4-5f37-487f-adc4-904fe0095445", "vulnerability": {"vulnId": "CVE-2021-35232", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-27T19:48:18+01:00"}, "gcve": {"object_uuid": "c04930d4-5f37-487f-adc4-904fe0095445", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-27T18:48:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-27T18:48:18+00:00"}, "scope": {"notes": "Hard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate Queries | Affected: SolarWinds / Web Help Desk | CVSS: 6.8 (MEDIUM) | EPSS: 0.003 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-35232", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35232"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35232"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate Queries", "cve_id": "CVE-2021-35232", "vendor": "SolarWinds", "ghsa_id": null, "product": "Web Help Desk", "added_date": "2021-12-27T18:48:18.000Z", "cvss_score": 6.8, "epss_score": 0.003, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.20528, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35232", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "aa3e2914-2286-457b-8ff2-7b0f99797bff", "vulnerability": {"vulnId": "CVE-2021-45461", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-22T19:25:54+01:00"}, "gcve": {"object_uuid": "aa3e2914-2286-457b-8ff2-7b0f99797bff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-22T18:25:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-22T18:25:54+00:00"}, "scope": {"notes": "FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute... | Affected: FreePBX / Rest Phone Apps | CVSS: 9.8 (CRITICAL) | EPSS: 0.21657 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-45461", "url": "https://www.cve.org/CVERecord?id=CVE-2021-45461"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-45461"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute...", "cve_id": "CVE-2021-45461", "vendor": "FreePBX", "ghsa_id": null, "product": "Rest Phone Apps", "added_date": "2021-12-22T18:25:54.000Z", "cvss_score": 9.8, "epss_score": 0.21657, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97563, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-45461", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "93e266e6-8929-40a9-884c-9a4dfa070d69", "vulnerability": {"vulnId": "CVE-2021-42912", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-16T17:54:08+01:00"}, "gcve": {"object_uuid": "93e266e6-8929-40a9-884c-9a4dfa070d69", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-16T16:54:08+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-16T16:54:08+00:00"}, "scope": {"notes": "FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in,... | Affected: FiberHome / ONU GPON AN5506-04-F RP2617 | CVSS: 8.8 (HIGH) | EPSS: 0.10087 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-42912", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42912"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42912"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in,...", "cve_id": "CVE-2021-42912", "vendor": "FiberHome", "ghsa_id": null, "product": "ONU GPON AN5506-04-F RP2617", "added_date": "2021-12-16T16:54:08.000Z", "cvss_score": 8.8, "epss_score": 0.10087, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95501, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-42912", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "362cef42-9ac6-41be-be3f-04d9c1a18dfd", "vulnerability": {"vulnId": "CVE-2021-36888", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-15T19:06:58+01:00"}, "gcve": {"object_uuid": "362cef42-9ac6-41be-be3f-04d9c1a18dfd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-15T18:06:58+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-15T18:06:58+00:00"}, "scope": {"notes": "WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full website compromise | Affected: Oxilab / Image Hover Effects Ultimate (WordPress plugin) | CVSS: 9.8 (CRITICAL) | EPSS: 0.06685 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-36888", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36888"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36888"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WordPress Image Hover Effects Ultimate plugin <= 9.6.1 - Unauthenticated Arbitrary Options Update leading to full website compromise", "cve_id": "CVE-2021-36888", "vendor": "Oxilab", "ghsa_id": null, "product": "Image Hover Effects Ultimate (WordPress plugin)", "added_date": "2021-12-15T18:06:58.000Z", "cvss_score": 9.8, "epss_score": 0.06685, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93698, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36888", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ecdbeb69-ba30-4c6a-ae64-ec29ca7bd42e", "vulnerability": {"vulnId": "CVE-2021-4102", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-15T01:00:00+01:00"}, "gcve": {"object_uuid": "ecdbeb69-ba30-4c6a-ae64-ec29ca7bd42e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-15T00:00:00+00:00"}, "scope": {"notes": "Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.07836 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-4102", "url": "https://www.cve.org/CVERecord?id=CVE-2021-4102"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-4102"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2021-4102", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-12-15T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.07836, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94504, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-4102", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "45dfbb86-c23c-423e-be98-64b59b6788d3", "vulnerability": {"vulnId": "CVE-2021-43890", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-15T01:00:00+01:00"}, "gcve": {"object_uuid": "45dfbb86-c23c-423e-be98-64b59b6788d3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-15T00:00:00+00:00"}, "scope": {"notes": "Windows AppX Installer Spoofing Vulnerability | Affected: Microsoft / App Installer | CVSS: 7.1 (HIGH) | EPSS: 0.10295 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-43890", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43890"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43890"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows AppX Installer Spoofing Vulnerability", "cve_id": "CVE-2021-43890", "vendor": "Microsoft", "ghsa_id": null, "product": "App Installer", "added_date": "2021-12-15T00:00:00.000Z", "cvss_score": 7.1, "epss_score": 0.10295, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95563, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-43890", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "68bff97f-75ce-4740-bd11-970c5283c6d1", "vulnerability": {"vulnId": "CVE-2019-13272", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "68bff97f-75ce-4740-bd11-970c5283c6d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a... | Affected: Linux / kernel | CVSS: 7.8 (HIGH) | EPSS: 0.52199 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-13272", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13272"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13272"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a...", "cve_id": "CVE-2019-13272", "vendor": "Linux", "ghsa_id": null, "product": "kernel", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.52199, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98926, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-13272", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e07edf8c-9685-450a-83ad-c9b0b099f111", "vulnerability": {"vulnId": "CVE-2017-17562", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e07edf8c-9685-450a-83ad-c9b0b099f111", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of... | Affected: Embedthis / GoAhead | CVSS: 8.1 (HIGH) | EPSS: 0.96262 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-17562", "url": "https://www.cve.org/CVERecord?id=CVE-2017-17562"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-17562"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of...", "cve_id": "CVE-2017-17562", "vendor": "Embedthis", "ghsa_id": null, "product": "GoAhead", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.96262, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99878, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-17562", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3310356d-37b2-4f5d-b772-84b603a89636", "vulnerability": {"vulnId": "CVE-2020-8816", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "3310356d-37b2-4f5d-b772-84b603a89636", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. | Affected: Pi-hole / Pi-hole Web | CVSS: 9.1 (CRITICAL) | EPSS: 0.7819 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8816", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8816"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8816"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.", "cve_id": "CVE-2020-8816", "vendor": "Pi-hole", "ghsa_id": null, "product": "Pi-hole Web", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.7819, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99567, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8816", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "68dbd76a-faba-474e-ad47-20c32f70809e", "vulnerability": {"vulnId": "CVE-2020-17463", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "68dbd76a-faba-474e-ad47-20c32f70809e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | Affected: Daylight Studio / FUEL CMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.89689 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-17463", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17463"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17463"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.", "cve_id": "CVE-2020-17463", "vendor": "Daylight Studio", "ghsa_id": null, "product": "FUEL CMS", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.89689, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99786, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17463", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a86f754-68bf-4b40-b09c-b190f9688df1", "vulnerability": {"vulnId": "CVE-2019-0193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "6a86f754-68bf-4b40-b09c-b190f9688df1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the... | Affected: Apache / Apache Solr | CVSS: 7.2 (HIGH) | EPSS: 0.83547 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0193", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0193"}, {"id": "GHSA-3GM7-V7VW-866C", "url": "https://github.com/advisories/GHSA-3GM7-V7VW-866C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the...", "cve_id": "CVE-2019-0193", "vendor": "Apache", "ghsa_id": "GHSA-3GM7-V7VW-866C", "product": "Apache Solr", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.83547, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99679, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d6964bd-b5c6-41be-88fc-a95065bebc8b", "vulnerability": {"vulnId": "CVE-2021-44228", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "6d6964bd-b5c6-41be-88fc-a95065bebc8b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | Affected: Apache / Apache Log4j2 | CVSS: 10.0 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44228", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44228"}, {"id": "GHSA-JFH8-C2JP-5V3Q", "url": "https://github.com/advisories/GHSA-JFH8-C2JP-5V3Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44228"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints", "cve_id": "CVE-2021-44228", "vendor": "Apache", "ghsa_id": "GHSA-JFH8-C2JP-5V3Q", "product": "Apache Log4j2", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 1.0, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-44228", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f98fb4f2-c4f0-4c92-b11a-5afa5b09648d", "vulnerability": {"vulnId": "CVE-2019-10758", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "f98fb4f2-c4f0-4c92-b11a-5afa5b09648d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to... | Affected: Mongo-express / mongo-express | CVSS: 9.9 (CRITICAL) | EPSS: 0.84726 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-10758", "url": "https://www.cve.org/CVERecord?id=CVE-2019-10758"}, {"id": "GHSA-H47J-HC6X-H3QQ", "url": "https://github.com/advisories/GHSA-H47J-HC6X-H3QQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-10758"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to...", "cve_id": "CVE-2019-10758", "vendor": "Mongo-express", "ghsa_id": "GHSA-H47J-HC6X-H3QQ", "product": "mongo-express", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.9, "epss_score": 0.84726, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99701, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-10758", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5be64331-7d22-4b39-9952-7576b09fd491", "vulnerability": {"vulnId": "CVE-2017-12149", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "5be64331-7d22-4b39-9952-7576b09fd491", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the... | Affected: Red Hat / jbossas | CVSS: 9.8 (CRITICAL) | EPSS: 0.90713 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-12149", "url": "https://www.cve.org/CVERecord?id=CVE-2017-12149"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-12149"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the...", "cve_id": "CVE-2017-12149", "vendor": "Red Hat", "ghsa_id": null, "product": "jbossas", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90713, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99802, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-12149", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e0a95845-6082-4632-af21-32be30ffb68c", "vulnerability": {"vulnId": "CVE-2021-35394", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "e0a95845-6082-4632-af21-32be30ffb68c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The... | Affected: Realtek / Jungle SDK | CVSS: 9.8 (CRITICAL) | EPSS: 0.99861 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-35394", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35394"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35394"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The...", "cve_id": "CVE-2021-35394", "vendor": "Realtek", "ghsa_id": null, "product": "Jungle SDK", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99861, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35394", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "194c3e9d-f3c7-4424-aa91-a4e947488e18", "vulnerability": {"vulnId": "CVE-2021-44515", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "194c3e9d-f3c7-4424-aa91-a4e947488e18", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild... | Affected: Zoho / ManageEngine Desktop Central | CVSS: 9.8 (CRITICAL) | EPSS: 0.99871 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44515", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44515"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44515"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild...", "cve_id": "CVE-2021-44515", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine Desktop Central", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99871, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99963, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44515", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3a7b693e-1460-4af4-863e-88a0fc698187", "vulnerability": {"vulnId": "CVE-2010-1871", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "3a7b693e-1460-4af4-863e-88a0fc698187", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss... | Affected: Red Hat / JBoss Enterprise Application Platform | CVSS: 8.8 (HIGH) | EPSS: 0.83397 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-1871", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1871"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-1871"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss...", "cve_id": "CVE-2010-1871", "vendor": "Red Hat", "ghsa_id": null, "product": "JBoss Enterprise Application Platform", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.83397, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99674, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-1871", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "678ffe82-2b3e-4aa8-9ae6-60b9b5bdb87b", "vulnerability": {"vulnId": "CVE-2021-44168", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "678ffe82-2b3e-4aa8-9ae6-60b9b5bdb87b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "A download of code without integrity check vulnerability in the \"execute restore src-vis\" command of FortiOS before 7.0.3 may allow a local... | Affected: Fortinet / Fortinet FortiOS | CVSS: 3.3 (LOW) | EPSS: 0.00865 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44168", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44168"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44168"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A download of code without integrity check vulnerability in the \"execute restore src-vis\" command of FortiOS before 7.0.3 may allow a local...", "cve_id": "CVE-2021-44168", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 3.3, "epss_score": 0.00865, "previous_ids": [], "cvss_severity": "LOW", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.57154, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44168", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6abf0a14-f7d0-4a6c-a22d-a14af623adc7", "vulnerability": {"vulnId": "CVE-2019-7238", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-10T01:00:00+01:00"}, "gcve": {"object_uuid": "6abf0a14-f7d0-4a6c-a22d-a14af623adc7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-10T00:00:00+00:00"}, "scope": {"notes": "Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. | Affected: Sonatype / Nexus Repository Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.77146 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7238", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7238"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7238"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.", "cve_id": "CVE-2019-7238", "vendor": "Sonatype", "ghsa_id": null, "product": "Nexus Repository Manager", "added_date": "2021-12-10T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.77146, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9954, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7238", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "00014b15-ac6d-41f2-9966-ae605c31a9f6", "vulnerability": {"vulnId": "CVE-2021-42567", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-07T22:10:49+01:00"}, "gcve": {"object_uuid": "00014b15-ac6d-41f2-9966-ae605c31a9f6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-07T21:10:49+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-07T21:10:49+00:00"}, "scope": {"notes": "Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. | Affected: Apereo / CAS | CVSS: 6.1 (MEDIUM) | EPSS: 0.08191 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-42567", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42567"}, {"id": "GHSA-GFHX-JJWQ-63GV", "url": "https://github.com/advisories/GHSA-GFHX-JJWQ-63GV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42567"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.", "cve_id": "CVE-2021-42567", "vendor": "Apereo", "ghsa_id": "GHSA-GFHX-JJWQ-63GV", "product": "CAS", "added_date": "2021-12-07T21:10:49.000Z", "cvss_score": 6.1, "epss_score": 0.08191, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94706, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-42567", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7c599394-c748-4ad7-ad55-244f84d07c2f", "vulnerability": {"vulnId": "CVE-2020-11261", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "7c599394-c748-4ad7-ad55-244f84d07c2f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-01T00:00:00+00:00"}, "scope": {"notes": "Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,... | Affected: Qualcomm / Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | CVSS: 7.8 (HIGH) | EPSS: 0.01604 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11261", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11261"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11261"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,...", "cve_id": "CVE-2020-11261", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", "added_date": "2021-12-01T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01604, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74967, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11261", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "703b6d01-126e-4b87-9cdd-4325d5651c92", "vulnerability": {"vulnId": "CVE-2021-37415", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "703b6d01-126e-4b87-9cdd-4325d5651c92", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-01T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | Affected: Zoho / ManageEngine ServiceDesk Plus | CVSS: 9.8 (CRITICAL) | EPSS: 0.99825 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-37415", "url": "https://www.cve.org/CVERecord?id=CVE-2021-37415"}, {"id": "GHSA-WF6J-6X58-69FG", "url": "https://github.com/advisories/GHSA-WF6J-6X58-69FG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-37415"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.", "cve_id": "CVE-2021-37415", "vendor": "Zoho", "ghsa_id": "GHSA-WF6J-6X58-69FG", "product": "ManageEngine ServiceDesk Plus", "added_date": "2021-12-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99825, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99959, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-37415", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a8a9f82-eaac-428c-87cc-66f0fb7ab299", "vulnerability": {"vulnId": "CVE-2018-14847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "6a8a9f82-eaac-428c-87cc-66f0fb7ab299", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-01T00:00:00+00:00"}, "scope": {"notes": "MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write... | Affected: MikroTik / RouterOS | CVSS: 9.1 (CRITICAL) | EPSS: 0.96087 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-14847", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write...", "cve_id": "CVE-2018-14847", "vendor": "MikroTik", "ghsa_id": null, "product": "RouterOS", "added_date": "2021-12-01T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.96087, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99877, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14847", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dd6503f6-fa2c-4429-8727-82e7aa8bc227", "vulnerability": {"vulnId": "CVE-2021-44077", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "dd6503f6-fa2c-4429-8727-82e7aa8bc227", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-01T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to... | Affected: Zoho / ManageEngine ServiceDesk Plus, ManageEngine ServiceDesk Plus MSP, ManageEngine SupportCenter Plus | CVSS: 9.8 (CRITICAL) | EPSS: 0.93298 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-44077", "url": "https://www.cve.org/CVERecord?id=CVE-2021-44077"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-44077"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to...", "cve_id": "CVE-2021-44077", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine ServiceDesk Plus, ManageEngine ServiceDesk Plus MSP, ManageEngine SupportCenter Plus", "added_date": "2021-12-01T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93298, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-44077", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4f94b250-d518-4dc5-90d7-e34e019ac801", "vulnerability": {"vulnId": "CVE-2021-40438", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-12-01T01:00:00+01:00"}, "gcve": {"object_uuid": "4f94b250-d518-4dc5-90d7-e34e019ac801", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-12-01T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-12-01T00:00:00+00:00"}, "scope": {"notes": "mod_proxy SSRF | Affected: Apache / Apache HTTP Server | CVSS: 9.0 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40438", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40438"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40438"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "mod_proxy SSRF", "cve_id": "CVE-2021-40438", "vendor": "Apache", "ghsa_id": null, "product": "Apache HTTP Server", "added_date": "2021-12-01T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99997, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-40438", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aeb7189a-7883-49f8-b83e-5f3dae0ad1cf", "vulnerability": {"vulnId": "CVE-2021-43778", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-24T19:50:10+01:00"}, "gcve": {"object_uuid": "aeb7189a-7883-49f8-b83e-5f3dae0ad1cf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-24T18:50:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-24T18:50:10+00:00"}, "scope": {"notes": "Path traversal in GLPI barcode plugin | Affected: pluginsGLPI / barcode | CVSS: 9.1 (CRITICAL) | EPSS: 0.52658 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-43778", "url": "https://www.cve.org/CVERecord?id=CVE-2021-43778"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-43778"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path traversal in GLPI barcode plugin", "cve_id": "CVE-2021-43778", "vendor": "pluginsGLPI", "ghsa_id": null, "product": "barcode", "added_date": "2021-11-24T18:50:10.000Z", "cvss_score": 9.1, "epss_score": 0.52658, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-43778", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "572ddea8-659e-42d8-acf4-97497a10c1d3", "vulnerability": {"vulnId": "CVE-2021-42292", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-17T01:00:00+01:00"}, "gcve": {"object_uuid": "572ddea8-659e-42d8-acf4-97497a10c1d3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-17T00:00:00+00:00"}, "scope": {"notes": "Microsoft Excel Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft 365 Apps for Enterprise, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2016, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021 | CVSS: 7.8 (HIGH) | EPSS: 0.43005 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42292", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42292"}, {"id": "GHSA-JP63-FCQH-36RC", "url": "https://github.com/advisories/GHSA-JP63-FCQH-36RC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42292"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Excel Security Feature Bypass Vulnerability", "cve_id": "CVE-2021-42292", "vendor": "Microsoft", "ghsa_id": "GHSA-JP63-FCQH-36RC", "product": "Microsoft 365 Apps for Enterprise, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2016, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016, Microsoft Office 2019, Microsoft Office 2019 for Mac, Microsoft Office LTSC 2021, Microsoft Office LTSC for Mac 2021", "added_date": "2021-11-17T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.43005, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98683, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-42292", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0568e910-bd64-4a21-8eee-5408f9061a52", "vulnerability": {"vulnId": "CVE-2021-22204", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-17T01:00:00+01:00"}, "gcve": {"object_uuid": "0568e910-bd64-4a21-8eee-5408f9061a52", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-17T00:00:00+00:00"}, "scope": {"notes": "Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the... | Affected: ExifTool / ExifTool | CVSS: 6.8 (MEDIUM) | EPSS: 0.99981 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22204", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22204"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22204"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the...", "cve_id": "CVE-2021-22204", "vendor": "ExifTool", "ghsa_id": null, "product": "ExifTool", "added_date": "2021-11-17T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.99981, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99981, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22204", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a553d771-ee20-4b27-8abe-80460cd76b77", "vulnerability": {"vulnId": "CVE-2021-42321", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-17T01:00:00+01:00"}, "gcve": {"object_uuid": "a553d771-ee20-4b27-8abe-80460cd76b77", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-17T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2019 Cumulative Update 11 | CVSS: 8.8 (HIGH) | EPSS: 0.91737 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42321", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42321"}, {"id": "GHSA-3F87-66X4-F3P7", "url": "https://github.com/advisories/GHSA-3F87-66X4-F3P7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42321"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-42321", "vendor": "Microsoft", "ghsa_id": "GHSA-3F87-66X4-F3P7", "product": "Microsoft Exchange Server 2016 Cumulative Update 21, Microsoft Exchange Server 2016 Cumulative Update 22, Microsoft Exchange Server 2019 Cumulative Update 10, Microsoft Exchange Server 2019 Cumulative Update 11", "added_date": "2021-11-17T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.91737, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99814, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-42321", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "10f40c91-33f1-4089-a589-742f0bde521f", "vulnerability": {"vulnId": "CVE-2021-40449", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-17T01:00:00+01:00"}, "gcve": {"object_uuid": "10f40c91-33f1-4089-a589-742f0bde521f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-17T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-17T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.74129 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40449", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40449"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40449"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-40449", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows Server 2022, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 11 version 21H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-17T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.74129, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99474, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-40449", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ad25f12b-856f-4b23-a389-94d6735be2cd", "vulnerability": {"vulnId": "CVE-2021-40444", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ad25f12b-856f-4b23-a389-94d6735be2cd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft MSHTML Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 | CVSS: 8.8 (HIGH) | EPSS: 0.9745 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40444", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40444"}, {"id": "GHSA-2H32-FHF6-XHH5", "url": "https://github.com/advisories/GHSA-2H32-FHF6-XHH5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40444"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft MSHTML Remote Code Execution Vulnerability", "cve_id": "CVE-2021-40444", "vendor": "Microsoft", "ghsa_id": "GHSA-2H32-FHF6-XHH5", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.9745, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99899, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-40444", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cf4ee533-d0e5-4f35-ae06-509fcf818248", "vulnerability": {"vulnId": "CVE-2020-0674", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cf4ee533-d0e5-4f35-ae06-509fcf818248", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... | Affected: Microsoft / Internet Explorer 10, Internet Explorer 11, Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 11 on Windows Server 2012, Internet Explorer 9 | CVSS: 7.5 (HIGH) | EPSS: 0.86863 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0674", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0674"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0674"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...", "cve_id": "CVE-2020-0674", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 10, Internet Explorer 11, Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 11 on Windows Server 2012, Internet Explorer 9", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.86863, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99742, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0674", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f9f19117-af48-4444-9e2c-ab49a0f408d9", "vulnerability": {"vulnId": "CVE-2021-1732", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f9f19117-af48-4444-9e2c-ab49a0f408d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.78376 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1732", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1732"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1732"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-1732", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.78376, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99571, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-1732", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "597bcaa0-4538-4fa0-83b4-949f832d147f", "vulnerability": {"vulnId": "CVE-2021-26411", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "597bcaa0-4538-4fa0-83b4-949f832d147f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Internet Explorer Memory Corruption Vulnerability | Affected: Microsoft / Internet Explorer 11, Internet Explorer 9, Microsoft Edge (EdgeHTML-based) | CVSS: 8.8 (HIGH) | EPSS: 0.80765 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26411", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26411"}, {"id": "GHSA-C5RH-MMR6-C7CH", "url": "https://github.com/advisories/GHSA-C5RH-MMR6-C7CH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26411"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Internet Explorer Memory Corruption Vulnerability", "cve_id": "CVE-2021-26411", "vendor": "Microsoft", "ghsa_id": "GHSA-C5RH-MMR6-C7CH", "product": "Internet Explorer 11, Internet Explorer 9, Microsoft Edge (EdgeHTML-based)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.80765, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99619, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-26411", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9645dae1-1dfa-48d2-b24e-8255cae8f02b", "vulnerability": {"vulnId": "CVE-2021-27065", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9645dae1-1dfa-48d2-b24e-8255cae8f02b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8 | CVSS: 7.8 (HIGH) | EPSS: 0.99876 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27065", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27065"}, {"id": "GHSA-RWM8-8C4X-V87Q", "url": "https://github.com/advisories/GHSA-RWM8-8C4X-V87Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27065"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-27065", "vendor": "Microsoft", "ghsa_id": "GHSA-RWM8-8C4X-V87Q", "product": "Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.99876, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99963, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27065", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a688c425-c9fd-4bdd-b1e9-b7862aeba5ba", "vulnerability": {"vulnId": "CVE-2019-0808", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a688c425-c9fd-4bdd-b1e9-b7862aeba5ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... | Affected: Microsoft / Windows, Windows Server | CVSS: 7.8 (HIGH) | EPSS: 0.53017 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0808", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0808"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0808"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...", "cve_id": "CVE-2019-0808", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.53017, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0808", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "db98b35f-749d-4903-9b3b-f0199c474b76", "vulnerability": {"vulnId": "CVE-2020-1147", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "db98b35f-749d-4903-9b3b-f0199c474b76", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source... | Affected: Microsoft / Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server, Microsoft Visual Studio 2019, Microsoft Visual Studio 2019 version 16.6 (includes 16.0 - 16.5), Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8), Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3), .NET Core, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, Microsoft .NET Framework 4.8 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems, Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems, Microsoft .NET Framework 4.8 on Windows RT 8.1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1909 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1903 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 4.6, Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 3.5 AND 4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 2004 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 2004 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 2004 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 2004 for ARM64-based Systems | CVSS: 7.8 (HIGH) | EPSS: 0.93966 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1147", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1147"}, {"id": "GHSA-G5VF-38CP-4PX9", "url": "https://github.com/advisories/GHSA-G5VF-38CP-4PX9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1147"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source...", "cve_id": "CVE-2020-1147", "vendor": "Microsoft", "ghsa_id": "GHSA-G5VF-38CP-4PX9", "product": "Microsoft SharePoint Enterprise Server, Microsoft SharePoint Server, Microsoft Visual Studio 2019, Microsoft Visual Studio 2019 version 16.6 (includes 16.0 - 16.5), Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8), Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3), .NET Core, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, Microsoft .NET Framework 4.8 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems, Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems, Microsoft .NET Framework 4.8 on Windows RT 8.1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1909 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1903 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 4.6, Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 3.5 AND 4.6/4.6.1/4.6.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6/4.6.1/4.6.2 on Windows 10 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 2004 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 2004 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 2004 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 2004 for ARM64-based Systems", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.93966, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99844, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1147", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7480e541-d61a-4998-8741-f3b3df5b1f49", "vulnerability": {"vulnId": "CVE-2019-1214", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7480e541-d61a-4998-8741-f3b3df5b1f49", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.01419 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1214", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1214"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1214"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka...", "cve_id": "CVE-2019-1214", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01419, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71845, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1214", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f13de53a-d9df-4734-8335-65c5327e03f8", "vulnerability": {"vulnId": "CVE-2021-38648", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f13de53a-d9df-4734-8335-65c5327e03f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Open Management Infrastructure Elevation of Privilege Vulnerability | Affected: Microsoft / Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | CVSS: 7.8 (HIGH) | EPSS: 0.11424 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38648", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38648"}, {"id": "GHSA-P8GR-7QCG-86P9", "url": "https://github.com/advisories/GHSA-P8GR-7QCG-86P9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38648"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Open Management Infrastructure Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-38648", "vendor": "Microsoft", "ghsa_id": "GHSA-P8GR-7QCG-86P9", "product": "Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.11424, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95881, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38648", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bc892ee5-0f84-40bb-9056-1c6b2de8e837", "vulnerability": {"vulnId": "CVE-2019-11580", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bc892ee5-0f84-40bb-9056-1c6b2de8e837", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send... | Affected: Atlassian / Crowd | CVSS: 9.8 (CRITICAL) | EPSS: 0.95355 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11580", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11580"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11580"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send...", "cve_id": "CVE-2019-11580", "vendor": "Atlassian", "ghsa_id": null, "product": "Crowd", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95355, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99866, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-11580", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "199b865f-325c-47ad-a7bc-6fa3141fa9e5", "vulnerability": {"vulnId": "CVE-2018-6789", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "199b865f-325c-47ad-a7bc-6fa3141fa9e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may... | Affected: Exim / Exim | CVSS: 9.8 (CRITICAL) | EPSS: 0.82137 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-6789", "url": "https://www.cve.org/CVERecord?id=CVE-2018-6789"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-6789"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may...", "cve_id": "CVE-2018-6789", "vendor": "Exim", "ghsa_id": null, "product": "Exim", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82137, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99646, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-6789", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "024ffc7a-3812-47d7-a3dc-4a1793171fb7", "vulnerability": {"vulnId": "CVE-2021-37976", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "024ffc7a-3812-47d7-a3dc-4a1793171fb7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information... | Affected: Google / Chrome | CVSS: 6.5 (MEDIUM) | EPSS: 0.19901 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-37976", "url": "https://www.cve.org/CVERecord?id=CVE-2021-37976"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-37976"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information...", "cve_id": "CVE-2021-37976", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.19901, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97354, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-37976", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fab095e1-188e-423f-89df-ec55ef738d8c", "vulnerability": {"vulnId": "CVE-2021-37975", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fab095e1-188e-423f-89df-ec55ef738d8c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.34887 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-37975", "url": "https://www.cve.org/CVERecord?id=CVE-2021-37975"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-37975"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2021-37975", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.34887, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98389, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-37975", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c9e7c5bf-1dc1-43e8-b186-ecd570b5ccd4", "vulnerability": {"vulnId": "CVE-2016-0185", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c9e7c5bf-1dc1-43e8-b186-ecd570b5ccd4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.69846 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0185", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0185"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0185"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media...", "cve_id": "CVE-2016-0185", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.69846, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99355, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-0185", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a19959a9-df6b-4ad8-95da-40f98c1e4ed0", "vulnerability": {"vulnId": "CVE-2021-31207", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a19959a9-df6b-4ad8-95da-40f98c1e4ed0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Security Feature Bypass Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 9, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2019 Cumulative Update 8 | CVSS: 6.6 (MEDIUM) | EPSS: 0.99782 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31207", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31207"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31207"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Security Feature Bypass Vulnerability", "cve_id": "CVE-2021-31207", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 9, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2019 Cumulative Update 8", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.99782, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99955, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-31207", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9c1b0e0a-162e-4950-8c0c-5bea8fad52ee", "vulnerability": {"vulnId": "CVE-2019-0797", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9c1b0e0a-162e-4950-8c0c-5bea8fad52ee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... | Affected: Microsoft / Windows Server, Windows | CVSS: 7.8 (HIGH) | EPSS: 0.0189 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0797", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0797"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0797"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...", "cve_id": "CVE-2019-0797", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server, Windows", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.0189, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78807, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0797", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4ec96345-ea9f-4f5c-91ae-88b8dc95d1f8", "vulnerability": {"vulnId": "CVE-2019-0541", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4ec96345-ea9f-4f5c-91ae-88b8dc95d1f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka \"MSHTML Engine Remote Code Execution... | Affected: Microsoft / Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office | CVSS: 8.8 (HIGH) | EPSS: 0.53202 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0541", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0541"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0541"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka \"MSHTML Engine Remote Code Execution...", "cve_id": "CVE-2019-0541", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.53202, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98951, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0541", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e2945af5-6bbf-4844-aea5-aba15ce28982", "vulnerability": {"vulnId": "CVE-2020-6820", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e2945af5-6bbf-4844-aea5-aba15ce28982", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild... | Affected: Mozilla / Thunderbird, Firefox, Firefox ESR | CVSS: 8.1 (HIGH) | EPSS: 0.07063 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-6820", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6820"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6820"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild...", "cve_id": "CVE-2020-6820", "vendor": "Mozilla", "ghsa_id": null, "product": "Thunderbird, Firefox, Firefox ESR", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.07063, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94013, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6820", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6c174ae5-c93d-4a68-8c6f-2537756cc690", "vulnerability": {"vulnId": "CVE-2021-27101", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6c174ae5-c93d-4a68-8c6f-2537756cc690", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is... | Affected: Accellion / FTA | CVSS: 9.8 (CRITICAL) | EPSS: 0.05998 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27101", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27101"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27101"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is...", "cve_id": "CVE-2021-27101", "vendor": "Accellion", "ghsa_id": null, "product": "FTA", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.05998, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.931, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27101", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9720fe73-acce-4ca0-84d8-c9df855ba707", "vulnerability": {"vulnId": "CVE-2021-27103", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9720fe73-acce-4ca0-84d8-c9df855ba707", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. | Affected: Accellion / FTA | CVSS: 9.8 (CRITICAL) | EPSS: 0.11406 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27103", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27103"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27103"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.", "cve_id": "CVE-2021-27103", "vendor": "Accellion", "ghsa_id": null, "product": "FTA", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.11406, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95876, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27103", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "74581d85-f25a-4eaf-82f2-3a5968ad11b2", "vulnerability": {"vulnId": "CVE-2021-28550", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "74581d85-f25a-4eaf-82f2-3a5968ad11b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution | Affected: Adobe / Acrobat Reader | CVSS: 9.6 (CRITICAL) | EPSS: 0.52005 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-28550", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28550"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28550"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution", "cve_id": "CVE-2021-28550", "vendor": "Adobe", "ghsa_id": null, "product": "Acrobat Reader", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.52005, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98922, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28550", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20cec9bd-059a-4f6d-812d-21288632b11e", "vulnerability": {"vulnId": "CVE-2020-3569", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "20cec9bd-059a-4f6d-812d-21288632b11e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities | Affected: Cisco / Cisco IOS XR Software | CVSS: 8.6 (HIGH) | EPSS: 0.0332 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3569", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3569"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3569"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities", "cve_id": "CVE-2020-3569", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XR Software", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.0332, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88185, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3569", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "084cd786-9b9c-4b4a-a3fe-04ed9b96f688", "vulnerability": {"vulnId": "CVE-2021-30554", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "084cd786-9b9c-4b4a-a3fe-04ed9b96f688", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.07367 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30554", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30554"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30554"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2021-30554", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.07367, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94228, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30554", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fb641e1b-1903-4bf0-baa0-52c80fa745e5", "vulnerability": {"vulnId": "CVE-2021-22502", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fb641e1b-1903-4bf0-baa0-52c80fa745e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be... | Affected: Micro Focus / Operation Bridge Reporter. | CVSS: 9.8 (CRITICAL) | EPSS: 0.9674 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22502", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22502"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22502"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be...", "cve_id": "CVE-2021-22502", "vendor": "Micro Focus", "ghsa_id": null, "product": "Operation Bridge Reporter.", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9674, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22502", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5d1438a5-909c-431f-8d13-ea0baa6d3f58", "vulnerability": {"vulnId": "CVE-2019-1367", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5d1438a5-909c-431f-8d13-ea0baa6d3f58", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... | Affected: Microsoft / Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10 | CVSS: 7.5 (HIGH) | EPSS: 0.52449 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1367", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1367"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1367"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...", "cve_id": "CVE-2019-1367", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.52449, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98931, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1367", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f0f73e55-775b-4b95-a7e9-6c7ea8b9d808", "vulnerability": {"vulnId": "CVE-2020-14750", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f0f73e55-775b-4b95-a7e9-6c7ea8b9d808", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.9927 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-14750", "url": "https://www.cve.org/CVERecord?id=CVE-2020-14750"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-14750"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...", "cve_id": "CVE-2020-14750", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9927, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-14750", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "28864db3-4494-4eb6-9c99-95943b0574a0", "vulnerability": {"vulnId": "CVE-2020-1380", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "28864db3-4494-4eb6-9c99-95943b0574a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Scripting Engine Memory Corruption Vulnerability | Affected: Microsoft / Internet Explorer 11 | CVSS: 7.8 (HIGH) | EPSS: 0.24188 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1380", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1380"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1380"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Scripting Engine Memory Corruption Vulnerability", "cve_id": "CVE-2020-1380", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 11", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.24188, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97788, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1380", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "00e4b229-613a-4c48-ae51-fa30fbaf631b", "vulnerability": {"vulnId": "CVE-2020-1472", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "00e4b229-613a-4c48-ae51-fa30fbaf631b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Netlogon Elevation of Privilege Vulnerability | Affected: Microsoft / Windows Server version 2004, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server, version 1909 (Server Core installation), Windows Server, version 1903 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server version 20H2 | CVSS: 5.5 (MEDIUM) | EPSS: 0.99389 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1472", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1472"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1472"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Netlogon Elevation of Privilege Vulnerability", "cve_id": "CVE-2020-1472", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server version 2004, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server, version 1909 (Server Core installation), Windows Server, version 1903 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.99389, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9994, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-1472", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "90c8807c-b454-439f-a27a-57313b8369f2", "vulnerability": {"vulnId": "CVE-2021-34448", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "90c8807c-b454-439f-a27a-57313b8369f2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Scripting Engine Memory Corruption Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019 | CVSS: 6.8 (MEDIUM) | EPSS: 0.40062 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-34448", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34448"}, {"id": "GHSA-6545-45RG-P2VP", "url": "https://github.com/advisories/GHSA-6545-45RG-P2VP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34448"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Scripting Engine Memory Corruption Vulnerability", "cve_id": "CVE-2021-34448", "vendor": "Microsoft", "ghsa_id": "GHSA-6545-45RG-P2VP", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.40062, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98591, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34448", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2f2be2cd-6c16-484c-ba75-a733eb7344b5", "vulnerability": {"vulnId": "CVE-2021-22894", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2f2be2cd-6c16-484c-ba75-a733eb7344b5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as... | Affected: Pulse Secure / Pulse Connect Secure | CVSS: 8.8 (HIGH) | EPSS: 0.41284 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22894", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22894"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22894"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as...", "cve_id": "CVE-2021-22894", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.41284, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9863, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22894", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2e22e719-7109-4046-a7dd-dbd6b25c9830", "vulnerability": {"vulnId": "CVE-2021-28310", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2e22e719-7109-4046-a7dd-dbd6b25c9830", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.0833 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-28310", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28310"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28310"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-28310", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.0833, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94786, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28310", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f78d05d-809d-46c7-9cda-c8024b7a122d", "vulnerability": {"vulnId": "CVE-2020-6207", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5f78d05d-809d-46c7-9cda-c8024b7a122d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a... | Affected: SAP SE / SAP Solution Manager (User Experience Monitoring) | CVSS: 9.8 (CRITICAL) | EPSS: 0.98135 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-6207", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6207"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6207"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a...", "cve_id": "CVE-2020-6207", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP Solution Manager (User Experience Monitoring)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98135, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99912, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6207", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2501afe4-be39-4590-96c5-7b5a91e33870", "vulnerability": {"vulnId": "CVE-2019-0803", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2501afe4-be39-4590-96c5-7b5a91e33870", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... | Affected: Microsoft / Windows, Windows Server | CVSS: 7.8 (HIGH) | EPSS: 0.44954 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0803", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0803"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0803"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...", "cve_id": "CVE-2019-0803", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.44954, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98742, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0803", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c07fdb51-6b02-4ce0-b7bd-4e6f76c33582", "vulnerability": {"vulnId": "CVE-2018-8653", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c07fdb51-6b02-4ce0-b7bd-4e6f76c33582", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting... | Affected: Microsoft / Internet Explorer 9, Internet Explorer 11, Internet Explorer 10 | CVSS: 7.5 (HIGH) | EPSS: 0.29606 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-8653", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8653"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8653"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka \"Scripting...", "cve_id": "CVE-2018-8653", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 9, Internet Explorer 11, Internet Explorer 10", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.29606, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9814, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8653", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9179a90c-d9a7-466f-9677-51a6bfc0d57f", "vulnerability": {"vulnId": "CVE-2012-0158", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9179a90c-d9a7-466f-9677-51a6bfc0d57f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003... | Affected: Microsoft / Office | CVSS: 8.8 (HIGH) | EPSS: 0.99976 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-0158", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0158"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0158"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003...", "cve_id": "CVE-2012-0158", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99976, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0158", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0573b87b-03cf-4050-b41b-5d1bb188d95a", "vulnerability": {"vulnId": "CVE-2020-0968", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0573b87b-03cf-4050-b41b-5d1bb188d95a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... | Affected: Microsoft / Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 11 on Windows Server 2012 | CVSS: 7.5 (HIGH) | EPSS: 0.30676 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0968", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0968"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0968"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...", "cve_id": "CVE-2020-0968", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 11 on Windows Server 2012", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.30676, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98196, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0968", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6778cb91-1bee-4469-8249-c3c41f408860", "vulnerability": {"vulnId": "CVE-2015-4852", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6778cb91-1bee-4469-8249-c3c41f408860", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.96032 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-4852", "url": "https://www.cve.org/CVERecord?id=CVE-2015-4852"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-4852"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary...", "cve_id": "CVE-2015-4852", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96032, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99875, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-4852", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d3776aa1-d03b-417f-afac-62e0d8dfce3b", "vulnerability": {"vulnId": "CVE-2019-18935", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d3776aa1-d03b-417f-afac-62e0d8dfce3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is... | Affected: Progress Software / Telerik UI for ASP.NET AJAX | CVSS: 9.8 (CRITICAL) | EPSS: 0.99737 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-18935", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18935"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18935"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is...", "cve_id": "CVE-2019-18935", "vendor": "Progress