{"meta":{"origin":"scheduled-collector","collectedAt":"2026-10-06T16:07:54.227Z","kev":{"catalogVersion":"2026.10.04","dateReleased":"2026-10-04T18:52:56.0635Z","count":1734},"epssDate":"2026-10-05","recent":{"from":"2026-10-02","to":"2026-10-06","count":9}},"entries":[{"id":"CVE-2026-88779","kev":true,"vendor":"Citrix","product":"NetScaler","name":"Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","desc":"Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.","added":"2026-10-04","due":"2026-10-07","ransomware":false,"epss":0.00534,"pct":0.43126,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"source":"50a63c94-1ea7-4568-8c11-eb79e7c5a2b5","type":"Secondary","version":"4.0","score":8.7,"severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"cwes":["CWE-119"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697174","https://community.citrix.com/techzone-blogs/110_security-updates/understanding-and-addressing-cve-2026-88779-in-citrix-netscaler-adc-and-citrix-netscaler-gateway/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-88779"],"published":"2026-10-04T04:16:43.680Z","modified":"2026-10-05T13:35:24.663Z"},{"id":"CVE-2026-102490","kev":true,"vendor":"Zammad GmbH","product":"Zammad","name":"Zammad GmbH Zammad Improper Privilege Management Vulnerability","desc":"Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.","added":"2026-10-02","due":"2026-10-05","ransomware":false,"epss":0.00629,"pct":0.48354,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"source":"csirt@divd.nl","type":"Secondary","version":"4.0","score":9.4,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X"}],"cwes":["CWE-269"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102490"],"published":"2026-09-30T17:16:40.707Z","modified":"2026-10-03T04:18:00.460Z"},{"id":"CVE-2026-102489","kev":true,"vendor":"Zammad GmbH","product":"Zammad","name":"Zammad GmbH Zammad Session Fixation Vulnerability","desc":"Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.","added":"2026-10-02","due":"2026-10-05","ransomware":false,"epss":0.01396,"pct":0.71474,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"source":"csirt@divd.nl","type":"Secondary","version":"4.0","score":9.4,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:X"}],"cwes":["CWE-384"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://zammad.com/en/product/releases/","https://community.zammad.org/t/take-care-local-privilege-escalation-cve-2026-102490-is-reported-as-being-actively-exploited/21297/2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-102489"],"published":"2026-09-30T17:16:40.550Z","modified":"2026-10-03T04:17:56.693Z"},{"id":"CVE-2026-104286","kev":true,"vendor":"Fortinet","product":"FortiMail","name":"Fortinet FortiMail Path Traversal Vulnerability","desc":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.","added":"2026-10-01","due":"2026-10-04","ransomware":false,"epss":0.02201,"pct":0.81917,"cvss":[{"source":"psirt@fortinet.com","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"cwes":["CWE-22","CWE-158"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://fortiguard.fortinet.com/psirt/FG-IR-26-175","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-104286"],"published":"2026-10-01T20:17:24.010Z","modified":"2026-10-02T12:35:33.990Z"},{"id":"CVE-2026-76504","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","name":"Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability","desc":"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.","added":"2026-09-30","due":"2026-10-03","ransomware":false,"epss":0.01575,"pct":0.74601,"cvss":[{"source":"psirt@cisco.com","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"cwes":["CWE-177"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-76504"],"published":"2026-09-30T13:17:20.247Z","modified":"2026-10-03T00:16:39.140Z"},{"id":"CVE-2026-86950","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Out-of-Bounds Write Vulnerability","desc":"Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.","added":"2026-09-29","due":"2026-10-02","ransomware":false,"epss":0.01242,"pct":0.68161,"cvss":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"cwes":["CWE-787"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://support.apple.com/en-us/149226","https://support.apple.com/en-us/149228","https://support.apple.com/en-us/149229","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-86950"],"published":"2026-09-28T20:17:11.193Z","modified":"2026-10-01T18:17:28.430Z"},{"id":"CVE-2026-88772","kev":true,"vendor":"Citrix","product":"NetScaler","name":"Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","desc":"Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service","added":"2026-09-27","due":"2026-09-30","ransomware":false,"epss":0.01301,"pct":0.69477,"cvss":[],"cwes":["CWE-119"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778","https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-88772"]},{"id":"CVE-2026-88771","kev":true,"vendor":"Citrix","product":"NetScaler","name":"Citrix NetScaler Improper Input Validation Vulnerability","desc":"Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.","added":"2026-09-27","due":"2026-09-30","ransomware":false,"epss":0.01083,"pct":0.64033,"cvss":[],"cwes":["CWE-119"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778","https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096","https://support.citrix.com/external/article/CTX694799/steps-to-take-if-netscaler-adc-is-suspec.