Software", "ghsa_id": null, "product": "Telerik UI for ASP.NET AJAX", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99737, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99953, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-18935", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06028101-76e8-4dda-a752-e8b15497de61", "vulnerability": {"vulnId": "CVE-2020-11651", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "06028101-76e8-4dda-a752-e8b15497de61", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly... | Affected: SaltStack / Salt | CVSS: 9.8 (CRITICAL) | EPSS: 0.96614 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11651", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11651"}, {"id": "GHSA-PJHF-VPX3-33R3", "url": "https://github.com/advisories/GHSA-PJHF-VPX3-33R3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11651"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly...", "cve_id": "CVE-2020-11651", "vendor": "SaltStack", "ghsa_id": "GHSA-PJHF-VPX3-33R3", "product": "Salt", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.96614, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99883, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11651", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0585b29f-3b85-4cb4-a246-604c6e5f1feb", "vulnerability": {"vulnId": "CVE-2016-9563", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0585b29f-3b85-4cb4-a246-604c6e5f1feb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the... | Affected: SAP / NetWeaver AS JAVA | CVSS: 6.5 (MEDIUM) | EPSS: 0.24226 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-9563", "url": "https://www.cve.org/CVERecord?id=CVE-2016-9563"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-9563"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the...", "cve_id": "CVE-2016-9563", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver AS JAVA", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.24226, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97792, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-9563", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ded34296-7a5a-4c0d-abc2-8a15ec77bf4d", "vulnerability": {"vulnId": "CVE-2021-35211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ded34296-7a5a-4c0d-abc2-8a15ec77bf4d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Serv-U Remote Memory Escape Vulnerability | Affected: SolarWinds / Serv-U Managed File Transfer Server and Serv-U Secured FTP | CVSS: 9.0 (CRITICAL) | EPSS: 0.9116 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-35211", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Serv-U Remote Memory Escape Vulnerability", "cve_id": "CVE-2021-35211", "vendor": "SolarWinds", "ghsa_id": null, "product": "Serv-U Managed File Transfer Server and Serv-U Secured FTP", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.9116, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99807, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-35211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fd0d4cf8-ae6b-4eeb-97a0-4e194d1ed47e", "vulnerability": {"vulnId": "CVE-2021-38000", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fd0d4cf8-ae6b-4eeb-97a0-4e194d1ed47e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily... | Affected: Google / Chrome | CVSS: 6.1 (MEDIUM) | EPSS: 0.04948 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38000", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38000"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38000"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily...", "cve_id": "CVE-2021-38000", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.04948, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91892, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38000", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ba465d3f-2dda-4866-89c6-0497013c7e39", "vulnerability": {"vulnId": "CVE-2018-0802", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ba465d3f-2dda-4866-89c6-0497013c7e39", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution... | Affected: Microsoft / Equation Editor | CVSS: 7.8 (HIGH) | EPSS: 0.93289 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0802", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0802"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0802"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution...", "cve_id": "CVE-2018-0802", "vendor": "Microsoft", "ghsa_id": null, "product": "Equation Editor", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.93289, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99835, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0802", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5ff34415-f780-4aad-90a4-bb59d794c597", "vulnerability": {"vulnId": "CVE-2021-26855", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5ff34415-f780-4aad-90a4-bb59d794c597", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8 | CVSS: 9.1 (CRITICAL) | EPSS: 0.99996 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26855", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26855"}, {"id": "GHSA-6784-2MH5-CQ56", "url": "https://github.com/advisories/GHSA-6784-2MH5-CQ56"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26855"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-26855", "vendor": "Microsoft", "ghsa_id": "GHSA-6784-2MH5-CQ56", "product": "Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.99996, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99988, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-26855", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "64ae9858-653c-415f-8feb-635d10b076e1", "vulnerability": {"vulnId": "CVE-2020-0601", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "64ae9858-653c-415f-8feb-635d10b076e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1909 for ARM64-based Systems | CVSS: 8.1 (HIGH) | EPSS: 0.89436 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0601", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0601"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0601"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker...", "cve_id": "CVE-2020-0601", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1909 for ARM64-based Systems", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.89436, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99782, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0601", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f1b24ae5-a2ca-4499-acb0-3ea8cd1eb2f7", "vulnerability": {"vulnId": "CVE-2021-36955", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f1b24ae5-a2ca-4499-acb0-3ea8cd1eb2f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Common Log File System Driver Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.04037 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36955", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36955"}, {"id": "GHSA-G26F-6MX8-J24W", "url": "https://github.com/advisories/GHSA-G26F-6MX8-J24W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36955"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-36955", "vendor": "Microsoft", "ghsa_id": "GHSA-G26F-6MX8-J24W", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 2004, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04037, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90294, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-36955", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8139aeff-596c-42f5-be65-aa1d42481a97", "vulnerability": {"vulnId": "CVE-2019-11510", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8139aeff-596c-42f5-be65-aa1d42481a97", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can... | Affected: Pulse Secure / Pulse Connect Secure | CVSS: 10.0 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11510", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11510"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11510"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can...", "cve_id": "CVE-2019-11510", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 1.0, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-11510", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "31a077da-8976-4b00-9a9a-21700231f134", "vulnerability": {"vulnId": "CVE-2010-5326", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "31a077da-8976-4b00-9a9a-21700231f134", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote... | Affected: SAP / NetWeaver Application Server Java | CVSS: 10.0 (CRITICAL) | EPSS: 0.1777 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-5326", "url": "https://www.cve.org/CVERecord?id=CVE-2010-5326"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-5326"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote...", "cve_id": "CVE-2010-5326", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver Application Server Java", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.1777, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97079, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-5326", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6a14d9e9-4394-40d7-87b0-86c1cae78a9d", "vulnerability": {"vulnId": "CVE-2016-3643", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6a14d9e9-4394-40d7-87b0-86c1cae78a9d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated... | Affected: SolarWinds / Virtualization Manager | CVSS: 7.8 (HIGH) | EPSS: 0.03674 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3643", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3643"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3643"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated...", "cve_id": "CVE-2016-3643", "vendor": "SolarWinds", "ghsa_id": null, "product": "Virtualization Manager", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03674, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3643", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06967deb-a517-429e-9e71-a1e7af43847e", "vulnerability": {"vulnId": "CVE-2021-36948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "06967deb-a517-429e-9e71-a1e7af43847e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Update Medic Service Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.2327 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36948", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36948"}, {"id": "GHSA-FCR2-QX8M-PFHP", "url": "https://github.com/advisories/GHSA-FCR2-QX8M-PFHP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Update Medic Service Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-36948", "vendor": "Microsoft", "ghsa_id": "GHSA-FCR2-QX8M-PFHP", "product": "Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.2327, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97715, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8409e7e5-6c0f-4f08-9407-81d967608b8d", "vulnerability": {"vulnId": "CVE-2017-11774", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8409e7e5-6c0f-4f08-9407-81d967608b8d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft... | Affected: Microsoft / Microsoft Outlook | CVSS: 7.8 (HIGH) | EPSS: 0.59627 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-11774", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11774"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11774"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft...", "cve_id": "CVE-2017-11774", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Outlook", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.59627, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99102, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-11774", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ff85b1f5-6b8d-446d-94a6-f83cc29a4bbb", "vulnerability": {"vulnId": "CVE-2020-1054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ff85b1f5-6b8d-446d-94a6-f83cc29a4bbb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Win32k Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1709, Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1803, Windows 10 Version 1809, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1909, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server, version 1803  (Server Core Installation), Windows Server, version 1903 (Server Core installation), Windows Server, version 1909 (Server Core installation) | CVSS: 7.0 (HIGH) | EPSS: 0.54158 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1054", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1054"}, {"id": "GHSA-5QFV-HVXP-FG32", "url": "https://github.com/advisories/GHSA-5QFV-HVXP-FG32"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Win32k Elevation of Privilege Vulnerability", "cve_id": "CVE-2020-1054", "vendor": "Microsoft", "ghsa_id": "GHSA-5QFV-HVXP-FG32", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1709, Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1803, Windows 10 Version 1809, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1909, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server, version 1803  (Server Core Installation), Windows Server, version 1903 (Server Core installation), Windows Server, version 1909 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.54158, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98978, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "51133a83-4765-4d4e-babc-5fb292fa52c2", "vulnerability": {"vulnId": "CVE-2016-3235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "51133a83-4765-4d4e-babc-5fb292fa52c2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which... | Affected: Microsoft / Visio | CVSS: 7.8 (HIGH) | EPSS: 0.43308 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3235", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3235"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which...", "cve_id": "CVE-2016-3235", "vendor": "Microsoft", "ghsa_id": null, "product": "Visio", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.43308, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98691, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "be20791c-68e5-4bce-aaed-d0b810804a0a", "vulnerability": {"vulnId": "CVE-2020-6819", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "be20791c-68e5-4bce-aaed-d0b810804a0a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in... | Affected: Mozilla / Thunderbird, Firefox, Firefox ESR | CVSS: 8.1 (HIGH) | EPSS: 0.03039 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-6819", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6819"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6819"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in...", "cve_id": "CVE-2020-6819", "vendor": "Mozilla", "ghsa_id": null, "product": "Thunderbird, Firefox, Firefox ESR", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.03039, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8705, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6819", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "18c409aa-e12c-4f00-a0bc-4edee8c290f7", "vulnerability": {"vulnId": "CVE-2021-1905", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "18c409aa-e12c-4f00-a0bc-4edee8c290f7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute,... | Affected: Qualcomm / Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | CVSS: 8.4 (HIGH) | EPSS: 0.01543 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1905", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1905"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1905"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute,...", "cve_id": "CVE-2021-1905", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.01543, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74041, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1905", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "04959d1d-8332-49fd-a811-3df9bed91fc8", "vulnerability": {"vulnId": "CVE-2020-10148", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "04959d1d-8332-49fd-a811-3df9bed91fc8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands | Affected: SolarWinds / Orion Platform | CVSS: 9.8 (CRITICAL) | EPSS: 0.9198 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-10148", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10148"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10148"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands", "cve_id": "CVE-2020-10148", "vendor": "SolarWinds", "ghsa_id": null, "product": "Orion Platform", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9198, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99818, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10148", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d3d593b2-d97c-4e3b-9410-b2f07ca98599", "vulnerability": {"vulnId": "CVE-2019-7481", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d3d593b2-d97c-4e3b-9410-b2f07ca98599", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100... | Affected: SonicWall / SMA100 | CVSS: 7.5 (HIGH) | EPSS: 0.99906 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-7481", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7481"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7481"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100...", "cve_id": "CVE-2019-7481", "vendor": "SonicWall", "ghsa_id": null, "product": "SMA100", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99906, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99966, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-7481", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4e005c49-d7c8-4c18-8dfe-8e04fa8012e5", "vulnerability": {"vulnId": "CVE-2021-1675", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4e005c49-d7c8-4c18-8dfe-8e04fa8012e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Print Spooler Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.85305 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1675", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1675"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1675"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Print Spooler Remote Code Execution Vulnerability", "cve_id": "CVE-2021-1675", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.85305, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99712, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-1675", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3397d75e-b0f5-40bb-8b51-fc9f423c18f9", "vulnerability": {"vulnId": "CVE-2020-8644", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3397d75e-b0f5-40bb-8b51-fc9f423c18f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. | Affected: PlaySMS / PlaySMS | CVSS: 9.8 (CRITICAL) | EPSS: 0.86689 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8644", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8644"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8644"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.", "cve_id": "CVE-2020-8644", "vendor": "PlaySMS", "ghsa_id": null, "product": "PlaySMS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86689, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99737, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8644", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e34f0ca9-2f51-45c0-9cc1-78b2bdc47084", "vulnerability": {"vulnId": "CVE-2021-22900", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e34f0ca9-2f51-45c0-9cc1-78b2bdc47084", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to... | Affected: Pulse Secure / Pulse Secure Secure | CVSS: 7.2 (HIGH) | EPSS: 0.14146 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22900", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22900"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22900"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to...", "cve_id": "CVE-2021-22900", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Secure Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.14146, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96469, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22900", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "58ae80d5-3446-4818-9d14-b09682acf252", "vulnerability": {"vulnId": "CVE-2020-16846", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "58ae80d5-3446-4818-9d14-b09682acf252", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in... | Affected: SaltStack / Salt | CVSS: 9.8 (CRITICAL) | EPSS: 0.99585 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-16846", "url": "https://www.cve.org/CVERecord?id=CVE-2020-16846"}, {"id": "GHSA-QR38-H96J-2J3W", "url": "https://github.com/advisories/GHSA-QR38-H96J-2J3W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-16846"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in...", "cve_id": "CVE-2020-16846", "vendor": "SaltStack", "ghsa_id": "GHSA-QR38-H96J-2J3W", "product": "Salt", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99585, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-16846", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "84897a45-c860-4045-8631-d7915d87747c", "vulnerability": {"vulnId": "CVE-2019-16256", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "84897a45-c860-4045-8631-d7915d87747c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location... | Affected: Samsung / SIMalliance Toolbox Browser | CVSS: 9.8 (CRITICAL) | EPSS: 0.04949 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-16256", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16256"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16256"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location...", "cve_id": "CVE-2019-16256", "vendor": "Samsung", "ghsa_id": null, "product": "SIMalliance Toolbox Browser", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.04949, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91895, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16256", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "020a857b-137f-481c-99f4-6ce49756735a", "vulnerability": {"vulnId": "CVE-2020-10199", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "020a857b-137f-481c-99f4-6ce49756735a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). | Affected: Sonatype / Nexus Repository | CVSS: 8.8 (HIGH) | EPSS: 0.99064 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-10199", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10199"}, {"id": "GHSA-G2F6-V5QH-H2MQ", "url": "https://github.com/advisories/GHSA-G2F6-V5QH-H2MQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10199"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).", "cve_id": "CVE-2020-10199", "vendor": "Sonatype", "ghsa_id": "GHSA-G2F6-V5QH-H2MQ", "product": "Nexus Repository", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99064, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99932, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10199", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9cf4c57a-7d49-4c77-b2e4-01d7c4cc6eb7", "vulnerability": {"vulnId": "CVE-2021-20016", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9cf4c57a-7d49-4c77-b2e4-01d7c4cc6eb7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access... | Affected: SonicWall / SonicWall SMA100 | CVSS: 9.8 (CRITICAL) | EPSS: 0.40038 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20016", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20016"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20016"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access...", "cve_id": "CVE-2021-20016", "vendor": "SonicWall", "ghsa_id": null, "product": "SonicWall SMA100", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.40038, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9859, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-20016", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dbd77618-71cf-433d-962d-e4c96dc3f88a", "vulnerability": {"vulnId": "CVE-2018-14558", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "dbd77618-71cf-433d-962d-e4c96dc3f88a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through... | Affected: Tenda / AC7, AC9, AC10 | CVSS: 9.8 (CRITICAL) | EPSS: 0.08742 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-14558", "url": "https://www.cve.org/CVERecord?id=CVE-2018-14558"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-14558"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through...", "cve_id": "CVE-2018-14558", "vendor": "Tenda", "ghsa_id": null, "product": "AC7, AC9, AC10", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08742, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95003, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-14558", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d45d15f1-a4a6-4ad7-a0d4-05c4cffbd5d3", "vulnerability": {"vulnId": "CVE-2020-1464", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d45d15f1-a4a6-4ad7-a0d4-05c4cffbd5d3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Spoofing Vulnerability | Affected: Microsoft / Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.38946 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1464", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1464"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1464"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Spoofing Vulnerability", "cve_id": "CVE-2020-1464", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.38946, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98548, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1464", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c81fb264-2c1c-452d-9c75-aacdedd1beea", "vulnerability": {"vulnId": "CVE-2021-27085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c81fb264-2c1c-452d-9c75-aacdedd1beea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Internet Explorer Remote Code Execution Vulnerability | Affected: Microsoft / Internet Explorer 11 | CVSS: 8.8 (HIGH) | EPSS: 0.05448 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27085", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27085"}, {"id": "GHSA-VM76-5X29-7JX8", "url": "https://github.com/advisories/GHSA-VM76-5X29-7JX8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Internet Explorer Remote Code Execution Vulnerability", "cve_id": "CVE-2021-27085", "vendor": "Microsoft", "ghsa_id": "GHSA-VM76-5X29-7JX8", "product": "Internet Explorer 11", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.05448, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92481, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7284018a-a280-4557-ad1c-61c2696bc40b", "vulnerability": {"vulnId": "CVE-2017-11882", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7284018a-a280-4557-ad1c-61c2696bc40b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow... | Affected: Microsoft / Microsoft Office | CVSS: 7.8 (HIGH) | EPSS: 0.99945 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-11882", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11882"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11882"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow...", "cve_id": "CVE-2017-11882", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Office", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.99945, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99973, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-11882", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "476639bd-beaa-4ac6-a2c0-a09d3b8a527c", "vulnerability": {"vulnId": "CVE-2017-0199", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "476639bd-beaa-4ac6-a2c0-a09d3b8a527c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server... | Affected: Microsoft / Office/WordPad | CVSS: 7.8 (HIGH) | EPSS: 0.99497 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0199", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0199"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0199"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server...", "cve_id": "CVE-2017-0199", "vendor": "Microsoft", "ghsa_id": null, "product": "Office/WordPad", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.99497, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99944, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0199", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "627a7aa8-a0c0-4bf4-bae0-cd8426cb6cee", "vulnerability": {"vulnId": "CVE-2021-22899", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "627a7aa8-a0c0-4bf4-bae0-cd8426cb6cee", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code... | Affected: Pulse Secure / Pulse Connect Secure | CVSS: 8.8 (HIGH) | EPSS: 0.22915 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22899", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22899"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22899"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code...", "cve_id": "CVE-2021-22899", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.22915, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97683, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22899", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "579d1bae-c1eb-40f1-bfab-50f3f6c805a0", "vulnerability": {"vulnId": "CVE-2019-11539", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "579d1bae-c1eb-40f1-bfab-50f3f6c805a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse... | Affected: Pulse Secure / Pulse Connect Secure | CVSS: 8.0 (HIGH) | EPSS: 0.98544 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11539", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11539"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11539"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse...", "cve_id": "CVE-2019-11539", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.98544, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99921, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-11539", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cda72fff-3579-46dd-b1a9-5fb15ec07278", "vulnerability": {"vulnId": "CVE-2020-11652", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cda72fff-3579-46dd-b1a9-5fb15ec07278", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some... | Affected: SaltStack / Salt | CVSS: 6.5 (MEDIUM) | EPSS: 0.86178 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11652", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11652"}, {"id": "GHSA-VP49-2G4R-M3X3", "url": "https://github.com/advisories/GHSA-VP49-2G4R-M3X3"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11652"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some...", "cve_id": "CVE-2020-11652", "vendor": "SaltStack", "ghsa_id": "GHSA-VP49-2G4R-M3X3", "product": "Salt", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.86178, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99727, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11652", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e368402c-70e2-473d-862c-b8cc57287f7a", "vulnerability": {"vulnId": "CVE-2020-8468", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e368402c-70e2-473d-862c-b8cc57287f7a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape... | Affected: Trend Micro / Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS) | CVSS: 8.8 (HIGH) | EPSS: 0.06165 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8468", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8468"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8468"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape...", "cve_id": "CVE-2020-8468", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.06165, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93265, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8468", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "73d90762-52e3-4ac7-b608-d90b4dfc7bec", "vulnerability": {"vulnId": "CVE-2017-8759", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "73d90762-52e3-4ac7-b608-d90b4dfc7bec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or... | Affected: Microsoft / Microsoft .NET Framework | CVSS: 7.8 (HIGH) | EPSS: 0.88698 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-8759", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8759"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8759"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or...", "cve_id": "CVE-2017-8759", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft .NET Framework", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.88698, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99773, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8759", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b7ca85d-54f2-4aab-938f-1356f81603a6", "vulnerability": {"vulnId": "CVE-2018-0798", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3b7ca85d-54f2-4aab-938f-1356f81603a6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution... | Affected: Microsoft / Equation Editor | CVSS: 8.8 (HIGH) | EPSS: 0.95121 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0798", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0798"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0798"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution...", "cve_id": "CVE-2018-0798", "vendor": "Microsoft", "ghsa_id": null, "product": "Equation Editor", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.95121, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99863, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0798", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6d366ad1-071f-4cf4-be67-b693680f22dd", "vulnerability": {"vulnId": "CVE-2015-1641", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6d366ad1-071f-4cf4-be67-b693680f22dd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word... | Affected: Microsoft / Word | CVSS: 7.8 (HIGH) | EPSS: 0.96698 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2015-1641", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1641"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1641"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word...", "cve_id": "CVE-2015-1641", "vendor": "Microsoft", "ghsa_id": null, "product": "Word", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.96698, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99884, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1641", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "143b950e-29d5-46fb-972c-49c7069951a3", "vulnerability": {"vulnId": "CVE-2019-0604", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "143b950e-29d5-46fb-972c-49c7069951a3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package,... | Affected: Microsoft / Microsoft SharePoint Server, Microsoft SharePoint Foundation, Microsoft SharePoint Enterprise Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99913 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0604", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0604"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0604"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package,...", "cve_id": "CVE-2019-0604", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft SharePoint Server, Microsoft SharePoint Foundation, Microsoft SharePoint Enterprise Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99913, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99967, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-0604", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3908e609-a9bc-48ff-ab18-feab61e6eea6", "vulnerability": {"vulnId": "CVE-2020-2555", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3908e609-a9bc-48ff-ab18-feab61e6eea6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are... | Affected: Oracle / WebCenter Portal, Utilities Framework | CVSS: 9.8 (CRITICAL) | EPSS: 0.97116 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-2555", "url": "https://www.cve.org/CVERecord?id=CVE-2020-2555"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-2555"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are...", "cve_id": "CVE-2020-2555", "vendor": "Oracle", "ghsa_id": null, "product": "WebCenter Portal, Utilities Framework", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97116, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99893, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-2555", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b58c861f-249c-4766-9d74-a30c954b3f35", "vulnerability": {"vulnId": "CVE-2012-3152", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b58c861f-249c-4766-9d74-a30c954b3f35", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote... | Affected: Oracle / Fusion Middleware | CVSS: 9.1 (CRITICAL) | EPSS: 0.98793 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-3152", "url": "https://www.cve.org/CVERecord?id=CVE-2012-3152"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-3152"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote...", "cve_id": "CVE-2012-3152", "vendor": "Oracle", "ghsa_id": null, "product": "Fusion Middleware", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.98793, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99926, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-3152", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4b1b615e-b126-4495-8684-ffcaf202ca89", "vulnerability": {"vulnId": "CVE-2019-18988", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4b1b615e-b126-4495-8684-ffcaf202ca89", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers'... | Affected: TeamViewer / TeamViewer Desktop | CVSS: 7.0 (HIGH) | EPSS: 0.04707 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-18988", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18988"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18988"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers'...", "cve_id": "CVE-2019-18988", "vendor": "TeamViewer", "ghsa_id": null, "product": "TeamViewer Desktop", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.04707, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91531, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18988", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e1a5fcbb-bc70-4700-8779-97d3d0add0ef", "vulnerability": {"vulnId": "CVE-2020-10987", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e1a5fcbb-bc70-4700-8779-97d3d0add0ef", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the... | Affected: Tenda / AC15 AC1900 | CVSS: 9.8 (CRITICAL) | EPSS: 0.7981 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-10987", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10987"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10987"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the...", "cve_id": "CVE-2020-10987", "vendor": "Tenda", "ghsa_id": null, "product": "AC15 AC1900", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7981, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10987", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "698bdbe2-2cee-4751-ac57-ee6eb5014b59", "vulnerability": {"vulnId": "CVE-2020-17496", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "698bdbe2-2cee-4751-ac57-ee6eb5014b59", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel... | Affected: vBulletin / vBulletin | CVSS: 9.8 (CRITICAL) | EPSS: 0.87366 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-17496", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17496"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17496"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel...", "cve_id": "CVE-2020-17496", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.87366, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99752, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17496", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "32b1f666-054f-4a62-9cf6-90292b3d892e", "vulnerability": {"vulnId": "CVE-2017-7269", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "32b1f666-054f-4a62-9cf6-90292b3d892e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server... | Affected: Microsoft / Internet Information Services (IIS) | CVSS: 9.8 (CRITICAL) | EPSS: 0.99823 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-7269", "url": "https://www.cve.org/CVERecord?id=CVE-2017-7269"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-7269"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server...", "cve_id": "CVE-2017-7269", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Information Services (IIS)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99823, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99959, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-7269", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "73b4fd08-87d6-4ba7-82e7-36447682e1a2", "vulnerability": {"vulnId": "CVE-2019-1429", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "73b4fd08-87d6-4ba7-82e7-36447682e1a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting... | Affected: Microsoft / Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10 | CVSS: 7.5 (HIGH) | EPSS: 0.7729 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1429", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1429"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1429"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...", "cve_id": "CVE-2019-1429", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer 9, Internet Explorer 11, Internet Explorer 11 on Windows Server 2012, Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems, Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems, Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems, Internet Explorer 10", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.7729, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99544, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1429", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6bed5a5a-d5d0-4c7b-81de-3faa1d0a1b31", "vulnerability": {"vulnId": "CVE-2019-0863", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6bed5a5a-d5d0-4c7b-81de-3faa1d0a1b31", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.05207 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0863", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0863"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0863"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of...", "cve_id": "CVE-2019-0863", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05207, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92232, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0863", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "efbd2127-2f60-404c-a383-8bcc5194cb05", "vulnerability": {"vulnId": "CVE-2020-8243", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "efbd2127-2f60-404c-a383-8bcc5194cb05", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to... | Affected: Pulse Secure / Pulse Connect Secre | CVSS: 7.2 (HIGH) | EPSS: 0.90759 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8243", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8243"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8243"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to...", "cve_id": "CVE-2020-8243", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secre", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.90759, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99802, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8243", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a199ff76-5820-4071-a364-21c4462ed6d6", "vulnerability": {"vulnId": "CVE-2021-35395", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a199ff76-5820-4071-a364-21c4462ed6d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access... | Affected: Realtek / Jungle SDK | CVSS: 9.8 (CRITICAL) | EPSS: 0.981 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-35395", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35395"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35395"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access...", "cve_id": "CVE-2021-35395", "vendor": "Realtek", "ghsa_id": null, "product": "Jungle SDK", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.981, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99911, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35395", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "15d2abd2-9609-4fd3-8193-43a865d5723e", "vulnerability": {"vulnId": "CVE-2020-6287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "15d2abd2-9609-4fd3-8193-43a865d5723e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an... | Affected: SAP SE / SAP NetWeaver AS JAVA (LM Configuration Wizard) | CVSS: 10.0 (CRITICAL) | EPSS: 0.94719 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-6287", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an...", "cve_id": "CVE-2020-6287", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP NetWeaver AS JAVA (LM Configuration Wizard)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.94719, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99857, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e645e90b-662e-4095-bb91-d4eae4ea12fd", "vulnerability": {"vulnId": "CVE-2019-9082", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e645e90b-662e-4095-bb91-d4eae4ea12fd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via... | Affected: ThinkPHP / ThinkPHP | CVSS: 8.8 (HIGH) | EPSS: 0.97419 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-9082", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9082"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9082"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via...", "cve_id": "CVE-2019-9082", "vendor": "ThinkPHP", "ghsa_id": null, "product": "ThinkPHP", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.97419, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99899, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9082", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "07df5201-07fa-4e08-8b55-214af4c2b24f", "vulnerability": {"vulnId": "CVE-2020-5847", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "07df5201-07fa-4e08-8b55-214af4c2b24f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Unraid through 6.8.0 allows Remote Code Execution. | Affected: Lime Technology / Unraid | CVSS: 9.8 (CRITICAL) | EPSS: 0.95844 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5847", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5847"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5847"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unraid through 6.8.0 allows Remote Code Execution.", "cve_id": "CVE-2020-5847", "vendor": "Lime Technology", "ghsa_id": null, "product": "Unraid", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95844, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99873, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5847", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b37ee1a2-348c-4ea4-8d03-bf02ca29ebfc", "vulnerability": {"vulnId": "CVE-2020-3950", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b37ee1a2-348c-4ea4-8d03-bf02ca29ebfc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before... | Affected: VMware / VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac | CVSS: 7.8 (HIGH) | EPSS: 0.07254 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3950", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3950"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3950"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before...", "cve_id": "CVE-2020-3950", "vendor": "VMware", "ghsa_id": null, "product": "VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07254, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94155, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3950", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "29edaa7e-7c72-4b76-8e0b-2570a8adbe81", "vulnerability": {"vulnId": "CVE-2021-26857", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "29edaa7e-7c72-4b76-8e0b-2570a8adbe81", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2010 Service Pack 3, Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8 | CVSS: 7.8 (HIGH) | EPSS: 0.95762 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26857", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26857"}, {"id": "GHSA-2QWQ-GQPM-Q83G", "url": "https://github.com/advisories/GHSA-2QWQ-GQPM-Q83G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26857"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-26857", "vendor": "Microsoft", "ghsa_id": "GHSA-2QWQ-GQPM-Q83G", "product": "Microsoft Exchange Server 2010 Service Pack 3, Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.95762, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99872, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-26857", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "72b0341b-7a50-4e4d-96bf-aaf2f79ec77d", "vulnerability": {"vulnId": "CVE-2019-17026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "72b0341b-7a50-4e4d-96bf-aaf2f79ec77d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks... | Affected: Mozilla / Firefox ESR, Thunderbird, Firefox | CVSS: 8.8 (HIGH) | EPSS: 0.46311 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-17026", "url": "https://www.cve.org/CVERecord?id=CVE-2019-17026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-17026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks...", "cve_id": "CVE-2019-17026", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox ESR, Thunderbird, Firefox", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.46311, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98781, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-17026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "73c4ee84-c1be-4f98-be3f-11c902b2cb2c", "vulnerability": {"vulnId": "CVE-2020-14871", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "73c4ee84-c1be-4f98-be3f-11c902b2cb2c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected... | Affected: Oracle / Solaris Operating System | CVSS: 10.0 (CRITICAL) | EPSS: 0.80157 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-14871", "url": "https://www.cve.org/CVERecord?id=CVE-2020-14871"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-14871"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected...", "cve_id": "CVE-2020-14871", "vendor": "Oracle", "ghsa_id": null, "product": "Solaris Operating System", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.80157, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99608, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-14871", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "caa84b32-39a2-4465-b634-a3535c06d6ff", "vulnerability": {"vulnId": "CVE-2020-10221", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "caa84b32-39a2-4465-b634-a3535c06d6ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in... | Affected: rConfig / rConfig | CVSS: 8.8 (HIGH) | EPSS: 0.77123 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-10221", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10221"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10221"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in...", "cve_id": "CVE-2020-10221", "vendor": "rConfig", "ghsa_id": null, "product": "rConfig", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.77123, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99539, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10221", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "20fd3e1b-d017-4a77-8a3b-195d3a40beb1", "vulnerability": {"vulnId": "CVE-2016-3976", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "20fd3e1b-d017-4a77-8a3b-195d3a40beb1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\\ (dot dot... | Affected: SAP / NetWeaver AS Java | CVSS: 7.5 (HIGH) | EPSS: 0.47252 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3976", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3976"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3976"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\\ (dot dot...", "cve_id": "CVE-2016-3976", "vendor": "SAP", "ghsa_id": null, "product": "NetWeaver AS Java", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.47252, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98803, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3976", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0afe823d-7e01-4167-864c-d150c6914aae", "vulnerability": {"vulnId": "CVE-2017-6327", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0afe823d-7e01-4167-864c-d150c6914aae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual... | Affected: Symantec / Messaging Gateway | CVSS: 8.8 (HIGH) | EPSS: 0.35911 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-6327", "url": "https://www.cve.org/CVERecord?id=CVE-2017-6327"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-6327"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual...", "cve_id": "CVE-2017-6327", "vendor": "Symantec", "ghsa_id": null, "product": "Messaging Gateway", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.35911, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98427, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-6327", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2221f368-e3cb-45f6-a54a-17ead1f39f98", "vulnerability": {"vulnId": "CVE-2019-20085", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2221f368-e3cb-45f6-a54a-17ead1f39f98", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "TVT NVMS-1000 devices allow GET /.. Directory Traversal | Affected: TVT / NVMS-1000 | CVSS: 7.5 (HIGH) | EPSS: 0.96071 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-20085", "url": "https://www.cve.org/CVERecord?id=CVE-2019-20085"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-20085"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TVT NVMS-1000 devices allow GET /.. Directory Traversal", "cve_id": "CVE-2019-20085", "vendor": "TVT", "ghsa_id": null, "product": "NVMS-1000", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.96071, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99876, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-20085", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fac40bd0-a499-4ddb-9214-a05c4b4e71f3", "vulnerability": {"vulnId": "CVE-2019-5544", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fac40bd0-a499-4ddb-9214-a05c4b4e71f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the... | Affected: VMware / ESXi and Horizon DaaS | CVSS: 9.8 (CRITICAL) | EPSS: 0.97258 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-5544", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5544"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5544"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the...", "cve_id": "CVE-2019-5544", "vendor": "VMware", "ghsa_id": null, "product": "ESXi and Horizon DaaS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.97258, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99895, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-5544", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "296d94d0-bb5f-4d70-b1ad-903a953ef2c6", "vulnerability": {"vulnId": "CVE-2021-22005", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "296d94d0-bb5f-4d70-b1ad-903a953ef2c6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on... | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22005", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22005"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22005"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on...", "cve_id": "CVE-2021-22005", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99997, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-22005", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "93140bac-e259-42e2-9ec7-9b31e950a5c0", "vulnerability": {"vulnId": "CVE-2019-11634", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "93140bac-e259-42e2-9ec7-9b31e950a5c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | Affected: Citrix / Workspace App | CVSS: 9.8 (CRITICAL) | EPSS: 0.08026 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-11634", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11634"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11634"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix Workspace App before 1904 for Windows has Incorrect Access Control.", "cve_id": "CVE-2019-11634", "vendor": "Citrix", "ghsa_id": null, "product": "Workspace App", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.08026, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94607, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-11634", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "50c48b58-e6ce-4f62-946b-f8f025e37372", "vulnerability": {"vulnId": "CVE-2020-8655", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "50c48b58-e6ce-4f62-946b-f8f025e37372", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user... | Affected: EyesOfNetwork / EyesOfNetwork | CVSS: 7.8 (HIGH) | EPSS: 0.60075 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8655", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8655"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8655"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user...", "cve_id": "CVE-2020-8655", "vendor": "EyesOfNetwork", "ghsa_id": null, "product": "EyesOfNetwork", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.60075, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99109, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8655", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "47e06f4f-801c-4212-beba-589339c7d70a", "vulnerability": {"vulnId": "CVE-2021-21224", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "47e06f4f-801c-4212-beba-589339c7d70a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.84173 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21224", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21224"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21224"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML...", "cve_id": "CVE-2021-21224", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.84173, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99689, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21224", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fc8e72af-c9e7-4cee-a7da-c4db1605f2b2", "vulnerability": {"vulnId": "CVE-2021-22506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fc8e72af-c9e7-4cee-a7da-c4db1605f2b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0.... | Affected: Micro Focus / Access Manager. | CVSS: 7.5 (HIGH) | EPSS: 0.25695 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22506", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all versions prior to version 5.0....", "cve_id": "CVE-2021-22506", "vendor": "Micro Focus", "ghsa_id": null, "product": "Access Manager.", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.25695, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5525d4ca-6d86-45b7-a581-ed39c0dd1b10", "vulnerability": {"vulnId": "CVE-2021-38645", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5525d4ca-6d86-45b7-a581-ed39c0dd1b10", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Open Management Infrastructure Elevation of Privilege Vulnerability | Affected: Microsoft / Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | CVSS: 7.8 (HIGH) | EPSS: 0.02727 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38645", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38645"}, {"id": "GHSA-727J-58H7-43F5", "url": "https://github.com/advisories/GHSA-727J-58H7-43F5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38645"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Open Management Infrastructure Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-38645", "vendor": "Microsoft", "ghsa_id": "GHSA-727J-58H7-43F5", "product": "Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02727, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85551, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38645", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "083b3efc-9ab1-447f-b37f-87fa7d17e3e8", "vulnerability": {"vulnId": "CVE-2019-19356", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "083b3efc-9ab1-447f-b37f-87fa7d17e3e8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been... | Affected: Netis / WF2419 | CVSS: 7.5 (HIGH) | EPSS: 0.28168 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-19356", "url": "https://www.cve.org/CVERecord?id=CVE-2019-19356"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-19356"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been...", "cve_id": "CVE-2019-19356", "vendor": "Netis", "ghsa_id": null, "product": "WF2419", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.28168, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98058, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-19356", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "04792480-a2ec-45bc-b208-7af8d61a3b9a", "vulnerability": {"vulnId": "CVE-2021-20021", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "04792480-a2ec-45bc-b208-7af8d61a3b9a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP... | Affected: SonicWall / Email Security | CVSS: 9.8 (CRITICAL) | EPSS: 0.8867 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20021", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20021"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20021"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP...", "cve_id": "CVE-2021-20021", "vendor": "SonicWall", "ghsa_id": null, "product": "Email Security", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.8867, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99773, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-20021", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "185f2b19-e49c-4693-874a-309ca55fbb42", "vulnerability": {"vulnId": "CVE-2021-36741", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "185f2b19-e49c-4693-874a-309ca55fbb42", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1... | Affected: Trend Micro / Trend Micro Apex One, Trend Micro OfficeScan, Trend Micro Worry-Free Business Security | CVSS: 8.8 (HIGH) | EPSS: 0.04951 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36741", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36741"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36741"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1...", "cve_id": "CVE-2021-36741", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex One, Trend Micro OfficeScan, Trend Micro Worry-Free Business Security", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.04951, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91899, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36741", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e5c3728-60b4-4228-9ebd-5bbeb67b544a", "vulnerability": {"vulnId": "CVE-2021-21985", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8e5c3728-60b4-4228-9ebd-5bbeb67b544a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in... | Affected: VMware / VMware vCenter Server and VMware Cloud Foundation | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21985", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21985"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21985"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in...", "cve_id": "CVE-2021-21985", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server and VMware Cloud Foundation", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99993, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-21985", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ce2039b0-ad20-4daf-85cd-d9e4111081d5", "vulnerability": {"vulnId": "CVE-2020-8515", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ce2039b0-ad20-4daf-85cd-d9e4111081d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as... | Affected: DrayTek / Vigor2960, Vigor3900, Vigor300B | CVSS: 9.8 (CRITICAL) | EPSS: 0.99993 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8515", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8515"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8515"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as...", "cve_id": "CVE-2020-8515", "vendor": "DrayTek", "ghsa_id": null, "product": "Vigor2960, Vigor3900, Vigor300B", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99993, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8515", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6cac6328-7ea7-4182-802b-435fab7b8f8f", "vulnerability": {"vulnId": "CVE-2021-35464", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6cac6328-7ea7-4182-802b-435fab7b8f8f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does... | Affected: ForgeRock / AM server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-35464", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35464"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35464"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The exploitation does...", "cve_id": "CVE-2021-35464", "vendor": "ForgeRock", "ghsa_id": null, "product": "AM server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99994, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-35464", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "01c9d548-4b88-4810-a928-e5ed34a29cce", "vulnerability": {"vulnId": "CVE-2020-4428", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "01c9d548-4b88-4810-a928-e5ed34a29cce", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM... | Affected: IBM / Data Risk Manager | CVSS: 9.1 (CRITICAL) | EPSS: 0.61692 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-4428", "url": "https://www.cve.org/CVERecord?id=CVE-2020-4428"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-4428"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM...", "cve_id": "CVE-2020-4428", "vendor": "IBM", "ghsa_id": null, "product": "Data Risk Manager", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.61692, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99148, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-4428", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9e7366d9-e505-41b7-8e7b-77676fd64489", "vulnerability": {"vulnId": "CVE-2021-38647", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9e7366d9-e505-41b7-8e7b-77676fd64489", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Affected: Microsoft / Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | CVSS: 9.8 (CRITICAL) | EPSS: 0.99933 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38647", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38647"}, {"id": "GHSA-RP2G-5HW2-Q565", "url": "https://github.com/advisories/GHSA-RP2G-5HW2-Q565"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38647"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Open Management Infrastructure (OMI) Remote Code Execution Vulnerability", "cve_id": "CVE-2021-38647", "vendor": "Microsoft", "ghsa_id": "GHSA-RP2G-5HW2-Q565", "product": "Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99933, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9997, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-38647", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "89c52b1e-9bda-4dbc-8d44-785be2ad4282", "vulnerability": {"vulnId": "CVE-2020-1040", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "89c52b1e-9bda-4dbc-8d44-785be2ad4282", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated... | Affected: Microsoft / Windows Server | CVSS: 9.0 (CRITICAL) | EPSS: 0.07393 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1040", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1040"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1040"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated...", "cve_id": "CVE-2020-1040", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.07393, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94243, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1040", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "92862368-83c4-4818-b45b-7ac9291e5b0f", "vulnerability": {"vulnId": "CVE-2017-16651", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "92862368-83c4-4818-b45b-7ac9291e5b0f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem,... | Affected: Roundcube / Roundcube Webmail | CVSS: 7.8 (HIGH) | EPSS: 0.45742 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-16651", "url": "https://www.cve.org/CVERecord?id=CVE-2017-16651"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-16651"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem,...", "cve_id": "CVE-2017-16651", "vendor": "Roundcube", "ghsa_id": null, "product": "Roundcube Webmail", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.45742, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98763, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-16651", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ffac9685-3a3e-4ea7-8dd8-cc98f31a1183", "vulnerability": {"vulnId": "CVE-2017-9248", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ffac9685-3a3e-4ea7-8dd8-cc98f31a1183", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect... | Affected: Progress Software / Telerik UI for ASP.NET AJAX | CVSS: 9.8 (CRITICAL) | EPSS: 0.75098 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-9248", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9248"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9248"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect...", "cve_id": "CVE-2017-9248", "vendor": "Progress Software", "ghsa_id": null, "product": "Telerik UI for ASP.NET AJAX", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.75098, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99496, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9248", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d67b78f4-4a3b-4e97-9c2a-0c7b713b5e10", "vulnerability": {"vulnId": "CVE-2019-16759", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d67b78f4-4a3b-4e97-9c2a-0c7b713b5e10", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | Affected: vBulletin / vBulletin | CVSS: 9.8 (CRITICAL) | EPSS: 0.99728 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-16759", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16759"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16759"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.", "cve_id": "CVE-2019-16759", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99728, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99952, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16759", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "937f20ab-ed33-46ae-af55-edc077870c30", "vulnerability": {"vulnId": "CVE-2020-29583", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "937f20ab-ed33-46ae-af55-edc077870c30", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account... | Affected: Zyxel / USG devices | CVSS: 9.8 (CRITICAL) | EPSS: 0.90155 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-29583", "url": "https://www.cve.org/CVERecord?id=CVE-2020-29583"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-29583"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account...", "cve_id": "CVE-2020-29583", "vendor": "Zyxel", "ghsa_id": null, "product": "USG devices", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90155, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99795, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-29583", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7e544ed8-4aa3-49a3-a366-2aee8af39219", "vulnerability": {"vulnId": "CVE-2020-8260", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7e544ed8-4aa3-49a3-a366-2aee8af39219", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code... | Affected: Pulse Secure / Pulse Connect Secure / Pulse Policy Secure | CVSS: 7.2 (HIGH) | EPSS: 0.9648 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8260", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8260"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8260"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code...", "cve_id": "CVE-2020-8260", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure / Pulse Policy Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.9648, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8260", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c9f8c3c9-ac74-4927-ab55-5b024df2301c", "vulnerability": {"vulnId": "CVE-2018-2380", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c9f8c3c9-ac74-4927-ab55-5b024df2301c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus... | Affected: SAP SE / SAP CRM | CVSS: 6.6 (MEDIUM) | EPSS: 0.28934 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-2380", "url": "https://www.cve.org/CVERecord?id=CVE-2018-2380"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-2380"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...", "cve_id": "CVE-2018-2380", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP CRM", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.6, "epss_score": 0.28934, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98105, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-2380", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f2283df3-29cc-4a3e-b8b8-72632cae5ab3", "vulnerability": {"vulnId": "CVE-2019-18187", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f2283df3-29cc-4a3e-b8b8-72632cae5ab3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files... | Affected: Trend Micro / Trend Micro OfficeScan | CVSS: 7.5 (HIGH) | EPSS: 0.25125 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-18187", "url": "https://www.cve.org/CVERecord?id=CVE-2019-18187"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-18187"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files...", "cve_id": "CVE-2019-18187", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro OfficeScan", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.25125, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9787, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-18187", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d0dba5f6-c379-475f-8575-1046e0d29271", "vulnerability": {"vulnId": "CVE-2020-3952", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d0dba5f6-c379-475f-8575-1046e0d29271", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does... | Affected: VMware / VMware vCenter Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.90384 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3952", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3952"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3952"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does...", "cve_id": "CVE-2020-3952", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.90384, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99797, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3952", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8f8cf802-6276-4484-8eb3-664e185cb9e1", "vulnerability": {"vulnId": "CVE-2020-25213", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8f8cf802-6276-4484-8eb3-664e185cb9e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it... | Affected: mndpsingh287 / wp-file-manager | CVSS: 10.0 (CRITICAL) | EPSS: 0.97328 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-25213", "url": "https://www.cve.org/CVERecord?id=CVE-2020-25213"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-25213"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it...", "cve_id": "CVE-2020-25213", "vendor": "mndpsingh287", "ghsa_id": null, "product": "wp-file-manager", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.97328, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99896, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-25213", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1435a376-0911-41ea-9ae3-fdc309f34f76", "vulnerability": {"vulnId": "CVE-2021-21972", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "1435a376-0911-41ea-9ae3-fdc309f34f76", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port... | Affected: VMware / VMware vCenter Server, VMware Cloud Foundation | CVSS: 9.8 (CRITICAL) | EPSS: 0.99865 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21972", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21972"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21972"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port...", "cve_id": "CVE-2021-21972", "vendor": "VMware", "ghsa_id": null, "product": "VMware vCenter Server, VMware Cloud Foundation", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99865, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99962, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-21972", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1162200e-cf62-409a-b6fd-33ad7ff76d74", "vulnerability": {"vulnId": "CVE-2021-40539", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "1162200e-cf62-409a-b6fd-33ad7ff76d74", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | Affected: Zoho / ManageEngine ADSelfService Plus | CVSS: 9.8 (CRITICAL) | EPSS: 0.9896 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-40539", "url": "https://www.cve.org/CVERecord?id=CVE-2021-40539"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-40539"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.", "cve_id": "CVE-2021-40539", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine ADSelfService Plus", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9896, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99929, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-40539", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c4bb904f-7400-4418-a1ce-cc0b9dee8a5e", "vulnerability": {"vulnId": "CVE-2020-12271", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c4bb904f-7400-4418-a1ce-cc0b9dee8a5e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in... | Affected: Sophos / XG Firewall | CVSS: 10.0 (CRITICAL) | EPSS: 0.42434 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-12271", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12271"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12271"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in...", "cve_id": "CVE-2020-12271", "vendor": "Sophos", "ghsa_id": null, "product": "XG Firewall", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.42434, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98664, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-12271", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5447503b-d0d6-4757-a441-06ff3f24f4bb", "vulnerability": {"vulnId": "CVE-2020-3992", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5447503b-d0d6-4757-a441-06ff3f24f4bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a... | Affected: VMware / VMware ESXi | CVSS: 9.8 (CRITICAL) | EPSS: 0.83015 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3992", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3992"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3992"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a...", "cve_id": "CVE-2020-3992", "vendor": "VMware", "ghsa_id": null, "product": "VMware ESXi", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83015, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99666, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-3992", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "43f29435-8802-40e2-9bfa-aaf4ccfcb362", "vulnerability": {"vulnId": "CVE-2019-8394", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "43f29435-8802-40e2-9bfa-aaf4ccfcb362", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. | Affected: Zoho / ManageEngine ServiceDesk Plus | CVSS: 6.5 (MEDIUM) | EPSS: 0.63336 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-8394", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8394"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8394"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.", "cve_id": "CVE-2019-8394", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine ServiceDesk Plus", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.63336, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99186, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8394", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fa1ad001-e09c-42fb-a9d7-25b45fefe82e", "vulnerability": {"vulnId": "CVE-2021-36742", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fa1ad001-e09c-42fb-a9d7-25b45fefe82e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1... | Affected: Trend Micro / Trend Micro Apex One, Trend Micro OfficeScan, Trend Micro Worry-Free Business Security | CVSS: 7.8 (HIGH) | EPSS: 0.01482 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36742", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36742"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36742"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1...", "cve_id": "CVE-2021-36742", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex One, Trend Micro OfficeScan, Trend Micro Worry-Free Business Security", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.01482, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-36742", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0e67dd35-e66f-4af9-bcdb-2266f00ede2b", "vulnerability": {"vulnId": "CVE-2019-9978", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0e67dd35-e66f-4af9-bcdb-2266f00ede2b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as... | Affected: Warfare Plugins / Social Warfare | CVSS: 6.1 (MEDIUM) | EPSS: 0.72946 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-9978", "url": "https://www.cve.org/CVERecord?id=CVE-2019-9978"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-9978"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as...", "cve_id": "CVE-2019-9978", "vendor": "Warfare Plugins", "ghsa_id": null, "product": "Social Warfare", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.72946, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99439, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-9978", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5ed3e0b6-e78f-47ec-8880-82a7e1ff531e", "vulnerability": {"vulnId": "CVE-2021-26858", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5ed3e0b6-e78f-47ec-8880-82a7e1ff531e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8 | CVSS: 7.8 (HIGH) | EPSS: 0.93651 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26858", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26858"}, {"id": "GHSA-R4WP-245Q-VR5W", "url": "https://github.com/advisories/GHSA-R4WP-245Q-VR5W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26858"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-26858", "vendor": "Microsoft", "ghsa_id": "GHSA-R4WP-245Q-VR5W", "product": "Microsoft Exchange Server 2013 Cumulative Update 21, Microsoft Exchange Server 2013 Cumulative Update 22, Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 10, Microsoft Exchange Server 2016 Cumulative Update 11, Microsoft Exchange Server 2016 Cumulative Update 12, Microsoft Exchange Server 2016 Cumulative Update 13, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2016 Cumulative Update 16, Microsoft Exchange Server 2016 Cumulative Update 17, Microsoft Exchange Server 2016 Cumulative Update 18, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 8, Microsoft Exchange Server 2016 Cumulative Update 9, Microsoft Exchange Server 2019, Microsoft Exchange Server 2019 Cumulative Update 1, Microsoft Exchange Server 2019 Cumulative Update 2, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2019 Cumulative Update 5, Microsoft Exchange Server 2019 Cumulative Update 6, Microsoft Exchange Server 2019 Cumulative Update 7, Microsoft Exchange Server 2019 Cumulative Update 8", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.93651, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99841, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-26858", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b52a68a1-2756-43e7-b8a4-3787a42cce34", "vulnerability": {"vulnId": "CVE-2020-26919", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b52a68a1-2756-43e7-b8a4-3787a42cce34", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level. | Affected: NETGEAR / JGS516PE | CVSS: 9.8 (CRITICAL) | EPSS: 0.57468 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-26919", "url": "https://www.cve.org/CVERecord?id=CVE-2020-26919"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-26919"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.", "cve_id": "CVE-2020-26919", "vendor": "NETGEAR", "ghsa_id": null, "product": "JGS516PE", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.57468, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99054, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-26919", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "279061ce-438b-4fd8-b50f-696ab6218c3b", "vulnerability": {"vulnId": "CVE-2020-14883", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "279061ce-438b-4fd8-b50f-696ab6218c3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 7.2 (HIGH) | EPSS: 0.97929 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-14883", "url": "https://www.cve.org/CVERecord?id=CVE-2020-14883"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-14883"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...", "cve_id": "CVE-2020-14883", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.97929, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99908, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-14883", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0567ff23-a85a-4717-859e-fa7f5982d684", "vulnerability": {"vulnId": "CVE-2020-24557", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0567ff23-a85a-4717-859e-fa7f5982d684", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a... | Affected: Trend Micro / Trend Micro Apex One, Trend Micro Worry-Free Business Security | CVSS: 7.8 (HIGH) | EPSS: 0.02666 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-24557", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24557"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24557"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a...", "cve_id": "CVE-2020-24557", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro Apex One, Trend Micro Worry-Free Business Security", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.02666, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85203, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24557", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "223f413c-afa5-4057-8d6e-cb258d730bce", "vulnerability": {"vulnId": "CVE-2020-4006", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "223f413c-afa5-4057-8d6e-cb258d730bce", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. | Affected: VMware / VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware Identity Manager (vIDM), VMware Identity Manager Connector (vIDM Connector), VMware Cloud Foundation, vRealize Suite Lifecycle Manager | CVSS: 9.1 (CRITICAL) | EPSS: 0.17302 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-4006", "url": "https://www.cve.org/CVERecord?id=CVE-2020-4006"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-4006"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.", "cve_id": "CVE-2020-4006", "vendor": "VMware", "ghsa_id": null, "product": "VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware Identity Manager (vIDM), VMware Identity Manager Connector (vIDM Connector), VMware Cloud Foundation, vRealize Suite Lifecycle Manager", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.17302, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97022, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-4006", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "137265dd-d850-4d39-a042-aec078130363", "vulnerability": {"vulnId": "CVE-2021-27561", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "137265dd-d850-4d39-a042-aec078130363", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication. | Affected: Yealink / Device Management | CVSS: 9.8 (CRITICAL) | EPSS: 0.82865 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27561", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27561"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27561"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.", "cve_id": "CVE-2021-27561", "vendor": "Yealink", "ghsa_id": null, "product": "Device Management", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.82865, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99663, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27561", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "850427ff-3627-4344-ae29-4aac692204bf", "vulnerability": {"vulnId": "CVE-2021-1906", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "850427ff-3627-4344-ae29-4aac692204bf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute,... | Affected: Qualcomm / Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | CVSS: 6.2 (MEDIUM) | EPSS: 0.0052 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1906", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1906"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1906"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute,...", "cve_id": "CVE-2021-1906", "vendor": "Qualcomm", "ghsa_id": null, "product": "Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.2, "epss_score": 0.0052, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.42028, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1906", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "29482989-cdf4-4a11-99f5-e4c4539ad186", "vulnerability": {"vulnId": "CVE-2021-20023", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "29482989-cdf4-4a11-99f5-e4c4539ad186", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the... | Affected: SonicWall / Email Security | CVSS: 4.9 (MEDIUM) | EPSS: 0.51407 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20023", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20023"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20023"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the...", "cve_id": "CVE-2021-20023", "vendor": "SonicWall", "ghsa_id": null, "product": "Email Security", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 4.9, "epss_score": 0.51407, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9891, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-20023", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1c3027e7-4d90-4f19-ba9b-d26e8ceb4244", "vulnerability": {"vulnId": "CVE-2020-11738", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "1c3027e7-4d90-4f19-ba9b-d26e8ceb4244", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file... | Affected: Snap Creek / Duplicator | CVSS: 7.5 (HIGH) | EPSS: 0.97822 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-11738", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11738"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11738"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file...", "cve_id": "CVE-2020-11738", "vendor": "Snap Creek", "ghsa_id": null, "product": "Duplicator", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.97822, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99906, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11738", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0b5119e5-be9a-484c-adb0-d9994cd46c72", "vulnerability": {"vulnId": "CVE-2021-20022", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0b5119e5-be9a-484c-adb0-d9994cd46c72", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the... | Affected: SonicWall / Email Security | CVSS: 7.2 (HIGH) | EPSS: 0.16509 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20022", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20022"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20022"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the...", "cve_id": "CVE-2021-20022", "vendor": "SonicWall", "ghsa_id": null, "product": "Email Security", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.16509, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96905, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-20022", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3b7eca1a-056a-4d53-b5d6-6f51229df598", "vulnerability": {"vulnId": "CVE-2020-10181", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3b7eca1a-056a-4d53-b5d6-6f51229df598", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges... | Affected: Sumavision / Enhanced Multimedia Router (EMR) | CVSS: 9.8 (CRITICAL) | EPSS: 0.14666 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-10181", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10181"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10181"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges...", "cve_id": "CVE-2020-10181", "vendor": "Sumavision", "ghsa_id": null, "product": "Enhanced Multimedia Router (EMR)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.14666, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96563, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10181", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c70ecbc8-c10d-43c1-9847-3bf046d74753", "vulnerability": {"vulnId": "CVE-2020-5849", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c70ecbc8-c10d-43c1-9847-3bf046d74753", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Unraid 6.8.0 allows authentication bypass. | Affected: Limetech / Unraid | CVSS: 7.5 (HIGH) | EPSS: 0.93243 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5849", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5849"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5849"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unraid 6.8.0 allows authentication bypass.", "cve_id": "CVE-2020-5849", "vendor": "Limetech", "ghsa_id": null, "product": "Unraid", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.93243, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99834, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5849", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f2c08249-78f3-49bd-8000-fbc815eb50c1", "vulnerability": {"vulnId": "CVE-2020-14882", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f2c08249-78f3-49bd-8000-fbc815eb50c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are... | Affected: Oracle / WebLogic Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99997 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-14882", "url": "https://www.cve.org/CVERecord?id=CVE-2020-14882"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-14882"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are...", "cve_id": "CVE-2020-14882", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99997, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": true, "cvss_estimated": false, "epss_percentile": 0.99989, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-14882", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b5462b5a-6f70-400c-8bb0-5f80cfa437db", "vulnerability": {"vulnId": "CVE-2021-31755", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b5462b5a-6f70-400c-8bb0-5f80cfa437db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows... | Affected: Tenda / AC11 | CVSS: 9.8 (CRITICAL) | EPSS: 0.86891 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31755", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31755"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31755"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows...", "cve_id": "CVE-2021-31755", "vendor": "Tenda", "ghsa_id": null, "product": "AC11", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86891, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99742, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31755", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e5bef7a-6236-4ab7-a228-21c8d33f9f3c", "vulnerability": {"vulnId": "CVE-2020-10189", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8e5bef7a-6236-4ab7-a228-21c8d33f9f3c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the... | Affected: Zoho / ManageEngine Desktop Central | CVSS: 9.8 (CRITICAL) | EPSS: 0.99941 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-10189", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10189"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10189"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the...", "cve_id": "CVE-2020-10189", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine Desktop Central", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99941, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99972, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10189", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "06225802-844c-46a0-a7fa-06ad5a5f7bb2", "vulnerability": {"vulnId": "CVE-2021-38649", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "06225802-844c-46a0-a7fa-06ad5a5f7bb2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Open Management Infrastructure Elevation of Privilege Vulnerability | Affected: Microsoft / Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM) | CVSS: 7.0 (HIGH) | EPSS: 0.02887 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38649", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38649"}, {"id": "GHSA-9RVC-MXJM-QH6V", "url": "https://github.com/advisories/GHSA-9RVC-MXJM-QH6V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38649"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Open Management Infrastructure Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-38649", "vendor": "Microsoft", "ghsa_id": "GHSA-9RVC-MXJM-QH6V", "product": "Azure Automation State Configuration, DSC Extension, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, Open Management Infrastructure, System Center Operations Manager (SCOM)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.02887, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86391, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38649", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2bd2b588-10b2-4daa-9940-472c905d4922", "vulnerability": {"vulnId": "CVE-2020-0688", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2bd2b588-10b2-4daa-9940-472c905d4922", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka... | Affected: Microsoft / Microsoft Exchange Server 2013, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30 | CVSS: 8.8 (HIGH) | EPSS: 0.99962 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0688", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0688"}, {"id": "GHSA-4G56-8MC7-HPJQ", "url": "https://github.com/advisories/GHSA-4G56-8MC7-HPJQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0688"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka...", "cve_id": "CVE-2020-0688", "vendor": "Microsoft", "ghsa_id": "GHSA-4G56-8MC7-HPJQ", "product": "Microsoft Exchange Server 2013, Microsoft Exchange Server 2019 Cumulative Update 3, Microsoft Exchange Server 2016 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 4, Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 30", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99962, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99975, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-0688", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4499828d-7ef5-4068-903f-4ec01b0bb7ea", "vulnerability": {"vulnId": "CVE-2021-27059", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4499828d-7ef5-4068-903f-4ec01b0bb7ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016 | CVSS: 7.6 (HIGH) | EPSS: 0.06076 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27059", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27059"}, {"id": "GHSA-4QXG-56MJ-C47P", "url": "https://github.com/advisories/GHSA-4QXG-56MJ-C47P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27059"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office Remote Code Execution Vulnerability", "cve_id": "CVE-2021-27059", "vendor": "Microsoft", "ghsa_id": "GHSA-4QXG-56MJ-C47P", "product": "Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, Microsoft Office 2016", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.6, "epss_score": 0.06076, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9318, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27059", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a25f2175-9e03-48e0-96b7-7c0216c56cf7", "vulnerability": {"vulnId": "CVE-2020-0646", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a25f2175-9e03-48e0-96b7-7c0216c56cf7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code... | Affected: Microsoft / Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, Microsoft .NET Framework 4.8 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems, Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems, Microsoft .NET Framework 4.8 on Windows RT 8.1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1903 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1909 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99222 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0646", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0646"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0646"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code...", "cve_id": "CVE-2020-0646", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, Microsoft .NET Framework 4.8 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 4.8 on Windows 7 for 32-bit Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 7 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows 8.1 for 32-bit systems, Microsoft .NET Framework 4.8 on Windows 8.1 for x64-based systems, Microsoft .NET Framework 4.8 on Windows RT 8.1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1903 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1903 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019  (Server Core installation), Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server, version 1909 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1909 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server, version 1803  (Server Core Installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1803 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016  (Server Core installation), Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.1/4.7.2 on Windows 10 Version 1709 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99222, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0646", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "183ffca5-de30-4d7d-8864-fbe62f65626f", "vulnerability": {"vulnId": "CVE-2019-15949", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "183ffca5-de30-4d7d-8864-fbe62f65626f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the... | Affected: Nagios / XI | CVSS: 8.8 (HIGH) | EPSS: 0.77039 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-15949", "url": "https://www.cve.org/CVERecord?id=CVE-2019-15949"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-15949"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the...", "cve_id": "CVE-2019-15949", "vendor": "Nagios", "ghsa_id": null, "product": "XI", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.77039, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99538, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-15949", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "da0ce379-1f9d-4b8b-ac8d-970f23182c32", "vulnerability": {"vulnId": "CVE-2019-1215", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "da0ce379-1f9d-4b8b-ac8d-970f23182c32", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.19254 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1215", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1215"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1215"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege...", "cve_id": "CVE-2019-1215", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.19254, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9726, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-1215", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e4681d50-ea78-41f9-b07a-5e70cf26dd1b", "vulnerability": {"vulnId": "CVE-2021-30858", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e4681d50-ea78-41f9-b07a-5e70cf26dd1b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6.... | Affected: Apple / macOS, iOS | CVSS: 8.8 (HIGH) | EPSS: 0.13379 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30858", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30858"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30858"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6....", "cve_id": "CVE-2021-30858", "vendor": "Apple", "ghsa_id": null, "product": "macOS, iOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.13379, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96306, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30858", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a6a90d01-be50-46f3-acc9-07c7bfb53331", "vulnerability": {"vulnId": "CVE-2021-20090", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a6a90d01-be50-46f3-acc9-07c7bfb53331", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=... | Affected: Buffalo / Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99983 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-20090", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20090"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20090"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=...", "cve_id": "CVE-2021-20090", "vendor": "Buffalo", "ghsa_id": null, "product": "Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99983, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99982, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20090", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8f0d5c1b-35fe-4178-bba8-f9d8a9247135", "vulnerability": {"vulnId": "CVE-2021-42258", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8f0d5c1b-35fe-4178-bba8-f9d8a9247135", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild... | Affected: BQE / BillQuick Web Suite | CVSS: 9.8 (CRITICAL) | EPSS: 0.74426 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42258", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42258"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42258"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild...", "cve_id": "CVE-2021-42258", "vendor": "BQE", "ghsa_id": null, "product": "BillQuick Web Suite", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.74426, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99481, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-42258", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a9cefde9-6d2f-4626-a93a-c49ceb524f4e", "vulnerability": {"vulnId": "CVE-2021-42013", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a9cefde9-6d2f-4626-a93a-c49ceb524f4e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) | Affected: Apache / Apache HTTP Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99964 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-42013", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42013"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42013"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)", "cve_id": "CVE-2021-42013", "vendor": "Apache", "ghsa_id": null, "product": "Apache HTTP Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99964, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99976, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-42013", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2e7eae76-ceb1-40cb-b2f3-93c54ac6ac13", "vulnerability": {"vulnId": "CVE-2021-21017", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2e7eae76-ceb1-40cb-b2f3-93c54ac6ac13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution | Affected: Adobe / Acrobat Reader | CVSS: 8.8 (HIGH) | EPSS: 0.86326 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21017", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21017"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21017"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution", "cve_id": "CVE-2021-21017", "vendor": "Adobe", "ghsa_id": null, "product": "Acrobat Reader", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.86326, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99729, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21017", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a3270693-0776-46af-971f-2bb97a310f13", "vulnerability": {"vulnId": "CVE-2019-3396", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a3270693-0776-46af-971f-2bb97a310f13", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3... | Affected: Atlassian / Confluence Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99913 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-3396", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3396"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3396"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3...", "cve_id": "CVE-2019-3396", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99913, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99967, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-3396", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6ed615c3-5677-4954-b8f9-83c8b69fa651", "vulnerability": {"vulnId": "CVE-2021-30713", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6ed615c3-5677-4954-b8f9-83c8b69fa651", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to... | Affected: Apple / macOS | CVSS: 7.8 (HIGH) | EPSS: 0.07038 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30713", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30713"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30713"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to...", "cve_id": "CVE-2021-30713", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07038, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93993, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30713", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "28b29114-bfc8-4f07-afad-59d42d9785bb", "vulnerability": {"vulnId": "CVE-2020-27950", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "28b29114-bfc8-4f07-afad-59d42d9785bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update... | Affected: Apple / watchOS, iOS and iPadOS, macOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.1652 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-27950", "url": "https://www.cve.org/CVERecord?id=CVE-2020-27950"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-27950"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update...", "cve_id": "CVE-2020-27950", "vendor": "Apple", "ghsa_id": null, "product": "watchOS, iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.1652, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96907, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-27950", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "82a58593-ac93-496c-a512-b6dac9b801ea", "vulnerability": {"vulnId": "CVE-2021-27102", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "82a58593-ac93-496c-a512-b6dac9b801ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. | Affected: Accellion / FTA | CVSS: 7.8 (HIGH) | EPSS: 0.03654 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27102", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27102"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27102"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.", "cve_id": "CVE-2021-27102", "vendor": "Accellion", "ghsa_id": null, "product": "FTA", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03654, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8925, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27102", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7167ac64-3925-4e15-b32d-63185e530676", "vulnerability": {"vulnId": "CVE-2021-28664", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7167ac64-3925-4e15-b32d-63185e530676", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve... | Affected: Arm / Mali GPU kernel driver | CVSS: 8.8 (HIGH) | EPSS: 0.05407 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-28664", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28664"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28664"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve...", "cve_id": "CVE-2021-28664", "vendor": "Arm", "ghsa_id": null, "product": "Mali GPU kernel driver", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.05407, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9244, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28664", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "89771959-1e86-4401-9b61-359672d8c764", "vulnerability": {"vulnId": "CVE-2017-9822", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "89771959-1e86-4401-9b61-359672d8c764", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka \"2017-08 (Critical) Possible remote code execution on DNN sites.\" | Affected: DotNetNuke / DotNetNuke CMS Fixed in 9.1.1 | CVSS: 8.8 (HIGH) | EPSS: 0.94789 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-9822", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9822"}, {"id": "GHSA-X2RG-FMCV-CRQ5", "url": "https://github.com/advisories/GHSA-X2RG-FMCV-CRQ5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9822"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka \"2017-08 (Critical) Possible remote code execution on DNN sites.\"", "cve_id": "CVE-2017-9822", "vendor": "DotNetNuke", "ghsa_id": "GHSA-X2RG-FMCV-CRQ5", "product": "DotNetNuke CMS Fixed in 9.1.1", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.94789, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99858, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-9822", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b61167fa-0ccd-41a0-adda-55c12ea30186", "vulnerability": {"vulnId": "CVE-2020-5735", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b61167fa-0ccd-41a0-adda-55c12ea30186", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to... | Affected: Amcrest / Amcrest | CVSS: 8.8 (HIGH) | EPSS: 0.36217 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5735", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5735"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5735"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to...", "cve_id": "CVE-2020-5735", "vendor": "Amcrest", "ghsa_id": null, "product": "Amcrest", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.36217, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98435, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5735", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "453694d8-b18e-43fd-83df-b84db41d38a5", "vulnerability": {"vulnId": "CVE-2021-30665", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "453694d8-b18e-43fd-83df-b84db41d38a5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS... | Affected: Apple / macOS | CVSS: 8.8 (HIGH) | EPSS: 0.03675 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30665", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30665"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30665"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS...", "cve_id": "CVE-2021-30665", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03675, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89311, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30665", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7ebee303-2af6-42a6-b622-bdfca6e0d69c", "vulnerability": {"vulnId": "CVE-2020-8193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7ebee303-2af6-42a6-b622-bdfca6e0d69c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... | Affected: Citrix / Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | CVSS: 6.5 (MEDIUM) | EPSS: 0.88411 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8193", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...", "cve_id": "CVE-2020-8193", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.88411, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99768, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "060ef9e1-b95d-4a4d-83b8-ce50f542e2db", "vulnerability": {"vulnId": "CVE-2019-5591", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "060ef9e1-b95d-4a4d-83b8-ce50f542e2db", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by... | Affected: Fortinet / Fortinet FortiOS | CVSS: 6.5 (MEDIUM) | EPSS: 0.18422 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-5591", "url": "https://www.cve.org/CVERecord?id=CVE-2019-5591"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-5591"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by...", "cve_id": "CVE-2019-5591", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.18422, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97156, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-5591", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d2767c65-3229-4dd9-8da9-40e114b61fa0", "vulnerability": {"vulnId": "CVE-2018-4878", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d2767c65-3229-4dd9-8da9-40e114b61fa0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the... | Affected: Adobe / Adobe Flash Player before 28.0.0.161 | CVSS: 7.8 (HIGH) | EPSS: 0.89532 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-4878", "url": "https://www.cve.org/CVERecord?id=CVE-2018-4878"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-4878"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the...", "cve_id": "CVE-2018-4878", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe Flash Player before 28.0.0.161", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.89532, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99784, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-4878", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "10e1561d-efaa-423b-89d2-55b9d175d9b3", "vulnerability": {"vulnId": "CVE-2020-17530", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "10e1561d-efaa-423b-89d2-55b9d175d9b3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts... | Affected: Apache / Apache Struts | CVSS: 9.8 (CRITICAL) | EPSS: 0.95931 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-17530", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17530"}, {"id": "GHSA-JC35-Q369-45PV", "url": "https://github.com/advisories/GHSA-JC35-Q369-45PV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17530"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts...", "cve_id": "CVE-2020-17530", "vendor": "Apache", "ghsa_id": "GHSA-JC35-Q369-45PV", "product": "Apache Struts", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.95931, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99874, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17530", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "42ceb576-30f9-475e-80cf-2800f967d42e", "vulnerability": {"vulnId": "CVE-2020-9818", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "42ceb576-30f9-475e-80cf-2800f967d42e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS... | Affected: Apple / iOS, iOS-1, watchOS | CVSS: 8.8 (HIGH) | EPSS: 0.02286 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9818", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9818"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9818"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS...", "cve_id": "CVE-2020-9818", "vendor": "Apple", "ghsa_id": null, "product": "iOS, iOS-1, watchOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.02286, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82565, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9818", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b4b330d5-ff8a-4ca7-967a-8a366b1c6831", "vulnerability": {"vulnId": "CVE-2020-3580", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b4b330d5-ff8a-4ca7-967a-8a366b1c6831", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software | CVSS: 6.1 (MEDIUM) | EPSS: 0.85575 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3580", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3580"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3580"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities", "cve_id": "CVE-2020-3580", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.85575, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99718, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-3580", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "868ffb19-20bb-4569-8127-45c7e10873ae", "vulnerability": {"vulnId": "CVE-2018-15811", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "868ffb19-20bb-4569-8127-45c7e10873ae", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | Affected: DNN / DotNetNuke | CVSS: 7.5 (HIGH) | EPSS: 0.76143 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-15811", "url": "https://www.cve.org/CVERecord?id=CVE-2018-15811"}, {"id": "GHSA-H595-8PW6-5Q6V", "url": "https://github.com/advisories/GHSA-H595-8PW6-5Q6V"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-15811"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.", "cve_id": "CVE-2018-15811", "vendor": "DNN", "ghsa_id": "GHSA-H595-8PW6-5Q6V", "product": "DotNetNuke", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.76143, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99521, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-15811", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cc12754b-a06c-4d64-b722-e6ece139d3b8", "vulnerability": {"vulnId": "CVE-2020-16017", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cc12754b-a06c-4d64-b722-e6ece139d3b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.02747 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-16017", "url": "https://www.cve.org/CVERecord?id=CVE-2020-16017"}, {"id": "GHSA-GVQV-779R-4JGP", "url": "https://github.com/advisories/GHSA-GVQV-779R-4JGP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-16017"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to...", "cve_id": "CVE-2020-16017", "vendor": "Google", "ghsa_id": "GHSA-GVQV-779R-4JGP", "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.02747, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85667, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-16017", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "405c00fd-5e98-4181-b5fb-5b133107994f", "vulnerability": {"vulnId": "CVE-2021-21148", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "405c00fd-5e98-4181-b5fb-5b133107994f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.19968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21148", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21148"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21148"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted...", "cve_id": "CVE-2021-21148", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.19968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97365, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21148", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6873218b-b37a-415d-97b9-892bfbc44773", "vulnerability": {"vulnId": "CVE-2020-9859", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6873218b-b37a-415d-97b9-892bfbc44773", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5... | Affected: Apple / iOS, macOS, tvOS, watchOS | CVSS: 7.8 (HIGH) | EPSS: 0.00829 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9859", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9859"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9859"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5...", "cve_id": "CVE-2020-9859", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS, tvOS, watchOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.00829, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.55974, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9859", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cd8d5867-de77-4f3b-8410-a596ab4a2e6c", "vulnerability": {"vulnId": "CVE-2021-26084", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cd8d5867-de77-4f3b-8410-a596ab4a2e6c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to... | Affected: Atlassian / Confluence Server, Confluence Data Center | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-26084", "url": "https://www.cve.org/CVERecord?id=CVE-2021-26084"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-26084"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to...", "cve_id": "CVE-2021-26084", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence Server, Confluence Data Center", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99993, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-26084", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e7041c0b-f693-4a91-9602-dddc1c0c931d", "vulnerability": {"vulnId": "CVE-2020-3452", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e7041c0b-f693-4a91-9602-dddc1c0c931d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability | Affected: Cisco / Cisco Adaptive Security Appliance (ASA) Software | CVSS: 7.5 (HIGH) | EPSS: 0.99992 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3452", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3452"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3452"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability", "cve_id": "CVE-2020-3452", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance (ASA) Software", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99992, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99987, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3452", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2022a4e0-1564-42b0-9120-2880ce0855e5", "vulnerability": {"vulnId": "CVE-2020-3566", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2022a4e0-1564-42b0-9120-2880ce0855e5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability | Affected: Cisco / Cisco IOS XR Software | CVSS: 8.6 (HIGH) | EPSS: 0.03702 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3566", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3566"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3566"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability", "cve_id": "CVE-2020-3566", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XR Software", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.03702, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89387, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3566", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "17222452-e81b-44e0-8c5f-a867a3a66388", "vulnerability": {"vulnId": "CVE-2018-18325", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "17222452-e81b-44e0-8c5f-a867a3a66388", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an... | Affected: DNN Software / DNN Platform | CVSS: 7.5 (HIGH) | EPSS: 0.7387 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-18325", "url": "https://www.cve.org/CVERecord?id=CVE-2018-18325"}, {"id": "GHSA-J3G9-6FX5-GJV7", "url": "https://github.com/advisories/GHSA-J3G9-6FX5-GJV7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-18325"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an...", "cve_id": "CVE-2018-18325", "vendor": "DNN Software", "ghsa_id": "GHSA-J3G9-6FX5-GJV7", "product": "DNN Platform", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.7387, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99467, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-18325", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "05d82b40-35e9-4daf-9bcd-bc6430639e24", "vulnerability": {"vulnId": "CVE-2019-15752", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "05d82b40-35e9-4daf-9bcd-bc6430639e24", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file... | Affected: Docker / Docker Desktop Community Edition | CVSS: 7.8 (HIGH) | EPSS: 0.48628 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-15752", "url": "https://www.cve.org/CVERecord?id=CVE-2019-15752"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-15752"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file...", "cve_id": "CVE-2019-15752", "vendor": "Docker", "ghsa_id": null, "product": "Docker Desktop Community Edition", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.48628, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98836, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-15752", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "879422db-7f0e-46f0-bb57-a535143e372a", "vulnerability": {"vulnId": "CVE-2018-13379", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "879422db-7f0e-46f0-bb57-a535143e372a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to... | Affected: Fortinet / Fortinet FortiOS, FortiProxy | CVSS: 9.1 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-13379", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13379"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13379"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to...", "cve_id": "CVE-2018-13379", "vendor": "Fortinet", "ghsa_id": null, "product": "Fortinet FortiOS, FortiProxy", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99995, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-13379", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "077c3505-0490-48e6-853e-fee5c5062a5b", "vulnerability": {"vulnId": "CVE-2021-37973", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "077c3505-0490-48e6-853e-fee5c5062a5b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.11735 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-37973", "url": "https://www.cve.org/CVERecord?id=CVE-2021-37973"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-37973"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially...", "cve_id": "CVE-2021-37973", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.11735, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-37973", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "25329053-1cf6-4033-9f53-51b4c0b2bc8f", "vulnerability": {"vulnId": "CVE-2021-21206", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "25329053-1cf6-4033-9f53-51b4c0b2bc8f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.09307 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21206", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21206"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21206"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2021-21206", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.09307, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95231, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21206", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4c2085d9-cda5-4d48-b967-f2b90fc9b46c", "vulnerability": {"vulnId": "CVE-2021-30661", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4c2085d9-cda5-4d48-b967-f2b90fc9b46c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5,... | Affected: Apple / iOS and iPadOS, Safari, tvOS, watchOS, macOS | CVSS: 8.8 (HIGH) | EPSS: 0.04491 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30661", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30661"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30661"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5,...", "cve_id": "CVE-2021-30661", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, Safari, tvOS, watchOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.04491, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91178, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30661", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "910671ab-05ea-480b-8514-95e74f93a991", "vulnerability": {"vulnId": "CVE-2021-1498", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "910671ab-05ea-480b-8514-95e74f93a991", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco HyperFlex HX Command Injection Vulnerabilities | Affected: Cisco / Cisco HyperFlex HX Data Platform | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1498", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1498"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1498"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco HyperFlex HX Command Injection Vulnerabilities", "cve_id": "CVE-2021-1498", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco HyperFlex HX Data Platform", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99991, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1498", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5341560b-b218-460b-a3a7-99ae02909ae0", "vulnerability": {"vulnId": "CVE-2020-8196", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5341560b-b218-460b-a3a7-99ae02909ae0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... | Affected: Citrix / Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | CVSS: 4.3 (MEDIUM) | EPSS: 0.26333 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8196", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8196"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8196"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...", "cve_id": "CVE-2020-8196", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.26333, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97946, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8196", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "79b774bc-7f83-47ed-8878-78cef73c7776", "vulnerability": {"vulnId": "CVE-2020-25506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "79b774bc-7f83-47ed-8878-78cef73c7776", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code... | Affected: D-Link / DNS-320 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-25506", "url": "https://www.cve.org/CVERecord?id=CVE-2020-25506"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-25506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code...", "cve_id": "CVE-2020-25506", "vendor": "D-Link", "ghsa_id": null, "product": "DNS-320", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99968, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99977, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-25506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f2d5b5bf-0708-423e-a5c1-3454ad7995ff", "vulnerability": {"vulnId": "CVE-2020-16010", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f2d5b5bf-0708-423e-a5c1-3454ad7995ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.06363 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-16010", "url": "https://www.cve.org/CVERecord?id=CVE-2020-16010"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-16010"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to...", "cve_id": "CVE-2020-16010", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.06363, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93442, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-16010", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b0be8937-181b-432f-b6d5-669fd0d36b22", "vulnerability": {"vulnId": "CVE-2020-16009", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b0be8937-181b-432f-b6d5-669fd0d36b22", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.48293 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-16009", "url": "https://www.cve.org/CVERecord?id=CVE-2020-16009"}, {"id": "GHSA-M7MF-48HP-5QMR", "url": "https://github.com/advisories/GHSA-M7MF-48HP-5QMR"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-16009"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2020-16009", "vendor": "Google", "ghsa_id": "GHSA-M7MF-48HP-5QMR", "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.48293, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98828, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-16009", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f05d36f3-cabf-4346-a632-713f8d6ee791", "vulnerability": {"vulnId": "CVE-2020-4427", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f05d36f3-cabf-4346-a632-713f8d6ee791", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured... | Affected: IBM / Data Risk Manager | CVSS: 9.8 (CRITICAL) | EPSS: 0.70031 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-4427", "url": "https://www.cve.org/CVERecord?id=CVE-2020-4427"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-4427"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured...", "cve_id": "CVE-2020-4427", "vendor": "IBM", "ghsa_id": null, "product": "Data Risk Manager", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.70031, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99359, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-4427", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9b6dac2c-d510-4ee2-b9f7-85d2e997fcad", "vulnerability": {"vulnId": "CVE-2020-7961", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9b6dac2c-d510-4ee2-b9f7-85d2e997fcad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services... | Affected: Liferay / Liferay Portal | CVSS: 9.8 (CRITICAL) | EPSS: 0.99905 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-7961", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7961"}, {"id": "GHSA-W7PM-CC4V-F3G8", "url": "https://github.com/advisories/GHSA-W7PM-CC4V-F3G8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-7961"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services...", "cve_id": "CVE-2020-7961", "vendor": "Liferay", "ghsa_id": "GHSA-W7PM-CC4V-F3G8", "product": "Liferay Portal", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99905, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99965, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-7961", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "05c7abbe-af85-4ffd-8bb8-9f16e85363a4", "vulnerability": {"vulnId": "CVE-2021-33739", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "05c7abbe-af85-4ffd-8bb8-9f16e85363a4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft DWM Core Library Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | CVSS: 8.4 (HIGH) | EPSS: 0.06555 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-33739", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33739"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33739"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-33739", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.06555, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93605, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33739", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ff63f828-5f17-48b2-9498-b5750c57af53", "vulnerability": {"vulnId": "CVE-2020-3118", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ff63f828-5f17-48b2-9498-b5750c57af53", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability | Affected: Cisco / Cisco IOS XR Software | CVSS: 8.8 (HIGH) | EPSS: 0.11685 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3118", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3118"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3118"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability", "cve_id": "CVE-2020-3118", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS XR Software", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.11685, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95939, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3118", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d45d45c4-4774-4ed3-ae1d-de8e2e5071c9", "vulnerability": {"vulnId": "CVE-2020-29557", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d45d45c4-4774-4ed3-ae1d-de8e2e5071c9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to... | Affected: D-Link / DIR-825 R1 | CVSS: 9.8 (CRITICAL) | EPSS: 0.5432 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-29557", "url": "https://www.cve.org/CVERecord?id=CVE-2020-29557"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-29557"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to...", "cve_id": "CVE-2020-29557", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-825 R1", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.5432, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98981, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-29557", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "21fe639d-c66b-4890-aafd-0507798e16bc", "vulnerability": {"vulnId": "CVE-2020-5902", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "21fe639d-c66b-4890-aafd-0507798e16bc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface... | Affected: F5 / BIG-IP | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-5902", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5902"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5902"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface...", "cve_id": "CVE-2020-5902", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 1.0, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-5902", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "720fe624-6efa-43df-b37f-b4a48b0fd290", "vulnerability": {"vulnId": "CVE-2021-21166", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "720fe624-6efa-43df-b37f-b4a48b0fd290", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.24027 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21166", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21166"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21166"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2021-21166", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.24027, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97777, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21166", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "52209b4e-1a78-4666-928b-26a33a6cd132", "vulnerability": {"vulnId": "CVE-2021-21193", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "52209b4e-1a78-4666-928b-26a33a6cd132", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.0987 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21193", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21193"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21193"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...", "cve_id": "CVE-2021-21193", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.0987, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95431, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21193", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7aafd238-a535-4b57-8d9c-cec5e8cc155f", "vulnerability": {"vulnId": "CVE-2016-3715", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7aafd238-a535-4b57-8d9c-cec5e8cc155f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | Affected: ImageMagick / ImageMagick | CVSS: 5.5 (MEDIUM) | EPSS: 0.75307 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3715", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3715"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3715"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.", "cve_id": "CVE-2016-3715", "vendor": "ImageMagick", "ghsa_id": null, "product": "ImageMagick", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.75307, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.995, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3715", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f7fc53fc-781f-44ae-b5c4-dc0b1053753b", "vulnerability": {"vulnId": "CVE-2021-31955", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f7fc53fc-781f-44ae-b5c4-dc0b1053753b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Information Disclosure Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2 | CVSS: 5.5 (MEDIUM) | EPSS: 0.81107 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31955", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31955"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31955"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Information Disclosure Vulnerability", "cve_id": "CVE-2021-31955", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.81107, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99625, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31955", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "853719b5-5ab5-497b-ba3e-ec40755f00a0", "vulnerability": {"vulnId": "CVE-2021-31199", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "853719b5-5ab5-497b-ba3e-ec40755f00a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 5.2 (MEDIUM) | EPSS: 0.02954 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31199", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31199"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31199"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-31199", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.2, "epss_score": 0.02954, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86698, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31199", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "498fedb2-7487-49a7-b0d1-6e8822108d0e", "vulnerability": {"vulnId": "CVE-2020-27930", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "498fedb2-7487-49a7-b0d1-6e8822108d0e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9,... | Affected: Apple / watchOS, iOS and iPadOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.22009 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-27930", "url": "https://www.cve.org/CVERecord?id=CVE-2020-27930"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-27930"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9,...", "cve_id": "CVE-2020-27930", "vendor": "Apple", "ghsa_id": null, "product": "watchOS, iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.22009, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97595, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-27930", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e4b255a5-be90-48b3-b987-e7bf22b6d077", "vulnerability": {"vulnId": "CVE-2021-1782", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e4b255a5-be90-48b3-b987-e7bf22b6d077", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 7.0 (HIGH) | EPSS: 0.02222 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1782", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1782"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1782"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update...", "cve_id": "CVE-2021-1782", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.0, "epss_score": 0.02222, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82063, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1782", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "15c054d1-4039-4bff-ad8e-d6e5ed44dc7e", "vulnerability": {"vulnId": "CVE-2021-28663", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "15c054d1-4039-4bff-ad8e-d6e5ed44dc7e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a... | Affected: Arm / Mali GPU kernel driver | CVSS: 8.8 (HIGH) | EPSS: 0.12084 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-28663", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28663"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28663"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a...", "cve_id": "CVE-2021-28663", "vendor": "Arm", "ghsa_id": null, "product": "Mali GPU kernel driver", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.12084, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96026, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28663", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "886cf970-e6ee-4ab2-a342-14b0ca591a26", "vulnerability": {"vulnId": "CVE-2021-1497", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "886cf970-e6ee-4ab2-a342-14b0ca591a26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco HyperFlex HX Command Injection Vulnerabilities | Affected: Cisco / Cisco HyperFlex HX Data Platform | CVSS: 9.8 (CRITICAL) | EPSS: 0.9993 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1497", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1497"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1497"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco HyperFlex HX Command Injection Vulnerabilities", "cve_id": "CVE-2021-1497", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco HyperFlex HX Data Platform", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9993, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1497", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ccfe6953-88b0-4865-9e2a-3b70ba572485", "vulnerability": {"vulnId": "CVE-2019-1653", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ccfe6953-88b0-4865-9e2a-3b70ba572485", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability | Affected: Cisco / Cisco Small Business RV Series Router Firmware | CVSS: 7.5 (HIGH) | EPSS: 0.99876 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-1653", "url": "https://www.cve.org/CVERecord?id=CVE-2019-1653"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-1653"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability", "cve_id": "CVE-2019-1653", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Small Business RV Series Router Firmware", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99876, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99963, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-1653", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1e56242a-80c6-4d74-996f-b94a8d058eb6", "vulnerability": {"vulnId": "CVE-2019-19781", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "1e56242a-80c6-4d74-996f-b94a8d058eb6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. | Affected: Citrix / Application Delivery Controller and Gateway | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-19781", "url": "https://www.cve.org/CVERecord?id=CVE-2019-19781"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-19781"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.", "cve_id": "CVE-2019-19781", "vendor": "Citrix", "ghsa_id": null, "product": "Application Delivery Controller and Gateway", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99998, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-19781", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f592b30f-6d45-4ee0-afcf-1f0093b2c941", "vulnerability": {"vulnId": "CVE-2021-22205", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f592b30f-6d45-4ee0-afcf-1f0093b2c941", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were... | Affected: GitLab / GitLab | CVSS: 10.0 (CRITICAL) | EPSS: 0.99731 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22205", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22205"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22205"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were...", "cve_id": "CVE-2021-22205", "vendor": "GitLab", "ghsa_id": null, "product": "GitLab", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.99731, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99952, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-22205", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "90b2cc5b-554b-4134-9750-92844a2c99b6", "vulnerability": {"vulnId": "CVE-2021-33771", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "90b2cc5b-554b-4134-9750-92844a2c99b6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.10172 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-33771", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33771"}, {"id": "GHSA-JV37-XG37-JXGP", "url": "https://github.com/advisories/GHSA-JV37-XG37-JXGP"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33771"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-33771", "vendor": "Microsoft", "ghsa_id": "GHSA-JV37-XG37-JXGP", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 8.1, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10172, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95527, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33771", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2aa4796f-83c4-41bc-bf17-644f2475e91c", "vulnerability": {"vulnId": "CVE-2021-30762", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2aa4796f-83c4-41bc-bf17-644f2475e91c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content... | Affected: Apple / iOS | CVSS: 8.8 (HIGH) | EPSS: 0.10986 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30762", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30762"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30762"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content...", "cve_id": "CVE-2021-30762", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10986, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95773, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30762", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "67247f21-91e3-4e71-9a2c-f18e47718bec", "vulnerability": {"vulnId": "CVE-2021-1870", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "67247f21-91e3-4e71-9a2c-f18e47718bec", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.0771 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1870", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1870"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1870"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security...", "cve_id": "CVE-2021-1870", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.0771, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94432, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1870", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2c70e6fd-f3db-4b00-bd8a-92831fee1909", "vulnerability": {"vulnId": "CVE-2019-3398", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2c70e6fd-f3db-4b00-bd8a-92831fee1909", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission... | Affected: Atlassian / Confluence | CVSS: 8.8 (HIGH) | EPSS: 0.96837 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-3398", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3398"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3398"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission...", "cve_id": "CVE-2019-3398", "vendor": "Atlassian", "ghsa_id": null, "product": "Confluence", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.96837, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99887, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-3398", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bdb69d40-a6fc-4daa-bdca-0505453552fc", "vulnerability": {"vulnId": "CVE-2020-3161", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bdb69d40-a6fc-4daa-bdca-0505453552fc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability | Affected: Cisco / Cisco IP phone | CVSS: 9.8 (CRITICAL) | EPSS: 0.83855 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-3161", "url": "https://www.cve.org/CVERecord?id=CVE-2020-3161"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-3161"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability", "cve_id": "CVE-2020-3161", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IP phone", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83855, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99685, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-3161", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d889e712-e79b-436f-81ae-0a73887dd1f9", "vulnerability": {"vulnId": "CVE-2018-0296", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d889e712-e79b-436f-81ae-0a73887dd1f9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an... | Affected: Cisco / Cisco Adaptive Security Appliance unknown | CVSS: 7.5 (HIGH) | EPSS: 0.99913 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0296", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0296"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0296"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an...", "cve_id": "CVE-2018-0296", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco Adaptive Security Appliance unknown", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99913, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99967, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0296", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a045ae60-c06a-47de-8c5e-866ba69e17a1", "vulnerability": {"vulnId": "CVE-2018-7600", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a045ae60-c06a-47de-8c5e-866ba69e17a1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an... | Affected: Drupal / Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 | CVSS: 9.8 (CRITICAL) | EPSS: 0.99991 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-7600", "url": "https://www.cve.org/CVERecord?id=CVE-2018-7600"}, {"id": "GHSA-7FH9-933G-885P", "url": "https://github.com/advisories/GHSA-7FH9-933G-885P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-7600"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an...", "cve_id": "CVE-2018-7600", "vendor": "Drupal", "ghsa_id": "GHSA-7FH9-933G-885P", "product": "Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99991, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99985, "used_in_malware": "yes", "vulnerability_id": "CVE-2018-7600", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6e593081-894d-48ae-8686-9c7f5533ebb1", "vulnerability": {"vulnId": "CVE-2021-23874", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6e593081-894d-48ae-8686-9c7f5533ebb1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "McAfee Total Protection (MTP) privilege escalation vulnerability | Affected: McAfee / McAfee Total Protection (MTP) | CVSS: 8.2 (HIGH) | EPSS: 0.01026 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-23874", "url": "https://www.cve.org/CVERecord?id=CVE-2021-23874"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-23874"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "McAfee Total Protection (MTP) privilege escalation vulnerability", "cve_id": "CVE-2021-23874", "vendor": "McAfee", "ghsa_id": null, "product": "McAfee Total Protection (MTP)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.2, "epss_score": 0.01026, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62291, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-23874", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cb482812-fcfb-4f2d-968e-5827814e1e8a", "vulnerability": {"vulnId": "CVE-2021-31956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cb482812-fcfb-4f2d-968e-5827814e1e8a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows NTFS Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.22273 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31956", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows NTFS Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-31956", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.22273, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97616, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "58f4a3ad-05b5-4e75-9045-ba0953c5efa1", "vulnerability": {"vulnId": "CVE-2019-13608", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "58f4a3ad-05b5-4e75-9045-ba0953c5efa1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. | Affected: Citrix / StoreFront Server | CVSS: 7.5 (HIGH) | EPSS: 0.30041 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-13608", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13608"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13608"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.", "cve_id": "CVE-2019-13608", "vendor": "Citrix", "ghsa_id": null, "product": "StoreFront Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.30041, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98161, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-13608", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3cc8f01c-ac1b-4d3d-a462-24b034ac773e", "vulnerability": {"vulnId": "CVE-2021-30633", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3cc8f01c-ac1b-4d3d-a462-24b034ac773e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.3318 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30633", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30633"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30633"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to...", "cve_id": "CVE-2021-30633", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.3318, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98321, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30633", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "75f204ef-2302-4ff9-a98f-2d6841907fe8", "vulnerability": {"vulnId": "CVE-2021-30116", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "75f204ef-2302-4ff9-a98f-2d6841907fe8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6 | Affected: Kaseya / VSA | CVSS: 10.0 (CRITICAL) | EPSS: 0.85735 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30116", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30116"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30116"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6", "cve_id": "CVE-2021-30116", "vendor": "Kaseya", "ghsa_id": null, "product": "VSA", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.85735, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99721, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-30116", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "5f94f311-60ba-4d5c-99b9-72184b4b80c8", "vulnerability": {"vulnId": "CVE-2016-0167", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "5f94f311-60ba-4d5c-99b9-72184b4b80c8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.05683 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-0167", "url": "https://www.cve.org/CVERecord?id=CVE-2016-0167"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-0167"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and...", "cve_id": "CVE-2016-0167", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05683, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92755, "used_in_malware": "yes", "vulnerability_id": "CVE-2016-0167", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6b649925-7d22-44cc-be1c-44eadcfe9a26", "vulnerability": {"vulnId": "CVE-2020-17087", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6b649925-7d22-44cc-be1c-44eadcfe9a26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Local Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.05431 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-17087", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17087"}, {"id": "GHSA-FRQF-HCMW-8JJF", "url": "https://github.com/advisories/GHSA-FRQF-HCMW-8JJF"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17087"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Local Elevation of Privilege Vulnerability", "cve_id": "CVE-2020-17087", "vendor": "Microsoft", "ghsa_id": "GHSA-FRQF-HCMW-8JJF", "product": "Windows 10 Version 1803, Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.05431, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92463, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17087", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9547d8e8-cd0b-40f1-918b-89ff785d512c", "vulnerability": {"vulnId": "CVE-2021-31979", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9547d8e8-cd0b-40f1-918b-89ff785d512c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Kernel Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.8 (HIGH) | EPSS: 0.0454 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31979", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31979"}, {"id": "GHSA-RHCM-C7C7-5WQ8", "url": "https://github.com/advisories/GHSA-RHCM-C7C7-5WQ8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31979"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Kernel Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-31979", "vendor": "Microsoft", "ghsa_id": "GHSA-RHCM-C7C7-5WQ8", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1909, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 21H1, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.0454, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91259, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31979", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f25328c7-7afb-432d-bc1a-bfaf2c767e2f", "vulnerability": {"vulnId": "CVE-2020-0938", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f25328c7-7afb-432d-bc1a-bfaf2c767e2f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.6895 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0938", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0938"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0938"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a...", "cve_id": "CVE-2020-0938", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.6895, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99332, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0938", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ede94627-b4d0-4fdf-a304-4d50e18ac807", "vulnerability": {"vulnId": "CVE-2020-12812", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ede94627-b4d0-4fdf-a304-4d50e18ac807", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in... | Affected: Fortinet / Fortinet FortiOS | CVSS: 7.5 (HIGH) | EPSS: 0.49344 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-12812", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12812"}, {"id": "GHSA-R9CJ-Q2HJ-HFQ9", "url": "https://github.com/advisories/GHSA-R9CJ-Q2HJ-HFQ9"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12812"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in...", "cve_id": "CVE-2020-12812", "vendor": "Fortinet", "ghsa_id": "GHSA-R9CJ-Q2HJ-HFQ9", "product": "Fortinet FortiOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.49344, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98857, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-12812", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "9f3788c1-631c-47c9-8209-3ea8ab07ef1c", "vulnerability": {"vulnId": "CVE-2020-15999", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "9f3788c1-631c-47c9-8209-3ea8ab07ef1c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 9.6 (CRITICAL) | EPSS: 0.44303 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-15999", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15999"}, {"id": "GHSA-PV36-H7JH-QM62", "url": "https://github.com/advisories/GHSA-PV36-H7JH-QM62"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15999"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2020-15999", "vendor": "Google", "ghsa_id": "GHSA-PV36-H7JH-QM62", "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.6, "epss_score": 0.44303, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98722, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15999", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8e90b75a-9367-4570-b0bc-90f0ea6aef8c", "vulnerability": {"vulnId": "CVE-2021-38003", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8e90b75a-9367-4570-b0bc-90f0ea6aef8c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.38573 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-38003", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38003"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38003"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2021-38003", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.38573, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98535, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38003", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "dde40a4c-d002-4fbf-a968-4e407687d987", "vulnerability": {"vulnId": "CVE-2021-30563", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "dde40a4c-d002-4fbf-a968-4e407687d987", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.08928 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30563", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30563"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30563"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2021-30563", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.08928, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9509, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30563", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "43abdd5f-4f57-46f5-a0c0-b47c1e73c2ac", "vulnerability": {"vulnId": "CVE-2020-4430", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "43abdd5f-4f57-46f5-a0c0-b47c1e73c2ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker... | Affected: IBM / Data Risk Manager | CVSS: 4.3 (MEDIUM) | EPSS: 0.68544 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-4430", "url": "https://www.cve.org/CVERecord?id=CVE-2020-4430"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-4430"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker...", "cve_id": "CVE-2020-4430", "vendor": "IBM", "ghsa_id": null, "product": "Data Risk Manager", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.68544, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-4430", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "79c65222-8f20-4fb4-91af-bb060f29648e", "vulnerability": {"vulnId": "CVE-2019-4716", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "79c65222-8f20-4fb4-91af-bb060f29648e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as \"admin\", and... | Affected: IBM / Planning Analytics | CVSS: 9.8 (CRITICAL) | EPSS: 0.86441 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-4716", "url": "https://www.cve.org/CVERecord?id=CVE-2019-4716"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-4716"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as \"admin\", and...", "cve_id": "CVE-2019-4716", "vendor": "IBM", "ghsa_id": null, "product": "Planning Analytics", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.86441, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-4716", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "592cb404-b896-4802-9081-7707fba3ac8f", "vulnerability": {"vulnId": "CVE-2021-31201", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "592cb404-b896-4802-9081-7707fba3ac8f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) | CVSS: 5.2 (MEDIUM) | EPSS: 0.02617 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-31201", "url": "https://www.cve.org/CVERecord?id=CVE-2021-31201"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-31201"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-31201", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.2, "epss_score": 0.02617, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84897, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-31201", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0bc28970-c41f-41b6-9824-8ebddfbb9183", "vulnerability": {"vulnId": "CVE-2020-1020", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0bc28970-c41f-41b6-9824-8ebddfbb9183", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation) | CVSS: 8.8 (HIGH) | EPSS: 0.65037 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1020", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1020"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1020"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a...", "cve_id": "CVE-2020-1020", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.65037, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99232, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1020", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "967aac96-c357-496f-a023-d877f83486ff", "vulnerability": {"vulnId": "CVE-2014-1812", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "967aac96-c357-496f-a023-d877f83486ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.64876 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2014-1812", "url": "https://www.cve.org/CVERecord?id=CVE-2014-1812"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-1812"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and...", "cve_id": "CVE-2014-1812", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.64876, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99227, "used_in_malware": "yes", "vulnerability_id": "CVE-2014-1812", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6652155b-de4f-402b-90f7-3e276eda5113", "vulnerability": {"vulnId": "CVE-2020-0683", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6652155b-de4f-402b-90f7-3e276eda5113", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation) | CVSS: 7.8 (HIGH) | EPSS: 0.07605 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0683", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0683"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0683"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation...", "cve_id": "CVE-2020-0683", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.07605, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94368, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0683", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "6899298e-7bce-4bf1-b16d-69da31ebc491", "vulnerability": {"vulnId": "CVE-2021-33742", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "6899298e-7bce-4bf1-b16d-69da31ebc491", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows MSHTML Platform Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2 | CVSS: 7.5 (HIGH) | EPSS: 0.59407 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-33742", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33742"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33742"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows MSHTML Platform Remote Code Execution Vulnerability", "cve_id": "CVE-2021-33742", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows 10 Version 1809, Windows Server 2019, Windows 10 Version 1909, Windows 10 Version 21H1, Windows 10 Version 2004, Windows 10 Version 20H2, Windows 10 Version 1507, Windows 10 Version 1607, Windows Server 2016, Windows 7, Windows 7 Service Pack 1, Windows 8.1, Windows Server 2008 Service Pack 2, Windows Server 2008  Service Pack 2, Windows Server 2008 R2 Service Pack 1, Windows Server 2012, Windows Server 2012 R2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.59407, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99096, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33742", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b99c67a1-f4c5-4e26-81e4-8c171d7d3504", "vulnerability": {"vulnId": "CVE-2020-17144", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b99c67a1-f4c5-4e26-81e4-8c171d7d3504", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31 | CVSS: 8.4 (HIGH) | EPSS: 0.36514 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-17144", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17144"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17144"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Remote Code Execution Vulnerability", "cve_id": "CVE-2020-17144", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 31", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.4, "epss_score": 0.36514, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98449, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17144", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fff470e6-815b-41fe-acfb-9c889287663e", "vulnerability": {"vulnId": "CVE-2021-34523", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "fff470e6-815b-41fe-acfb-9c889287663e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Elevation of Privilege Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 | CVSS: 9.0 (CRITICAL) | EPSS: 0.9999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-34523", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34523"}, {"id": "GHSA-GCRR-725Q-F8JW", "url": "https://github.com/advisories/GHSA-GCRR-725Q-F8JW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34523"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability", "cve_id": "CVE-2021-34523", "vendor": "Microsoft", "ghsa_id": "GHSA-GCRR-725Q-F8JW", "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.9999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99985, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-34523", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "10dc2f24-cbf8-45f1-bf60-1281008d3b1a", "vulnerability": {"vulnId": "CVE-2016-7255", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "10dc2f24-cbf8-45f1-bf60-1281008d3b1a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold... | Affected: Microsoft / Windows | CVSS: 7.8 (HIGH) | EPSS: 0.80968 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-7255", "url": "https://www.cve.org/CVERecord?id=CVE-2016-7255"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-7255"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold...", "cve_id": "CVE-2016-7255", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.80968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99622, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-7255", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8393c82a-f485-4ac2-b343-fb9377d48ce1", "vulnerability": {"vulnId": "CVE-2019-0708", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8393c82a-f485-4ac2-b343-fb9377d48ce1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker... | Affected: Microsoft / Windows, Windows Server | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0708", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0708"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0708"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker...", "cve_id": "CVE-2019-0708", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99999, "used_in_malware": "yes", "vulnerability_id": "CVE-2019-0708", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d1d17545-35ff-4896-a70b-d5747b13f7ea", "vulnerability": {"vulnId": "CVE-2021-34473", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "d1d17545-35ff-4896-a70b-d5747b13f7ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Exchange Server Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9 | CVSS: 9.1 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-34473", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34473"}, {"id": "GHSA-FGQ9-P33G-XCFC", "url": "https://github.com/advisories/GHSA-FGQ9-P33G-XCFC"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34473"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cve_id": "CVE-2021-34473", "vendor": "Microsoft", "ghsa_id": "GHSA-FGQ9-P33G-XCFC", "product": "Microsoft Exchange Server 2013 Cumulative Update 23, Microsoft Exchange Server 2016 Cumulative Update 19, Microsoft Exchange Server 2016 Cumulative Update 20, Microsoft Exchange Server 2019 Cumulative Update 8, Microsoft Exchange Server 2019 Cumulative Update 9", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.1, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99996, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-34473", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a7bc45af-b6df-4cef-8cf9-c30bf1ee249e", "vulnerability": {"vulnId": "CVE-2018-0171", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a7bc45af-b6df-4cef-8cf9-c30bf1ee249e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to... | Affected: Cisco / Cisco IOS and IOS XE | CVSS: 9.8 (CRITICAL) | EPSS: 0.99479 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-0171", "url": "https://www.cve.org/CVERecord?id=CVE-2018-0171"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-0171"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to...", "cve_id": "CVE-2018-0171", "vendor": "Cisco", "ghsa_id": null, "product": "Cisco IOS and IOS XE", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99479, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99943, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-0171", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f847c266-198b-4b40-8109-6cde9bc68915", "vulnerability": {"vulnId": "CVE-2021-22986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "f847c266-198b-4b40-8109-6cde9bc68915", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd... | Affected: F5 / BIG-IP; BIG-IQ | CVSS: 9.8 (CRITICAL) | EPSS: 0.99898 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22986", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22986"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd...", "cve_id": "CVE-2021-22986", "vendor": "F5", "ghsa_id": null, "product": "BIG-IP; BIG-IQ", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99898, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99965, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-22986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3037e472-554c-4a10-a26a-b6c6ca35e26e", "vulnerability": {"vulnId": "CVE-2020-16013", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3037e472-554c-4a10-a26a-b6c6ca35e26e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.02751 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-16013", "url": "https://www.cve.org/CVERecord?id=CVE-2020-16013"}, {"id": "GHSA-X7FX-MCC9-27J7", "url": "https://github.com/advisories/GHSA-X7FX-MCC9-27J7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-16013"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a...", "cve_id": "CVE-2020-16013", "vendor": "Google", "ghsa_id": "GHSA-X7FX-MCC9-27J7", "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.02751, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8568, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-16013", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "2ef4ec97-44d9-4981-a780-a4ffdfd715dc", "vulnerability": {"vulnId": "CVE-2021-30551", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "2ef4ec97-44d9-4981-a780-a4ffdfd715dc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.64701 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30551", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30551"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30551"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2021-30551", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.64701, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99223, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30551", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "42e22c50-e2fa-44a7-be37-32179761809b", "vulnerability": {"vulnId": "CVE-2021-21220", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "42e22c50-e2fa-44a7-be37-32179761809b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.70435 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-21220", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21220"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21220"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap...", "cve_id": "CVE-2021-21220", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.70435, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99372, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21220", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "00dc34dd-2e1c-4c1e-bdd6-a37c821bee40", "vulnerability": {"vulnId": "CVE-2020-15505", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "00dc34dd-2e1c-4c1e-bdd6-a37c821bee40", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,... | Affected: MobileIron / Core & Connector, Sentry, Monitor and Reporting Database (RDB) | CVSS: 9.8 (CRITICAL) | EPSS: 0.99737 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-15505", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15505"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15505"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3,...", "cve_id": "CVE-2020-15505", "vendor": "MobileIron", "ghsa_id": null, "product": "Core & Connector, Sentry, Monitor and Reporting Database (RDB)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99737, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99953, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15505", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "87579820-8f20-44e0-8d0c-d198acab03ff", "vulnerability": {"vulnId": "CVE-2020-0986", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "87579820-8f20-44e0-8d0c-d198acab03ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of... | Affected: Microsoft / Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004 for 32-bit Systems, Windows Server, version 2004 (Server Core installation), Windows 10 Version 2004 for ARM64-based Systems, Windows 10 Version 2004 for x64-based Systems | CVSS: 7.8 (HIGH) | EPSS: 0.16277 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0986", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0986"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0986"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of...", "cve_id": "CVE-2020-0986", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server, Windows 10 Version 1909 for 32-bit Systems, Windows 10 Version 1909 for x64-based Systems, Windows 10 Version 1909 for ARM64-based Systems, Windows Server, version 1909 (Server Core installation), Windows 10 Version 1903 for 32-bit Systems, Windows 10 Version 1903 for x64-based Systems, Windows 10 Version 1903 for ARM64-based Systems, Windows Server, version 1903 (Server Core installation), Windows 10 Version 2004 for 32-bit Systems, Windows Server, version 2004 (Server Core installation), Windows 10 Version 2004 for ARM64-based Systems, Windows 10 Version 2004 for x64-based Systems", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.16277, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0986", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "4fe963f2-9665-4622-af06-b99d1d6e5c33", "vulnerability": {"vulnId": "CVE-2020-1350", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "4fe963f2-9665-4622-af06-b99d1d6e5c33", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS... | Affected: Microsoft / Windows Server, Windows Server, version 1909 (Server Core installation), Windows Server, version 1903 (Server Core installation), Windows Server, version 2004 (Server Core installation) | CVSS: 10.0 (CRITICAL) | EPSS: 0.96721 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-1350", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1350"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1350"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS...", "cve_id": "CVE-2020-1350", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows Server, Windows Server, version 1909 (Server Core installation), Windows Server, version 1903 (Server Core installation), Windows Server, version 2004 (Server Core installation)", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.96721, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99885, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1350", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "87424010-7a8d-4804-8a96-054c1687b4bb", "vulnerability": {"vulnId": "CVE-2021-30869", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "87424010-7a8d-4804-8a96-054c1687b4bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2,... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.04135 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30869", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30869"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30869"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2,...", "cve_id": "CVE-2021-30869", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04135, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90512, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30869", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aaec88a2-78cb-40cf-ae41-49661028ab9e", "vulnerability": {"vulnId": "CVE-2020-8195", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "aaec88a2-78cb-40cf-ae41-49661028ab9e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix... | Affected: Citrix / Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP | CVSS: 6.5 (MEDIUM) | EPSS: 0.33029 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8195", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8195"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8195"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix...", "cve_id": "CVE-2020-8195", "vendor": "Citrix", "ghsa_id": null, "product": "Citrix ADC, Citrix Gateway, Citrix SDWAN WAN-OP", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.33029, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98314, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8195", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "33474f9a-7416-4acc-9538-ef76364b43ff", "vulnerability": {"vulnId": "CVE-2020-8657", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "33474f9a-7416-4acc-9538-ef76364b43ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API... | Affected: EyesOfNetwork / EyesOfNetwork | CVSS: 9.8 (CRITICAL) | EPSS: 0.91874 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8657", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8657"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8657"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API...", "cve_id": "CVE-2020-8657", "vendor": "EyesOfNetwork", "ghsa_id": null, "product": "EyesOfNetwork", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.91874, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99816, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8657", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7961b42c-b152-4bac-8063-0e07d94232a8", "vulnerability": {"vulnId": "CVE-2021-30632", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7961b42c-b152-4bac-8063-0e07d94232a8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted... | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.6319 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30632", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30632"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30632"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted...", "cve_id": "CVE-2021-30632", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.6319, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99183, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30632", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "8169d2fc-1406-4271-bf34-79d7fc795cb2", "vulnerability": {"vulnId": "CVE-2021-1647", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "8169d2fc-1406-4271-bf34-79d7fc795cb2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Defender Remote Code Execution Vulnerability | Affected: Microsoft / Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft Security Essentials, Microsoft System Center 2012 Endpoint Protection, Windows Defender | CVSS: 7.8 (HIGH) | EPSS: 0.39392 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1647", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1647"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1647"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Defender Remote Code Execution Vulnerability", "cve_id": "CVE-2021-1647", "vendor": "Microsoft", "ghsa_id": null, "product": "Microsoft System Center Endpoint Protection, Microsoft System Center 2012 R2 Endpoint Protection, Microsoft Security Essentials, Microsoft System Center 2012 Endpoint Protection, Windows Defender", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.39392, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98565, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1647", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a813f8a2-5f9f-46fa-afc4-5d6953f0dd5d", "vulnerability": {"vulnId": "CVE-2017-0143", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a813f8a2-5f9f-46fa-afc4-5d6953f0dd5d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;... | Affected: Microsoft / Windows SMB | CVSS: 8.8 (HIGH) | EPSS: 0.93307 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-0143", "url": "https://www.cve.org/CVERecord?id=CVE-2017-0143"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-0143"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...", "cve_id": "CVE-2017-0143", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows SMB", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.93307, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99836, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-0143", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "21170ac4-8ca6-4ee7-a038-442606e1d4d5", "vulnerability": {"vulnId": "CVE-2019-0859", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "21170ac4-8ca6-4ee7-a038-442606e1d4d5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k... | Affected: Microsoft / Windows, Windows Server | CVSS: 7.8 (HIGH) | EPSS: 0.04151 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0859", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0859"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0859"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...", "cve_id": "CVE-2019-0859", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows, Windows Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.04151, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90542, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0859", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "801a3ed8-c333-488e-b11d-3bd6cbb3304f", "vulnerability": {"vulnId": "CVE-2021-36942", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "801a3ed8-c333-488e-b11d-3bd6cbb3304f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows LSA Spoofing Vulnerability | Affected: Microsoft / Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2 | CVSS: 7.5 (HIGH) | EPSS: 0.66023 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-36942", "url": "https://www.cve.org/CVERecord?id=CVE-2021-36942"}, {"id": "GHSA-P8QF-GCXQ-47XM", "url": "https://github.com/advisories/GHSA-P8QF-GCXQ-47XM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-36942"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows LSA Spoofing Vulnerability", "cve_id": "CVE-2021-36942", "vendor": "Microsoft", "ghsa_id": "GHSA-P8QF-GCXQ-47XM", "product": "Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server version 2004, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.66023, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99255, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-36942", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a0d67469-e93c-4d87-9bbe-2766ae6d94fe", "vulnerability": {"vulnId": "CVE-2020-6418", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a0d67469-e93c-4d87-9bbe-2766ae6d94fe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Affected: Google / Chrome | CVSS: 8.8 (HIGH) | EPSS: 0.78808 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-6418", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6418"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6418"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.", "cve_id": "CVE-2020-6418", "vendor": "Google", "ghsa_id": null, "product": "Chrome", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.78808, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99581, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6418", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e3b19fd8-52f1-4c69-b8b9-152537240b3e", "vulnerability": {"vulnId": "CVE-2016-3718", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e3b19fd8-52f1-4c69-b8b9-152537240b3e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery... | Affected: ImageMagick / ImageMagick | CVSS: 5.5 (MEDIUM) | EPSS: 0.76741 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-3718", "url": "https://www.cve.org/CVERecord?id=CVE-2016-3718"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-3718"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery...", "cve_id": "CVE-2016-3718", "vendor": "ImageMagick", "ghsa_id": null, "product": "ImageMagick", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.76741, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99533, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-3718", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aa668c96-cfd7-431c-9376-2f9c54c81c6d", "vulnerability": {"vulnId": "CVE-2020-0878", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "aa668c96-cfd7-431c-9376-2f9c54c81c6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Microsoft Browser Memory Corruption Vulnerability | Affected: Microsoft / ChakraCore, Microsoft Edge (EdgeHTML-based), Internet Explorer 9, Internet Explorer 11 | CVSS: 4.2 (MEDIUM) | EPSS: 0.02696 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0878", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0878"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0878"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Browser Memory Corruption Vulnerability", "cve_id": "CVE-2020-0878", "vendor": "Microsoft", "ghsa_id": null, "product": "ChakraCore, Microsoft Edge (EdgeHTML-based), Internet Explorer 9, Internet Explorer 11", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 4.2, "epss_score": 0.02696, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85391, "used_in_malware": "yes", "vulnerability_id": "CVE-2020-0878", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "62b8c9c3-bf24-4ac3-b594-c88ea0b06fe8", "vulnerability": {"vulnId": "CVE-2021-34527", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "62b8c9c3-bf24-4ac3-b594-c88ea0b06fe8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Windows Print Spooler Remote Code Execution Vulnerability | Affected: Microsoft / Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 20H2 | CVSS: 8.8 (HIGH) | EPSS: 0.99792 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-34527", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34527"}, {"id": "GHSA-75F9-MM5V-2RGM", "url": "https://github.com/advisories/GHSA-75F9-MM5V-2RGM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34527"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Windows Print Spooler Remote Code Execution Vulnerability", "cve_id": "CVE-2021-34527", "vendor": "Microsoft", "ghsa_id": "GHSA-75F9-MM5V-2RGM", "product": "Windows 10 Version 1507, Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 20H2, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 21H2, Windows 11 version 22H2, Windows 8.1, Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2008 Service Pack 2, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server version 20H2", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.99792, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99956, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-34527", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "008b506d-1d30-4cff-a96f-fdf95161219f", "vulnerability": {"vulnId": "CVE-2018-4939", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "008b506d-1d30-4cff-a96f-fdf95161219f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data... | Affected: Adobe / Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions | CVSS: 9.8 (CRITICAL) | EPSS: 