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-88772"]},{"id":"CVE-2026-67279","kev":true,"vendor":"MikroTik","product":"RouterOS","name":"Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability","desc":"Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.","added":"2026-09-25","due":"2026-09-28","ransomware":false,"epss":0.01027,"pct":0.6239,"cvss":[],"cwes":["CWE-841"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://mikrotik.com/supportsec/september-2026-vulnerability/?utm_source=chatgpt.com","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-67279"]},{"id":"CVE-2026-65660","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Code Injection Vulnerability","desc":"Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.","added":"2026-09-25","due":"2026-09-28","ransomware":false,"epss":0.02101,"pct":0.81067,"cvss":[],"cwes":["CWE-94"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-65660"]},{"id":"CVE-2026-87902","kev":true,"vendor":"WordPress","product":"Core","name":"WordPress Core Remote File Inclusion Vulnerability","desc":"WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.","added":"2026-09-25","due":"2026-09-28","ransomware":false,"epss":0.46117,"pct":0.98777,"cvss":[],"cwes":["CWE-98"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-87902"]},{"id":"CVE-2026-5430","kev":true,"vendor":"WSO2","product":"Multiple Products","name":"WSO2 Multiple Products Path Traversal Vulnerability","desc":"WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.","added":"2026-09-24","due":"2026-09-27","ransomware":false,"epss":0.00588,"pct":0.46265,"cvss":[],"cwes":["CWE-347"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-5430"]},{"id":"CVE-2026-71362","kev":true,"vendor":"Adobe","product":"Commerce and Magento","name":"Adobe Commerce and Magento Incorrect Authorization Vulnerability","desc":"Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.","added":"2026-09-24","due":"2026-09-27","ransomware":false,"epss":0.87507,"pct":0.99755,"cvss":[],"cwes":["CWE-863"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://helpx.adobe.com/security/products/magento/apsb26-92.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-71362"]},{"id":"CVE-2026-93952","kev":true,"vendor":"Arista","product":"VeloCloud Orchestrator","name":"Arista VeloCloud Orchestrator Improper Input Validation Vulnerability","desc":"Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.","added":"2026-09-22","due":"2026-09-25","ransomware":false,"epss":0.01062,"pct":0.63411,"cvss":[],"cwes":["CWE-20"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-93952"]},{"id":"CVE-2026-94127","kev":true,"vendor":"F5","product":"BIG-IP APM","name":"F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability","desc":"F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.","added":"2026-09-22","due":"2026-09-25","ransomware":false,"epss":0.02226,"pct":0.82127,"cvss":[],"cwes":["CWE-122"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://my.f5.com/manage/s/article/K000162605","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-94127"]},{"id":"CVE-2026-93616","kev":true,"vendor":"Check Point","product":"Multiple Products","name":"Check Point Multiple Products Path Traversal Vulnerability","desc":"Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.","added":"2026-09-22","due":"2026-09-25","ransomware":false,"epss":0.19654,"pct":0.97323,"cvss":[],"cwes":["CWE-22"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://support.checkpoint.com/results/sk/sk1000171/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-93616"]},{"id":"CVE-2026-85102","kev":true,"vendor":"Check Point","product":"Multiple Products","name":"Check Point Multiple Products Improper Certificate Validation Vulnerability","desc":"Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","added":"2026-09-22","due":"2026-09-25","ransomware":false,"epss":0.07546,"pct":0.9434,"cvss":[],"cwes":["CWE-295"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://support.checkpoint.com/results/sk/sk1000117","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-85102"]},{"id":"CVE-2026-7273","kev":true,"vendor":"Zyxel","product":"GS1900 Series Switches","name":"Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability","desc":"Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.","added":"2026-09-21","due":"2026-09-24","ransomware":false,"epss":0.02501,"pct":0.8417,"cvss":[],"cwes":["CWE-121"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-7273"]},{"id":"CVE-2025-39964","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Race Condition Vulnerability","desc":"Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.","added":"2026-09-18","due":"2026-09-21","ransomware":false,"epss":0.01276,"pct":0.68944,"cvss":[],"cwes":["CWE-362"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce","https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9","https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8","https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84","https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d","https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042","https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2025-39964"]},{"id":"CVE-2026-53266","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Out-of-Bounds Write Vulnerability","desc":"Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.","added":"2026-09-18","due":"2026-09-21","ransomware":false,"epss":0.00827,"pct":0.55998,"cvss":[],"cwes":["CWE-787"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://git.kernel.org/stable/c/bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87","https://git.kernel.org/stable/c/76280b78cc9f23bdc6438e10ad6dff148ef8375b","https://git.kernel.org/stable/c/b7e91939ba9be805a62a257fa4e227dffbb88fa0","https://git.kernel.org/stable/c/afd64b59c3de9bbbdd3759e834fdc55cda716e0b","https://git.kernel.org/stable/c/153ea96c806aea395daba907a4f88480b6ad5093","https://git.kernel.org/stable/c/b18675263db1147c8e1cab625400c13a0d87bd2d","https://git.kernel.org/stable/c/c9b5ff59feffb92a147a84a5aa28acd2cb8ff4c5","https://git.kernel.org/stable/c/67ba971ae02514d85818fe0c32549ab4bfa3bf49","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-53266"]},{"id":"CVE-2025-39682","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability","desc":"Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.","added":"2026-09-18","due":"2026-09-21","ransomware":false,"epss":0.0288,"pct":0.86386,"cvss":[],"cwes":["CWE-754"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f","https://git.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677","https://git.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9","https://git.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e","https://git.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2025-39682"]},{"id":"CVE-2026-58704","kev":true,"vendor":"Google","product":"Pixel","name":"Google Pixel Improper Authorization Vulnerability","desc":"Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.","added":"2026-09-16","due":"2026-09-19","ransomware":false,"epss":0.00591,"pct":0.46402,"cvss":[],"cwes":["CWE-693"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-58704"]},{"id":"CVE-2026-76460","kev":true,"vendor":"Cisco","product":"Identity Services Engine","name":"Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability","desc":"Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.","added":"2026-09-16","due":"2026-09-19","ransomware":false,"epss":0.14026,"pct":0.96457,"cvss":[],"cwes":["CWE-648"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-76460"]},{"id":"CVE-2026-87886","kev":true,"vendor":"Acronis","product":"Backup","name":"Acronis Backup Incorrect Default Permissions Vulnerability","desc":"Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.","added":"2026-09-16","due":"2026-09-19","ransomware":false,"epss":0.00233,"pct":0.12897,"cvss":[],"cwes":["CWE-276"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://security-advisory.acronis.com/advisories/SEC-10986","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-87886"]},{"id":"CVE-2026-76461","kev":true,"vendor":"Cisco","product":"Secure Email Gateway","name":"Cisco Secure Email Gateway SQL Injection Vulnerability","desc":"Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.","added":"2026-09-14","due":"2026-09-17","ransomware":false,"epss":0.28269,"pct":0.9807,"cvss":[],"cwes":["CWE-89"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-76461"]},{"id":"CVE-2026-84869","kev":true,"vendor":"ConnectWise","product":"ScreenConnect","name":"ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability","desc":"ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.","added":"2026-09-11","due":"2026-09-14","ransomware":false,"epss":0.00924,"pct":0.59076,"cvss":[],"cwes":["CWE-269","CWE-862"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-84869"]},{"id":"CVE-2026-42016","kev":true,"vendor":"JFrog","product":"Artifactory","name":"JFrog Artifactory Incorrect Authorization Vulnerability","desc":"JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.","added":"2026-09-11","due":"2026-09-25","ransomware":false,"epss":0.08643,"pct":0.94965,"cvss":[],"cwes":["CWE-863"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://docs.jfrog.com/releases/docs/jfrog-security-advisories","https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-42016"]},{"id":"CVE-2026-42018","kev":true,"vendor":"JFrog","product":"Artifactory","name":"JFrog