0.6167 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-4939", "url": "https://www.cve.org/CVERecord?id=CVE-2018-4939"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-4939"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data...", "cve_id": "CVE-2018-4939", "vendor": "Adobe", "ghsa_id": null, "product": "Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.6167, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99148, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-4939", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "51cab86b-2ba1-4d3d-87ee-defdf15ec644", "vulnerability": {"vulnId": "CVE-2021-22893", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "51cab86b-2ba1-4d3d-87ee-defdf15ec644", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and... | Affected: Pulse Secure / Pulse Connect Secure | CVSS: 10.0 (CRITICAL) | EPSS: 0.47172 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-22893", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22893"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22893"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and...", "cve_id": "CVE-2021-22893", "vendor": "Pulse Secure", "ghsa_id": null, "product": "Pulse Connect Secure", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.47172, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98801, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-22893", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c1dcb5e1-3bdf-4e10-9a70-d9d2530829d6", "vulnerability": {"vulnId": "CVE-2018-20062", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c1dcb5e1-3bdf-4e10-9a70-d9d2530829d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of... | Affected: NoneCms / NoneCms | CVSS: 9.8 (CRITICAL) | EPSS: 0.9953 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-20062", "url": "https://www.cve.org/CVERecord?id=CVE-2018-20062"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-20062"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of...", "cve_id": "CVE-2018-20062", "vendor": "NoneCms", "ghsa_id": null, "product": "NoneCms", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9953, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99945, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-20062", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "db8f9a97-69e1-4aa0-9525-ea69b1f0fd42", "vulnerability": {"vulnId": "CVE-2017-9805", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "db8f9a97-69e1-4aa0-9525-ea69b1f0fd42", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for... | Affected: Apache / Apache Struts | CVSS: 8.1 (HIGH) | EPSS: 0.99396 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-9805", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9805"}, {"id": "GHSA-GG9M-FJ3V-R58C", "url": "https://github.com/advisories/GHSA-GG9M-FJ3V-R58C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9805"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for...", "cve_id": "CVE-2017-9805", "vendor": "Apache", "ghsa_id": "GHSA-GG9M-FJ3V-R58C", "product": "Apache Struts", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.99396, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99941, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9805", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "59da365d-807a-4367-83a8-d6569006d034", "vulnerability": {"vulnId": "CVE-2020-8467", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "59da365d-807a-4367-83a8-d6569006d034", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute... | Affected: Trend Micro / Trend Micro OfficeScan, Trend Micro Apex One | CVSS: 8.8 (HIGH) | EPSS: 0.109 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8467", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8467"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8467"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute...", "cve_id": "CVE-2020-8467", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro OfficeScan, Trend Micro Apex One", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.109, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8467", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5878f31-aca0-477f-943b-fbf7064ff58f", "vulnerability": {"vulnId": "CVE-2020-8599", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a5878f31-aca0-477f-943b-fbf7064ff58f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an... | Affected: Trend Micro / Trend Micro OfficeScan, Trend Micro Apex One | CVSS: 9.8 (CRITICAL) | EPSS: 0.11858 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-8599", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8599"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8599"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an...", "cve_id": "CVE-2020-8599", "vendor": "Trend Micro", "ghsa_id": null, "product": "Trend Micro OfficeScan, Trend Micro Apex One", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.11858, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95976, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8599", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "1bfcf6dd-5a8f-4d95-945f-d0a42f575032", "vulnerability": {"vulnId": "CVE-2016-4437", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "1bfcf6dd-5a8f-4d95-945f-d0a42f575032", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary... | Affected: Apache / Shiro | CVSS: 9.8 (CRITICAL) | EPSS: 0.93039 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2016-4437", "url": "https://www.cve.org/CVERecord?id=CVE-2016-4437"}, {"id": "GHSA-P836-389H-J692", "url": "https://github.com/advisories/GHSA-P836-389H-J692"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-4437"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary...", "cve_id": "CVE-2016-4437", "vendor": "Apache", "ghsa_id": "GHSA-P836-389H-J692", "product": "Shiro", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.93039, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99832, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-4437", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "988ee7f7-a6c6-44f8-9209-ecc2354950b8", "vulnerability": {"vulnId": "CVE-2021-30860", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "988ee7f7-a6c6-44f8-9209-ecc2354950b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS... | Affected: Apple / macOS, watchOS, iOS | CVSS: 7.8 (HIGH) | EPSS: 0.75994 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30860", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30860"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30860"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS...", "cve_id": "CVE-2021-30860", "vendor": "Apple", "ghsa_id": null, "product": "macOS, watchOS, iOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.75994, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99516, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30860", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "545430da-8007-4fea-977b-abd194ca9efe", "vulnerability": {"vulnId": "CVE-2018-15961", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "545430da-8007-4fea-977b-abd194ca9efe", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload... | Affected: Adobe / ColdFusion | CVSS: 9.8 (CRITICAL) | EPSS: 0.9995 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-15961", "url": "https://www.cve.org/CVERecord?id=CVE-2018-15961"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-15961"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload...", "cve_id": "CVE-2018-15961", "vendor": "Adobe", "ghsa_id": null, "product": "ColdFusion", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.9995, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99974, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-15961", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e82d651b-083e-4b7e-a74d-aafde5592495", "vulnerability": {"vulnId": "CVE-2019-2215", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e82d651b-083e-4b7e-a74d-aafde5592495", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.72105 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-2215", "url": "https://www.cve.org/CVERecord?id=CVE-2019-2215"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-2215"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit...", "cve_id": "CVE-2019-2215", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.72105, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99416, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-2215", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b2caaeb7-0bbb-4f37-893d-ffe225309078", "vulnerability": {"vulnId": "CVE-2019-17558", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b2caaeb7-0bbb-4f37-893d-ffe225309078", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be... | Affected: Apache / Apache Solr | CVSS: 7.5 (HIGH) | EPSS: 0.98567 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-17558", "url": "https://www.cve.org/CVERecord?id=CVE-2019-17558"}, {"id": "GHSA-WW97-9W65-2CRX", "url": "https://github.com/advisories/GHSA-WW97-9W65-2CRX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-17558"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be...", "cve_id": "CVE-2019-17558", "vendor": "Apache", "ghsa_id": "GHSA-WW97-9W65-2CRX", "product": "Apache Solr", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.98567, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99921, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-17558", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "ec194657-4503-42c2-b9b6-c9f0ab6a8934", "vulnerability": {"vulnId": "CVE-2020-27932", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "ec194657-4503-42c2-b9b6-c9f0ab6a8934", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS... | Affected: Apple / watchOS, iOS and iPadOS, macOS | CVSS: 7.8 (HIGH) | EPSS: 0.10337 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-27932", "url": "https://www.cve.org/CVERecord?id=CVE-2020-27932"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-27932"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS...", "cve_id": "CVE-2020-27932", "vendor": "Apple", "ghsa_id": null, "product": "watchOS, iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.10337, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95577, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-27932", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "7369623e-5817-44d0-b2c7-581cf469e2b8", "vulnerability": {"vulnId": "CVE-2020-9819", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "7369623e-5817-44d0-b2c7-581cf469e2b8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5,... | Affected: Apple / iOS, iOS-1, watchOS, watchOS-1 | CVSS: 4.3 (MEDIUM) | EPSS: 0.02178 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-9819", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9819"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9819"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5,...", "cve_id": "CVE-2020-9819", "vendor": "Apple", "ghsa_id": null, "product": "iOS, iOS-1, watchOS, watchOS-1", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.02178, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.81677, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9819", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "98f9b17c-4107-4a0d-ab85-750941d517b2", "vulnerability": {"vulnId": "CVE-2018-11776", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "98f9b17c-4107-4a0d-ab85-750941d517b2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by... | Affected: Apache / Apache Struts | CVSS: 8.1 (HIGH) | EPSS: 0.99991 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2018-11776", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11776"}, {"id": "GHSA-CR6J-3JP9-RW65", "url": "https://github.com/advisories/GHSA-CR6J-3JP9-RW65"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11776"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by...", "cve_id": "CVE-2018-11776", "vendor": "Apache", "ghsa_id": "GHSA-CR6J-3JP9-RW65", "product": "Apache Struts", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.1, "epss_score": 0.99991, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99986, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11776", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "36ec45ef-0307-4dd3-a243-9a73f3d3960b", "vulnerability": {"vulnId": "CVE-2021-30666", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "36ec45ef-0307-4dd3-a243-9a73f3d3960b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content... | Affected: Apple / iOS | CVSS: 8.8 (HIGH) | EPSS: 0.02998 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30666", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30666"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30666"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content...", "cve_id": "CVE-2021-30666", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.02998, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86886, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30666", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c872f6d7-4dfd-4f4e-a3b8-a1a15c0bbc99", "vulnerability": {"vulnId": "CVE-2021-27104", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "c872f6d7-4dfd-4f4e-a3b8-a1a15c0bbc99", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is... | Affected: Accellion / FTA | CVSS: 9.8 (CRITICAL) | EPSS: 0.56686 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27104", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27104"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27104"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is...", "cve_id": "CVE-2021-27104", "vendor": "Accellion", "ghsa_id": null, "product": "FTA", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.56686, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99037, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-27104", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "cf7b3e08-771c-4e21-9943-36878c17cbb8", "vulnerability": {"vulnId": "CVE-2020-0041", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "cf7b3e08-771c-4e21-9943-36878c17cbb8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of... | Affected: Google / Android | CVSS: 7.8 (HIGH) | EPSS: 0.03145 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0041", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0041"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0041"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of...", "cve_id": "CVE-2020-0041", "vendor": "Google", "ghsa_id": null, "product": "Android", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03145, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87471, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0041", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "bf5bb0de-55d0-4f8a-9635-cbd7330081f3", "vulnerability": {"vulnId": "CVE-2019-0211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "bf5bb0de-55d0-4f8a-9635-cbd7330081f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or... | Affected: Apache / Apache HTTP Server | CVSS: 7.8 (HIGH) | EPSS: 0.65005 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-0211", "url": "https://www.cve.org/CVERecord?id=CVE-2019-0211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-0211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or...", "cve_id": "CVE-2019-0211", "vendor": "Apache", "ghsa_id": null, "product": "Apache HTTP Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.65005, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99231, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-0211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "564efae1-fba1-4c95-b088-a8437e93fd3e", "vulnerability": {"vulnId": "CVE-2017-5638", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "564efae1-fba1-4c95-b088-a8437e93fd3e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message... | Affected: Apache / Apache Struts | CVSS: 9.8 (CRITICAL) | EPSS: 0.99999 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2017-5638", "url": "https://www.cve.org/CVERecord?id=CVE-2017-5638"}, {"id": "GHSA-J77Q-2QQG-6989", "url": "https://github.com/advisories/GHSA-J77Q-2QQG-6989"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-5638"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message...", "cve_id": "CVE-2017-5638", "vendor": "Apache", "ghsa_id": "GHSA-J77Q-2QQG-6989", "product": "Apache Struts", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.99999, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99994, "used_in_malware": "yes", "vulnerability_id": "CVE-2017-5638", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "106b0196-fd1a-493a-b3fa-4656eff4e864", "vulnerability": {"vulnId": "CVE-2019-6223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "106b0196-fd1a-493a-b3fa-4656eff4e864", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS... | Affected: Apple / iOS, macOS | CVSS: 7.5 (HIGH) | EPSS: 0.02629 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2019-6223", "url": "https://www.cve.org/CVERecord?id=CVE-2019-6223"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-6223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS...", "cve_id": "CVE-2019-6223", "vendor": "Apple", "ghsa_id": null, "product": "iOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02629, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.84969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-6223", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b78f77a7-98d6-45b4-90da-3bb18d6d4e56", "vulnerability": {"vulnId": "CVE-2021-1879", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b78f77a7-98d6-45b4-90da-3bb18d6d4e56", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS... | Affected: Apple / iOS and iPadOS, iOS, watchOS | CVSS: 6.1 (MEDIUM) | EPSS: 0.07082 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1879", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1879"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1879"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS...", "cve_id": "CVE-2021-1879", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, iOS, watchOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.07082, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94029, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1879", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "3abd0b38-5917-4727-bc28-eea299e73346", "vulnerability": {"vulnId": "CVE-2021-30657", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "3abd0b38-5917-4727-bc28-eea299e73346", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A... | Affected: Apple / macOS | CVSS: 5.5 (MEDIUM) | EPSS: 0.68531 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30657", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30657"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30657"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A...", "cve_id": "CVE-2021-30657", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.68531, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30657", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "a5c912c4-5ea2-4b14-9276-1af92b84c864", "vulnerability": {"vulnId": "CVE-2021-30663", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "a5c912c4-5ea2-4b14-9276-1af92b84c864", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3,... | Affected: Apple / macOS | CVSS: 8.8 (HIGH) | EPSS: 0.03493 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30663", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30663"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30663"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3,...", "cve_id": "CVE-2021-30663", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.03493, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88757, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30663", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "eb2cc887-b8ce-4de3-841b-6df58f7208a5", "vulnerability": {"vulnId": "CVE-2020-0069", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "eb2cc887-b8ce-4de3-841b-6df58f7208a5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and... | Affected: Mediatek / Android | CVSS: 7.8 (HIGH) | EPSS: 0.0137 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2020-0069", "url": "https://www.cve.org/CVERecord?id=CVE-2020-0069"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-0069"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and...", "cve_id": "CVE-2020-0069", "vendor": "Mediatek", "ghsa_id": null, "product": "Android", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.0137, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.70915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-0069", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "39ccfff2-adda-4e4f-baac-ba41f3f559bb", "vulnerability": {"vulnId": "CVE-2021-1871", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "39ccfff2-adda-4e4f-baac-ba41f3f559bb", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security... | Affected: Apple / iOS and iPadOS, macOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.07002 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-1871", "url": "https://www.cve.org/CVERecord?id=CVE-2021-1871"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-1871"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security...", "cve_id": "CVE-2021-1871", "vendor": "Apple", "ghsa_id": null, "product": "iOS and iPadOS, macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.07002, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93968, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-1871", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e8a6d466-c532-461b-9675-ed192353198d", "vulnerability": {"vulnId": "CVE-2021-30761", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "e8a6d466-c532-461b-9675-ed192353198d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web... | Affected: Apple / iOS | CVSS: 8.8 (HIGH) | EPSS: 0.10545 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30761", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30761"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30761"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web...", "cve_id": "CVE-2021-30761", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.10545, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95641, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30761", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "0712f328-92fa-4bba-b475-daa57028a97b", "vulnerability": {"vulnId": "CVE-2021-41773", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "0712f328-92fa-4bba-b475-daa57028a97b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 | Affected: Apache / Apache HTTP Server | CVSS: 7.5 (HIGH) | EPSS: 0.99992 | Used in malware: yes | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-41773", "url": "https://www.cve.org/CVERecord?id=CVE-2021-41773"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-41773"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "confirmed_compromise", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49", "cve_id": "CVE-2021-41773", "vendor": "Apache", "ghsa_id": null, "product": "Apache HTTP Server", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.99992, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99986, "used_in_malware": "yes", "vulnerability_id": "CVE-2021-41773", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "36b3fb83-2323-4b1f-bb10-2168f041d37a", "vulnerability": {"vulnId": "CVE-2021-30807", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "36b3fb83-2323-4b1f-bb10-2168f041d37a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1,... | Affected: Apple / macOS | CVSS: 7.8 (HIGH) | EPSS: 0.28839 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-30807", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30807"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30807"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1,...", "cve_id": "CVE-2021-30807", "vendor": "Apple", "ghsa_id": null, "product": "macOS", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.28839, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.981, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30807", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "b7542403-c5d6-4914-ad95-4fbd3fbf1a89", "vulnerability": {"vulnId": "CVE-2021-27562", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-03T01:00:00+01:00"}, "gcve": {"object_uuid": "b7542403-c5d6-4914-ad95-4fbd3fbf1a89", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-03T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-03T00:00:00+00:00"}, "scope": {"notes": "In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when... | Affected: Arm / Trusted Firmware M | CVSS: 5.5 (MEDIUM) | EPSS: 0.03093 | Used in malware: unknown | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2021-27562", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27562"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27562"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when...", "cve_id": "CVE-2021-27562", "vendor": "Arm", "ghsa_id": null, "product": "Trusted Firmware M", "added_date": "2021-11-03T00:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.03093, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87272, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27562", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": false}}]}
{"uuid": "524a6fad-241a-4603-b902-ebd26417cc70", "vulnerability": {"vulnId": "CVE-2021-42359", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-11-02T08:04:17+01:00"}, "gcve": {"object_uuid": "524a6fad-241a-4603-b902-ebd26417cc70", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-11-02T07:04:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-11-02T07:04:17+00:00"}, "scope": {"notes": "WP DSGVO Tools (GDPR) <= 3.1.23 Unauthenticated Arbitrary Post Deletion | Affected: Legalweb / WP DSGVO Tools (GDPR) | CVSS: 7.5 (HIGH) | EPSS: 0.03839 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-42359", "url": "https://www.cve.org/CVERecord?id=CVE-2021-42359"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-42359"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WP DSGVO Tools (GDPR) <= 3.1.23 Unauthenticated Arbitrary Post Deletion", "cve_id": "CVE-2021-42359", "vendor": "Legalweb", "ghsa_id": null, "product": "WP DSGVO Tools (GDPR)", "added_date": "2021-11-02T07:04:17.000Z", "cvss_score": 7.5, "epss_score": 0.03839, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89785, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-42359", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ae04b8fb-1f37-4163-81e7-7a493743209b", "vulnerability": {"vulnId": "CVE-2021-21745", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-10-20T17:20:50+02:00"}, "gcve": {"object_uuid": "ae04b8fb-1f37-4163-81e7-7a493743209b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-10-20T15:20:50+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-10-20T15:20:50+00:00"}, "scope": {"notes": "ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform... | Affected: ZTE / MF971R | CVSS: 4.3 (MEDIUM) | EPSS: 0.55709 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-21745", "url": "https://www.cve.org/CVERecord?id=CVE-2021-21745"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-21745"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform...", "cve_id": "CVE-2021-21745", "vendor": "ZTE", "ghsa_id": null, "product": "MF971R", "added_date": "2021-10-20T15:20:50.000Z", "cvss_score": 4.3, "epss_score": 0.55709, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99013, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-21745", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "daee91a4-bccd-4b35-b416-04a4dc7d993a", "vulnerability": {"vulnId": "CVE-2021-39211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-09-15T18:55:10+02:00"}, "gcve": {"object_uuid": "daee91a4-bccd-4b35-b416-04a4dc7d993a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-09-15T16:55:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-09-15T16:55:10+00:00"}, "scope": {"notes": "Disclosure of GLPI and server information in telemetry endpoint | Affected: Glpi-project / glpi | CVSS: 5.3 (MEDIUM) | EPSS: 0.04699 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-39211", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Disclosure of GLPI and server information in telemetry endpoint", "cve_id": "CVE-2021-39211", "vendor": "Glpi-project", "ghsa_id": null, "product": "glpi", "added_date": "2021-09-15T16:55:10.000Z", "cvss_score": 5.3, "epss_score": 0.04699, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91519, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "586df38b-5d39-4c5b-b117-2519edf8fd26", "vulnerability": {"vulnId": "CVE-2021-39316", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-08-31T13:05:58+02:00"}, "gcve": {"object_uuid": "586df38b-5d39-4c5b-b117-2519edf8fd26", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-08-31T11:05:58+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-08-31T11:05:58+00:00"}, "scope": {"notes": "ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure | Affected: ZoomIt / ZoomSounds - WordPress Wave Audio Player with Playlist | CVSS: 7.5 (HIGH) | EPSS: 0.65763 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-39316", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39316"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39316"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure", "cve_id": "CVE-2021-39316", "vendor": "ZoomIt", "ghsa_id": null, "product": "ZoomSounds - WordPress Wave Audio Player with Playlist", "added_date": "2021-08-31T11:05:58.000Z", "cvss_score": 7.5, "epss_score": 0.65763, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99248, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39316", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7cdf9d33-a743-49c9-aa74-d89e698172a2", "vulnerability": {"vulnId": "CVE-2021-38154", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-08-29T06:59:18+02:00"}, "gcve": {"object_uuid": "7cdf9d33-a743-49c9-aa74-d89e698172a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-08-29T04:59:18+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-08-29T04:59:18+00:00"}, "scope": {"notes": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access,... | Affected: Canon / imageRUNNER ADVANCE iR-ADV C5250 | CVSS: 7.5 (HIGH) | EPSS: 0.04 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-38154", "url": "https://www.cve.org/CVERecord?id=CVE-2021-38154"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-38154"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access,...", "cve_id": "CVE-2021-38154", "vendor": "Canon", "ghsa_id": null, "product": "imageRUNNER ADVANCE iR-ADV C5250", "added_date": "2021-08-29T04:59:18.000Z", "cvss_score": 7.5, "epss_score": 0.04, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90216, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-38154", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "79b36802-2886-43c3-967a-9230feedbcde", "vulnerability": {"vulnId": "CVE-2021-39509", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-08-24T20:52:26+02:00"}, "gcve": {"object_uuid": "79b36802-2886-43c3-967a-9230feedbcde", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-08-24T18:52:26+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-08-24T18:52:26+00:00"}, "scope": {"notes": "An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of... | Affected: D-Link / DIR-816 | CVSS: 9.8 (CRITICAL) | EPSS: 0.05098 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-39509", "url": "https://www.cve.org/CVERecord?id=CVE-2021-39509"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-39509"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of...", "cve_id": "CVE-2021-39509", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-816", "added_date": "2021-08-24T18:52:26.000Z", "cvss_score": 9.8, "epss_score": 0.05098, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92097, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-39509", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "38bd4151-d7f7-4764-acce-cb6d32052fe0", "vulnerability": {"vulnId": "CVE-2021-35327", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-08-05T22:39:17+02:00"}, "gcve": {"object_uuid": "38bd4151-d7f7-4764-acce-cb6d32052fe0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-08-05T20:39:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-08-05T20:39:17+00:00"}, "scope": {"notes": "A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default... | Affected: TOTOLINK / A720R | CVSS: 9.8 (CRITICAL) | EPSS: 0.01384 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-35327", "url": "https://www.cve.org/CVERecord?id=CVE-2021-35327"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-35327"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default...", "cve_id": "CVE-2021-35327", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A720R", "added_date": "2021-08-05T20:39:17.000Z", "cvss_score": 9.8, "epss_score": 0.01384, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71182, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-35327", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3bb27849-15ce-4224-9718-6c5452ead133", "vulnerability": {"vulnId": "CVE-2021-32790", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-07-26T18:30:12+02:00"}, "gcve": {"object_uuid": "3bb27849-15ce-4224-9718-6c5452ead133", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-07-26T16:30:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-07-26T16:30:12+00:00"}, "scope": {"notes": "Blind SQL Injection possible via Authenticated Web-hook Search API Endpoint | Affected: Woocommerce / woocommerce | CVSS: 4.9 (MEDIUM) | EPSS: 0.01265 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-32790", "url": "https://www.cve.org/CVERecord?id=CVE-2021-32790"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-32790"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Blind SQL Injection possible via Authenticated Web-hook Search API Endpoint", "cve_id": "CVE-2021-32790", "vendor": "Woocommerce", "ghsa_id": null, "product": "woocommerce", "added_date": "2021-07-26T16:30:12.000Z", "cvss_score": 4.9, "epss_score": 0.01265, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.68648, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-32790", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4e53f349-382d-4048-8bc9-aa4343dba3ff", "vulnerability": {"vulnId": "CVE-2021-34621", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-06-28T13:22:25+02:00"}, "gcve": {"object_uuid": "4e53f349-382d-4048-8bc9-aa4343dba3ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-06-28T11:22:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-06-28T11:22:25+00:00"}, "scope": {"notes": "ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation | Affected: ProfilePress / ProfilePress | CVSS: 9.8 (CRITICAL) | EPSS: 0.68862 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-34621", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34621"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34621"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation", "cve_id": "CVE-2021-34621", "vendor": "ProfilePress", "ghsa_id": null, "product": "ProfilePress", "added_date": "2021-06-28T11:22:25.000Z", "cvss_score": 9.8, "epss_score": 0.68862, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99329, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34621", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "23e26a8f-a828-4205-9de0-b365967410e3", "vulnerability": {"vulnId": "CVE-2021-34619", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-06-14T10:23:03+02:00"}, "gcve": {"object_uuid": "23e26a8f-a828-4205-9de0-b365967410e3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-06-14T08:23:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-06-14T08:23:03+00:00"}, "scope": {"notes": "Cross-Site Request Forgery in WooCommerce Stock Manager WordPress Plugin | Affected: StoreApps / WooCommerce Stock Manager | CVSS: 8.8 (HIGH) | EPSS: 0.00719 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-34619", "url": "https://www.cve.org/CVERecord?id=CVE-2021-34619"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-34619"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross-Site Request Forgery in WooCommerce Stock Manager WordPress Plugin", "cve_id": "CVE-2021-34619", "vendor": "StoreApps", "ghsa_id": null, "product": "WooCommerce Stock Manager", "added_date": "2021-06-14T08:23:03.000Z", "cvss_score": 8.8, "epss_score": 0.00719, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.52151, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-34619", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a5172396-3344-42a1-93cd-b463c42b32b9", "vulnerability": {"vulnId": "CVE-2021-33357", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-06-09T19:51:55+02:00"}, "gcve": {"object_uuid": "a5172396-3344-42a1-93cd-b463c42b32b9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-06-09T17:51:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-06-09T17:51:55+00:00"}, "scope": {"notes": "A vulnerability exists in RaspAP 2.6 to 2.6.5 in the \"iface\" GET parameter in /ajax/networking/get_netcfg.php, when the \"iface\" parameter value... | Affected: RaspAP / RaspAP | CVSS: 9.8 (CRITICAL) | EPSS: 0.17446 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-33357", "url": "https://www.cve.org/CVERecord?id=CVE-2021-33357"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-33357"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A vulnerability exists in RaspAP 2.6 to 2.6.5 in the \"iface\" GET parameter in /ajax/networking/get_netcfg.php, when the \"iface\" parameter value...", "cve_id": "CVE-2021-33357", "vendor": "RaspAP", "ghsa_id": null, "product": "RaspAP", "added_date": "2021-06-09T17:51:55.000Z", "cvss_score": 9.8, "epss_score": 0.17446, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97041, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-33357", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7e606498-eef5-4673-884c-5603bbeca58a", "vulnerability": {"vulnId": "CVE-2021-22214", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-06-08T16:59:37+02:00"}, "gcve": {"object_uuid": "7e606498-eef5-4673-884c-5603bbeca58a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-06-08T14:59:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-06-08T14:59:37+00:00"}, "scope": {"notes": "When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions... | Affected: GitLab / GitLab | CVSS: 6.8 (MEDIUM) | EPSS: 0.27806 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-22214", "url": "https://www.cve.org/CVERecord?id=CVE-2021-22214"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-22214"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions...", "cve_id": "CVE-2021-22214", "vendor": "GitLab", "ghsa_id": null, "product": "GitLab", "added_date": "2021-06-08T14:59:37.000Z", "cvss_score": 6.8, "epss_score": 0.27806, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98039, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-22214", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "47786ba5-af62-4487-b77e-0887d7df1c63", "vulnerability": {"vulnId": "CVE-2021-24370", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-06-01T10:59:19+02:00"}, "gcve": {"object_uuid": "47786ba5-af62-4487-b77e-0887d7df1c63", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-06-01T08:59:19+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-06-01T08:59:19+00:00"}, "scope": {"notes": "Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE | Affected: Webdados / Fancy Product Designer | CVSS: 9.8 (CRITICAL) | EPSS: 0.47371 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24370", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24370"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24370"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Fancy Product Designer < 4.6.9 - Unauthenticated Arbitrary File Upload and RCE", "cve_id": "CVE-2021-24370", "vendor": "Webdados", "ghsa_id": null, "product": "Fancy Product Designer", "added_date": "2021-06-01T08:59:19.000Z", "cvss_score": 9.8, "epss_score": 0.47371, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98805, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24370", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7dbd5842-414f-47ac-b80f-e6ae545f4ec9", "vulnerability": {"vulnId": "CVE-2021-30461", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-05-29T15:02:12+02:00"}, "gcve": {"object_uuid": "7dbd5842-414f-47ac-b80f-e6ae545f4ec9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-05-29T13:02:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-05-29T13:02:12+00:00"}, "scope": {"notes": "A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR... | Affected: VoIPmonitor / VoIPmonitor | CVSS: 9.8 (CRITICAL) | EPSS: 0.36632 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-30461", "url": "https://www.cve.org/CVERecord?id=CVE-2021-30461"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-30461"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR...", "cve_id": "CVE-2021-30461", "vendor": "VoIPmonitor", "ghsa_id": null, "product": "VoIPmonitor", "added_date": "2021-05-29T13:02:12.000Z", "cvss_score": 9.8, "epss_score": 0.36632, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98455, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-30461", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "191654b3-fa07-4ff0-b012-ece6ba060d45", "vulnerability": {"vulnId": "CVE-2021-32819", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-05-14T02:00:00+02:00"}, "gcve": {"object_uuid": "191654b3-fa07-4ff0-b012-ece6ba060d45", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-05-14T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-05-14T00:00:00+00:00"}, "scope": {"notes": "Remote code execution in squirrelly | Affected: Squirrellyjs / squirrelly | CVSS: 8.0 (HIGH) | EPSS: 0.58286 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-32819", "url": "https://www.cve.org/CVERecord?id=CVE-2021-32819"}, {"id": "GHSA-Q8J6-PWQX-PM96", "url": "https://github.com/advisories/GHSA-Q8J6-PWQX-PM96"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-32819"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote code execution in squirrelly", "cve_id": "CVE-2021-32819", "vendor": "Squirrellyjs", "ghsa_id": "GHSA-Q8J6-PWQX-PM96", "product": "squirrelly", "added_date": "2021-05-14T00:00:00.000Z", "cvss_score": 8.0, "epss_score": 0.58286, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99071, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-32819", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d8d92465-8bc4-4304-a92a-95c67784572e", "vulnerability": {"vulnId": "CVE-2020-23575", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-05-11T00:24:06+02:00"}, "gcve": {"object_uuid": "d8d92465-8bc4-4304-a92a-95c67784572e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-05-10T22:24:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-05-10T22:24:06+00:00"}, "scope": {"notes": "A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an... | Affected: Kyocera / d-COPIA253MF plus | CVSS: 7.5 (HIGH) | EPSS: 0.36765 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-23575", "url": "https://www.cve.org/CVERecord?id=CVE-2020-23575"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-23575"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an...", "cve_id": "CVE-2020-23575", "vendor": "Kyocera", "ghsa_id": null, "product": "d-COPIA253MF plus", "added_date": "2021-05-10T22:24:06.000Z", "cvss_score": 7.5, "epss_score": 0.36765, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9846, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-23575", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6a405451-e77c-49e4-8e6a-f1ae3f3efbaf", "vulnerability": {"vulnId": "CVE-2021-28149", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-05-06T17:12:30+02:00"}, "gcve": {"object_uuid": "6a405451-e77c-49e4-8e6a-f1ae3f3efbaf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-05-06T15:12:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-05-06T15:12:30+00:00"}, "scope": {"notes": "Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote... | Affected: Hongdian / H8922 | CVSS: 6.5 (MEDIUM) | EPSS: 0.1592 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-28149", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28149"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28149"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote...", "cve_id": "CVE-2021-28149", "vendor": "Hongdian", "ghsa_id": null, "product": "H8922", "added_date": "2021-05-06T15:12:30.000Z", "cvss_score": 6.5, "epss_score": 0.1592, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96795, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28149", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f25789b4-465e-43cc-9a09-c14f28d1d044", "vulnerability": {"vulnId": "CVE-2021-28150", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-05-06T17:12:09+02:00"}, "gcve": {"object_uuid": "f25789b4-465e-43cc-9a09-c14f28d1d044", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-05-06T15:12:09+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-05-06T15:12:09+00:00"}, "scope": {"notes": "Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via... | Affected: Hongdian / H8922 | CVSS: 5.5 (MEDIUM) | EPSS: 0.02794 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-28150", "url": "https://www.cve.org/CVERecord?id=CVE-2021-28150"}, {"id": "GHSA-V446-8P4R-76M4", "url": "https://github.com/advisories/GHSA-V446-8P4R-76M4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-28150"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via...", "cve_id": "CVE-2021-28150", "vendor": "Hongdian", "ghsa_id": "GHSA-V446-8P4R-76M4", "product": "H8922", "added_date": "2021-05-06T15:12:09.000Z", "cvss_score": 5.5, "epss_score": 0.02794, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85935, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-28150", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ea313553-a8b5-4d00-af68-4ba1f79c62f8", "vulnerability": {"vulnId": "CVE-2021-3287", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-04-22T14:58:00+02:00"}, "gcve": {"object_uuid": "ea313553-a8b5-4d00-af68-4ba1f79c62f8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-04-22T12:58:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-04-22T12:58:00+00:00"}, "scope": {"notes": "Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. | Affected: Zoho / ManageEngine OpManager | CVSS: 9.8 (CRITICAL) | EPSS: 0.51332 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-3287", "url": "https://www.cve.org/CVERecord?id=CVE-2021-3287"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-3287"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.", "cve_id": "CVE-2021-3287", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine OpManager", "added_date": "2021-04-22T12:58:00.000Z", "cvss_score": 9.8, "epss_score": 0.51332, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98905, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-3287", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "59852c89-7f1b-4801-9bd4-86cffd05dee9", "vulnerability": {"vulnId": "CVE-2021-27692", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-04-16T01:14:32+02:00"}, "gcve": {"object_uuid": "59852c89-7f1b-4801-9bd4-86cffd05dee9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-04-15T23:14:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-04-15T23:14:32+00:00"}, "scope": {"notes": "Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute... | Affected: Tenda / G1 and G3 routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.03194 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-27692", "url": "https://www.cve.org/CVERecord?id=CVE-2021-27692"}, {"id": "GHSA-RXJ2-G98J-WFHH", "url": "https://github.com/advisories/GHSA-RXJ2-G98J-WFHH"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-27692"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute...", "cve_id": "CVE-2021-27692", "vendor": "Tenda", "ghsa_id": "GHSA-RXJ2-G98J-WFHH", "product": "G1 and G3 routers", "added_date": "2021-04-15T23:14:32.000Z", "cvss_score": 9.8, "epss_score": 0.03194, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87664, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-27692", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1cfc8c3a-dc76-47c5-bff6-1feff69646a7", "vulnerability": {"vulnId": "CVE-2020-17453", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-04-05T02:00:00+02:00"}, "gcve": {"object_uuid": "1cfc8c3a-dc76-47c5-bff6-1feff69646a7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-04-05T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-04-05T00:00:00+00:00"}, "scope": {"notes": "WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. | Affected: WSO2 / WSO2 Management Console | CVSS: 6.1 (MEDIUM) | EPSS: 0.26225 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-17453", "url": "https://www.cve.org/CVERecord?id=CVE-2020-17453"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-17453"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.", "cve_id": "CVE-2020-17453", "vendor": "WSO2", "ghsa_id": null, "product": "WSO2 Management Console", "added_date": "2021-04-05T00:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.26225, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97942, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-17453", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5fe5f7a7-ab7a-4f2b-8355-b3714cefb4ad", "vulnerability": {"vulnId": "CVE-2020-19625", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-03-26T15:31:21+01:00"}, "gcve": {"object_uuid": "5fe5f7a7-ab7a-4f2b-8355-b3714cefb4ad", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-03-26T14:31:21+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-03-26T14:31:21+00:00"}, "scope": {"notes": "Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary... | Affected: Oria / gridx | CVSS: 9.8 (CRITICAL) | EPSS: 0.13143 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-19625", "url": "https://www.cve.org/CVERecord?id=CVE-2020-19625"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-19625"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary...", "cve_id": "CVE-2020-19625", "vendor": "Oria", "ghsa_id": null, "product": "gridx", "added_date": "2021-03-26T14:31:21.000Z", "cvss_score": 9.8, "epss_score": 0.13143, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96251, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-19625", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "14e9eeda-6feb-4193-991d-f6c3773b7caf", "vulnerability": {"vulnId": "CVE-2021-24217", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-03-25T08:17:45+01:00"}, "gcve": {"object_uuid": "14e9eeda-6feb-4193-991d-f6c3773b7caf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-03-25T07:17:45+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-03-25T07:17:45+00:00"}, "scope": {"notes": "Facebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain | Affected: Facebook / Facebook for WordPress | CVSS: 8.1 (HIGH) | EPSS: 0.0352 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24217", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24217"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24217"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Facebook for WordPress < 3.0.0 - PHP Object Injection with POP Chain", "cve_id": "CVE-2021-24217", "vendor": "Facebook", "ghsa_id": null, "product": "Facebook for WordPress", "added_date": "2021-03-25T07:17:45.000Z", "cvss_score": 8.1, "epss_score": 0.0352, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88838, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24217", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a7c72db5-b90f-459f-82f2-3c5b777ec5f5", "vulnerability": {"vulnId": "CVE-2021-24219", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-03-24T11:36:04+01:00"}, "gcve": {"object_uuid": "a7c72db5-b90f-459f-82f2-3c5b777ec5f5", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-03-24T10:36:04+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-03-24T10:36:04+00:00"}, "scope": {"notes": "All Thrive Themes and Plugins - Unauthenticated Option Update | Affected: Thrive Themes / Thrive Optimize, Thrive Comments, Thrive Headline Optimizer, Thrive Leads, Thrive Ultimatum, Thrive Quiz Builder, Thrive Apprentice, Thrive Visual Editor, Thrive Dashboard, Thrive Ovation, Thrive Clever Widgets, Rise by Thrive Themes, Ignition by Thrive Themes, Luxe by Thrive Themes, FocusBlog by Thrive Themes, Minus by Thrive Themes, Squared by Thrive Themes, Voice, Performag by Thrive Themes, Pressive by Thrive Themes, Storied by Thrive Themes, Thrive Themes Builder | CVSS: 5.3 (MEDIUM) | EPSS: 0.02059 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24219", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24219"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24219"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "All Thrive Themes and Plugins - Unauthenticated Option Update", "cve_id": "CVE-2021-24219", "vendor": "Thrive Themes", "ghsa_id": null, "product": "Thrive Optimize, Thrive Comments, Thrive Headline Optimizer, Thrive Leads, Thrive Ultimatum, Thrive Quiz Builder, Thrive Apprentice, Thrive Visual Editor, Thrive Dashboard, Thrive Ovation, Thrive Clever Widgets, Rise by Thrive Themes, Ignition by Thrive Themes, Luxe by Thrive Themes, FocusBlog by Thrive Themes, Minus by Thrive Themes, Squared by Thrive Themes, Voice, Performag by Thrive Themes, Pressive by Thrive Themes, Storied by Thrive Themes, Thrive Themes Builder", "added_date": "2021-03-24T10:36:04.000Z", "cvss_score": 5.3, "epss_score": 0.02059, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80609, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24219", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1820cdf2-22db-4067-a94b-a716592909c9", "vulnerability": {"vulnId": "CVE-2021-24170", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-03-03T07:33:07+01:00"}, "gcve": {"object_uuid": "1820cdf2-22db-4067-a94b-a716592909c9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-03-03T06:33:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-03-03T06:33:07+00:00"}, "scope": {"notes": "User Profile Picture < 2.5.0 - Sensitive Information Disclosure | Affected: User Profile Picture / User Profile Picture | CVSS: 7.5 (HIGH) | EPSS: 0.04788 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-24170", "url": "https://www.cve.org/CVERecord?id=CVE-2021-24170"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-24170"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "User Profile Picture < 2.5.0 - Sensitive Information Disclosure", "cve_id": "CVE-2021-24170", "vendor": "User Profile Picture", "ghsa_id": null, "product": "User Profile Picture", "added_date": "2021-03-03T06:33:07.000Z", "cvss_score": 7.5, "epss_score": 0.04788, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91651, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-24170", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9bb6ab78-9043-41f0-8c98-4a2bab833335", "vulnerability": {"vulnId": "CVE-2021-25864", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-01-26T08:09:07+01:00"}, "gcve": {"object_uuid": "9bb6ab78-9043-41f0-8c98-4a2bab833335", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-01-26T07:09:07+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-01-26T07:09:07+00:00"}, "scope": {"notes": "node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an... | Affected: Foddy / node-red-contrib-huemagic | CVSS: 7.5 (HIGH) | EPSS: 0.09331 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-25864", "url": "https://www.cve.org/CVERecord?id=CVE-2021-25864"}, {"id": "GHSA-FRPW-JRWX-HCFV", "url": "https://github.com/advisories/GHSA-FRPW-JRWX-HCFV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-25864"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an...", "cve_id": "CVE-2021-25864", "vendor": "Foddy", "ghsa_id": "GHSA-FRPW-JRWX-HCFV", "product": "node-red-contrib-huemagic", "added_date": "2021-01-26T07:09:07.000Z", "cvss_score": 7.5, "epss_score": 0.09331, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95239, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-25864", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a785d3f9-3035-469d-b127-8a833d30c465", "vulnerability": {"vulnId": "CVE-2021-20617", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2021-01-14T09:20:16+01:00"}, "gcve": {"object_uuid": "a785d3f9-3035-469d-b127-8a833d30c465", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2021-01-14T08:20:16+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2021-01-14T08:20:16+00:00"}, "scope": {"notes": "Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute... | Affected: Seeds / acmailer and acmailer DB | CVSS: 9.8 (CRITICAL) | EPSS: 0.07871 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2021-20617", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20617"}, {"id": "GHSA-6456-HR4P-P4PQ", "url": "https://github.com/advisories/GHSA-6456-HR4P-P4PQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2021-20617"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute...", "cve_id": "CVE-2021-20617", "vendor": "Seeds", "ghsa_id": "GHSA-6456-HR4P-P4PQ", "product": "acmailer and acmailer DB", "added_date": "2021-01-14T08:20:16.000Z", "cvss_score": 9.8, "epss_score": 0.07871, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94528, "used_in_malware": "unknown", "vulnerability_id": "CVE-2021-20617", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9a8d566f-bec5-4f7f-9210-818ae582ff76", "vulnerability": {"vulnId": "CVE-2020-10770", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-12-15T01:00:00+01:00"}, "gcve": {"object_uuid": "9a8d566f-bec5-4f7f-9210-818ae582ff76", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-12-15T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-12-15T00:00:00+00:00"}, "scope": {"notes": "A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter... | Affected: Red Hat / Keycloak | CVSS: 5.3 (MEDIUM) | EPSS: 0.69724 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-10770", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10770"}, {"id": "GHSA-JH7Q-5MWF-QVHW", "url": "https://github.com/advisories/GHSA-JH7Q-5MWF-QVHW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10770"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter...", "cve_id": "CVE-2020-10770", "vendor": "Red Hat", "ghsa_id": "GHSA-JH7Q-5MWF-QVHW", "product": "Keycloak", "added_date": "2020-12-15T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.69724, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99351, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10770", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "17aeeee2-3c16-4199-bb42-d64291ca5007", "vulnerability": {"vulnId": "CVE-2020-27387", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-11-05T02:18:12+01:00"}, "gcve": {"object_uuid": "17aeeee2-3c16-4199-bb42-d64291ca5007", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-11-05T01:18:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-11-05T01:18:12+00:00"}, "scope": {"notes": "An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to... | Affected: HorizontCMS / HorizontCMS | CVSS: 8.8 (HIGH) | EPSS: 0.18461 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-27387", "url": "https://www.cve.org/CVERecord?id=CVE-2020-27387"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-27387"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to...", "cve_id": "CVE-2020-27387", "vendor": "HorizontCMS", "ghsa_id": null, "product": "HorizontCMS", "added_date": "2020-11-05T01:18:12.000Z", "cvss_score": 8.8, "epss_score": 0.18461, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97161, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-27387", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fd646c98-25ea-4b63-bda8-f56d5331c88f", "vulnerability": {"vulnId": "CVE-2020-6308", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-10-20T15:31:10+02:00"}, "gcve": {"object_uuid": "fd646c98-25ea-4b63-bda8-f56d5331c88f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-10-20T13:31:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-10-20T13:31:10+00:00"}, "scope": {"notes": "SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary... | Affected: SAP SE / SAP BusinessObjects Business Intelligence Platform (Web Services) | CVSS: 5.3 (MEDIUM) | EPSS: 0.61736 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-6308", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6308"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6308"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SAP BusinessObjects Business Intelligence Platform (Web Services) versions - 410, 420, 430, allows an unauthenticated attacker to inject arbitrary...", "cve_id": "CVE-2020-6308", "vendor": "SAP SE", "ghsa_id": null, "product": "SAP BusinessObjects Business Intelligence Platform (Web Services)", "added_date": "2020-10-20T13:31:10.000Z", "cvss_score": 5.3, "epss_score": 0.61736, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6308", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "54ff1219-7834-412a-9c83-a09067e7b6d6", "vulnerability": {"vulnId": "CVE-2020-26876", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-10-07T18:56:25+02:00"}, "gcve": {"object_uuid": "54ff1219-7834-412a-9c83-a09067e7b6d6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-10-07T16:56:25+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-10-07T16:56:25+00:00"}, "scope": {"notes": "The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by... | Affected: Red Timmy / wp-courses | CVSS: 7.5 (HIGH) | EPSS: 0.10551 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-26876", "url": "https://www.cve.org/CVERecord?id=CVE-2020-26876"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-26876"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by...", "cve_id": "CVE-2020-26876", "vendor": "Red Timmy", "ghsa_id": null, "product": "wp-courses", "added_date": "2020-10-07T16:56:25.000Z", "cvss_score": 7.5, "epss_score": 0.10551, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95643, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-26876", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a55bb097-3c68-4902-85d6-2b804c16e95b", "vulnerability": {"vulnId": "CVE-2020-24219", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-10-06T15:16:05+02:00"}, "gcve": {"object_uuid": "a55bb097-3c68-4902-85d6-2b804c16e95b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-10-06T13:16:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-10-06T13:16:05+00:00"}, "scope": {"notes": "An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to... | Affected: URayTech / IPTV/H.264/H.265 video encoders | CVSS: 7.5 (HIGH) | EPSS: 0.23636 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-24219", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24219"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24219"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to...", "cve_id": "CVE-2020-24219", "vendor": "URayTech", "ghsa_id": null, "product": "IPTV/H.264/H.265 video encoders", "added_date": "2020-10-06T13:16:05.000Z", "cvss_score": 7.5, "epss_score": 0.23636, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97748, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24219", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4c6e351e-d889-45b7-abbc-36f2b5d79d67", "vulnerability": {"vulnId": "CVE-2020-35948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-09-22T15:28:02+02:00"}, "gcve": {"object_uuid": "4c6e351e-d889-45b7-abbc-36f2b5d79d67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-09-22T13:28:02+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-09-22T13:28:02+00:00"}, "scope": {"notes": "An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify... | Affected: Watchful.li / XCloner Backup and Restore | CVSS: 9.9 (CRITICAL) | EPSS: 0.24937 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35948", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify...", "cve_id": "CVE-2020-35948", "vendor": "Watchful.li", "ghsa_id": null, "product": "XCloner Backup and Restore", "added_date": "2020-09-22T13:28:02.000Z", "cvss_score": 9.9, "epss_score": 0.24937, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97852, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4fddf099-bc44-41c1-944b-01b2af008194", "vulnerability": {"vulnId": "CVE-2020-25540", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-09-14T14:22:40+02:00"}, "gcve": {"object_uuid": "4fddf099-bc44-41c1-944b-01b2af008194", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-09-14T12:22:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-09-14T12:22:40+00:00"}, "scope": {"notes": "ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET... | Affected: ThinkAdmin / ThinkAdmin v6 | CVSS: 7.5 (HIGH) | EPSS: 0.75332 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-25540", "url": "https://www.cve.org/CVERecord?id=CVE-2020-25540"}, {"id": "GHSA-2QM5-R82G-5HCX", "url": "https://github.com/advisories/GHSA-2QM5-R82G-5HCX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-25540"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET...", "cve_id": "CVE-2020-25540", "vendor": "ThinkAdmin", "ghsa_id": "GHSA-2QM5-R82G-5HCX", "product": "ThinkAdmin v6", "added_date": "2020-09-14T12:22:40.000Z", "cvss_score": 7.5, "epss_score": 0.75332, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99501, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-25540", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "61a536e8-a2ea-45e4-8168-1a2975fcc122", "vulnerability": {"vulnId": "CVE-2020-5775", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-08-21T19:36:56+02:00"}, "gcve": {"object_uuid": "61a536e8-a2ea-45e4-8168-1a2975fcc122", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-08-21T17:36:56+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-08-21T17:36:56+00:00"}, "scope": {"notes": "Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET... | Affected: Instructure / Canvas LMS | CVSS: 5.8 (MEDIUM) | EPSS: 0.06531 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-5775", "url": "https://www.cve.org/CVERecord?id=CVE-2020-5775"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-5775"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET...", "cve_id": "CVE-2020-5775", "vendor": "Instructure", "ghsa_id": null, "product": "Canvas LMS", "added_date": "2020-08-21T17:36:56.000Z", "cvss_score": 5.8, "epss_score": 0.06531, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93584, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-5775", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6240ed62-0f5e-4562-a27b-9b55b2c28604", "vulnerability": {"vulnId": "CVE-2020-35949", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-08-13T14:09:59+02:00"}, "gcve": {"object_uuid": "6240ed62-0f5e-4562-a27b-9b55b2c28604", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-08-13T12:09:59+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-08-13T12:09:59+00:00"}, "scope": {"notes": "An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to... | Affected: Quiz and Survey Master / Quiz and Survey Master | CVSS: 10.0 (CRITICAL) | EPSS: 0.05146 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35949", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35949"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35949"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to...", "cve_id": "CVE-2020-35949", "vendor": "Quiz and Survey Master", "ghsa_id": null, "product": "Quiz and Survey Master", "added_date": "2020-08-13T12:09:59.000Z", "cvss_score": 10.0, "epss_score": 0.05146, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92158, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35949", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fa00242b-f598-4a46-993e-fbc11f48a61b", "vulnerability": {"vulnId": "CVE-2020-35945", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-08-04T07:57:42+02:00"}, "gcve": {"object_uuid": "fa00242b-f598-4a46-993e-fbc11f48a61b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-08-04T05:57:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-08-04T05:57:42+00:00"}, "scope": {"notes": "An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with... | Affected: Elegant Themes / Divi | CVSS: 9.9 (CRITICAL) | EPSS: 0.02451 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-35945", "url": "https://www.cve.org/CVERecord?id=CVE-2020-35945"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-35945"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with...", "cve_id": "CVE-2020-35945", "vendor": "Elegant Themes", "ghsa_id": null, "product": "Divi", "added_date": "2020-08-04T05:57:42.000Z", "cvss_score": 9.9, "epss_score": 0.02451, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83809, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-35945", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a8a65a7a-980c-433d-9f8c-2d72e3af6e59", "vulnerability": {"vulnId": "CVE-2020-24186", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-07-28T16:15:03+02:00"}, "gcve": {"object_uuid": "a8a65a7a-980c-433d-9f8c-2d72e3af6e59", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-07-28T14:15:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-07-28T14:15:03+00:00"}, "scope": {"notes": "A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to... | Affected: gVectors / wpDiscuz | CVSS: 10.0 (CRITICAL) | EPSS: 0.94616 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-24186", "url": "https://www.cve.org/CVERecord?id=CVE-2020-24186"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-24186"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to...", "cve_id": "CVE-2020-24186", "vendor": "gVectors", "ghsa_id": null, "product": "wpDiscuz", "added_date": "2020-07-28T14:15:03.000Z", "cvss_score": 10.0, "epss_score": 0.94616, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99855, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-24186", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f9a17529-e4f9-417a-9646-87eb1b80fd90", "vulnerability": {"vulnId": "CVE-2020-15920", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-07-24T02:58:51+02:00"}, "gcve": {"object_uuid": "f9a17529-e4f9-417a-9646-87eb1b80fd90", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-07-24T00:58:51+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-07-24T00:58:51+00:00"}, "scope": {"notes": "There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with... | Affected: Mida Solutions / eFramework | CVSS: 9.8 (CRITICAL) | EPSS: 0.98239 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-15920", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15920"}, {"id": "GHSA-87C7-XX7R-6CW2", "url": "https://github.com/advisories/GHSA-87C7-XX7R-6CW2"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15920"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with...", "cve_id": "CVE-2020-15920", "vendor": "Mida Solutions", "ghsa_id": "GHSA-87C7-XX7R-6CW2", "product": "eFramework", "added_date": "2020-07-24T00:58:51.000Z", "cvss_score": 9.8, "epss_score": 0.98239, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99914, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15920", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "77d71ed4-eab8-4290-806b-c4a78493fe59", "vulnerability": {"vulnId": "CVE-2020-15916", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-07-23T19:53:48+02:00"}, "gcve": {"object_uuid": "77d71ed4-eab8-4290-806b-c4a78493fe59", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-07-23T17:53:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-07-23T17:53:48+00:00"}, "scope": {"notes": "goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell... | Affected: Tenda / AC15 AC1900 | CVSS: 9.8 (CRITICAL) | EPSS: 0.03429 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-15916", "url": "https://www.cve.org/CVERecord?id=CVE-2020-15916"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-15916"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell...", "cve_id": "CVE-2020-15916", "vendor": "Tenda", "ghsa_id": null, "product": "AC15 AC1900", "added_date": "2020-07-23T17:53:48.000Z", "cvss_score": 9.8, "epss_score": 0.03429, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88539, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-15916", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "83853185-58a1-4e03-89d1-ad137f87e9c3", "vulnerability": {"vulnId": "CVE-2020-13158", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-06-22T19:43:12+02:00"}, "gcve": {"object_uuid": "83853185-58a1-4e03-89d1-ad137f87e9c3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-06-22T17:43:12+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-06-22T17:43:12+00:00"}, "scope": {"notes": "Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter. | Affected: Artica / Artica Proxy | CVSS: 7.5 (HIGH) | EPSS: 0.53973 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-13158", "url": "https://www.cve.org/CVERecord?id=CVE-2020-13158"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-13158"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.", "cve_id": "CVE-2020-13158", "vendor": "Artica", "ghsa_id": null, "product": "Artica Proxy", "added_date": "2020-06-22T17:43:12.000Z", "cvss_score": 7.5, "epss_score": 0.53973, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98973, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-13158", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "60617fa8-a442-4dd4-a797-89bd83ae66d7", "vulnerability": {"vulnId": "CVE-2020-11798", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-06-10T02:00:00+02:00"}, "gcve": {"object_uuid": "60617fa8-a442-4dd4-a797-89bd83ae66d7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-06-10T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-06-10T00:00:00+00:00"}, "scope": {"notes": "A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an... | Affected: Mitel / MiCollab AWV | CVSS: 5.3 (MEDIUM) | EPSS: 0.48771 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-11798", "url": "https://www.cve.org/CVERecord?id=CVE-2020-11798"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-11798"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an...", "cve_id": "CVE-2020-11798", "vendor": "Mitel", "ghsa_id": null, "product": "MiCollab AWV", "added_date": "2020-06-10T00:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.48771, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9884, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-11798", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "801c6b45-382b-47f6-aae9-2b134d2ea229", "vulnerability": {"vulnId": "CVE-2020-9314", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-05-11T00:23:34+02:00"}, "gcve": {"object_uuid": "801c6b45-382b-47f6-aae9-2b134d2ea229", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-05-10T22:23:34+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-05-10T22:23:34+00:00"}, "scope": {"notes": "** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the... | Affected: Oracle / iPlanet Web Server | CVSS: 4.8 (MEDIUM) | EPSS: 0.01282 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-9314", "url": "https://www.cve.org/CVERecord?id=CVE-2020-9314"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-9314"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the...", "cve_id": "CVE-2020-9314", "vendor": "Oracle", "ghsa_id": null, "product": "iPlanet Web Server", "added_date": "2020-05-10T22:23:34.000Z", "cvss_score": 4.8, "epss_score": 0.01282, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69009, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-9314", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1bf099fe-1007-4a71-9fc4-8cf0df2a96b4", "vulnerability": {"vulnId": "CVE-2020-1943", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-04-01T20:18:48+02:00"}, "gcve": {"object_uuid": "1bf099fe-1007-4a71-9fc4-8cf0df2a96b4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-04-01T18:18:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-04-01T18:18:48+00:00"}, "scope": {"notes": "Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07. | Affected: Apache / Apache OFBiz | CVSS: 6.1 (MEDIUM) | EPSS: 0.97309 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-1943", "url": "https://www.cve.org/CVERecord?id=CVE-2020-1943"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-1943"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.", "cve_id": "CVE-2020-1943", "vendor": "Apache", "ghsa_id": null, "product": "Apache OFBiz", "added_date": "2020-04-01T18:18:48.000Z", "cvss_score": 6.1, "epss_score": 0.97309, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99896, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-1943", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "938777bc-4e1b-4ecc-9d2f-fbe6b0b09bf6", "vulnerability": {"vulnId": "CVE-2020-10826", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-03-26T17:05:03+01:00"}, "gcve": {"object_uuid": "938777bc-4e1b-4ecc-9d2f-fbe6b0b09bf6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-03-26T16:05:03+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-03-26T16:05:03+00:00"}, "scope": {"notes": "/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via... | Affected: Draytek / Vigor3900, Vigor2960, Vigor300B | CVSS: 9.8 (CRITICAL) | EPSS: 0.39389 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-10826", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10826"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10826"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via...", "cve_id": "CVE-2020-10826", "vendor": "Draytek", "ghsa_id": null, "product": "Vigor3900, Vigor2960, Vigor300B", "added_date": "2020-03-26T16:05:03.000Z", "cvss_score": 9.8, "epss_score": 0.39389, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98565, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10826", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0b5fdf6e-0fb4-47b5-a95b-0db736ba6312", "vulnerability": {"vulnId": "CVE-2020-12075", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-03-24T08:10:05+01:00"}, "gcve": {"object_uuid": "0b5fdf6e-0fb4-47b5-a95b-0db736ba6312", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-03-24T07:10:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-03-24T07:10:05+00:00"}, "scope": {"notes": "The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. | Affected: Supsystic.com / data-tables-generator-by-supsystic | CVSS: 8.8 (HIGH) | EPSS: 0.01042 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-12075", "url": "https://www.cve.org/CVERecord?id=CVE-2020-12075"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-12075"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.", "cve_id": "CVE-2020-12075", "vendor": "Supsystic.com", "ghsa_id": null, "product": "data-tables-generator-by-supsystic", "added_date": "2020-03-24T07:10:05.000Z", "cvss_score": 8.8, "epss_score": 0.01042, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.62747, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-12075", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2d9ac553-a99b-4951-a3d0-48f88b7f0821", "vulnerability": {"vulnId": "CVE-2018-20334", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-03-20T01:11:06+01:00"}, "gcve": {"object_uuid": "2d9ac553-a99b-4951-a3d0-48f88b7f0821", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-03-20T00:11:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-03-20T00:11:06+00:00"}, "scope": {"notes": "An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell... | Affected: ASUS / ASUSWRT | CVSS: 9.8 (CRITICAL) | EPSS: 0.03773 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-20334", "url": "https://www.cve.org/CVERecord?id=CVE-2018-20334"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-20334"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell...", "cve_id": "CVE-2018-20334", "vendor": "ASUS", "ghsa_id": null, "product": "ASUSWRT", "added_date": "2020-03-20T00:11:06.000Z", "cvss_score": 9.8, "epss_score": 0.03773, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89594, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-20334", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "870b9920-e225-41e1-a81c-a2812087c3e3", "vulnerability": {"vulnId": "CVE-2019-20504", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-03-09T01:55:30+01:00"}, "gcve": {"object_uuid": "870b9920-e225-41e1-a81c-a2812087c3e3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-03-09T00:55:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-03-09T00:55:30+00:00"}, "scope": {"notes": "service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via... | Affected: Quest / KACE K1000 Systems Management Appliance | CVSS: 9.8 (CRITICAL) | EPSS: 0.0955 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-20504", "url": "https://www.cve.org/CVERecord?id=CVE-2019-20504"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-20504"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via...", "cve_id": "CVE-2019-20504", "vendor": "Quest", "ghsa_id": null, "product": "KACE K1000 Systems Management Appliance", "added_date": "2020-03-09T00:55:30.000Z", "cvss_score": 9.8, "epss_score": 0.0955, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95319, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-20504", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fa05c63e-6157-40ec-8ecd-7d046294b133", "vulnerability": {"vulnId": "CVE-2020-10215", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-03-07T01:30:05+01:00"}, "gcve": {"object_uuid": "fa05c63e-6157-40ec-8ecd-7d046294b133", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-03-07T00:30:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-03-07T00:30:05+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name... | Affected: D-Link / DIR-825 Rev.B 2.10 | CVSS: 8.8 (HIGH) | EPSS: 0.05255 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-10215", "url": "https://www.cve.org/CVERecord?id=CVE-2020-10215"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-10215"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name...", "cve_id": "CVE-2020-10215", "vendor": "D-Link", "ghsa_id": null, "product": "DIR-825 Rev.B 2.10", "added_date": "2020-03-07T00:30:05.000Z", "cvss_score": 8.8, "epss_score": 0.05255, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92286, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-10215", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0577ddf3-1f78-4a68-bec0-c6d2a9ee9143", "vulnerability": {"vulnId": "CVE-2014-8739", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-02-08T18:21:54+01:00"}, "gcve": {"object_uuid": "0577ddf3-1f78-4a68-bec0-c6d2a9ee9143", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-02-08T17:21:54+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-02-08T17:21:54+00:00"}, "scope": {"notes": "Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative... | Affected: jQuery / File Upload Plugin | CVSS: 9.8 (CRITICAL) | EPSS: 0.91656 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-8739", "url": "https://www.cve.org/CVERecord?id=CVE-2014-8739"}, {"id": "GHSA-WXG6-F773-G2F7", "url": "https://github.com/advisories/GHSA-WXG6-F773-G2F7"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-8739"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative...", "cve_id": "CVE-2014-8739", "vendor": "jQuery", "ghsa_id": "GHSA-WXG6-F773-G2F7", "product": "File Upload Plugin", "added_date": "2020-02-08T17:21:54.000Z", "cvss_score": 9.8, "epss_score": 0.91656, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99813, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-8739", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "80f3f827-54ff-46f3-8ab6-1741f840ab5a", "vulnerability": {"vulnId": "CVE-2020-8656", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-02-07T00:47:30+01:00"}, "gcve": {"object_uuid": "80f3f827-54ff-46f3-8ab6-1741f840ab5a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-02-06T23:47:30+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-02-06T23:47:30+00:00"}, "scope": {"notes": "An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to... | Affected: EyesOfNetwork / EyesOfNetwork 5.3 | CVSS: 9.8 (CRITICAL) | EPSS: 0.846 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8656", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8656"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8656"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to...", "cve_id": "CVE-2020-8656", "vendor": "EyesOfNetwork", "ghsa_id": null, "product": "EyesOfNetwork 5.3", "added_date": "2020-02-06T23:47:30.000Z", "cvss_score": 9.8, "epss_score": 0.846, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99698, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8656", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "76ae0e8c-26da-4d49-903b-4b83d1f6f7be", "vulnerability": {"vulnId": "CVE-2020-8115", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-02-04T20:08:57+01:00"}, "gcve": {"object_uuid": "76ae0e8c-26da-4d49-903b-4b83d1f6f7be", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-02-04T19:08:57+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-02-04T19:08:57+00:00"}, "scope": {"notes": "A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo... | Affected: Revive Adserver / Revive Adserver | CVSS: 6.1 (MEDIUM) | EPSS: 0.07055 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8115", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8115"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8115"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo...", "cve_id": "CVE-2020-8115", "vendor": "Revive Adserver", "ghsa_id": null, "product": "Revive Adserver", "added_date": "2020-02-04T19:08:57.000Z", "cvss_score": 6.1, "epss_score": 0.07055, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94007, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8115", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "990a579c-bd63-46e9-8ff4-b55b30351f67", "vulnerability": {"vulnId": "CVE-2013-1599", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-01-28T20:54:43+01:00"}, "gcve": {"object_uuid": "990a579c-bd63-46e9-8ff4-b55b30351f67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-01-28T19:54:43+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-01-28T19:54:43+00:00"}, "scope": {"notes": "A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635... | Affected: D-Link / DCS-3411/3430, DCS-5605/5635, DCS-1100L/1130L, DCS-1100/1130, DCS-2102/2121, DCS-3410, DCS-5230, DCS-6410, DCS-7410, DCS-7510, WCS-1100 | CVSS: 9.8 (CRITICAL) | EPSS: 0.40353 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-1599", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1599"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1599"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635...", "cve_id": "CVE-2013-1599", "vendor": "D-Link", "ghsa_id": null, "product": "DCS-3411/3430, DCS-5605/5635, DCS-1100L/1130L, DCS-1100/1130, DCS-2102/2121, DCS-3410, DCS-5230, DCS-6410, DCS-7410, DCS-7510, WCS-1100", "added_date": "2020-01-28T19:54:43.000Z", "cvss_score": 9.8, "epss_score": 0.40353, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98601, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1599", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6a4557dc-3c87-4273-9263-bf2700daf16a", "vulnerability": {"vulnId": "CVE-2020-8417", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-01-28T15:27:48+01:00"}, "gcve": {"object_uuid": "6a4557dc-3c87-4273-9263-bf2700daf16a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-01-28T14:27:48+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-01-28T14:27:48+00:00"}, "scope": {"notes": "The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu. | Affected: Code Snippets / Code Snippets plugin for WordPress | CVSS: 8.8 (HIGH) | EPSS: 0.11905 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-8417", "url": "https://www.cve.org/CVERecord?id=CVE-2020-8417"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-8417"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.", "cve_id": "CVE-2020-8417", "vendor": "Code Snippets", "ghsa_id": null, "product": "Code Snippets plugin for WordPress", "added_date": "2020-01-28T14:27:48.000Z", "cvss_score": 8.8, "epss_score": 0.11905, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95988, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-8417", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ce7135f8-7f2f-40c0-9f00-188462ef3176", "vulnerability": {"vulnId": "CVE-2020-6167", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2020-01-08T12:25:14+01:00"}, "gcve": {"object_uuid": "ce7135f8-7f2f-40c0-9f00-188462ef3176", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2020-01-08T11:25:14+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2020-01-08T11:25:14+00:00"}, "scope": {"notes": "A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject... | Affected: WebFactory / Minimal Coming Soon & Maintenance Mode | CVSS: 8.8 (HIGH) | EPSS: 0.00924 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2020-6167", "url": "https://www.cve.org/CVERecord?id=CVE-2020-6167"}, {"id": "previdian", "url": "https://previdian.com/CVE-2020-6167"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject...", "cve_id": "CVE-2020-6167", "vendor": "WebFactory", "ghsa_id": null, "product": "Minimal Coming Soon & Maintenance Mode", "added_date": "2020-01-08T11:25:14.000Z", "cvss_score": 8.8, "epss_score": 0.00924, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.59001, "used_in_malware": "unknown", "vulnerability_id": "CVE-2020-6167", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "041eae7b-b836-4c2a-845b-4fcbbdd08410", "vulnerability": {"vulnId": "CVE-2019-19915", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-12-19T11:20:28+01:00"}, "gcve": {"object_uuid": "041eae7b-b836-4c2a-845b-4fcbbdd08410", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-12-19T10:20:28+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-12-19T10:20:28+00:00"}, "scope": {"notes": "The \"301 Redirects - Easy Redirect Manager\" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or... | Affected: WebFactory / 301 Redirects - Easy Redirect Manager | CVSS: 9.0 (CRITICAL) | EPSS: 0.00859 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-19915", "url": "https://www.cve.org/CVERecord?id=CVE-2019-19915"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-19915"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The \"301 Redirects - Easy Redirect Manager\" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or...", "cve_id": "CVE-2019-19915", "vendor": "WebFactory", "ghsa_id": null, "product": "301 Redirects - Easy Redirect Manager", "added_date": "2019-12-19T10:20:28.000Z", "cvss_score": 9.0, "epss_score": 0.00859, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.56969, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-19915", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0403c32c-0c02-450e-9293-36b6e30bec5f", "vulnerability": {"vulnId": "CVE-2019-14251", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-12-09T17:39:37+01:00"}, "gcve": {"object_uuid": "0403c32c-0c02-450e-9293-36b6e30bec5f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-12-09T16:39:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-12-09T16:39:37+00:00"}, "scope": {"notes": "An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once... | Affected: Temenos / T24 | CVSS: 7.5 (HIGH) | EPSS: 0.07849 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-14251", "url": "https://www.cve.org/CVERecord?id=CVE-2019-14251"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-14251"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once...", "cve_id": "CVE-2019-14251", "vendor": "Temenos", "ghsa_id": null, "product": "T24", "added_date": "2019-12-09T16:39:37.000Z", "cvss_score": 7.5, "epss_score": 0.07849, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94512, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-14251", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "42ce7baf-d841-4377-8a49-f653b52f09e0", "vulnerability": {"vulnId": "CVE-2019-17503", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-10-11T18:21:11+02:00"}, "gcve": {"object_uuid": "42ce7baf-d841-4377-8a49-f653b52f09e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-10-11T16:21:11+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-10-11T16:21:11+00:00"}, "scope": {"notes": "An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka... | Affected: Kirona / Dynamic Resource Scheduling (DRS) | CVSS: 5.3 (MEDIUM) | EPSS: 0.48303 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-17503", "url": "https://www.cve.org/CVERecord?id=CVE-2019-17503"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-17503"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka...", "cve_id": "CVE-2019-17503", "vendor": "Kirona", "ghsa_id": null, "product": "Dynamic Resource Scheduling (DRS)", "added_date": "2019-10-11T16:21:11.000Z", "cvss_score": 5.3, "epss_score": 0.48303, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98828, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-17503", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a7b28212-e0d2-4cbb-8cd8-45fc58061b67", "vulnerability": {"vulnId": "CVE-2019-16932", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-09-30T17:08:55+02:00"}, "gcve": {"object_uuid": "a7b28212-e0d2-4cbb-8cd8-45fc58061b67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-09-30T15:08:55+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-09-30T15:08:55+00:00"}, "scope": {"notes": "A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data. | Affected: Nathandavison / Visualizer | CVSS: 10.0 (CRITICAL) | EPSS: 0.39137 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-16932", "url": "https://www.cve.org/CVERecord?id=CVE-2019-16932"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-16932"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.", "cve_id": "CVE-2019-16932", "vendor": "Nathandavison", "ghsa_id": null, "product": "Visualizer", "added_date": "2019-09-30T15:08:55.000Z", "cvss_score": 10.0, "epss_score": 0.39137, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98554, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-16932", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6c659b94-b934-49ba-87ba-c313b09f25c3", "vulnerability": {"vulnId": "CVE-2019-14223", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-09-06T18:04:29+02:00"}, "gcve": {"object_uuid": "6c659b94-b934-49ba-87ba-c313b09f25c3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-09-06T16:04:29+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-09-06T16:04:29+00:00"}, "scope": {"notes": "An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an... | Affected: Alfresco / Alfresco Community Edition | CVSS: 6.1 (MEDIUM) | EPSS: 0.04474 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-14223", "url": "https://www.cve.org/CVERecord?id=CVE-2019-14223"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-14223"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an...", "cve_id": "CVE-2019-14223", "vendor": "Alfresco", "ghsa_id": null, "product": "Alfresco Community Edition", "added_date": "2019-09-06T16:04:29.000Z", "cvss_score": 6.1, "epss_score": 0.04474, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9115, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-14223", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3d4c522f-f7b7-470f-957a-658e790b7c88", "vulnerability": {"vulnId": "CVE-2019-13462", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-08-12T18:30:41+02:00"}, "gcve": {"object_uuid": "3d4c522f-f7b7-470f-957a-658e790b7c88", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-08-12T16:30:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-08-12T16:30:41+00:00"}, "scope": {"notes": "Lansweeper before 7.1.117.4 allows unauthenticated SQL injection. | Affected: Lansweeper / Lansweeper | CVSS: 9.1 (CRITICAL) | EPSS: 0.1131 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-13462", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13462"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13462"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.", "cve_id": "CVE-2019-13462", "vendor": "Lansweeper", "ghsa_id": null, "product": "Lansweeper", "added_date": "2019-08-12T16:30:41.000Z", "cvss_score": 9.1, "epss_score": 0.1131, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95855, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-13462", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b0eb8dc1-622c-436e-8d17-be1c05a516ba", "vulnerability": {"vulnId": "CVE-2019-13396", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-07-10T15:45:05+02:00"}, "gcve": {"object_uuid": "b0eb8dc1-622c-436e-8d17-be1c05a516ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-07-10T13:45:05+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-07-10T13:45:05+00:00"}, "scope": {"notes": "FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an... | Affected: FlightPath / FlightPath | CVSS: 5.3 (MEDIUM) | EPSS: 0.62572 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-13396", "url": "https://www.cve.org/CVERecord?id=CVE-2019-13396"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-13396"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an...", "cve_id": "CVE-2019-13396", "vendor": "FlightPath", "ghsa_id": null, "product": "FlightPath", "added_date": "2019-07-10T13:45:05.000Z", "cvss_score": 5.3, "epss_score": 0.62572, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99168, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-13396", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "63e52dbf-dbf6-4500-b042-a24c59772ec9", "vulnerability": {"vulnId": "CVE-2019-7254", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-07-02T20:51:42+02:00"}, "gcve": {"object_uuid": "63e52dbf-dbf6-4500-b042-a24c59772ec9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-07-02T18:51:42+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-07-02T18:51:42+00:00"}, "scope": {"notes": "Linear eMerge E3-Series devices allow File Inclusion. | Affected: Linear / eMerge E3-Series | CVSS: 7.5 (HIGH) | EPSS: 0.82292 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-7254", "url": "https://www.cve.org/CVERecord?id=CVE-2019-7254"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-7254"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Linear eMerge E3-Series devices allow File Inclusion.", "cve_id": "CVE-2019-7254", "vendor": "Linear", "ghsa_id": null, "product": "eMerge E3-Series", "added_date": "2019-07-02T18:51:42.000Z", "cvss_score": 7.5, "epss_score": 0.82292, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99651, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-7254", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "70adc0ad-d761-4389-bea6-7f4072a40e1a", "vulnerability": {"vulnId": "CVE-2018-18852", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-06-18T17:00:32+02:00"}, "gcve": {"object_uuid": "70adc0ad-d761-4389-bea6-7f4072a40e1a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-06-18T15:00:32+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-06-18T15:00:32+00:00"}, "scope": {"notes": "Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use... | Affected: Cerio / DT-300N | CVSS: 8.8 (HIGH) | EPSS: 0.63797 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-18852", "url": "https://www.cve.org/CVERecord?id=CVE-2018-18852"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-18852"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use...", "cve_id": "CVE-2018-18852", "vendor": "Cerio", "ghsa_id": null, "product": "DT-300N", "added_date": "2019-06-18T15:00:32.000Z", "cvss_score": 8.8, "epss_score": 0.63797, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99199, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-18852", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2e601b5a-6d96-404d-ab9a-796a8464fed0", "vulnerability": {"vulnId": "CVE-2018-20470", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-06-17T15:26:53+02:00"}, "gcve": {"object_uuid": "2e601b5a-6d96-404d-ab9a-796a8464fed0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-06-17T13:26:53+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-06-17T13:26:53+00:00"}, "scope": {"notes": "An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web... | Affected: Tyto / Sahi Pro | CVSS: 7.5 (HIGH) | EPSS: 0.4606 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-20470", "url": "https://www.cve.org/CVERecord?id=CVE-2018-20470"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-20470"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web...", "cve_id": "CVE-2018-20470", "vendor": "Tyto", "ghsa_id": null, "product": "Sahi Pro", "added_date": "2019-06-17T13:26:53.000Z", "cvss_score": 7.5, "epss_score": 0.4606, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98773, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-20470", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bb15f587-082c-415e-9ad9-fa2cb64a4a1e", "vulnerability": {"vulnId": "CVE-2018-20841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-06-11T22:45:17+02:00"}, "gcve": {"object_uuid": "bb15f587-082c-415e-9ad9-fa2cb64a4a1e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-06-11T20:45:17+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-06-11T20:45:17+00:00"}, "scope": {"notes": "HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in... | Affected: HooToo / TripMate Titan HT-TM05 and HT-05 routers | CVSS: 9.8 (CRITICAL) | EPSS: 0.47901 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-20841", "url": "https://www.cve.org/CVERecord?id=CVE-2018-20841"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-20841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in...", "cve_id": "CVE-2018-20841", "vendor": "HooToo", "ghsa_id": null, "product": "TripMate Titan HT-TM05 and HT-05 routers", "added_date": "2019-06-11T20:45:17.000Z", "cvss_score": 9.8, "epss_score": 0.47901, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98819, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-20841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "cca8b5f2-22f4-4e74-ad79-9f3fc8fbed8b", "vulnerability": {"vulnId": "CVE-2019-11370", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-06-03T21:44:10+02:00"}, "gcve": {"object_uuid": "cca8b5f2-22f4-4e74-ad79-9f3fc8fbed8b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-06-03T19:44:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-06-03T19:44:10+00:00"}, "scope": {"notes": "Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html \"System contact\" field. | Affected: Carel / pCOWeb | CVSS: 5.4 (MEDIUM) | EPSS: 0.04935 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-11370", "url": "https://www.cve.org/CVERecord?id=CVE-2019-11370"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-11370"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html \"System contact\" field.", "cve_id": "CVE-2019-11370", "vendor": "Carel", "ghsa_id": null, "product": "pCOWeb", "added_date": "2019-06-03T19:44:10.000Z", "cvss_score": 5.4, "epss_score": 0.04935, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91869, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-11370", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "47da573a-c995-4447-abc7-1c94c91c6fa0", "vulnerability": {"vulnId": "CVE-2019-12314", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-05-24T15:46:44+02:00"}, "gcve": {"object_uuid": "47da573a-c995-4447-abc7-1c94c91c6fa0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-05-24T13:46:44+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-05-24T13:46:44+00:00"}, "scope": {"notes": "Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a... | Affected: Deltek / Maconomy | CVSS: 9.8 (CRITICAL) | EPSS: 0.8422 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-12314", "url": "https://www.cve.org/CVERecord?id=CVE-2019-12314"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-12314"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a...", "cve_id": "CVE-2019-12314", "vendor": "Deltek", "ghsa_id": null, "product": "Maconomy", "added_date": "2019-05-24T13:46:44.000Z", "cvss_score": 9.8, "epss_score": 0.8422, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99691, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-12314", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ec58fc57-4ff9-47fe-9e43-c462d20e3c85", "vulnerability": {"vulnId": "CVE-2019-8387", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-05-08T15:17:10+02:00"}, "gcve": {"object_uuid": "ec58fc57-4ff9-47fe-9e43-c462d20e3c85", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-05-08T13:17:10+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-05-08T13:17:10+00:00"}, "scope": {"notes": "MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. | Affected: MASTER / IPCAMERA01 | CVSS: 9.8 (CRITICAL) | EPSS: 0.55721 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-8387", "url": "https://www.cve.org/CVERecord?id=CVE-2019-8387"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-8387"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.", "cve_id": "CVE-2019-8387", "vendor": "MASTER", "ghsa_id": null, "product": "IPCAMERA01", "added_date": "2019-05-08T13:17:10.000Z", "cvss_score": 9.8, "epss_score": 0.55721, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99014, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-8387", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "fd061d8c-67cf-4c2f-aa37-aae078b3f8bd", "vulnerability": {"vulnId": "CVE-2019-2618", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-04-23T20:16:41+02:00"}, "gcve": {"object_uuid": "fd061d8c-67cf-4c2f-aa37-aae078b3f8bd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-04-23T18:16:41+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-04-23T18:16:41+00:00"}, "scope": {"notes": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are... | Affected: Oracle / WebLogic Server | CVSS: 5.5 (MEDIUM) | EPSS: 0.32881 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-2618", "url": "https://www.cve.org/CVERecord?id=CVE-2019-2618"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-2618"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are...", "cve_id": "CVE-2019-2618", "vendor": "Oracle", "ghsa_id": null, "product": "WebLogic Server", "added_date": "2019-04-23T18:16:41.000Z", "cvss_score": 5.5, "epss_score": 0.32881, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98308, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-2618", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "71845af9-ec67-4da1-ab23-75497583d117", "vulnerability": {"vulnId": "CVE-2019-2588", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-04-23T20:16:40+02:00"}, "gcve": {"object_uuid": "71845af9-ec67-4da1-ab23-75497583d117", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-04-23T18:16:40+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-04-23T18:16:40+00:00"}, "scope": {"notes": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported... | Affected: Oracle / BI Publisher (formerly XML Publisher) | CVSS: 4.9 (MEDIUM) | EPSS: 0.36787 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-2588", "url": "https://www.cve.org/CVERecord?id=CVE-2019-2588"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-2588"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported...", "cve_id": "CVE-2019-2588", "vendor": "Oracle", "ghsa_id": null, "product": "BI Publisher (formerly XML Publisher)", "added_date": "2019-04-23T18:16:40.000Z", "cvss_score": 4.9, "epss_score": 0.36787, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98461, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-2588", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f8366cf9-def5-4623-8ca0-f538c7a33eb7", "vulnerability": {"vulnId": "CVE-2019-3914", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-04-11T15:53:37+02:00"}, "gcve": {"object_uuid": "f8366cf9-def5-4623-8ca0-f538c7a33eb7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-04-11T13:53:37+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-04-11T13:53:37+00:00"}, "scope": {"notes": "Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker... | Affected: Verizon / Fios Quantum Gateway (G1100) | CVSS: 7.2 (HIGH) | EPSS: 0.29885 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-3914", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3914"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3914"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker...", "cve_id": "CVE-2019-3914", "vendor": "Verizon", "ghsa_id": null, "product": "Fios Quantum Gateway (G1100)", "added_date": "2019-04-11T13:53:37.000Z", "cvss_score": 7.2, "epss_score": 0.29885, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98154, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-3914", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "69e215a6-68ad-4c91-90c7-b4e57468c623", "vulnerability": {"vulnId": "CVE-2018-19365", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-03-18T20:58:13+01:00"}, "gcve": {"object_uuid": "69e215a6-68ad-4c91-90c7-b4e57468c623", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-03-18T19:58:13+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-03-18T19:58:13+00:00"}, "scope": {"notes": "The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically... | Affected: Wowza Media Systems / Wowza Streaming Engine | CVSS: 9.1 (CRITICAL) | EPSS: 0.22292 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-19365", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19365"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19365"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically...", "cve_id": "CVE-2018-19365", "vendor": "Wowza Media Systems", "ghsa_id": null, "product": "Wowza Streaming Engine", "added_date": "2019-03-18T19:58:13.000Z", "cvss_score": 9.1, "epss_score": 0.22292, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97618, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-19365", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ca004617-e31e-4dad-b690-67235beb8393", "vulnerability": {"vulnId": "CVE-2019-3495", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-03-18T18:14:33+01:00"}, "gcve": {"object_uuid": "ca004617-e31e-4dad-b690-67235beb8393", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-03-18T17:14:33+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-03-18T17:14:33+00:00"}, "scope": {"notes": "An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload,... | Affected: Wifi-soft / UniBox controller | CVSS: 8.8 (HIGH) | EPSS: 0.04945 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-3495", "url": "https://www.cve.org/CVERecord?id=CVE-2019-3495"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-3495"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload,...", "cve_id": "CVE-2019-3495", "vendor": "Wifi-soft", "ghsa_id": null, "product": "UniBox controller", "added_date": "2019-03-18T17:14:33.000Z", "cvss_score": 8.8, "epss_score": 0.04945, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91888, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-3495", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "64cf0a0c-67bf-49e1-93c8-d3287b5925ab", "vulnerability": {"vulnId": "CVE-2019-4061", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-02-27T23:00:00+01:00"}, "gcve": {"object_uuid": "64cf0a0c-67bf-49e1-93c8-d3287b5925ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-02-27T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-02-27T22:00:00+00:00"}, "scope": {"notes": "IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed... | Affected: IBM / BigFix Platform | CVSS: 5.3 (MEDIUM) | EPSS: 0.22547 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-4061", "url": "https://www.cve.org/CVERecord?id=CVE-2019-4061"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-4061"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "IBM BigFix Platform 9.2 and 9.5 could allow an attacker to query the relay remotely and gather information about the updates and fixlets deployed...", "cve_id": "CVE-2019-4061", "vendor": "IBM", "ghsa_id": null, "product": "BigFix Platform", "added_date": "2019-02-27T22:00:00.000Z", "cvss_score": 5.3, "epss_score": 0.22547, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97647, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-4061", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3610d864-ee4a-401d-bc30-14215a0a5209", "vulnerability": {"vulnId": "CVE-2018-15517", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-01-31T20:00:00+01:00"}, "gcve": {"object_uuid": "3610d864-ee4a-401d-bc30-14215a0a5209", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-01-31T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-01-31T19:00:00+00:00"}, "scope": {"notes": "The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually... | Affected: D-Link / Central WiFiManager CWM-100 | CVSS: 8.6 (HIGH) | EPSS: 0.44101 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-15517", "url": "https://www.cve.org/CVERecord?id=CVE-2018-15517"}, {"id": "GHSA-HQ7J-8QV3-MMRM", "url": "https://github.com/advisories/GHSA-HQ7J-8QV3-MMRM"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-15517"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually...", "cve_id": "CVE-2018-15517", "vendor": "D-Link", "ghsa_id": "GHSA-HQ7J-8QV3-MMRM", "product": "Central WiFiManager CWM-100", "added_date": "2019-01-31T19:00:00.000Z", "cvss_score": 8.6, "epss_score": 0.44101, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98715, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-15517", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5c0d38eb-9b02-4fae-9453-4801c865c9a0", "vulnerability": {"vulnId": "CVE-2019-6703", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2019-01-25T13:23:06+01:00"}, "gcve": {"object_uuid": "5c0d38eb-9b02-4fae-9453-4801c865c9a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2019-01-25T12:23:06+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2019-01-25T12:23:06+00:00"}, "scope": {"notes": "Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows... | Affected: Calmar Webmedia / Total Donations plugin for WordPress | CVSS: 9.8 (CRITICAL) | EPSS: 0.26076 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2019-6703", "url": "https://www.cve.org/CVERecord?id=CVE-2019-6703"}, {"id": "previdian", "url": "https://previdian.com/CVE-2019-6703"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows...", "cve_id": "CVE-2019-6703", "vendor": "Calmar Webmedia", "ghsa_id": null, "product": "Total Donations plugin for WordPress", "added_date": "2019-01-25T12:23:06.000Z", "cvss_score": 9.8, "epss_score": 0.26076, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97932, "used_in_malware": "unknown", "vulnerability_id": "CVE-2019-6703", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9aef7a4e-9231-4e27-af45-94a8d4f0cd2a", "vulnerability": {"vulnId": "CVE-2018-13307", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-11-27T22:00:00+01:00"}, "gcve": {"object_uuid": "9aef7a4e-9231-4e27-af45-94a8d4f0cd2a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-11-27T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-11-27T21:00:00+00:00"}, "scope": {"notes": "System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the \"ntpServerIp2\" POST... | Affected: TOTOLINK / A3002RU | CVSS: 9.8 (CRITICAL) | EPSS: 0.03195 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-13307", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13307"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13307"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the \"ntpServerIp2\" POST...", "cve_id": "CVE-2018-13307", "vendor": "TOTOLINK", "ghsa_id": null, "product": "A3002RU", "added_date": "2018-11-27T21:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.03195, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.87668, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-13307", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2bbf8916-0741-4e48-8a98-5493a99f30d4", "vulnerability": {"vulnId": "CVE-2018-13350", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-11-27T22:00:00+01:00"}, "gcve": {"object_uuid": "2bbf8916-0741-4e48-8a98-5493a99f30d4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-11-27T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-11-27T21:00:00+00:00"}, "scope": {"notes": "SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the \"Event\" parameter. | Affected: TerraMaster / TOS | CVSS: 9.8 (CRITICAL) | EPSS: 0.16661 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-13350", "url": "https://www.cve.org/CVERecord?id=CVE-2018-13350"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-13350"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the \"Event\" parameter.", "cve_id": "CVE-2018-13350", "vendor": "TerraMaster", "ghsa_id": null, "product": "TOS", "added_date": "2018-11-27T21:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.16661, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96936, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-13350", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "32acf697-1a98-48d7-900c-4f3c1a7c8eb8", "vulnerability": {"vulnId": "CVE-2018-19207", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-11-12T18:00:00+01:00"}, "gcve": {"object_uuid": "32acf697-1a98-48d7-900c-4f3c1a7c8eb8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-11-12T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-11-12T17:00:00+00:00"}, "scope": {"notes": "The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because... | Affected: Van Ons / WP GDPR Compliance | CVSS: 9.8 (CRITICAL) | EPSS: 0.88065 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-19207", "url": "https://www.cve.org/CVERecord?id=CVE-2018-19207"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-19207"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because...", "cve_id": "CVE-2018-19207", "vendor": "Van Ons", "ghsa_id": null, "product": "WP GDPR Compliance", "added_date": "2018-11-12T17:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.88065, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99763, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-19207", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b063aedf-d362-4a56-bef2-fe0cf4215351", "vulnerability": {"vulnId": "CVE-2018-18956", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-11-05T22:00:00+01:00"}, "gcve": {"object_uuid": "b063aedf-d362-4a56-bef2-fe0cf4215351", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-11-05T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-11-05T21:00:00+00:00"}, "scope": {"notes": "The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault... | Affected: Suricata / Suricata | CVSS: 7.5 (HIGH) | EPSS: 0.02794 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-18956", "url": "https://www.cve.org/CVERecord?id=CVE-2018-18956"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-18956"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault...", "cve_id": "CVE-2018-18956", "vendor": "Suricata", "ghsa_id": null, "product": "Suricata", "added_date": "2018-11-05T21:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02794, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8593, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-18956", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f40f7314-36f2-4c32-8a0b-be652845a240", "vulnerability": {"vulnId": "CVE-2017-18349", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-10-23T22:00:00+02:00"}, "gcve": {"object_uuid": "f40f7314-36f2-4c32-8a0b-be652845a240", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-10-23T20:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-10-23T20:00:00+00:00"}, "scope": {"notes": "parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary... | Affected: Alibaba / Fastjson | CVSS: 9.8 (CRITICAL) | EPSS: 0.3924 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-18349", "url": "https://www.cve.org/CVERecord?id=CVE-2017-18349"}, {"id": "GHSA-XJRR-XV9M-4PW5", "url": "https://github.com/advisories/GHSA-XJRR-XV9M-4PW5"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-18349"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary...", "cve_id": "CVE-2017-18349", "vendor": "Alibaba", "ghsa_id": "GHSA-XJRR-XV9M-4PW5", "product": "Fastjson", "added_date": "2018-10-23T20:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.3924, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98559, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-18349", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2a86ee96-9537-4894-9a77-682203076ae4", "vulnerability": {"vulnId": "CVE-2018-10823", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-10-17T16:00:00+02:00"}, "gcve": {"object_uuid": "2a86ee96-9537-4894-9a77-682203076ae4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-10-17T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-10-17T14:00:00+00:00"}, "scope": {"notes": "An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and... | Affected: D-Link / DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, DWR-111 | CVSS: 8.8 (HIGH) | EPSS: 0.77699 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10823", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10823"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10823"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and...", "cve_id": "CVE-2018-10823", "vendor": "D-Link", "ghsa_id": null, "product": "DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, DWR-111", "added_date": "2018-10-17T14:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.77699, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99554, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10823", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6a75c108-f184-423f-8164-03d9f79d76e0", "vulnerability": {"vulnId": "CVE-2018-8006", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-10-10T16:00:00+02:00"}, "gcve": {"object_uuid": "6a75c108-f184-423f-8164-03d9f79d76e0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-10-10T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-10-10T14:00:00+00:00"}, "scope": {"notes": "An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of... | Affected: Apache / Apache ActiveMQ | CVSS: 6.1 (MEDIUM) | EPSS: 0.55418 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-8006", "url": "https://www.cve.org/CVERecord?id=CVE-2018-8006"}, {"id": "GHSA-HVWM-2624-RP9X", "url": "https://github.com/advisories/GHSA-HVWM-2624-RP9X"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-8006"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of...", "cve_id": "CVE-2018-8006", "vendor": "Apache", "ghsa_id": "GHSA-HVWM-2624-RP9X", "product": "Apache ActiveMQ", "added_date": "2018-10-10T14:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.55418, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99007, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-8006", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "406542a8-1d82-42dd-8ea1-f6091d3b4f55", "vulnerability": {"vulnId": "CVE-2018-17283", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-09-21T05:00:00+02:00"}, "gcve": {"object_uuid": "406542a8-1d82-42dd-8ea1-f6091d3b4f55", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-09-21T03:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-09-21T03:00:00+00:00"}, "scope": {"notes": "Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a... | Affected: Zoho / ManageEngine OpManager | CVSS: 7.5 (HIGH) | EPSS: 0.66347 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-17283", "url": "https://www.cve.org/CVERecord?id=CVE-2018-17283"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-17283"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a...", "cve_id": "CVE-2018-17283", "vendor": "Zoho", "ghsa_id": null, "product": "ManageEngine OpManager", "added_date": "2018-09-21T03:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.66347, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99262, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-17283", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7ff3f2eb-8cde-46e4-93d3-fcd35ec0dc40", "vulnerability": {"vulnId": "CVE-2018-15138", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-08-15T19:00:00+02:00"}, "gcve": {"object_uuid": "7ff3f2eb-8cde-46e4-93d3-fcd35ec0dc40", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-08-15T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-08-15T17:00:00+00:00"}, "scope": {"notes": "Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. | Affected: Ericsson-LG / iPECS NMS 30M | CVSS: 7.5 (HIGH) | EPSS: 0.12851 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-15138", "url": "https://www.cve.org/CVERecord?id=CVE-2018-15138"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-15138"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.", "cve_id": "CVE-2018-15138", "vendor": "Ericsson-LG", "ghsa_id": null, "product": "iPECS NMS 30M", "added_date": "2018-08-15T17:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.12851, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96183, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-15138", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "969885c6-11be-4a46-866f-a123dcdbd9e6", "vulnerability": {"vulnId": "CVE-2018-11329", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-05-22T07:00:00+02:00"}, "gcve": {"object_uuid": "969885c6-11be-4a46-866f-a123dcdbd9e6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-05-22T05:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-05-22T05:00:00+00:00"}, "scope": {"notes": "The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take over the contract's... | Affected: Ether Cartel / Ether Cartel | CVSS: 7.5 (HIGH) | EPSS: 0.00868 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11329", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11329"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11329"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take over the contract's...", "cve_id": "CVE-2018-11329", "vendor": "Ether Cartel", "ghsa_id": null, "product": "Ether Cartel", "added_date": "2018-05-22T05:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.00868, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.5725, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11329", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "349eb63a-7922-4bfd-9917-e8725d0e8bb0", "vulnerability": {"vulnId": "CVE-2018-11239", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-05-19T20:00:00+02:00"}, "gcve": {"object_uuid": "349eb63a-7922-4bfd-9917-e8725d0e8bb0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-05-19T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-05-19T18:00:00+00:00"}, "scope": {"notes": "An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to... | Affected: Hexagon / HXG (Ethereum ERC20 token) | CVSS: 7.5 (HIGH) | EPSS: 0.00912 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-11239", "url": "https://www.cve.org/CVERecord?id=CVE-2018-11239"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-11239"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to...", "cve_id": "CVE-2018-11239", "vendor": "Hexagon", "ghsa_id": null, "product": "HXG (Ethereum ERC20 token)", "added_date": "2018-05-19T18:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.00912, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.58566, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-11239", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bc8da5fa-114e-46cf-83e2-f54af66e02a2", "vulnerability": {"vulnId": "CVE-2018-10657", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-05-02T18:00:00+02:00"}, "gcve": {"object_uuid": "bc8da5fa-114e-46cf-83e2-f54af66e02a2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-05-02T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-05-02T16:00:00+00:00"}, "scope": {"notes": "Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable,... | Affected: Matrix / Synapse | CVSS: 7.5 (HIGH) | EPSS: 0.01522 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10657", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10657"}, {"id": "GHSA-VMCC-4P4X-X7WG", "url": "https://github.com/advisories/GHSA-VMCC-4P4X-X7WG"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10657"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable,...", "cve_id": "CVE-2018-10657", "vendor": "Matrix", "ghsa_id": "GHSA-VMCC-4P4X-X7WG", "product": "Synapse", "added_date": "2018-05-02T16:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01522, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.73686, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10657", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "46ea7e5e-b166-4e8d-9d57-b225cc8da41a", "vulnerability": {"vulnId": "CVE-2018-10468", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-04-28T15:00:00+02:00"}, "gcve": {"object_uuid": "46ea7e5e-b166-4e8d-9d57-b225cc8da41a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-04-28T13:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-04-28T13:00:00+00:00"}, "scope": {"notes": "The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal... | Affected: Useless Ethereum Token / UET | CVSS: 7.5 (HIGH) | EPSS: 0.0157 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10468", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10468"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10468"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal...", "cve_id": "CVE-2018-10468", "vendor": "Useless Ethereum Token", "ghsa_id": null, "product": "UET", "added_date": "2018-04-28T13:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.0157, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.74463, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10468", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0ed68d9e-3553-4707-9499-e3c537a9674e", "vulnerability": {"vulnId": "CVE-2018-10376", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-04-25T11:00:00+02:00"}, "gcve": {"object_uuid": "0ed68d9e-3553-4707-9499-e3c537a9674e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-04-25T09:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-04-25T09:00:00+00:00"}, "scope": {"notes": "An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows... | Affected: SmartMesh / SmartMesh | CVSS: 7.5 (HIGH) | EPSS: 0.01797 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10376", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10376"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10376"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows...", "cve_id": "CVE-2018-10376", "vendor": "SmartMesh", "ghsa_id": null, "product": "SmartMesh", "added_date": "2018-04-25T09:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01797, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77651, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10376", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3216571f-ce3b-44f6-a6bf-2e79a9c73388", "vulnerability": {"vulnId": "CVE-2018-10299", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-04-23T06:00:00+02:00"}, "gcve": {"object_uuid": "3216571f-ce3b-44f6-a6bf-2e79a9c73388", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-04-23T04:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-04-23T04:00:00+00:00"}, "scope": {"notes": "An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used... | Affected: Beauty Chain / Beauty Ecosystem Coin (BEC) | CVSS: 7.5 (HIGH) | EPSS: 0.02665 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-10299", "url": "https://www.cve.org/CVERecord?id=CVE-2018-10299"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-10299"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used...", "cve_id": "CVE-2018-10299", "vendor": "Beauty