Artifactory Improper Authentication Vulnerability","desc":"JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.","added":"2026-09-11","due":"2026-09-25","ransomware":false,"epss":0.09805,"pct":0.95417,"cvss":[],"cwes":["CWE-287"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://docs.jfrog.com/releases/docs/jfrog-security-advisories","https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-42018"]},{"id":"CVE-2026-85706","kev":true,"vendor":"GitLab","product":"Community Edition and Enterprise Edition","name":"GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability","desc":"GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.","added":"2026-09-11","due":"2026-09-14","ransomware":false,"epss":0.92956,"pct":0.9983,"cvss":[],"cwes":["CWE-35"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-85706"]},{"id":"CVE-2026-86060","kev":true,"vendor":"MikroTik","product":"RouterOS","name":"MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability","desc":"MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.","added":"2026-09-10","due":"2026-09-13","ransomware":false,"epss":0.06392,"pct":0.9347,"cvss":[],"cwes":["CWE-88"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://mikrotik.com/supportsec/september-2026-vulnerability","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-86060"]},{"id":"CVE-2026-67277","kev":true,"vendor":"MikroTik","product":"RouterOS","name":"MikroTik RouterOS Missing Authentication for Critical Function Vulnerability","desc":"MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.","added":"2026-09-10","due":"2026-09-13","ransomware":false,"epss":0.0156,"pct":0.74384,"cvss":[],"cwes":["CWE-306"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://mikrotik.com/supportsec/september-2026-vulnerability/","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-67277"]},{"id":"CVE-2026-19490","kev":true,"vendor":"Citrix","product":"NetScaler","name":"Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability","desc":"Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.","added":"2026-09-09","due":"2026-09-12","ransomware":false,"epss":0.23158,"pct":0.97709,"cvss":[],"cwes":["CWE-288"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://support.citrix.com/external/article/CTX696939/netscaler-adc-and-netscaler-gateway-secu.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-19490"]},{"id":"CVE-2025-25249","kev":true,"vendor":"Fortinet","product":"Multiple Products","name":"Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","desc":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.","added":"2026-09-09","due":"2026-09-12","ransomware":false,"epss":0.03859,"pct":0.89856,"cvss":[],"cwes":["CWE-122","CWE-787"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://fortiguard.fortinet.com/psirt/FG-IR-25-084","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2025-25249"]},{"id":"CVE-2026-87491","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out of Bounds Write Vulnerability","desc":"Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.","added":"2026-09-09","due":"2026-09-23","ransomware":false,"epss":0.03142,"pct":0.87485,"cvss":[],"cwes":["CWE-787"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-87491"]},{"id":"CVE-2026-20079","kev":true,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management","name":"Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability","desc":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.","added":"2026-09-09","due":"2026-09-12","ransomware":false,"epss":0.8818,"pct":0.99765,"cvss":[],"cwes":["CWE-288"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-20079"]},{"id":"CVE-2026-75650","kev":true,"vendor":"Adobe","product":"Commerce and Magento","name":"Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability","desc":"Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.","added":"2026-09-08","due":"2026-09-11","ransomware":false,"epss":0.03949,"pct":0.90102,"cvss":[],"cwes":["CWE-1336"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://helpx.adobe.com/security/products/magento/apsb26-146.html","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-75650"]},{"id":"CVE-2026-81963","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Link Following Vulnerability","desc":"Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.","added":"2026-09-08","due":"2026-09-22","ransomware":false,"epss":0.00393,"pct":0.31187,"cvss":[],"cwes":["CWE-59","CWE-284"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-81963","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-81963"]},{"id":"CVE-2026-86218","kev":true,"vendor":"N-able","product":"N-central","name":"N-able N-central Static Code Injection Vulnerability","desc":"N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.","added":"2026-09-08","due":"2026-09-11","ransomware":false,"epss":0.12928,"pct":0.96206,"cvss":[],"cwes":["CWE-96"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/","https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-86218"]},{"id":"CVE-2026-85880","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Heap-Based Buffer Overflow Vulnerability","desc":"Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.","added":"2026-09-08","due":"2026-09-22","ransomware":false,"epss":0.03616,"pct":0.89156,"cvss":[],"cwes":["CWE-122","CWE-908"],"action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","refs":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85880","https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk","https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk","https://nvd.nist.gov/vuln/detail/CVE-2026-85880"]},{"id":"CVE-2026-85046","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2026-09-04","due":"2026-09-18","ransomware":false,"epss":0.48881,"pct":0.98847,"cvss":[]},{"id":"CVE-2026-59822","kev":true,"vendor":"BerriAI","product":"LiteLLM","name":"BerriAI LiteLLM Improper Authentication Vulnerability","added":"2026-09-02","due":"2026-09-16","ransomware":false,"epss":0.00836,"pct":0.56262,"cvss":[]},{"id":"CVE-2026-48710","kev":true,"vendor":"Kludex","product":"Starlette","name":"Kludex Starlette HTTP Request/Response Smuggling Vulnerability","added":"2026-09-02","due":"2026-09-16","ransomware":false,"epss":0.07056,"pct":0.9402,"cvss":[]},{"id":"CVE-2026-49869","kev":true,"vendor":"Kestra","product":"Kestra OSS","name":"Kestra OSS OS Command Injection Vulnerability","added":"2026-09-02","due":"2026-09-05","ransomware":false,"epss":0.02095,"pct":0.81006,"cvss":[]},{"id":"CVE-2026-82329","kev":true,"vendor":"JFrog","product":"Artifactory","name":"JFrog Artifactory Improper Authentication Vulnerability","added":"2026-09-02","due":"2026-09-05","ransomware":false,"epss":0.14121,"pct":0.96474,"cvss":[]},{"id":"CVE-2026-9586","kev":true,"vendor":"Sangoma","product":"Switchvox","name":"Sangoma Switchvox SQL Injection Vulnerability","added":"2026-09-02","due":"2026-09-05","ransomware":false,"epss":0.18979,"pct":0.97228,"cvss":[]},{"id":"CVE-2026-83548","kev":true,"vendor":"SonicWall","product":"SMA1000 Appliances","name":"SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability","added":"2026-09-02","due":"2026-09-05","ransomware":false,"epss":0.08757,"pct":0.95021,"cvss":[]},{"id":"CVE-2026-83549","kev":true,"vendor":"SonicWall","product":"SMA1000 Appliances","name":"SonicWall SMA1000 Appliances OS Command Injection Vulnerability","added":"2026-09-02","due":"2026-09-05","ransomware":false,"epss":0.1076,"pct":0.95712,"cvss":[]},{"id":"CVE-2026-82078","kev":true,"vendor":"PaperCut","product":"NG/MF","name":"PaperCut NG/MF Unsafe Reflection Vulnerability","added":"2026-08-31","due":"2026-09-14","ransomware":false,"epss":0.61394,"pct":0.99143,"cvss":[]},{"id":"CVE-2026-81578","kev":true,"vendor":"PaperCut","product":"NG/MF","name":"PaperCut NG/MF Missing Authentication for Critical Function Vulnerability","added":"2026-08-31","due":"2026-09-14","ransomware":false,"epss":0.84594,"pct":0.99699,"cvss":[]},{"id":"CVE-2023-49105","kev":true,"vendor":"ownCloud","product":"ownCloud","name":"ownCloud Improper Authentication Vulnerability","added":"2026-08-27","due":"2026-08-30","ransomware":false,"epss":0.42919,"pct":0.98684,"cvss":[]},{"id":"CVE-2026-53362","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Unspecified Vulnerability","added":"2026-08-27","due":"2026-08-30","ransomware":false,"epss":0.00709,"pct":0.51891,"cvss":[]},{"id":"CVE-2026-66384","kev":true,"vendor":"JFrog","product":"Artifactory","name":"JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability","added":"2026-08-27","due":"2026-09-10","ransomware":false,"epss":0.00665,"pct":0.50055,"cvss":[]},{"id":"CVE-2021-23758","kev":true,"vendor":"Ajax.NET Professional","product":"Ajax.NET Professional","name":"Ajax.NET Professional Deserialization of Untrusted Data Vulnerability","added":"2026-08-26","due":"2026-09-09","ransomware":false,"epss":0.82578,"pct":0.99659,"cvss":[]},{"id":"CVE-2015-3246","kev":true,"vendor":"Red Hat","product":"Libuser","name":"Red Hat Libuser Race Condition Vulnerability","added":"2026-08-26","due":"2026-09-09","ransomware":false,"epss":0.08434,"pct":0.94848,"cvss":[]},{"id":"CVE-2015-5287","kev":true,"vendor":"Red Hat","product":"Automatic Bug Reporting Tool","name":"Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability","added":"2026-08-26","due":"2026-09-09","ransomware":false,"epss":0.04962,"pct":0.91932,"cvss":[]},{"id":"CVE-2022-0995","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Out-of-Bounds Write