Chain", "ghsa_id": null, "product": "Beauty Ecosystem Coin (BEC)", "added_date": "2018-04-23T04:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.02665, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85202, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-10299", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "928319d2-034c-4f2f-8b93-a5004048b09a", "vulnerability": {"vulnId": "CVE-2018-7700", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-03-27T20:00:00+02:00"}, "gcve": {"object_uuid": "928319d2-034c-4f2f-8b93-a5004048b09a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-03-27T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-03-27T18:00:00+00:00"}, "scope": {"notes": "DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a... | Affected: DedeCMS / DedeCMS 5.7 | CVSS: 8.8 (HIGH) | EPSS: 0.74118 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2018-7700", "url": "https://www.cve.org/CVERecord?id=CVE-2018-7700"}, {"id": "previdian", "url": "https://previdian.com/CVE-2018-7700"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a...", "cve_id": "CVE-2018-7700", "vendor": "DedeCMS", "ghsa_id": null, "product": "DedeCMS 5.7", "added_date": "2018-03-27T18:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.74118, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99473, "used_in_malware": "unknown", "vulnerability_id": "CVE-2018-7700", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "32ca61eb-f197-4caf-8d09-869f097de293", "vulnerability": {"vulnId": "CVE-2017-18046", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-01-21T23:00:00+01:00"}, "gcve": {"object_uuid": "32ca61eb-f197-4caf-8d09-869f097de293", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-01-21T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-01-21T22:00:00+00:00"}, "scope": {"notes": "Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary... | Affected: Dasan / GPON ONT WiFi Router H640X | CVSS: 9.8 (CRITICAL) | EPSS: 0.05045 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-18046", "url": "https://www.cve.org/CVERecord?id=CVE-2017-18046"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-18046"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary...", "cve_id": "CVE-2017-18046", "vendor": "Dasan", "ghsa_id": null, "product": "GPON ONT WiFi Router H640X", "added_date": "2018-01-21T22:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.05045, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92029, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-18046", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c80b7199-7180-4d0c-8807-43001de0d1ea", "vulnerability": {"vulnId": "CVE-2017-8046", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2018-01-04T07:00:00+01:00"}, "gcve": {"object_uuid": "c80b7199-7180-4d0c-8807-43001de0d1ea", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2018-01-04T06:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2018-01-04T06:00:00+00:00"}, "scope": {"notes": "Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and... | Affected: Pivotal / Pivotal Spring Data REST and Spring Boot | CVSS: 9.8 (CRITICAL) | EPSS: 0.7453 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-8046", "url": "https://www.cve.org/CVERecord?id=CVE-2017-8046"}, {"id": "GHSA-9QF9-28H9-HQCJ", "url": "https://github.com/advisories/GHSA-9QF9-28H9-HQCJ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-8046"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and...", "cve_id": "CVE-2017-8046", "vendor": "Pivotal", "ghsa_id": "GHSA-9QF9-28H9-HQCJ", "product": "Pivotal Spring Data REST and Spring Boot", "added_date": "2018-01-04T06:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.7453, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99486, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-8046", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4b780a03-5cec-4c94-a184-2d56e142731b", "vulnerability": {"vulnId": "CVE-2017-17105", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-12-18T18:00:00+01:00"}, "gcve": {"object_uuid": "4b780a03-5cec-4c94-a184-2d56e142731b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-12-18T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-12-18T17:00:00+00:00"}, "scope": {"notes": "Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote... | Affected: Zivif / PR115-204-P-RS | CVSS: 9.8 (CRITICAL) | EPSS: 0.84558 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-17105", "url": "https://www.cve.org/CVERecord?id=CVE-2017-17105"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-17105"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote...", "cve_id": "CVE-2017-17105", "vendor": "Zivif", "ghsa_id": null, "product": "PR115-204-P-RS", "added_date": "2017-12-18T17:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.84558, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99697, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-17105", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "97156e92-4b91-4e42-883e-ba03535358d1", "vulnerability": {"vulnId": "CVE-2017-17106", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-12-18T18:00:00+01:00"}, "gcve": {"object_uuid": "97156e92-4b91-4e42-883e-ba03535358d1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-12-18T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-12-18T17:00:00+00:00"}, "scope": {"notes": "Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web... | Affected: Zivif / PR115-204-P-RS | CVSS: 9.8 (CRITICAL) | EPSS: 0.15256 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-17106", "url": "https://www.cve.org/CVERecord?id=CVE-2017-17106"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-17106"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web...", "cve_id": "CVE-2017-17106", "vendor": "Zivif", "ghsa_id": null, "product": "PR115-204-P-RS", "added_date": "2017-12-18T17:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.15256, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96667, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-17106", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8586e122-ce1b-4194-b402-9e1cf3bd7c6e", "vulnerability": {"vulnId": "CVE-2017-17560", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-12-12T19:00:00+01:00"}, "gcve": {"object_uuid": "8586e122-ce1b-4194-b402-9e1cf3bd7c6e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-12-12T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-12-12T18:00:00+00:00"}, "scope": {"notes": "An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component,... | Affected: Western Digital / MyCloud PR4100 | CVSS: 9.8 (CRITICAL) | EPSS: 0.73404 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-17560", "url": "https://www.cve.org/CVERecord?id=CVE-2017-17560"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-17560"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component,...", "cve_id": "CVE-2017-17560", "vendor": "Western Digital", "ghsa_id": null, "product": "MyCloud PR4100", "added_date": "2017-12-12T18:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.73404, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99452, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-17560", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0850091f-8551-4ad6-b712-3bd6d13f8601", "vulnerability": {"vulnId": "CVE-2017-16959", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-11-27T11:00:00+01:00"}, "gcve": {"object_uuid": "0850091f-8551-4ad6-b712-3bd6d13f8601", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-11-27T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-11-27T10:00:00+00:00"}, "scope": {"notes": "The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence... | Affected: TP-Link / TL-WVR, TL-WAR, TL-ER, TL-R devices | CVSS: 6.5 (MEDIUM) | EPSS: 0.0191 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-16959", "url": "https://www.cve.org/CVERecord?id=CVE-2017-16959"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-16959"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence...", "cve_id": "CVE-2017-16959", "vendor": "TP-Link", "ghsa_id": null, "product": "TL-WVR, TL-WAR, TL-ER, TL-R devices", "added_date": "2017-11-27T10:00:00.000Z", "cvss_score": 6.5, "epss_score": 0.0191, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.79043, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-16959", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6a108b3f-509f-41b0-a0a7-8d291eb3ef2e", "vulnerability": {"vulnId": "CVE-2017-9506", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-08-23T21:00:00+02:00"}, "gcve": {"object_uuid": "6a108b3f-509f-41b0-a0a7-8d291eb3ef2e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-08-23T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-08-23T19:00:00+00:00"}, "scope": {"notes": "The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote... | Affected: Atlassian / Atlassian OAuth Plugin | CVSS: 6.1 (MEDIUM) | EPSS: 0.71601 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-9506", "url": "https://www.cve.org/CVERecord?id=CVE-2017-9506"}, {"id": "GHSA-WR82-63QC-G2H8", "url": "https://github.com/advisories/GHSA-WR82-63QC-G2H8"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-9506"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote...", "cve_id": "CVE-2017-9506", "vendor": "Atlassian", "ghsa_id": "GHSA-WR82-63QC-G2H8", "product": "Atlassian OAuth Plugin", "added_date": "2017-08-23T19:00:00.000Z", "cvss_score": 6.1, "epss_score": 0.71601, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99403, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-9506", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ba2170a2-e249-4804-ac76-b94da8d9c9a0", "vulnerability": {"vulnId": "CVE-2017-11610", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-08-23T16:00:00+02:00"}, "gcve": {"object_uuid": "ba2170a2-e249-4804-ac76-b94da8d9c9a0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-08-23T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-08-23T14:00:00+00:00"}, "scope": {"notes": "The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to... | Affected: Supervisor / Supervisor | CVSS: 8.8 (HIGH) | EPSS: 0.87378 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-11610", "url": "https://www.cve.org/CVERecord?id=CVE-2017-11610"}, {"id": "GHSA-X7C8-4X3H-874W", "url": "https://github.com/advisories/GHSA-X7C8-4X3H-874W"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-11610"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to...", "cve_id": "CVE-2017-11610", "vendor": "Supervisor", "ghsa_id": "GHSA-X7C8-4X3H-874W", "product": "Supervisor", "added_date": "2017-08-23T14:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.87378, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99753, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-11610", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d2f530ca-5a65-409e-8246-b5897945bcb9", "vulnerability": {"vulnId": "CVE-2015-2280", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-07-24T17:00:00+02:00"}, "gcve": {"object_uuid": "d2f530ca-5a65-409e-8246-b5897945bcb9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-07-24T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-07-24T15:00:00+00:00"}, "scope": {"notes": "snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote... | Affected: AirLink101 / SkyIPCam1620W | CVSS: 8.8 (HIGH) | EPSS: 0.16987 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-2280", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2280"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2280"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote...", "cve_id": "CVE-2015-2280", "vendor": "AirLink101", "ghsa_id": null, "product": "SkyIPCam1620W", "added_date": "2017-07-24T15:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.16987, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96979, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2280", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0150b48e-f11a-465a-9d5c-ea4c92381525", "vulnerability": {"vulnId": "CVE-2017-5173", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-05-19T04:43:00+02:00"}, "gcve": {"object_uuid": "0150b48e-f11a-465a-9d5c-ea4c92381525", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-05-19T02:43:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-05-19T02:43:00+00:00"}, "scope": {"notes": "An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An... | Affected: Geutebruck / IP Camera G-Cam/EFD-2250 | CVSS: 9.8 (CRITICAL) | EPSS: 0.29578 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-5173", "url": "https://www.cve.org/CVERecord?id=CVE-2017-5173"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-5173"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An...", "cve_id": "CVE-2017-5173", "vendor": "Geutebruck", "ghsa_id": null, "product": "IP Camera G-Cam/EFD-2250", "added_date": "2017-05-19T02:43:00.000Z", "cvss_score": 9.8, "epss_score": 0.29578, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98138, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-5173", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7eafe1ad-7886-4fcb-a4ff-ff0b90161a1b", "vulnerability": {"vulnId": "CVE-2014-1677", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-04-03T17:00:00+02:00"}, "gcve": {"object_uuid": "7eafe1ad-7886-4fcb-a4ff-ff0b90161a1b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-04-03T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-04-03T15:00:00+00:00"}, "scope": {"notes": "Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information. | Affected: Technicolor / TC7200 | CVSS: 7.5 (HIGH) | EPSS: 0.17706 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-1677", "url": "https://www.cve.org/CVERecord?id=CVE-2014-1677"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-1677"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.", "cve_id": "CVE-2014-1677", "vendor": "Technicolor", "ghsa_id": null, "product": "TC7200", "added_date": "2017-04-03T15:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.17706, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97073, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-1677", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b6e8624a-441f-4796-a8d2-072e32574d02", "vulnerability": {"vulnId": "CVE-2017-1001000", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2017-02-09T13:00:00+01:00"}, "gcve": {"object_uuid": "b6e8624a-441f-4796-a8d2-072e32574d02", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2017-02-09T12:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2017-02-09T12:00:00+00:00"}, "scope": {"notes": "The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2... | Affected: WordPress / WordPress | CVSS: 7.5 (HIGH) | EPSS: 0.84935 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2017-1001000", "url": "https://www.cve.org/CVERecord?id=CVE-2017-1001000"}, {"id": "previdian", "url": "https://previdian.com/CVE-2017-1001000"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2...", "cve_id": "CVE-2017-1001000", "vendor": "WordPress", "ghsa_id": null, "product": "WordPress", "added_date": "2017-02-09T12:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.84935, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99706, "used_in_malware": "unknown", "vulnerability_id": "CVE-2017-1001000", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "80396d11-37f5-46cd-ac49-3e53fe20727f", "vulnerability": {"vulnId": "CVE-2016-5700", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2016-10-03T18:00:00+02:00"}, "gcve": {"object_uuid": "80396d11-37f5-46cd-ac49-3e53fe20727f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2016-10-03T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2016-10-03T16:00:00+00:00"}, "scope": {"notes": "Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0... | Affected: F5 Networks / BIG-IP | CVSS: 9.8 (CRITICAL) | EPSS: 0.06422 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-5700", "url": "https://www.cve.org/CVERecord?id=CVE-2016-5700"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-5700"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0...", "cve_id": "CVE-2016-5700", "vendor": "F5 Networks", "ghsa_id": null, "product": "BIG-IP", "added_date": "2016-10-03T16:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.06422, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93491, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-5700", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a7b3c759-59fb-4c1d-b535-baa03b35e942", "vulnerability": {"vulnId": "CVE-2016-6195", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2016-08-30T21:00:00+02:00"}, "gcve": {"object_uuid": "a7b3c759-59fb-4c1d-b535-baa03b35e942", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2016-08-30T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2016-08-30T19:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows... | Affected: vBulletin / vBulletin | CVSS: 9.8 (CRITICAL) | EPSS: 0.68493 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2016-6195", "url": "https://www.cve.org/CVERecord?id=CVE-2016-6195"}, {"id": "GHSA-VHXF-9672-MR6M", "url": "https://github.com/advisories/GHSA-VHXF-9672-MR6M"}, {"id": "previdian", "url": "https://previdian.com/CVE-2016-6195"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows...", "cve_id": "CVE-2016-6195", "vendor": "vBulletin", "ghsa_id": "GHSA-VHXF-9672-MR6M", "product": "vBulletin", "added_date": "2016-08-30T19:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.68493, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99318, "used_in_malware": "unknown", "vulnerability_id": "CVE-2016-6195", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2b2d0738-7a5f-4b90-97a3-2c2d191d348d", "vulnerability": {"vulnId": "CVE-2015-8562", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2015-12-16T22:00:00+01:00"}, "gcve": {"object_uuid": "2b2d0738-7a5f-4b90-97a3-2c2d191d348d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2015-12-16T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2015-12-16T21:00:00+00:00"}, "scope": {"notes": "Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP... | Affected: Joomla! / Joomla! | CVSS: 7.5 (HIGH) | EPSS: 0.98283 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-8562", "url": "https://www.cve.org/CVERecord?id=CVE-2015-8562"}, {"id": "GHSA-PCCQ-V233-RX3Q", "url": "https://github.com/advisories/GHSA-PCCQ-V233-RX3Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-8562"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP...", "cve_id": "CVE-2015-8562", "vendor": "Joomla!", "ghsa_id": "GHSA-PCCQ-V233-RX3Q", "product": "Joomla!", "added_date": "2015-12-16T21:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.98283, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99915, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-8562", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f578e838-f175-4d78-81b4-997e107db135", "vulnerability": {"vulnId": "CVE-2015-2863", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2015-07-21T01:00:00+02:00"}, "gcve": {"object_uuid": "f578e838-f175-4d78-81b4-997e107db135", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2015-07-20T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2015-07-20T23:00:00+00:00"}, "scope": {"notes": "Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1... | Affected: Kaseya / Virtual System Administrator (VSA) | CVSS: 4.3 (MEDIUM) | EPSS: 0.10317 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-2863", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2863"}, {"id": "GHSA-MCGP-344H-G8G4", "url": "https://github.com/advisories/GHSA-MCGP-344H-G8G4"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2863"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1...", "cve_id": "CVE-2015-2863", "vendor": "Kaseya", "ghsa_id": "GHSA-MCGP-344H-G8G4", "product": "Virtual System Administrator (VSA)", "added_date": "2015-07-20T23:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.10317, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9557, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2863", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9abdcfbf-cd2f-4338-a8e8-8b9b9efcdbfd", "vulnerability": {"vulnId": "CVE-2014-9727", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2015-05-29T17:00:00+02:00"}, "gcve": {"object_uuid": "9abdcfbf-cd2f-4338-a8e8-8b9b9efcdbfd", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2015-05-29T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2015-05-29T15:00:00+00:00"}, "scope": {"notes": "AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm. | Affected: AVM / Fritz!Box | CVSS: 10.0 (HIGH) | EPSS: 0.71668 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-9727", "url": "https://www.cve.org/CVERecord?id=CVE-2014-9727"}, {"id": "GHSA-XW24-98Q7-5JVX", "url": "https://github.com/advisories/GHSA-XW24-98Q7-5JVX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-9727"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.", "cve_id": "CVE-2014-9727", "vendor": "AVM", "ghsa_id": "GHSA-XW24-98Q7-5JVX", "product": "Fritz!Box", "added_date": "2015-05-29T15:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.71668, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99405, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-9727", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0a9bcfef-757f-4b7e-86c6-01a5ed5e5567", "vulnerability": {"vulnId": "CVE-2015-2945", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2015-05-25T19:00:00+02:00"}, "gcve": {"object_uuid": "0a9bcfef-757f-4b7e-86c6-01a5ed5e5567", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2015-05-25T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2015-05-25T17:00:00+00:00"}, "scope": {"notes": "mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP... | Affected: Hajime Fujimoto / mt-phpincgi | CVSS: 7.5 (HIGH) | EPSS: 0.01716 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-2945", "url": "https://www.cve.org/CVERecord?id=CVE-2015-2945"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-2945"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP...", "cve_id": "CVE-2015-2945", "vendor": "Hajime Fujimoto", "ghsa_id": null, "product": "mt-phpincgi", "added_date": "2015-05-25T17:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01716, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76583, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-2945", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "83d929a6-4e9e-4012-9861-b72f7e14fdd0", "vulnerability": {"vulnId": "CVE-2015-1494", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2015-02-17T16:00:00+01:00"}, "gcve": {"object_uuid": "83d929a6-4e9e-4012-9861-b72f7e14fdd0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2015-02-17T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2015-02-17T15:00:00+00:00"}, "scope": {"notes": "The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site... | Affected: FancyBox / FancyBox for WordPress | CVSS: 4.3 (MEDIUM) | EPSS: 0.06407 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2015-1494", "url": "https://www.cve.org/CVERecord?id=CVE-2015-1494"}, {"id": "GHSA-44CC-C4HQ-R7VV", "url": "https://github.com/advisories/GHSA-44CC-C4HQ-R7VV"}, {"id": "previdian", "url": "https://previdian.com/CVE-2015-1494"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site...", "cve_id": "CVE-2015-1494", "vendor": "FancyBox", "ghsa_id": "GHSA-44CC-C4HQ-R7VV", "product": "FancyBox for WordPress", "added_date": "2015-02-17T15:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.06407, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93468, "used_in_malware": "unknown", "vulnerability_id": "CVE-2015-1494", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "032cc9e8-fc3f-47cc-851b-4f7902bd731a", "vulnerability": {"vulnId": "CVE-2014-7235", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-10-07T16:00:00+02:00"}, "gcve": {"object_uuid": "032cc9e8-fc3f-47cc-851b-4f7902bd731a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-10-07T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-10-07T14:00:00+00:00"}, "scope": {"notes": "htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before... | Affected: FreePBX / ARI Framework module/Asterisk Recording Interface (ARI) | CVSS: 10.0 (HIGH) | EPSS: 0.43262 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-7235", "url": "https://www.cve.org/CVERecord?id=CVE-2014-7235"}, {"id": "GHSA-7PC8-WP58-MR3P", "url": "https://github.com/advisories/GHSA-7PC8-WP58-MR3P"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-7235"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before...", "cve_id": "CVE-2014-7235", "vendor": "FreePBX", "ghsa_id": "GHSA-7PC8-WP58-MR3P", "product": "ARI Framework module/Asterisk Recording Interface (ARI)", "added_date": "2014-10-07T14:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.43262, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98689, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-7235", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bcccc3f4-fde9-4cd9-bece-1d8a01db5845", "vulnerability": {"vulnId": "CVE-2014-6293", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-10-03T16:00:00+02:00"}, "gcve": {"object_uuid": "bcccc3f4-fde9-4cd9-bece-1d8a01db5845", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-10-03T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-10-03T14:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands... | Affected: TYPO3 / ke_stats | CVSS: 7.5 (HIGH) | EPSS: 0.01688 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-6293", "url": "https://www.cve.org/CVERecord?id=CVE-2014-6293"}, {"id": "GHSA-9QX7-M687-GQX6", "url": "https://github.com/advisories/GHSA-9QX7-M687-GQX6"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-6293"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands...", "cve_id": "CVE-2014-6293", "vendor": "TYPO3", "ghsa_id": "GHSA-9QX7-M687-GQX6", "product": "ke_stats", "added_date": "2014-10-03T14:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01688, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.76204, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-6293", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b3ed8e9c-fd3f-4654-b3a4-9dae9fe28448", "vulnerability": {"vulnId": "CVE-2014-1809", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-05-14T12:00:00+02:00"}, "gcve": {"object_uuid": "b3ed8e9c-fd3f-4654-b3a4-9dae9fe28448", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-05-14T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-05-14T10:00:00+00:00"}, "scope": {"notes": "The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to... | Affected: Microsoft / Office | CVSS: 6.8 (MEDIUM) | EPSS: 0.10117 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-1809", "url": "https://www.cve.org/CVERecord?id=CVE-2014-1809"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-1809"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to...", "cve_id": "CVE-2014-1809", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2014-05-14T10:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.10117, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95511, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-1809", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9c776303-2fdf-45ac-9dc4-e304643b01e7", "vulnerability": {"vulnId": "CVE-2014-1807", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-05-14T12:00:00+02:00"}, "gcve": {"object_uuid": "9c776303-2fdf-45ac-9dc4-e304643b01e7", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-05-14T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-05-14T10:00:00+00:00"}, "scope": {"notes": "The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,... | Affected: Microsoft / Windows | CVSS: 7.2 (HIGH) | EPSS: 0.01767 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-1807", "url": "https://www.cve.org/CVERecord?id=CVE-2014-1807"}, {"id": "GHSA-CR6G-JXW7-2XJQ", "url": "https://github.com/advisories/GHSA-CR6G-JXW7-2XJQ"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-1807"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,...", "cve_id": "CVE-2014-1807", "vendor": "Microsoft", "ghsa_id": "GHSA-CR6G-JXW7-2XJQ", "product": "Windows", "added_date": "2014-05-14T10:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.01767, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.77262, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-1807", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "546e693f-bd99-47a0-94fb-68e221ed2e49", "vulnerability": {"vulnId": "CVE-2014-0515", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-04-29T12:00:00+02:00"}, "gcve": {"object_uuid": "546e693f-bd99-47a0-94fb-68e221ed2e49", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-04-29T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-04-29T10:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356... | Affected: Adobe / Flash Player | CVSS: 10.0 (HIGH) | EPSS: 0.94569 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-0515", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0515"}, {"id": "GHSA-77RC-JC7Q-8WRW", "url": "https://github.com/advisories/GHSA-77RC-JC7Q-8WRW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0515"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356...", "cve_id": "CVE-2014-0515", "vendor": "Adobe", "ghsa_id": "GHSA-77RC-JC7Q-8WRW", "product": "Flash Player", "added_date": "2014-04-29T10:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.94569, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99853, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0515", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f148518e-aaa3-4658-8837-7a00977356e1", "vulnerability": {"vulnId": "CVE-2013-5948", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-04-21T16:00:00+02:00"}, "gcve": {"object_uuid": "f148518e-aaa3-4658-8837-7a00977356e1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-04-21T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-04-21T14:00:00+00:00"}, "scope": {"notes": "The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows... | Affected: ASUS / RT-AC68U | CVSS: 8.5 (HIGH) | EPSS: 0.09522 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-5948", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5948"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5948"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows...", "cve_id": "CVE-2013-5948", "vendor": "ASUS", "ghsa_id": null, "product": "RT-AC68U", "added_date": "2014-04-21T14:00:00.000Z", "cvss_score": 8.5, "epss_score": 0.09522, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95307, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5948", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "64b976d2-1bb3-4a41-963b-d229603c0ef2", "vulnerability": {"vulnId": "CVE-2014-0253", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-02-12T03:00:00+01:00"}, "gcve": {"object_uuid": "64b976d2-1bb3-4a41-963b-d229603c0ef2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-02-12T02:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-02-12T02:00:00+00:00"}, "scope": {"notes": "Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote... | Affected: Microsoft / .NET Framework | CVSS: 5.0 (MEDIUM) | EPSS: 0.38697 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-0253", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0253"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0253"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote...", "cve_id": "CVE-2014-0253", "vendor": "Microsoft", "ghsa_id": null, "product": ".NET Framework", "added_date": "2014-02-12T02:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.38697, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98539, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0253", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7cd679c9-3961-475f-90e7-21df718f17fc", "vulnerability": {"vulnId": "CVE-2014-0295", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-02-12T03:00:00+01:00"}, "gcve": {"object_uuid": "7cd679c9-3961-475f-90e7-21df718f17fc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-02-12T02:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-02-12T02:00:00+00:00"}, "scope": {"notes": "VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote... | Affected: Microsoft / .NET Framework | CVSS: 4.3 (MEDIUM) | EPSS: 0.13768 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2014-0295", "url": "https://www.cve.org/CVERecord?id=CVE-2014-0295"}, {"id": "previdian", "url": "https://previdian.com/CVE-2014-0295"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote...", "cve_id": "CVE-2014-0295", "vendor": "Microsoft", "ghsa_id": null, "product": ".NET Framework", "added_date": "2014-02-12T02:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.13768, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96402, "used_in_malware": "unknown", "vulnerability_id": "CVE-2014-0295", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3362bc8f-ccd3-4e50-869a-bbcc88d90781", "vulnerability": {"vulnId": "CVE-2013-1904", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-02-08T01:00:00+01:00"}, "gcve": {"object_uuid": "3362bc8f-ccd3-4e50-869a-bbcc88d90781", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-02-08T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-02-08T00:00:00+00:00"}, "scope": {"notes": "Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers... | Affected: Roundcube / Webmail | CVSS: 5.0 (MEDIUM) | EPSS: 0.02287 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-1904", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1904"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1904"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers...", "cve_id": "CVE-2013-1904", "vendor": "Roundcube", "ghsa_id": null, "product": "Webmail", "added_date": "2014-02-08T00:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.02287, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.8257, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1904", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "69cdfeaf-9d71-458f-b08e-c16abfba9070", "vulnerability": {"vulnId": "CVE-2013-7246", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-01-30T19:00:00+01:00"}, "gcve": {"object_uuid": "69cdfeaf-9d71-458f-b08e-c16abfba9070", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-01-30T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-01-30T18:00:00+00:00"}, "scope": {"notes": "Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to... | Affected: Daum / DaumGame ActiveX plugin | CVSS: 9.3 (HIGH) | EPSS: 0.112 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-7246", "url": "https://www.cve.org/CVERecord?id=CVE-2013-7246"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-7246"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to...", "cve_id": "CVE-2013-7246", "vendor": "Daum", "ghsa_id": null, "product": "DaumGame ActiveX plugin", "added_date": "2014-01-30T18:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.112, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95834, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-7246", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "88933e78-6ef4-43d2-b156-35798ea315df", "vulnerability": {"vulnId": "CVE-2013-5211", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2014-01-02T12:00:00+01:00"}, "gcve": {"object_uuid": "88933e78-6ef4-43d2-b156-35798ea315df", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2014-01-02T11:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2014-01-02T11:00:00+00:00"}, "scope": {"notes": "The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification)... | Affected: NTP / NTP | CVSS: 5.0 (MEDIUM) | EPSS: 0.97549 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-5211", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5211"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5211"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification)...", "cve_id": "CVE-2013-5211", "vendor": "NTP", "ghsa_id": null, "product": "NTP", "added_date": "2014-01-02T11:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.97549, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99901, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5211", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e10bc1b5-4b90-4ac9-b6c7-3b9bcfa867ff", "vulnerability": {"vulnId": "CVE-2013-7102", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-12-24T00:00:00+01:00"}, "gcve": {"object_uuid": "e10bc1b5-4b90-4ac9-b6c7-3b9bcfa867ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-12-23T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-12-23T23:00:00+00:00"}, "scope": {"notes": "Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in... | Affected: OptimizePress / OptimizePress theme for WordPress | CVSS: 6.8 (MEDIUM) | EPSS: 0.14802 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-7102", "url": "https://www.cve.org/CVERecord?id=CVE-2013-7102"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-7102"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in...", "cve_id": "CVE-2013-7102", "vendor": "OptimizePress", "ghsa_id": null, "product": "OptimizePress theme for WordPress", "added_date": "2013-12-23T23:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.14802, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96587, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-7102", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a9b4c20a-225c-4e5c-8342-fa020fb3eb14", "vulnerability": {"vulnId": "CVE-2013-5331", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-12-11T16:00:00+01:00"}, "gcve": {"object_uuid": "a9b4c20a-225c-4e5c-8342-fa020fb3eb14", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-12-11T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-12-11T15:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe... | Affected: Adobe / Flash Player | CVSS: 9.3 (HIGH) | EPSS: 0.72495 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-5331", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5331"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5331"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe...", "cve_id": "CVE-2013-5331", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2013-12-11T15:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.72495, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99427, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5331", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9f512041-a4cd-4ae5-8e36-5f36f4cad13c", "vulnerability": {"vulnId": "CVE-2013-5054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-12-11T01:00:00+01:00"}, "gcve": {"object_uuid": "9f512041-a4cd-4ae5-8e36-5f36f4cad13c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-12-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-12-11T00:00:00+00:00"}, "scope": {"notes": "Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an... | Affected: Microsoft / Office 2013 | CVSS: 4.3 (MEDIUM) | EPSS: 0.12769 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-5054", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an...", "cve_id": "CVE-2013-5054", "vendor": "Microsoft", "ghsa_id": null, "product": "Office 2013", "added_date": "2013-12-11T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.12769, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96159, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "0c7693d1-093f-4c2f-ba5d-e2e29d071778", "vulnerability": {"vulnId": "CVE-2013-5057", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-12-11T01:00:00+01:00"}, "gcve": {"object_uuid": "0c7693d1-093f-4c2f-ba5d-e2e29d071778", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-12-11T00:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-12-11T00:00:00+00:00"}, "scope": {"notes": "hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote... | Affected: Microsoft / Office | CVSS: 4.3 (MEDIUM) | EPSS: 0.09926 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-5057", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5057"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5057"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote...", "cve_id": "CVE-2013-5057", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2013-12-11T00:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.09926, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95453, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5057", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "38946940-e32f-45e1-8cfc-456f622beec4", "vulnerability": {"vulnId": "CVE-2013-3918", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-11-12T02:00:00+01:00"}, "gcve": {"object_uuid": "38946940-e32f-45e1-8cfc-456f622beec4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-11-12T01:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-11-12T01:00:00+00:00"}, "scope": {"notes": "The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.73693 | Used in malware: unknown | Listed 4585 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2013-3918", "url": "https://www.cve.org/CVERecord?id=CVE-2013-3918"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-3918"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista...", "cve_id": "CVE-2013-3918", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2013-11-12T01:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.73693, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99461, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-3918", "ahead_of_cisa_kev": {"unit": "day", "count": 4585}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "e1337354-9e3a-4d44-9a90-21664cf023a1", "vulnerability": {"vulnId": "CVE-2011-4106", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-10-26T18:00:00+02:00"}, "gcve": {"object_uuid": "e1337354-9e3a-4d44-9a90-21664cf023a1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-10-26T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-10-26T16:00:00+00:00"}, "scope": {"notes": "TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and... | Affected: TimThumb / timthumb.php | CVSS: 6.8 (MEDIUM) | EPSS: 0.23342 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-4106", "url": "https://www.cve.org/CVERecord?id=CVE-2011-4106"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-4106"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and...", "cve_id": "CVE-2011-4106", "vendor": "TimThumb", "ghsa_id": null, "product": "timthumb.php", "added_date": "2013-10-26T16:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.23342, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9772, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-4106", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9c06ad14-2146-4235-87f4-9387add180ce", "vulnerability": {"vulnId": "CVE-2013-6026", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-10-19T12:00:00+02:00"}, "gcve": {"object_uuid": "9c06ad14-2146-4235-87f4-9387add180ce", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-10-19T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-10-19T10:00:00+00:00"}, "scope": {"notes": "The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and... | Affected: D-Link, Planex, Alpha Networks / [\"DIR-100\", \"DIR-120\", \"DI-624S\", \"DI-524UP\", \"DI-604S\", \"DI-604UP\", \"DI-604+\", \"TM-G5240\", \"BRL-04R\", \"BRL-04UR\", \"BRL-04CW\"] | CVSS: 10.0 (HIGH) | EPSS: 0.0768 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-6026", "url": "https://www.cve.org/CVERecord?id=CVE-2013-6026"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-6026"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and...", "cve_id": "CVE-2013-6026", "vendor": "D-Link, Planex, Alpha Networks", "ghsa_id": null, "product": "[\"DIR-100\", \"DIR-120\", \"DI-624S\", \"DI-524UP\", \"DI-604S\", \"DI-604UP\", \"DI-604+\", \"TM-G5240\", \"BRL-04R\", \"BRL-04UR\", \"BRL-04CW\"]", "added_date": "2013-10-19T10:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.0768, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94414, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-6026", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c93a47b0-afb0-4894-b879-c2259fd9f8ab", "vulnerability": {"vulnId": "CVE-2013-6129", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-10-19T12:00:00+02:00"}, "gcve": {"object_uuid": "c93a47b0-afb0-4894-b879-c2259fd9f8ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-10-19T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-10-19T10:00:00+00:00"}, "scope": {"notes": "The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid,... | Affected: vBulletin / vBulletin | CVSS: 7.5 (HIGH) | EPSS: 0.51887 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-6129", "url": "https://www.cve.org/CVERecord?id=CVE-2013-6129"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-6129"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid,...", "cve_id": "CVE-2013-6129", "vendor": "vBulletin", "ghsa_id": null, "product": "vBulletin", "added_date": "2013-10-19T10:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.51887, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98918, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-6129", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6cb9aede-b9c1-4341-9b5b-ee79fedf7d79", "vulnerability": {"vulnId": "CVE-2013-5576", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-10-09T16:44:00+02:00"}, "gcve": {"object_uuid": "6cb9aede-b9c1-4341-9b5b-ee79fedf7d79", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-10-09T14:44:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-10-09T14:44:00+00:00"}, "scope": {"notes": "administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote... | Affected: Joomla! / Joomla! | CVSS: 6.8 (MEDIUM) | EPSS: 0.48191 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-5576", "url": "https://www.cve.org/CVERecord?id=CVE-2013-5576"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-5576"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote...", "cve_id": "CVE-2013-5576", "vendor": "Joomla!", "ghsa_id": null, "product": "Joomla!", "added_date": "2013-10-09T14:44:00.000Z", "cvss_score": 6.8, "epss_score": 0.48191, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98825, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-5576", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "f4c99b5f-4788-42dd-8517-ef4bba91f985", "vulnerability": {"vulnId": "CVE-2013-4854", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-07-27T01:00:00+02:00"}, "gcve": {"object_uuid": "f4c99b5f-4788-42dd-8517-ef4bba91f985", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-07-26T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-07-26T23:00:00+00:00"}, "scope": {"notes": "The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND... | Affected: ISC / BIND | CVSS: 7.8 (HIGH) | EPSS: 0.3415 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-4854", "url": "https://www.cve.org/CVERecord?id=CVE-2013-4854"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-4854"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND...", "cve_id": "CVE-2013-4854", "vendor": "ISC", "ghsa_id": null, "product": "BIND", "added_date": "2013-07-26T23:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.3415, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98359, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-4854", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "a3a73228-c449-4716-907d-af024e5df8ac", "vulnerability": {"vulnId": "CVE-2013-1493", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-03-04T17:00:00+01:00"}, "gcve": {"object_uuid": "a3a73228-c449-4716-907d-af024e5df8ac", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-03-04T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-03-04T16:00:00+00:00"}, "scope": {"notes": "The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40... | Affected: Oracle / Java SE | CVSS: 10.0 (HIGH) | EPSS: 0.86151 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-1493", "url": "https://www.cve.org/CVERecord?id=CVE-2013-1493"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-1493"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40...", "cve_id": "CVE-2013-1493", "vendor": "Oracle", "ghsa_id": null, "product": "Java SE", "added_date": "2013-03-04T16:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.86151, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-1493", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "500c26ce-6870-4faf-959c-4c76ee4062c0", "vulnerability": {"vulnId": "CVE-2013-0634", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-02-08T12:00:00+01:00"}, "gcve": {"object_uuid": "500c26ce-6870-4faf-959c-4c76ee4062c0", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-02-08T11:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-02-08T11:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on... | Affected: Adobe / Flash Player | CVSS: 9.3 (HIGH) | EPSS: 0.77597 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-0634", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0634"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0634"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on...", "cve_id": "CVE-2013-0634", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2013-02-08T11:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.77597, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99551, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0634", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7e9cd655-c292-4e83-8bd5-98bb586c3700", "vulnerability": {"vulnId": "CVE-2013-0633", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-02-08T12:00:00+01:00"}, "gcve": {"object_uuid": "7e9cd655-c292-4e83-8bd5-98bb586c3700", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-02-08T11:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-02-08T11:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before... | Affected: Adobe / Flash Player | CVSS: 9.3 (HIGH) | EPSS: 0.20881 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2013-0633", "url": "https://www.cve.org/CVERecord?id=CVE-2013-0633"}, {"id": "previdian", "url": "https://previdian.com/CVE-2013-0633"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before...", "cve_id": "CVE-2013-0633", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2013-02-08T11:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.20881, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97489, "used_in_malware": "unknown", "vulnerability_id": "CVE-2013-0633", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "97ba808d-abd0-49e8-9dcb-42ea8ef777ba", "vulnerability": {"vulnId": "CVE-2012-6498", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-01-08T16:00:00+01:00"}, "gcve": {"object_uuid": "97ba808d-abd0-49e8-9dcb-42ea8ef777ba", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-01-08T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-01-08T15:00:00+00:00"}, "scope": {"notes": "Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading... | Affected: Atomymaxsite / Atomymaxsite | CVSS: 6.8 (MEDIUM) | EPSS: 0.02025 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-6498", "url": "https://www.cve.org/CVERecord?id=CVE-2012-6498"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-6498"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading...", "cve_id": "CVE-2012-6498", "vendor": "Atomymaxsite", "ghsa_id": null, "product": "Atomymaxsite", "added_date": "2013-01-08T15:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.02025, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.80278, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-6498", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "145dfe22-d8f5-4a51-89fb-1ecec16f489a", "vulnerability": {"vulnId": "CVE-2012-6467", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2013-01-02T12:00:00+01:00"}, "gcve": {"object_uuid": "145dfe22-d8f5-4a51-89fb-1ecec16f489a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2013-01-02T11:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2013-01-02T11:00:00+00:00"}, "scope": {"notes": "Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for... | Affected: Opera / Opera Browser | CVSS: 4.3 (MEDIUM) | EPSS: 0.0146 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-6467", "url": "https://www.cve.org/CVERecord?id=CVE-2012-6467"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-6467"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for...", "cve_id": "CVE-2012-6467", "vendor": "Opera", "ghsa_id": null, "product": "Opera Browser", "added_date": "2013-01-02T11:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.0146, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.72624, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-6467", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "dce3fb36-c7c8-4500-8ab8-82a00967d667", "vulnerability": {"vulnId": "CVE-2011-5148", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-08-31T23:00:00+02:00"}, "gcve": {"object_uuid": "dce3fb36-c7c8-4500-8ab8-82a00967d667", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-08-31T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-08-31T21:00:00+00:00"}, "scope": {"notes": "Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote... | Affected: Joomla! / Simple File Upload | CVSS: 6.8 (MEDIUM) | EPSS: 0.04839 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-5148", "url": "https://www.cve.org/CVERecord?id=CVE-2011-5148"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-5148"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote...", "cve_id": "CVE-2011-5148", "vendor": "Joomla!", "ghsa_id": null, "product": "Simple File Upload", "added_date": "2012-08-31T21:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.04839, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91726, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-5148", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1ace1515-b8e6-41bf-98e5-d88688bc7b6d", "vulnerability": {"vulnId": "CVE-2012-1854", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-07-10T23:00:00+02:00"}, "gcve": {"object_uuid": "1ace1515-b8e6-41bf-98e5-d88688bc7b6d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-07-10T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-07-10T21:00:00+00:00"}, "scope": {"notes": "Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for... | Affected: Microsoft / Office | CVSS: 7.8 (HIGH) | EPSS: 0.21028 | Used in malware: unknown | Listed 5075 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2012-1854", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1854"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1854"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for...", "cve_id": "CVE-2012-1854", "vendor": "Microsoft", "ghsa_id": null, "product": "Office", "added_date": "2012-07-10T21:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.21028, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97504, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1854", "ahead_of_cisa_kev": {"unit": "day", "count": 5075}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "fc85d0e5-832e-4e55-9570-1d676d5e9d81", "vulnerability": {"vulnId": "CVE-2012-0297", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-05-21T22:00:00+02:00"}, "gcve": {"object_uuid": "fc85d0e5-832e-4e55-9570-1d676d5e9d81", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-05-21T20:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-05-21T20:00:00+00:00"}, "scope": {"notes": "The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote... | Affected: Symantec / Web Gateway | CVSS: 10.0 (HIGH) | EPSS: 0.72955 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-0297", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0297"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0297"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote...", "cve_id": "CVE-2012-0297", "vendor": "Symantec", "ghsa_id": null, "product": "Web Gateway", "added_date": "2012-05-21T20:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.72955, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99439, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0297", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1e523755-6162-4ee2-be37-0a0ff3f9c2ff", "vulnerability": {"vulnId": "CVE-2012-2376", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-05-21T17:00:00+02:00"}, "gcve": {"object_uuid": "1e523755-6162-4ee2-be37-0a0ff3f9c2ff", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-05-21T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-05-21T15:00:00+00:00"}, "scope": {"notes": "Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via... | Affected: PHP / PHP | CVSS: 10.0 (HIGH) | EPSS: 0.19842 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-2376", "url": "https://www.cve.org/CVERecord?id=CVE-2012-2376"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-2376"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via...", "cve_id": "CVE-2012-2376", "vendor": "PHP", "ghsa_id": null, "product": "PHP", "added_date": "2012-05-21T15:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.19842, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97344, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-2376", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4cd402a5-e94f-498c-acec-50ff1dedbf6a", "vulnerability": {"vulnId": "CVE-2012-0779", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-05-04T21:00:00+02:00"}, "gcve": {"object_uuid": "4cd402a5-e94f-498c-acec-50ff1dedbf6a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-05-04T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-05-04T19:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and... | Affected: Adobe / Flash Player | CVSS: 9.3 (HIGH) | EPSS: 0.87085 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-0779", "url": "https://www.cve.org/CVERecord?id=CVE-2012-0779"}, {"id": "GHSA-52CX-XFMV-V52G", "url": "https://github.com/advisories/GHSA-52CX-XFMV-V52G"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-0779"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and...", "cve_id": "CVE-2012-0779", "vendor": "Adobe", "ghsa_id": "GHSA-52CX-XFMV-V52G", "product": "Flash Player", "added_date": "2012-05-04T19:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.87085, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-0779", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1574128a-a038-4a08-93f9-1db3445af71d", "vulnerability": {"vulnId": "CVE-2012-1795", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-03-20T19:00:00+01:00"}, "gcve": {"object_uuid": "1574128a-a038-4a08-93f9-1db3445af71d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-03-20T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-03-20T18:00:00+00:00"}, "scope": {"notes": "webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter,... | Affected: Webglimpse / Webglimpse | CVSS: 7.5 (HIGH) | EPSS: 0.04167 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-1795", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1795"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1795"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter,...", "cve_id": "CVE-2012-1795", "vendor": "Webglimpse", "ghsa_id": null, "product": "Webglimpse", "added_date": "2012-03-20T18:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.04167, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90573, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1795", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6d376553-10e2-461c-bb13-5c34de78903e", "vulnerability": {"vulnId": "CVE-2012-1557", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-03-12T20:00:00+01:00"}, "gcve": {"object_uuid": "6d376553-10e2-461c-bb13-5c34de78903e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-03-12T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-03-12T19:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x... | Affected: Parallels / Plesk Panel | CVSS: 7.5 (HIGH) | EPSS: 0.06041 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-1557", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1557"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1557"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in admin/plib/api-rpc/Agent.php in Parallels Plesk Panel 7.x and 8.x before 8.6 MU#2, 9.x before 9.5 MU#11, 10.0.x...", "cve_id": "CVE-2012-1557", "vendor": "Parallels", "ghsa_id": null, "product": "Plesk Panel", "added_date": "2012-03-12T19:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.06041, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93145, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1557", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2cd1fc59-a070-4c42-a4c4-d1977ecb2998", "vulnerability": {"vulnId": "CVE-2012-1071", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2012-02-14T18:00:00+01:00"}, "gcve": {"object_uuid": "2cd1fc59-a070-4c42-a4c4-d1977ecb2998", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2012-02-14T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2012-02-14T17:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL... | Affected: TYPO3 / mv_cooking extension | CVSS: 7.5 (HIGH) | EPSS: 0.01288 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2012-1071", "url": "https://www.cve.org/CVERecord?id=CVE-2012-1071"}, {"id": "previdian", "url": "https://previdian.com/CVE-2012-1071"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL...", "cve_id": "CVE-2012-1071", "vendor": "TYPO3", "ghsa_id": null, "product": "mv_cooking extension", "added_date": "2012-02-14T17:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01288, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69139, "used_in_malware": "unknown", "vulnerability_id": "CVE-2012-1071", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "44d5f494-54b8-41f3-98a9-313abfdaa7df", "vulnerability": {"vulnId": "CVE-2011-4862", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-12-25T02:00:00+01:00"}, "gcve": {"object_uuid": "44d5f494-54b8-41f3-98a9-313abfdaa7df", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-12-25T01:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-12-25T01:00:00+00:00"}, "scope": {"notes": "Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and... | Affected: FreeBSD / FreeBSD | CVSS: 10.0 (HIGH) | EPSS: 0.94983 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-4862", "url": "https://www.cve.org/CVERecord?id=CVE-2011-4862"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-4862"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and...", "cve_id": "CVE-2011-4862", "vendor": "FreeBSD", "ghsa_id": null, "product": "FreeBSD", "added_date": "2011-12-25T01:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.94983, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99861, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-4862", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "d4e8a2ca-e9a7-4c7a-91a8-6e3ca760c67d", "vulnerability": {"vulnId": "CVE-2011-4369", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-12-16T20:00:00+01:00"}, "gcve": {"object_uuid": "d4e8a2ca-e9a7-4c7a-91a8-6e3ca760c67d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-12-16T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-12-16T19:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6... | Affected: Adobe / Reader and Acrobat | CVSS: 10.0 (HIGH) | EPSS: 0.07519 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-4369", "url": "https://www.cve.org/CVERecord?id=CVE-2011-4369"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-4369"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6...", "cve_id": "CVE-2011-4369", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2011-12-16T19:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.07519, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94313, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-4369", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2f5baed6-9c75-475e-b067-47d36df7f26f", "vulnerability": {"vulnId": "CVE-2011-3402", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-11-04T22:00:00+01:00"}, "gcve": {"object_uuid": "2f5baed6-9c75-475e-b067-47d36df7f26f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-11-04T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-11-04T21:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.78138 | Used in malware: unknown | Listed 5324 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2011-3402", "url": "https://www.cve.org/CVERecord?id=CVE-2011-3402"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-3402"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows...", "cve_id": "CVE-2011-3402", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2011-11-04T21:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.78138, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99566, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-3402", "ahead_of_cisa_kev": {"unit": "day", "count": 5324}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "af68c654-628e-4310-8fc3-8ea3b2bd823d", "vulnerability": {"vulnId": "CVE-2011-4075", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-11-02T18:00:00+01:00"}, "gcve": {"object_uuid": "af68c654-628e-4310-8fc3-8ea3b2bd823d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-11-02T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-11-02T17:00:00+00:00"}, "scope": {"notes": "The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby... | Affected: phpLDAPadmin / phpLDAPadmin | CVSS: 7.5 (HIGH) | EPSS: 0.51891 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-4075", "url": "https://www.cve.org/CVERecord?id=CVE-2011-4075"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-4075"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby...", "cve_id": "CVE-2011-4075", "vendor": "phpLDAPadmin", "ghsa_id": null, "product": "phpLDAPadmin", "added_date": "2011-11-02T17:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.51891, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98918, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-4075", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4e33bb6d-6e38-4eb7-87f3-aa4c6593e1da", "vulnerability": {"vulnId": "CVE-2011-2444", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-09-22T03:00:00+02:00"}, "gcve": {"object_uuid": "4e33bb6d-6e38-4eb7-87f3-aa4c6593e1da", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-09-22T01:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-09-22T01:00:00+00:00"}, "scope": {"notes": "Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7... | Affected: Adobe / Flash Player | CVSS: 4.3 (MEDIUM) | EPSS: 0.02701 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-2444", "url": "https://www.cve.org/CVERecord?id=CVE-2011-2444"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-2444"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7...", "cve_id": "CVE-2011-2444", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2011-09-22T01:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.02701, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.85411, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-2444", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9e69e3c0-9193-4c4e-ab47-8819a78164f1", "vulnerability": {"vulnId": "CVE-2011-1968", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-08-10T23:16:00+02:00"}, "gcve": {"object_uuid": "9e69e3c0-9193-4c4e-ab47-8819a78164f1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-08-10T21:16:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-08-10T21:16:00+00:00"}, "scope": {"notes": "The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets... | Affected: Microsoft / Windows | CVSS: 7.1 (HIGH) | EPSS: 0.25708 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-1968", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1968"}, {"id": "GHSA-7FFR-G48R-P39Q", "url": "https://github.com/advisories/GHSA-7FFR-G48R-P39Q"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1968"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets...", "cve_id": "CVE-2011-1968", "vendor": "Microsoft", "ghsa_id": "GHSA-7FFR-G48R-P39Q", "product": "Windows", "added_date": "2011-08-10T21:16:00.000Z", "cvss_score": 7.1, "epss_score": 0.25708, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97908, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1968", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7982e10c-e230-4e16-adce-ac5fb9d492c8", "vulnerability": {"vulnId": "CVE-2011-2900", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-08-05T23:00:00+02:00"}, "gcve": {"object_uuid": "7982e10c-e230-4e16-adce-ac5fb9d492c8", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-08-05T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-08-05T21:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web... | Affected: Mongoose / Mongoose | CVSS: 7.5 (HIGH) | EPSS: 0.13256 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-2900", "url": "https://www.cve.org/CVERecord?id=CVE-2011-2900"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-2900"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web...", "cve_id": "CVE-2011-2900", "vendor": "Mongoose", "ghsa_id": null, "product": "Mongoose", "added_date": "2011-08-05T21:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.13256, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96273, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-2900", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "9069e5ac-8547-402c-83da-29d9efa18d2e", "vulnerability": {"vulnId": "CVE-2011-0226", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-07-20T00:00:00+02:00"}, "gcve": {"object_uuid": "9069e5ac-8547-402c-83da-29d9efa18d2e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-07-19T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-07-19T22:00:00+00:00"}, "scope": {"notes": "Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and... | Affected: Apple / iOS | CVSS: 9.3 (HIGH) | EPSS: 0.06646 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-0226", "url": "https://www.cve.org/CVERecord?id=CVE-2011-0226"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-0226"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and...", "cve_id": "CVE-2011-0226", "vendor": "Apple", "ghsa_id": null, "product": "iOS", "added_date": "2011-07-19T22:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.06646, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9367, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-0226", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "89694bd7-1d0b-41ea-affa-579aa1bdd05b", "vulnerability": {"vulnId": "CVE-2011-1331", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-07-19T00:00:00+02:00"}, "gcve": {"object_uuid": "89694bd7-1d0b-41ea-affa-579aa1bdd05b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-07-18T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-07-18T22:00:00+00:00"}, "scope": {"notes": "JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro... | Affected: JustSystems / Ichitaro | CVSS: 9.3 (HIGH) | EPSS: 0.05564 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-1331", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1331"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1331"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro...", "cve_id": "CVE-2011-1331", "vendor": "JustSystems", "ghsa_id": null, "product": "Ichitaro", "added_date": "2011-07-18T22:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.05564, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92612, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1331", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "06d8d7d8-263b-42d5-85a7-61f39e972053", "vulnerability": {"vulnId": "CVE-2011-2110", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-06-17T01:00:00+02:00"}, "gcve": {"object_uuid": "06d8d7d8-263b-42d5-85a7-61f39e972053", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-06-16T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-06-16T23:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to... | Affected: Adobe / Flash Player | CVSS: 10.0 (HIGH) | EPSS: 0.86421 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-2110", "url": "https://www.cve.org/CVERecord?id=CVE-2011-2110"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-2110"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to...", "cve_id": "CVE-2011-2110", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2011-06-16T23:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.86421, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99731, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-2110", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e74a1a23-b1a0-4585-8a2c-850c9bad88c1", "vulnerability": {"vulnId": "CVE-2009-5076", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-06-08T12:00:00+02:00"}, "gcve": {"object_uuid": "e74a1a23-b1a0-4585-8a2c-850c9bad88c1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-06-08T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-06-08T10:00:00+00:00"}, "scope": {"notes": "CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator... | Affected: CRE Loaded / CRE Loaded | CVSS: 7.5 (HIGH) | EPSS: 0.01409 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-5076", "url": "https://www.cve.org/CVERecord?id=CVE-2009-5076"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-5076"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator...", "cve_id": "CVE-2009-5076", "vendor": "CRE Loaded", "ghsa_id": null, "product": "CRE Loaded", "added_date": "2011-06-08T10:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01409, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.71652, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-5076", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "822cd472-d3bb-49b2-b210-0464873df24b", "vulnerability": {"vulnId": "CVE-2011-1950", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-06-06T21:00:00+02:00"}, "gcve": {"object_uuid": "822cd472-d3bb-49b2-b210-0464873df24b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-06-06T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-06-06T19:00:00+00:00"}, "scope": {"notes": "plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as... | Affected: Plone / Plone | CVSS: 5.5 (MEDIUM) | EPSS: 0.02349 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-1950", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1950"}, {"id": "GHSA-2QX8-589J-GCPX", "url": "https://github.com/advisories/GHSA-2QX8-589J-GCPX"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1950"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as...", "cve_id": "CVE-2011-1950", "vendor": "Plone", "ghsa_id": "GHSA-2QX8-589J-GCPX", "product": "Plone", "added_date": "2011-06-06T19:00:00.000Z", "cvss_score": 5.5, "epss_score": 0.02349, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.83065, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1950", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "940ec19d-e9bb-4b06-9ab7-484070f988c3", "vulnerability": {"vulnId": "CVE-2011-1752", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-06-06T21:00:00+02:00"}, "gcve": {"object_uuid": "940ec19d-e9bb-4b06-9ab7-484070f988c3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-06-06T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-06-06T19:00:00+00:00"}, "scope": {"notes": "The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of... | Affected: Apache / Subversion | CVSS: 5.0 (MEDIUM) | EPSS: 0.08483 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-1752", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1752"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1752"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of...", "cve_id": "CVE-2011-1752", "vendor": "Apache", "ghsa_id": null, "product": "Subversion", "added_date": "2011-06-06T19:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.08483, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94863, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1752", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "620fd393-4b6a-47af-90ba-b15e52bbf39b", "vulnerability": {"vulnId": "CVE-2011-0627", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-05-14T00:00:00+02:00"}, "gcve": {"object_uuid": "620fd393-4b6a-47af-90ba-b15e52bbf39b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-05-13T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-05-13T22:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute... | Affected: Adobe / Flash Player | CVSS: 9.3 (HIGH) | EPSS: 0.05107 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-0627", "url": "https://www.cve.org/CVERecord?id=CVE-2011-0627"}, {"id": "GHSA-585F-RVF9-F227", "url": "https://github.com/advisories/GHSA-585F-RVF9-F227"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-0627"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute...", "cve_id": "CVE-2011-0627", "vendor": "Adobe", "ghsa_id": "GHSA-585F-RVF9-F227", "product": "Flash Player", "added_date": "2011-05-13T22:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.05107, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92108, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-0627", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "37a301a8-9ced-4adc-9b88-524bc04d0337", "vulnerability": {"vulnId": "CVE-2011-1722", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2011-04-19T21:00:00+02:00"}, "gcve": {"object_uuid": "37a301a8-9ced-4adc-9b88-524bc04d0337", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2011-04-19T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2011-04-19T19:00:00+00:00"}, "scope": {"notes": "Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to... | Affected: TYPO3 / WEC Discussion Forum | CVSS: 7.5 (HIGH) | EPSS: 0.01299 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2011-1722", "url": "https://www.cve.org/CVERecord?id=CVE-2011-1722"}, {"id": "previdian", "url": "https://previdian.com/CVE-2011-1722"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to...", "cve_id": "CVE-2011-1722", "vendor": "TYPO3", "ghsa_id": null, "product": "WEC Discussion Forum", "added_date": "2011-04-19T19:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.01299, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.69374, "used_in_malware": "unknown", "vulnerability_id": "CVE-2011-1722", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "7d03de73-4296-4530-ba55-97502d497589", "vulnerability": {"vulnId": "CVE-2010-4270", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-11-17T00:00:00+01:00"}, "gcve": {"object_uuid": "7d03de73-4296-4530-ba55-97502d497589", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-11-16T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-11-16T23:00:00+00:00"}, "scope": {"notes": "Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for... | Affected: nBill / nBill | CVSS: 5.0 (MEDIUM) | EPSS: 0.01841 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-4270", "url": "https://www.cve.org/CVERecord?id=CVE-2010-4270"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-4270"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for...", "cve_id": "CVE-2010-4270", "vendor": "nBill", "ghsa_id": null, "product": "nBill", "added_date": "2010-11-16T23:00:00.000Z", "cvss_score": 5.0, "epss_score": 0.01841, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78224, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-4270", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "bc9e0169-0c79-48b1-9ae6-3b9153d9f6d2", "vulnerability": {"vulnId": "CVE-2010-3962", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-11-05T17:28:00+01:00"}, "gcve": {"object_uuid": "bc9e0169-0c79-48b1-9ae6-3b9153d9f6d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-11-05T16:28:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-11-05T16:28:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to... | Affected: Microsoft / Internet Explorer | CVSS: 8.1 (HIGH) | EPSS: 0.96831 | Used in malware: unknown | Listed 5688 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-3962", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3962"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3962"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to...", "cve_id": "CVE-2010-3962", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2010-11-05T16:28:00.000Z", "cvss_score": 8.1, "epss_score": 0.96831, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99887, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3962", "ahead_of_cisa_kev": {"unit": "day", "count": 5688}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "02822fdf-a50a-4c85-a2cf-c417e46b0470", "vulnerability": {"vulnId": "CVE-2010-3654", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-10-29T20:00:00+02:00"}, "gcve": {"object_uuid": "02822fdf-a50a-4c85-a2cf-c417e46b0470", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-10-29T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-10-29T18:00:00+00:00"}, "scope": {"notes": "Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll... | Affected: Adobe / Flash Player | CVSS: 9.3 (HIGH) | EPSS: 0.69679 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-3654", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3654"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3654"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll...", "cve_id": "CVE-2010-3654", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2010-10-29T18:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.69679, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9935, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3654", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "076fc10b-1f7e-4bf2-9827-ecb684266f97", "vulnerability": {"vulnId": "CVE-2010-3765", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-10-28T00:00:00+02:00"}, "gcve": {"object_uuid": "076fc10b-1f7e-4bf2-9827-ecb684266f97", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-10-27T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-10-27T22:00:00+00:00"}, "scope": {"notes": "Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before... | Affected: Mozilla / Firefox, Thunderbird, SeaMonkey | CVSS: 9.8 (CRITICAL) | EPSS: 0.83156 | Used in malware: unknown | Listed 5697 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-3765", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3765"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3765"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before...", "cve_id": "CVE-2010-3765", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Thunderbird, SeaMonkey", "added_date": "2010-10-27T22:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.83156, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99669, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3765", "ahead_of_cisa_kev": {"unit": "day", "count": 5697}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "aef5c983-dea5-4c6e-b9c7-8d2ab68431ce", "vulnerability": {"vulnId": "CVE-2010-3653", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-10-26T19:00:00+02:00"}, "gcve": {"object_uuid": "aef5c983-dea5-4c6e-b9c7-8d2ab68431ce", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-10-26T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-10-26T17:00:00+00:00"}, "scope": {"notes": "The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of... | Affected: Adobe / Shockwave Player | CVSS: 9.3 (HIGH) | EPSS: 0.74626 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-3653", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3653"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3653"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of...", "cve_id": "CVE-2010-3653", "vendor": "Adobe", "ghsa_id": null, "product": "Shockwave Player", "added_date": "2010-10-26T17:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.74626, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99487, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3653", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "767af330-f980-4830-a56d-0dfe7737f4de", "vulnerability": {"vulnId": "CVE-2010-3888", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-10-08T23:00:00+02:00"}, "gcve": {"object_uuid": "767af330-f980-4830-a56d-0dfe7737f4de", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-10-08T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-10-08T21:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the... | Affected: Microsoft / Windows | CVSS: 7.2 (HIGH) | EPSS: 0.03929 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-3888", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3888"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3888"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the...", "cve_id": "CVE-2010-3888", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2010-10-08T21:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.03929, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9003, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3888", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "12d965e6-0eef-41f4-9cd4-3cbc46939eca", "vulnerability": {"vulnId": "CVE-2010-3889", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-10-08T23:00:00+02:00"}, "gcve": {"object_uuid": "12d965e6-0eef-41f4-9cd4-3cbc46939eca", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-10-08T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-10-08T21:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the... | Affected: Microsoft / Windows | CVSS: 7.2 (HIGH) | EPSS: 0.01606 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-3889", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3889"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3889"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the...", "cve_id": "CVE-2010-3889", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2010-10-08T21:00:00.000Z", "cvss_score": 7.2, "epss_score": 0.01606, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.75, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3889", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8643e9a5-a4c5-4c56-81d4-2e05f2814f0a", "vulnerability": {"vulnId": "CVE-2010-3081", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-09-24T21:00:00+02:00"}, "gcve": {"object_uuid": "8643e9a5-a4c5-4c56-81d4-2e05f2814f0a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-09-24T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-09-24T19:00:00+00:00"}, "scope": {"notes": "The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly... | Affected: Linux / Linux Kernel | CVSS: 7.8 (HIGH) | EPSS: 0.03533 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-3081", "url": "https://www.cve.org/CVERecord?id=CVE-2010-3081"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-3081"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly...", "cve_id": "CVE-2010-3081", "vendor": "Linux", "ghsa_id": null, "product": "Linux Kernel", "added_date": "2010-09-24T19:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.03533, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.88873, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-3081", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "72572b24-d4b5-419b-a6b4-043d1e10cc9c", "vulnerability": {"vulnId": "CVE-2010-2729", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-09-15T20:00:00+02:00"}, "gcve": {"object_uuid": "72572b24-d4b5-419b-a6b4-043d1e10cc9c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-09-15T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-09-15T18:00:00+00:00"}, "scope": {"notes": "The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2,... | Affected: Microsoft / Windows | CVSS: 9.3 (HIGH) | EPSS: 0.75636 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-2729", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2729"}, {"id": "GHSA-H544-VRH7-5WGW", "url": "https://github.com/advisories/GHSA-H544-VRH7-5WGW"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-2729"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2,...", "cve_id": "CVE-2010-2729", "vendor": "Microsoft", "ghsa_id": "GHSA-H544-VRH7-5WGW", "product": "Windows", "added_date": "2010-09-15T18:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.75636, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99506, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-2729", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "2fa87a5f-2e2e-4b46-b35e-3b4d3521af8c", "vulnerability": {"vulnId": "CVE-2010-2884", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-09-15T19:26:00+02:00"}, "gcve": {"object_uuid": "2fa87a5f-2e2e-4b46-b35e-3b4d3521af8c", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-09-15T17:26:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-09-15T17:26:00+00:00"}, "scope": {"notes": "Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and... | Affected: Adobe / Flash Player, Reader, Acrobat | CVSS: 9.3 (HIGH) | EPSS: 0.15621 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-2884", "url": "https://www.cve.org/CVERecord?id=CVE-2010-2884"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-2884"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and...", "cve_id": "CVE-2010-2884", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player, Reader, Acrobat", "added_date": "2010-09-15T17:26:00.000Z", "cvss_score": 9.3, "epss_score": 0.15621, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96741, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-2884", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "69c22155-c294-4f0d-8d6f-222edfcdb367", "vulnerability": {"vulnId": "CVE-2010-1165", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-04-20T17:00:00+02:00"}, "gcve": {"object_uuid": "69c22155-c294-4f0d-8d6f-222edfcdb367", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-04-20T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-04-20T15:00:00+00:00"}, "scope": {"notes": "Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka... | Affected: Atlassian / JIRA | CVSS: 9.0 (HIGH) | EPSS: 0.04436 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-1165", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1165"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-1165"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka...", "cve_id": "CVE-2010-1165", "vendor": "Atlassian", "ghsa_id": null, "product": "JIRA", "added_date": "2010-04-20T15:00:00.000Z", "cvss_score": 9.0, "epss_score": 0.04436, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91082, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-1165", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "526e2f4e-bea8-422b-a4f5-ffd4c90e12e4", "vulnerability": {"vulnId": "CVE-2010-1164", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-04-20T17:00:00+02:00"}, "gcve": {"object_uuid": "526e2f4e-bea8-422b-a4f5-ffd4c90e12e4", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-04-20T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-04-20T15:00:00+00:00"}, "scope": {"notes": "Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or... | Affected: Atlassian / JIRA | CVSS: 4.3 (MEDIUM) | EPSS: 0.02235 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2010-1164", "url": "https://www.cve.org/CVERecord?id=CVE-2010-1164"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-1164"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or...", "cve_id": "CVE-2010-1164", "vendor": "Atlassian", "ghsa_id": null, "product": "JIRA", "added_date": "2010-04-20T15:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.02235, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82168, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-1164", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "23e2dc0e-8ddf-4f67-81c9-d5bb4c1e1a93", "vulnerability": {"vulnId": "CVE-2010-0806", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-03-10T23:00:00+01:00"}, "gcve": {"object_uuid": "23e2dc0e-8ddf-4f67-81c9-d5bb4c1e1a93", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-03-10T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-03-10T22:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.82172 | Used in malware: unknown | Listed 5928 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-0806", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0806"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0806"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers...", "cve_id": "CVE-2010-0806", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2010-03-10T22:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.82172, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99647, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-0806", "ahead_of_cisa_kev": {"unit": "day", "count": 5928}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "d64f5aa4-9c3a-41a1-9d58-4c59dbb61ea9", "vulnerability": {"vulnId": "CVE-2010-0249", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2010-01-15T18:00:00+01:00"}, "gcve": {"object_uuid": "d64f5aa4-9c3a-41a1-9d58-4c59dbb61ea9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2010-01-15T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2010-01-15T17:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003... | Affected: Microsoft / Internet Explorer | CVSS: 8.8 (HIGH) | EPSS: 0.91939 | Used in malware: unknown | Listed 5982 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2010-0249", "url": "https://www.cve.org/CVERecord?id=CVE-2010-0249"}, {"id": "previdian", "url": "https://previdian.com/CVE-2010-0249"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003...", "cve_id": "CVE-2010-0249", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2010-01-15T17:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.91939, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99817, "used_in_malware": "unknown", "vulnerability_id": "CVE-2010-0249", "ahead_of_cisa_kev": {"unit": "day", "count": 5982}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "f4778154-a25f-4578-a376-6de60b1351f3", "vulnerability": {"vulnId": "CVE-2009-3459", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-10-13T12:00:00+02:00"}, "gcve": {"object_uuid": "f4778154-a25f-4578-a376-6de60b1351f3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-10-13T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-10-13T10:00:00+00:00"}, "scope": {"notes": "Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute... | Affected: Adobe / Reader and Acrobat | CVSS: 8.8 (HIGH) | EPSS: 0.86583 | Used in malware: unknown | Listed 6076 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-3459", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3459"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-3459"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute...", "cve_id": "CVE-2009-3459", "vendor": "Adobe", "ghsa_id": null, "product": "Reader and Acrobat", "added_date": "2009-10-13T10:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.86583, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99735, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-3459", "ahead_of_cisa_kev": {"unit": "day", "count": 6076}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c90528c4-9279-447c-88e8-29ee37a22c33", "vulnerability": {"vulnId": "CVE-2008-7168", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-09-08T12:00:00+02:00"}, "gcve": {"object_uuid": "c90528c4-9279-447c-88e8-29ee37a22c33", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-09-08T10:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-09-08T10:00:00+00:00"}, "scope": {"notes": "Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and... | Affected: UUSee / UUUpgrade ActiveX control | CVSS: 9.3 (HIGH) | EPSS: 0.05647 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-7168", "url": "https://www.cve.org/CVERecord?id=CVE-2008-7168"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-7168"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and...", "cve_id": "CVE-2008-7168", "vendor": "UUSee", "ghsa_id": null, "product": "UUUpgrade ActiveX control", "added_date": "2009-09-08T10:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.05647, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.92723, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-7168", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "1b022b02-7bbd-4c10-b83b-da9c1a883540", "vulnerability": {"vulnId": "CVE-2009-3041", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-09-01T20:04:00+02:00"}, "gcve": {"object_uuid": "1b022b02-7bbd-4c10-b83b-da9c1a883540", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-09-01T18:04:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-09-01T18:04:00+00:00"}, "scope": {"notes": "SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which... | Affected: SPIP / SPIP | CVSS: 7.5 (HIGH) | EPSS: 0.06589 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-3041", "url": "https://www.cve.org/CVERecord?id=CVE-2009-3041"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-3041"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which...", "cve_id": "CVE-2009-3041", "vendor": "SPIP", "ghsa_id": null, "product": "SPIP", "added_date": "2009-09-01T18:04:00.000Z", "cvss_score": 7.5, "epss_score": 0.06589, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.93634, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-3041", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "894ecabd-b927-44fe-8b98-a3f269859c24", "vulnerability": {"vulnId": "CVE-2009-1136", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-07-15T17:00:00+02:00"}, "gcve": {"object_uuid": "894ecabd-b927-44fe-8b98-a3f269859c24", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-07-15T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-07-15T15:00:00+00:00"}, "scope": {"notes": "The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office... | Affected: Microsoft / Office Web Components | CVSS: 9.3 (HIGH) | EPSS: 0.6202 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1136", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1136"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1136"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office...", "cve_id": "CVE-2009-1136", "vendor": "Microsoft", "ghsa_id": null, "product": "Office Web Components", "added_date": "2009-07-15T15:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.6202, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99155, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1136", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "345a0aef-c9f9-4078-a669-0dbea204ce3a", "vulnerability": {"vulnId": "CVE-2008-0015", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-07-08T01:00:00+02:00"}, "gcve": {"object_uuid": "345a0aef-c9f9-4078-a669-0dbea204ce3a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-07-07T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-07-07T23:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest... | Affected: Microsoft / Windows | CVSS: 8.8 (HIGH) | EPSS: 0.76576 | Used in malware: unknown | Listed 6174 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2008-0015", "url": "https://www.cve.org/CVERecord?id=CVE-2008-0015"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-0015"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest...", "cve_id": "CVE-2008-0015", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2009-07-07T23:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.76576, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99528, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-0015", "ahead_of_cisa_kev": {"unit": "day", "count": 6174}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "65caaf3a-ed4e-4381-bf2b-a3f1db68410e", "vulnerability": {"vulnId": "CVE-2009-2265", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-07-05T18:00:00+02:00"}, "gcve": {"object_uuid": "65caaf3a-ed4e-4381-bf2b-a3f1db68410e", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-07-05T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-07-05T16:00:00+00:00"}, "scope": {"notes": "Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories... | Affected: FCKeditor / FCKeditor | CVSS: 7.5 (HIGH) | EPSS: 0.83744 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-2265", "url": "https://www.cve.org/CVERecord?id=CVE-2009-2265"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-2265"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories...", "cve_id": "CVE-2009-2265", "vendor": "FCKeditor", "ghsa_id": null, "product": "FCKeditor", "added_date": "2009-07-05T16:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.83744, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99683, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-2265", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "3b8e403b-201f-4bf2-9f44-f37143f42ecf", "vulnerability": {"vulnId": "CVE-2009-1391", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-06-17T01:00:00+02:00"}, "gcve": {"object_uuid": "3b8e403b-201f-4bf2-9f44-f37143f42ecf", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-06-16T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-06-16T23:00:00+00:00"}, "scope": {"notes": "Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly... | Affected: Perl / Compress::Raw::Zlib | CVSS: 6.8 (MEDIUM) | EPSS: 0.07441 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1391", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1391"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1391"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly...", "cve_id": "CVE-2009-1391", "vendor": "Perl", "ghsa_id": null, "product": "Compress::Raw::Zlib", "added_date": "2009-06-16T23:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.07441, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9427, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1391", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "07a78f40-1b3b-4aae-a154-8348a4a42be3", "vulnerability": {"vulnId": "CVE-2009-1537", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-05-29T20:00:00+02:00"}, "gcve": {"object_uuid": "07a78f40-1b3b-4aae-a154-8348a4a42be3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-05-29T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-05-29T18:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000... | Affected: Microsoft / DirectX | CVSS: 8.8 (HIGH) | EPSS: 0.51207 | Used in malware: unknown | Listed 6213 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-1537", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1537"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1537"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000...", "cve_id": "CVE-2009-1537", "vendor": "Microsoft", "ghsa_id": null, "product": "DirectX", "added_date": "2009-05-29T18:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.51207, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98904, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1537", "ahead_of_cisa_kev": {"unit": "day", "count": 6213}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "492784ce-d28e-44f8-a19f-ebb764a04ad3", "vulnerability": {"vulnId": "CVE-2009-1807", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-05-28T22:14:00+02:00"}, "gcve": {"object_uuid": "492784ce-d28e-44f8-a19f-ebb764a04ad3", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-05-28T20:14:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-05-28T20:14:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the... | Affected: Baofeng / Baofeng products | CVSS: 9.3 (HIGH) | EPSS: 0.07531 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1807", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1807"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1807"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the...", "cve_id": "CVE-2009-1807", "vendor": "Baofeng", "ghsa_id": null, "product": "Baofeng products", "added_date": "2009-05-28T20:14:00.000Z", "cvss_score": 9.3, "epss_score": 0.07531, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94318, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1807", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "564bdc20-670e-4a43-a2cf-46f376dd31ed", "vulnerability": {"vulnId": "CVE-2009-1800", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-05-28T16:00:00+02:00"}, "gcve": {"object_uuid": "564bdc20-670e-4a43-a2cf-46f376dd31ed", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-05-28T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-05-28T14:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote... | Affected: Chinagames / iGame | CVSS: 7.5 (HIGH) | EPSS: 0.10899 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1800", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1800"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1800"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote...", "cve_id": "CVE-2009-1800", "vendor": "Chinagames", "ghsa_id": null, "product": "iGame", "added_date": "2009-05-28T14:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.10899, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95746, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1800", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "006b537f-3b68-4151-8f59-99454fde3c75", "vulnerability": {"vulnId": "CVE-2009-1612", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-05-11T22:00:00+02:00"}, "gcve": {"object_uuid": "006b537f-3b68-4151-8f59-99454fde3c75", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-05-11T20:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-05-11T20:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute... | Affected: Baofeng / Storm | CVSS: 9.3 (HIGH) | EPSS: 0.33255 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1612", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1612"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1612"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute...", "cve_id": "CVE-2009-1612", "vendor": "Baofeng", "ghsa_id": null, "product": "Storm", "added_date": "2009-05-11T20:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.33255, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98323, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1612", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "5560f897-e53b-461e-8e78-4f777977af3b", "vulnerability": {"vulnId": "CVE-2009-1481", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-04-29T20:06:00+02:00"}, "gcve": {"object_uuid": "5560f897-e53b-461e-8e78-4f777977af3b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-04-29T18:06:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-04-29T18:06:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in action.asp in PuterJam's Blog (PJBlog3) 3.0.6.170 allows remote attackers to execute arbitrary SQL commands via the... | Affected: PuterJam / PJBlog3 | CVSS: 7.5 (HIGH) | EPSS: 0.01173 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1481", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1481"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1481"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in action.asp in PuterJam's Blog (PJBlog3) 3.0.6.170 allows remote attackers to execute arbitrary SQL commands via the...", "cve_id": "CVE-2009-1481", "vendor": "PuterJam", "ghsa_id": null, "product": "PJBlog3", "added_date": "2009-04-29T18:06:00.000Z", "cvss_score": 7.5, "epss_score": 0.01173, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.66321, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1481", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "8e593eb4-8e05-4298-b925-a34c6723d1ab", "vulnerability": {"vulnId": "CVE-2009-1308", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-04-22T20:00:00+02:00"}, "gcve": {"object_uuid": "8e593eb4-8e05-4298-b925-a34c6723d1ab", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-04-22T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-04-22T18:00:00+00:00"}, "scope": {"notes": "Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary... | Affected: Mozilla / Firefox, Thunderbird, SeaMonkey | CVSS: 4.3 (MEDIUM) | EPSS: 0.02288 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1308", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1308"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1308"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary...", "cve_id": "CVE-2009-1308", "vendor": "Mozilla", "ghsa_id": null, "product": "Firefox, Thunderbird, SeaMonkey", "added_date": "2009-04-22T18:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.02288, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.82576, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1308", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c24ba040-63b6-4270-8898-8b229d934311", "vulnerability": {"vulnId": "CVE-2009-0556", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-04-03T20:00:00+02:00"}, "gcve": {"object_uuid": "c24ba040-63b6-4270-8898-8b229d934311", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-04-03T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-04-03T18:00:00+00:00"}, "scope": {"notes": "Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute... | Affected: Microsoft / Office PowerPoint | CVSS: 8.8 (HIGH) | EPSS: 0.67312 | Used in malware: unknown | Listed 6269 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-0556", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0556"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0556"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute...", "cve_id": "CVE-2009-0556", "vendor": "Microsoft", "ghsa_id": null, "product": "Office PowerPoint", "added_date": "2009-04-03T18:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.67312, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99286, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0556", "ahead_of_cisa_kev": {"unit": "day", "count": 6269}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "c26eaa95-2a45-47cc-bff5-f5c0890ab53a", "vulnerability": {"vulnId": "CVE-2009-1054", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-03-24T15:00:00+01:00"}, "gcve": {"object_uuid": "c26eaa95-2a45-47cc-bff5-f5c0890ab53a", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-03-24T14:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-03-24T14:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to... | Affected: JustSystems / Ichitaro | CVSS: 9.3 (HIGH) | EPSS: 0.03909 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-1054", "url": "https://www.cve.org/CVERecord?id=CVE-2009-1054"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-1054"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to...", "cve_id": "CVE-2009-1054", "vendor": "JustSystems", "ghsa_id": null, "product": "Ichitaro", "added_date": "2009-03-24T14:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.03909, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-1054", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ec6fc9a3-81e7-4954-b5de-9282e0569840", "vulnerability": {"vulnId": "CVE-2009-0238", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-02-25T17:00:00+01:00"}, "gcve": {"object_uuid": "ec6fc9a3-81e7-4954-b5de-9282e0569840", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-02-25T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-02-25T16:00:00+00:00"}, "scope": {"notes": "Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word,... | Affected: Microsoft / Office Excel | CVSS: 8.8 (HIGH) | EPSS: 0.43212 | Used in malware: unknown | Listed 6306 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2009-0238", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0238"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0238"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word,...", "cve_id": "CVE-2009-0238", "vendor": "Microsoft", "ghsa_id": null, "product": "Office Excel", "added_date": "2009-02-25T16:00:00.000Z", "cvss_score": 8.8, "epss_score": 0.43212, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98687, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0238", "ahead_of_cisa_kev": {"unit": "day", "count": 6306}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "83fe4ff1-6017-408d-911b-161789410397", "vulnerability": {"vulnId": "CVE-2009-0658", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2009-02-20T20:00:00+01:00"}, "gcve": {"object_uuid": "83fe4ff1-6017-408d-911b-161789410397", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2009-02-20T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2009-02-20T19:00:00+00:00"}, "scope": {"notes": "Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF... | Affected: Adobe / Reader | CVSS: 7.8 (HIGH) | EPSS: 0.87832 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2009-0658", "url": "https://www.cve.org/CVERecord?id=CVE-2009-0658"}, {"id": "previdian", "url": "https://previdian.com/CVE-2009-0658"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF...", "cve_id": "CVE-2009-0658", "vendor": "Adobe", "ghsa_id": null, "product": "Reader", "added_date": "2009-02-20T19:00:00.000Z", "cvss_score": 7.8, "epss_score": 0.87832, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99759, "used_in_malware": "unknown", "vulnerability_id": "CVE-2009-0658", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e2dcb004-0aa9-4e42-bdfb-b5fee9a35161", "vulnerability": {"vulnId": "CVE-2008-4844", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-12-11T16:00:00+01:00"}, "gcve": {"object_uuid": "e2dcb004-0aa9-4e42-bdfb-b5fee9a35161", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-12-11T15:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-12-11T15:00:00+00:00"}, "scope": {"notes": "Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1,... | Affected: Microsoft / Internet Explorer | CVSS: 9.3 (HIGH) | EPSS: 0.66513 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-4844", "url": "https://www.cve.org/CVERecord?id=CVE-2008-4844"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-4844"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1,...", "cve_id": "CVE-2008-4844", "vendor": "Microsoft", "ghsa_id": null, "product": "Internet Explorer", "added_date": "2008-12-11T15:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.66513, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99265, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-4844", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "ed5f4f6c-f0af-4da8-9395-57e404d8d745", "vulnerability": {"vulnId": "CVE-2008-4841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-12-10T14:33:00+01:00"}, "gcve": {"object_uuid": "ed5f4f6c-f0af-4da8-9395-57e404d8d745", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-12-10T13:33:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-12-10T13:33:00+00:00"}, "scope": {"notes": "The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute... | Affected: Microsoft / Windows | CVSS: 9.3 (HIGH) | EPSS: 0.4303 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-4841", "url": "https://www.cve.org/CVERecord?id=CVE-2008-4841"}, {"id": "GHSA-8XQ3-88JM-PH6C", "url": "https://github.com/advisories/GHSA-8XQ3-88JM-PH6C"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-4841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute...", "cve_id": "CVE-2008-4841", "vendor": "Microsoft", "ghsa_id": "GHSA-8XQ3-88JM-PH6C", "product": "Windows", "added_date": "2008-12-10T13:33:00.000Z", "cvss_score": 9.3, "epss_score": 0.4303, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98683, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-4841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "426336a1-ab7c-4e1f-93e6-102459f5b3d2", "vulnerability": {"vulnId": "CVE-2008-5227", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-11-26T00:00:00+01:00"}, "gcve": {"object_uuid": "426336a1-ab7c-4e1f-93e6-102459f5b3d2", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-11-25T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-11-25T23:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in PHPCow allows remote attackers to execute arbitrary code via unknown vectors, related to a \"file inclusion... | Affected: PHPCow / PHPCow | CVSS: 10.0 (HIGH) | EPSS: 0.04686 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-5227", "url": "https://www.cve.org/CVERecord?id=CVE-2008-5227"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-5227"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in PHPCow allows remote attackers to execute arbitrary code via unknown vectors, related to a \"file inclusion...", "cve_id": "CVE-2008-5227", "vendor": "PHPCow", "ghsa_id": null, "product": "PHPCow", "added_date": "2008-11-25T23:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.04686, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91498, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-5227", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "61271d65-0d65-4926-ab24-9d1b96a095c9", "vulnerability": {"vulnId": "CVE-2008-4250", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-10-23T23:00:00+02:00"}, "gcve": {"object_uuid": "61271d65-0d65-4926-ab24-9d1b96a095c9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-10-23T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-10-23T21:00:00+00:00"}, "scope": {"notes": "The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows... | Affected: Microsoft / Windows | CVSS: 9.8 (CRITICAL) | EPSS: 0.98751 | Used in malware: unknown | Listed 6431 days ahead of CISA KEV | Not yet in CISA KEV: False"}, "references": [{"id": "CVE-2008-4250", "url": "https://www.cve.org/CVERecord?id=CVE-2008-4250"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-4250"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows...", "cve_id": "CVE-2008-4250", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows", "added_date": "2008-10-23T21:00:00.000Z", "cvss_score": 9.8, "epss_score": 0.98751, "previous_ids": [], "cvss_severity": "CRITICAL", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99925, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-4250", "ahead_of_cisa_kev": {"unit": "day", "count": 6431}, "not_yet_in_cisa_kev": false}}]}
{"uuid": "03c45373-6545-4903-8b3c-de87bdcb51cc", "vulnerability": {"vulnId": "CVE-2008-3919", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-09-04T20:00:00+02:00"}, "gcve": {"object_uuid": "03c45373-6545-4903-8b3c-de87bdcb51cc", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-09-04T18:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-09-04T18:00:00+00:00"}, "scope": {"notes": "Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document,... | Affected: JustSystems / Ichitaro | CVSS: 9.3 (HIGH) | EPSS: 0.03909 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-3919", "url": "https://www.cve.org/CVERecord?id=CVE-2008-3919"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-3919"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document,...", "cve_id": "CVE-2008-3919", "vendor": "JustSystems", "ghsa_id": null, "product": "Ichitaro", "added_date": "2008-09-04T18:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.03909, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.89961, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-3919", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "49fe4a8a-d780-43ab-8067-ec7dcf16dc97", "vulnerability": {"vulnId": "CVE-2008-3873", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-08-29T19:00:00+02:00"}, "gcve": {"object_uuid": "49fe4a8a-d780-43ab-8067-ec7dcf16dc97", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-08-29T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-08-29T17:00:00+00:00"}, "scope": {"notes": "The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a... | Affected: Adobe / Flash Player | CVSS: 4.3 (MEDIUM) | EPSS: 0.15749 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-3873", "url": "https://www.cve.org/CVERecord?id=CVE-2008-3873"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-3873"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a...", "cve_id": "CVE-2008-3873", "vendor": "Adobe", "ghsa_id": null, "product": "Flash Player", "added_date": "2008-08-29T17:00:00.000Z", "cvss_score": 4.3, "epss_score": 0.15749, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.96768, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-3873", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "4c393a8c-b752-494b-aa41-c62e4ae49c67", "vulnerability": {"vulnId": "CVE-2008-3704", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-08-18T21:00:00+02:00"}, "gcve": {"object_uuid": "4c393a8c-b752-494b-aa41-c62e4ae49c67", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-08-18T19:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-08-18T19:00:00+00:00"}, "scope": {"notes": "Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft... | Affected: Microsoft / Visual Studio | CVSS: 9.3 (HIGH) | EPSS: 0.55917 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-3704", "url": "https://www.cve.org/CVERecord?id=CVE-2008-3704"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-3704"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft...", "cve_id": "CVE-2008-3704", "vendor": "Microsoft", "ghsa_id": null, "product": "Visual Studio", "added_date": "2008-08-18T19:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.55917, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.99019, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-3704", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "049b9803-b597-4695-bf2a-a3a6abc9787b", "vulnerability": {"vulnId": "CVE-2008-3648", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-08-13T01:00:00+02:00"}, "gcve": {"object_uuid": "049b9803-b597-4695-bf2a-a3a6abc9787b", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-08-12T23:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-08-12T23:00:00+00:00"}, "scope": {"notes": "nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone... | Affected: Microsoft / Windows XP SP2 | CVSS: 9.3 (HIGH) | EPSS: 0.21968 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-3648", "url": "https://www.cve.org/CVERecord?id=CVE-2008-3648"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-3648"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone...", "cve_id": "CVE-2008-3648", "vendor": "Microsoft", "ghsa_id": null, "product": "Windows XP SP2", "added_date": "2008-08-12T23:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.21968, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.97592, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-3648", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c7925bf3-7747-40f1-a985-2d933d79301f", "vulnerability": {"vulnId": "CVE-2008-2244", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-07-10T00:00:00+02:00"}, "gcve": {"object_uuid": "c7925bf3-7747-40f1-a985-2d933d79301f", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-07-09T22:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-07-09T22:00:00+00:00"}, "scope": {"notes": "Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the... | Affected: Microsoft / Office Word 2002 SP3 | CVSS: 9.3 (HIGH) | EPSS: 0.32139 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-2244", "url": "https://www.cve.org/CVERecord?id=CVE-2008-2244"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-2244"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the...", "cve_id": "CVE-2008-2244", "vendor": "Microsoft", "ghsa_id": null, "product": "Office Word 2002 SP3", "added_date": "2008-07-09T22:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.32139, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.98268, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-2244", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "15a33248-4e84-4c18-9bf4-b2a1215e1ff1", "vulnerability": {"vulnId": "CVE-2008-1841", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-04-16T19:00:00+02:00"}, "gcve": {"object_uuid": "15a33248-4e84-4c18-9bf4-b2a1215e1ff1", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-04-16T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-04-16T17:00:00+00:00"}, "scope": {"notes": "SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier... | Affected: Coppermine / Photo Gallery | CVSS: 6.8 (MEDIUM) | EPSS: 0.01858 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-1841", "url": "https://www.cve.org/CVERecord?id=CVE-2008-1841"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-1841"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier...", "cve_id": "CVE-2008-1841", "vendor": "Coppermine", "ghsa_id": null, "product": "Photo Gallery", "added_date": "2008-04-16T17:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.01858, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.78448, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-1841", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "b39b3c93-fa0d-4e23-b886-18e906a57164", "vulnerability": {"vulnId": "CVE-2008-1092", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-03-25T17:00:00+01:00"}, "gcve": {"object_uuid": "b39b3c93-fa0d-4e23-b886-18e906a57164", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-03-25T16:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-03-25T16:00:00+00:00"}, "scope": {"notes": "Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted... | Affected: Microsoft / Jet Database Engine | CVSS: 9.3 (HIGH) | EPSS: 0.25877 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-1092", "url": "https://www.cve.org/CVERecord?id=CVE-2008-1092"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-1092"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted...", "cve_id": "CVE-2008-1092", "vendor": "Microsoft", "ghsa_id": null, "product": "Jet Database Engine", "added_date": "2008-03-25T16:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.25877, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.9792, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-1092", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "e1adb1ab-68b4-441c-969a-e5f815769353", "vulnerability": {"vulnId": "CVE-2008-0647", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2008-02-07T21:00:00+01:00"}, "gcve": {"object_uuid": "e1adb1ab-68b4-441c-969a-e5f815769353", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2008-02-07T20:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2008-02-07T20:00:00+00:00"}, "scope": {"notes": "Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld... | Affected: Ourgame / GLWorld | CVSS: 10.0 (HIGH) | EPSS: 0.073 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2008-0647", "url": "https://www.cve.org/CVERecord?id=CVE-2008-0647"}, {"id": "previdian", "url": "https://previdian.com/CVE-2008-0647"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld...", "cve_id": "CVE-2008-0647", "vendor": "Ourgame", "ghsa_id": null, "product": "GLWorld", "added_date": "2008-02-07T20:00:00.000Z", "cvss_score": 10.0, "epss_score": 0.073, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.94184, "used_in_malware": "unknown", "vulnerability_id": "CVE-2008-0647", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "473935f5-d110-44c3-933e-1f55670b417d", "vulnerability": {"vulnId": "CVE-2007-6436", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2007-12-18T21:00:00+01:00"}, "gcve": {"object_uuid": "473935f5-d110-44c3-933e-1f55670b417d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2007-12-18T20:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2007-12-18T20:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in JSGCI.DLL in JustSystems Ichitaro 2005, 2006, and 2007 allows user-assisted remote attackers to execute arbitrary... | Affected: JustSystems / Ichitaro | CVSS: 9.3 (HIGH) | EPSS: 0.04093 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2007-6436", "url": "https://www.cve.org/CVERecord?id=CVE-2007-6436"}, {"id": "previdian", "url": "https://previdian.com/CVE-2007-6436"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in JSGCI.DLL in JustSystems Ichitaro 2005, 2006, and 2007 allows user-assisted remote attackers to execute arbitrary...", "cve_id": "CVE-2007-6436", "vendor": "JustSystems", "ghsa_id": null, "product": "Ichitaro", "added_date": "2007-12-18T20:00:00.000Z", "cvss_score": 9.3, "epss_score": 0.04093, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.90416, "used_in_malware": "unknown", "vulnerability_id": "CVE-2007-6436", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "c37e2dbd-4ea0-494f-a69e-ef6cfa409a3d", "vulnerability": {"vulnId": "CVE-2007-5807", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2007-11-05T18:00:00+01:00"}, "gcve": {"object_uuid": "c37e2dbd-4ea0-494f-a69e-ef6cfa409a3d", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2007-11-05T17:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2007-11-05T17:00:00+00:00"}, "scope": {"notes": "Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via... | Affected: SSReader / Ultra Star Reader ActiveX control | CVSS: 6.8 (MEDIUM) | EPSS: 0.0284 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2007-5807", "url": "https://www.cve.org/CVERecord?id=CVE-2007-5807"}, {"id": "previdian", "url": "https://previdian.com/CVE-2007-5807"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via...", "cve_id": "CVE-2007-5807", "vendor": "SSReader", "ghsa_id": null, "product": "Ultra Star Reader ActiveX control", "added_date": "2007-11-05T17:00:00.000Z", "cvss_score": 6.8, "epss_score": 0.0284, "previous_ids": [], "cvss_severity": "MEDIUM", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.86173, "used_in_malware": "unknown", "vulnerability_id": "CVE-2007-5807", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "6b617ef1-fefc-4e63-a381-c1c117dc80d9", "vulnerability": {"vulnId": "CVE-2007-5722", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2007-10-30T22:00:00+01:00"}, "gcve": {"object_uuid": "6b617ef1-fefc-4e63-a381-c1c117dc80d9", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2007-10-30T21:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2007-10-30T21:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly... | Affected: Ourgame / GLWorld | CVSS: 7.5 (HIGH) | EPSS: 0.11695 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2007-5722", "url": "https://www.cve.org/CVERecord?id=CVE-2007-5722"}, {"id": "previdian", "url": "https://previdian.com/CVE-2007-5722"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly...", "cve_id": "CVE-2007-5722", "vendor": "Ourgame", "ghsa_id": null, "product": "GLWorld", "added_date": "2007-10-30T21:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.11695, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.95943, "used_in_malware": "unknown", "vulnerability_id": "CVE-2007-5722", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
{"uuid": "100a532e-f06b-45d8-90ac-29bd97078ad6", "vulnerability": {"vulnId": "CVE-2006-4326", "altId": []}, "status": {"exploited": true, "status_reason": "confirmed", "status_updated_at": "2006-08-24T03:00:00+02:00"}, "gcve": {"object_uuid": "100a532e-f06b-45d8-90ac-29bd97078ad6", "origin_uuid": "caeb2787-0d58-4236-9039-7c86c3e566f3"}, "characteristics": {}, "timestamps": {"asserted_at": "2006-08-24T01:00:00+00:00", "recorded_at": "2026-10-02T07:08:31+00:00", "first_seen_at": "2006-08-24T01:00:00+00:00"}, "scope": {"notes": "Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and... | Affected: Justsystem / Ichitaro | CVSS: 7.5 (HIGH) | EPSS: 0.04564 | Used in malware: unknown | Not yet in CISA KEV: True"}, "references": [{"id": "CVE-2006-4326", "url": "https://www.cve.org/CVERecord?id=CVE-2006-4326"}, {"id": "previdian", "url": "https://previdian.com/CVE-2006-4326"}], "evidence": [{"source": "previdian", "type": "public_report", "signal": "successful_exploitation", "confidence": 0.7, "details": {"feed": "Previdian (previdian.com)", "title": "Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and...", "cve_id": "CVE-2006-4326", "vendor": "Justsystem", "ghsa_id": null, "product": "Ichitaro", "added_date": "2006-08-24T01:00:00.000Z", "cvss_score": 7.5, "epss_score": 0.04564, "previous_ids": [], "cvss_severity": "HIGH", "virtual_patch": false, "cvss_estimated": false, "epss_percentile": 0.91311, "used_in_malware": "unknown", "vulnerability_id": "CVE-2006-4326", "ahead_of_cisa_kev": null, "not_yet_in_cisa_kev": true}}]}