Vulnerability","added":"2026-08-26","due":"2026-09-09","ransomware":false,"epss":0.08788,"pct":0.95035,"cvss":[]},{"id":"CVE-2026-8452","kev":true,"vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","name":"Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability","added":"2026-08-26","due":"2026-08-29","ransomware":false,"epss":0.01011,"pct":0.61922,"cvss":[]},{"id":"CVE-2019-1068","kev":true,"vendor":"Microsoft","product":"SQL Server","name":"Microsoft SQL Server Remote Code Execution Vulnerability","added":"2026-08-26","due":"2026-08-29","ransomware":false,"epss":0.56999,"pct":0.99045,"cvss":[]},{"id":"CVE-2026-60004","kev":true,"vendor":"Gitea","product":"Gitea","name":"Gitea Code Injection Vulnerability","added":"2026-08-25","due":"2026-08-28","ransomware":false,"epss":0.23988,"pct":0.97779,"cvss":[]},{"id":"CVE-2026-21962","kev":true,"vendor":"Oracle","product":"HTTP Server and Oracle Weblogic Server Proxy Plug-in","name":"Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability","added":"2026-08-24","due":"2026-08-27","ransomware":false,"epss":0.73192,"pct":0.99447,"cvss":[]},{"id":"CVE-2026-73570","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability","added":"2026-08-21","due":"2026-08-24","ransomware":false,"epss":0.11946,"pct":0.96006,"cvss":[]},{"id":"CVE-2026-72530","kev":true,"vendor":"TrueConf","product":"Server","name":"TrueConf Server Code Injection Vulnerability","added":"2026-08-20","due":"2026-09-03","ransomware":false,"epss":0.01686,"pct":0.76229,"cvss":[]},{"id":"CVE-2026-72529","kev":true,"vendor":"TrueConf","product":"Server","name":"TrueConf Server Missing Authentication for Critical Function Vulnerability","added":"2026-08-20","due":"2026-08-23","ransomware":false,"epss":0.01464,"pct":0.72754,"cvss":[]},{"id":"CVE-2026-64849","kev":true,"vendor":"MLflow","product":"MLflow","name":"MLflow Server-Side Request Forgery Vulnerability","added":"2026-08-19","due":"2026-09-02","ransomware":false,"epss":0.09839,"pct":0.95429,"cvss":[]},{"id":"CVE-2026-33824","kev":true,"vendor":"Microsoft","product":"Internet Key Exchange (IKE) Service Extensions","name":"Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability","added":"2026-08-18","due":"2026-08-21","ransomware":false,"epss":0.01619,"pct":0.75243,"cvss":[]},{"id":"CVE-2026-59310","kev":true,"vendor":"Broadcom","product":"VMware vCenter","name":"Broadcom VMware vCenter Path Traversal Vulnerability","added":"2026-08-18","due":"2026-08-21","ransomware":true,"epss":0.02565,"pct":0.84596,"cvss":[]},{"id":"CVE-2026-55040","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Weak Authentication Vulnerability","added":"2026-08-18","due":"2026-08-21","ransomware":false,"epss":0.69536,"pct":0.99347,"cvss":[]},{"id":"CVE-2026-65400","kev":true,"vendor":"Apple","product":"macOS","name":"Apple macOS Improper Authentication Vulnerability","added":"2026-08-18","due":"2026-08-21","ransomware":false,"epss":0.01723,"pct":0.76727,"cvss":[]},{"id":"CVE-2025-62593","kev":true,"vendor":"Ray-Project","product":"Ray","name":"Ray-Project Ray Code Injection Vulnerability","added":"2026-08-17","due":"2026-08-20","ransomware":false,"epss":0.62459,"pct":0.99167,"cvss":[]},{"id":"CVE-2026-20349","kev":true,"vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)","name":"Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability","added":"2026-08-11","due":"2026-08-14","ransomware":false,"epss":0.0101,"pct":0.61895,"cvss":[]},{"id":"CVE-2026-68820","kev":true,"vendor":"Microsoft","product":"Windows Ancillary Function Driver for WinSock","name":"Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability","added":"2026-08-11","due":"2026-08-25","ransomware":false,"epss":0.00332,"pct":0.2414,"cvss":[]},{"id":"CVE-2026-72898","kev":true,"vendor":"Metabase","product":"Metabase","name":"Metabase SQL Injection Vulnerability","added":"2026-08-11","due":"2026-08-14","ransomware":false,"epss":0.19048,"pct":0.97237,"cvss":[]},{"id":"CVE-2026-8037","kev":true,"vendor":"Progress","product":"LoadMaster","name":"Progress LoadMaster Command Injection Vulnerability","added":"2026-08-07","due":"2026-08-10","ransomware":false,"epss":0.77362,"pct":0.99546,"cvss":[]},{"id":"CVE-2026-63077","kev":true,"vendor":"JetBrains","product":"TeamCity","name":"JetBrains TeamCity Deserialization of Untrusted Data Vulnerability","added":"2026-08-05","due":"2026-08-08","ransomware":true,"epss":0.8957,"pct":0.99784,"cvss":[]},{"id":"CVE-2026-18556","kev":true,"vendor":"N-able","product":"N-central","name":"N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability","added":"2026-08-04","due":"2026-08-07","ransomware":false,"epss":0.07882,"pct":0.94547,"cvss":[]},{"id":"CVE-2026-34486","kev":true,"vendor":"Apache","product":"Tomcat","name":"Apache Tomcat Missing Encryption of Sensitive Data Vulnerability","added":"2026-08-04","due":"2026-08-07","ransomware":false,"epss":0.06561,"pct":0.93622,"cvss":[]},{"id":"CVE-2026-9198","kev":true,"vendor":"IBM","product":"Langflow","name":"IBM Langflow Code Injection Vulnerability","added":"2026-08-04","due":"2026-08-07","ransomware":false,"epss":0.28658,"pct":0.9809,"cvss":[]},{"id":"CVE-2026-18577","kev":true,"vendor":"N-able","product":"N-central","name":"N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability","added":"2026-08-03","due":"2026-08-06","ransomware":false,"epss":0.14622,"pct":0.96562,"cvss":[]},{"id":"CVE-2026-20316","kev":true,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC)","name":"Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability","added":"2026-07-29","due":"2026-08-01","ransomware":true,"epss":0.35096,"pct":0.98399,"cvss":[]},{"id":"CVE-2025-68686","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability","added":"2026-07-27","due":"2026-08-10","ransomware":false,"epss":0.29601,"pct":0.98144,"cvss":[]},{"id":"CVE-2026-16812","kev":true,"vendor":"Arista","product":"VeloCloud Orchestrator","name":"Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability","added":"2026-07-27","due":"2026-07-30","ransomware":false,"epss":0.01001,"pct":0.61556,"cvss":[]},{"id":"CVE-2026-16232","kev":true,"vendor":"Check Point","product":"SmartConsole","name":"Check Point SmartConsole Improper Authentication Vulnerability","added":"2026-07-22","due":"2026-07-25","ransomware":false,"epss":0.77972,"pct":0.99564,"cvss":[]},{"id":"CVE-2026-50522","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","added":"2026-07-22","due":"2026-07-25","ransomware":false,"epss":0.03042,"pct":0.87085,"cvss":[]},{"id":"CVE-2026-60137","kev":true,"vendor":"WordPress","product":"Core","name":"WordPress Core SQL Injection Vulnerability","added":"2026-07-21","due":"2026-08-04","ransomware":false,"epss":0.05906,"pct":0.93016,"cvss":[]},{"id":"CVE-2026-63030","kev":true,"vendor":"WordPress","product":"Core","name":"WordPress Core Interpretation Conflict Vulnerability","added":"2026-07-21","due":"2026-07-24","ransomware":false,"epss":0.10119,"pct":0.9552,"cvss":[]},{"id":"CVE-2026-0770","kev":true,"vendor":"Langflow","product":"Langflow","name":"Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability","added":"2026-07-21","due":"2026-07-24","ransomware":false,"epss":0.63013,"pct":0.9918,"cvss":[]},{"id":"CVE-2021-27137","kev":true,"vendor":"DD-WRT","product":"DD-WRT","name":"DD-WRT Stack-Based Buffer Overflow Vulnerability","added":"2026-07-21","due":"2026-07-24","ransomware":false,"epss":0.03995,"pct":0.9022,"cvss":[]},{"id":"CVE-2026-58644","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","added":"2026-07-16","due":"2026-07-19","ransomware":false,"epss":0.15873,"pct":0.96795,"cvss":[]},{"id":"CVE-2026-25089","kev":true,"vendor":"Fortinet","product":"FortiSandbox","name":"Fortinet FortiSandbox OS Command Injection Vulnerability","added":"2026-07-16","due":"2026-07-19","ransomware":false,"epss":0.76112,"pct":0.99521,"cvss":[]},{"id":"CVE-2026-39808","kev":true,"vendor":"Fortinet","product":"FortiSandbox","name":"Fortinet FortiSandbox OS Command Injection Vulnerability","added":"2026-07-16","due":"2026-07-19","ransomware":false,"epss":0.47362,"pct":0.98807,"cvss":[]},{"id":"CVE-2026-46817","kev":true,"vendor":"Oracle","product":"E-Business Suite","name":"Oracle E-Business Suite Improper Privilege Management Vulnerability","added":"2026-07-15","due":"2026-07-18","ransomware":false,"epss":0.00814,"pct":0.55564,"cvss":[]},{"id":"CVE-2023-4346","kev":true,"vendor":"KNX Association","product":"KNX Protocol Connection Authorization Option 1","name":"KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability","added":"2026-07-15","due":"2026-07-29","ransomware":false,"epss":0.01294,"pct":0.69333,"cvss":[]},{"id":"CVE-2026-56155","kev":true,"vendor":"Microsoft","product":"Active Directory Federation Services","name":"Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability","added":"2026-07-14","due":"2026-07-28","ransomware":false,"epss":0.00346,"pct":0.2588,"cvss":[]},{"id":"CVE-2026-56164","kev":true,"vendor":"Microsoft","product":"SharePoint Server","name":"Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability","added":"2026-07-14","due":"2026-07-17","ransomware":false,"epss":0.01011,"pct":0.61918,"cvss":[]},{"id":"CVE-2026-15409","kev":true,"vendor":"SonicWall","product":"SMA1000 Appliances","name":"SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability","added":"2026-07-14","due":"2026-07-17","ransomware":true,"epss":0.06795,"pct":0.93811,"cvss":[]},{"id":"CVE-2026-15410","kev":true,"vendor":"SonicWall","product":"SMA1000 Appliances","name":"SonicWall SMA1000 Appliances Code Injection Vulnerability","added":"2026-07-14","due":"2026-07-17","ransomware":true,"epss":0.11791,"pct":0.95969,"cvss":[]},{"id":"CVE-2008-4128","kev":true,"vendor":"Cisco","product":"IOS","name":"Cisco IOS Cross-Site Request Forgery Vulnerability","added":"2026-07-13","due":"2026-07-16","ransomware":false,"epss":0.33871,"pct":0.98352,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.1,"severity":"HIGH"}],"published":"2008-09-18T20:00:00.530Z","modified":"2026-09-24T12:52:19.010Z"},{"id":"CVE-2026-56291","kev":true,"vendor":"Balbooa","product":"Forms","name":"Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2026-07-10","due":"2026-07-13","ransomware":false,"epss":0.14854,"pct":0.96604,"cvss":[]},{"id":"CVE-2026-48939","kev":true,"vendor":"iCagenda","product":"iCagenda","name":"iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2026-07-10","due":"2026-07-13","ransomware":false,"epss":0.20069,"pct":0.97381,"cvss":[]},{"id":"CVE-2026-48908","kev":true,"vendor":"JoomShaper","product":"SP Page Builder","name":"JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2026-07-07","due":"2026-07-10","ransomware":false,"epss":0.88512,"pct":0.99771,"cvss":[]},{"id":"CVE-2026-55255","kev":true,"vendor":"Langflow","product":"Langflow","name":"Langflow Authorization Bypass Through User-Controlled Key Vulnerability","added":"2026-07-07","due":"2026-07-10","ransomware":false,"epss":0.00887,"pct":0.57892,"cvss":[]},{"id":"CVE-2026-56290","kev":true,"vendor":"Joomlack","product":"Page Builder","name":"Joomlack Page Builder Improper Access Control Vulnerability","added":"2026-07-07","due":"2026-07-10","ransomware":false,"epss":0.30866,"pct":0.98207,"cvss":[]},{"id":"CVE-2026-48282","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Path Traversal Vulnerability","added":"2026-07-07","due":"2026-07-10","ransomware":false,"epss":0.42388,"pct":0.98666,"cvss":[]},{"id":"CVE-2026-45659","kev":true,"vendor":"Microsoft","product":"SharePoint Server","name":"Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability","added":"2026-07-01","due":"2026-07-04","ransomware":true,"epss":0.02704,"pct":0.85456,"cvss":[]},{"id":"CVE-2026-48558","kev":true,"vendor":"SimpleHelp","product":"SimpleHelp","name":"SimpleHelp Authentication Bypass Vulnerability","added":"2026-06-29","due":"2026-07-02","ransomware":false,"epss":0.05719,"pct":0.92808,"cvss":[]},{"id":"CVE-2026-12569","kev":true,"vendor":"PTC","product":"Windchill and FlexPLM","name":"PTC Windchill and FlexPLM Improper Input Validation Vulnerability","added":"2026-06-25","due":"2026-06-28","ransomware":true,"epss":0.46049,"pct":0.98775,"cvss":[]},{"id":"CVE-2026-20230","kev":true,"vendor":"Cisco","product":"Unified Communications Manager","name":"Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability","added":"2026-06-25","due":"2026-06-28","ransomware":false,"epss":0.882,"pct":0.99766,"cvss":[]},{"id":"CVE-2025-67038","kev":true,"vendor":"Lantronix","product":"EDS5000","name":"Lantronix EDS5000 Code Injection Vulnerability","added":"2026-06-23","due":"2026-06-26","ransomware":false,"epss":0.1926,"pct":0.97266,"cvss":[]},{"id":"CVE-2026-34910","kev":true,"vendor":"Ubiquiti","product":"UniFi OS","name":"Ubiquiti UniFi OS Improper Input Validation Vulnerability","added":"2026-06-23","due":"2026-06-26","ransomware":false,"epss":0.45768,"pct":0.98767,"cvss":[]},{"id":"CVE-2026-34909","kev":true,"vendor":"Ubiquiti","product":"UniFi OS","name":"Ubiquiti UniFi OS Path Traversal Vulnerability","added":"2026-06-23","due":"2026-06-26","ransomware":false,"epss":0.01793,"pct":0.7766,"cvss":[]},{"id":"CVE-2026-34908","kev":true,"vendor":"Ubiquiti","product":"UniFi OS","name":"Ubiquiti UniFi OS Improper Access Control Vulnerability","added":"2026-06-23","due":"2026-06-26","ransomware":false,"epss":0.15207,"pct":0.96662,"cvss":[]},{"id":"CVE-2026-20253","kev":true,"vendor":"Splunk","product":"Enterprise","name":"Splunk Enterprise Missing Authentication for Critical Function Vulnerability","added":"2026-06-18","due":"2026-06-21","ransomware":false,"epss":0.96939,"pct":0.99889,"cvss":[]},{"id":"CVE-2026-48907","kev":true,"vendor":"Widget Factory","product":"Joomla Content Editor","name":"Widget Factory Joomla Content Editor Improper Access Control Vulnerability","added":"2026-06-16","due":"2026-06-19","ransomware":false,"epss":0.1619,"pct":0.96851,"cvss":[]},{"id":"CVE-2026-54420","kev":true,"vendor":"LiteSpeed","product":"cPanel Plugin","name":"LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability","added":"2026-06-15","due":"2026-06-18","ransomware":false,"epss":0.00806,"pct":0.55322,"cvss":[]},{"id":"CVE-2026-20262","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","name":"Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability","added":"2026-06-15","due":"2026-06-29","ransomware":false,"epss":0.28171,"pct":0.98063,"cvss":[]},{"id":"CVE-2026-35273","kev":true,"vendor":"Oracle","product":"PeopleSoft Enterprise PeopleTools","name":"Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability","added":"2026-06-12","due":"2026-06-15","ransomware":true,"epss":0.09444,"pct":0.95286,"cvss":[]},{"id":"CVE-2026-10520","kev":true,"vendor":"Ivanti","product":"Sentry","name":"Ivanti Sentry OS Command Injection Vulnerability","added":"2026-06-11","due":"2026-06-14","ransomware":false,"epss":0.99915,"pct":0.99968,"cvss":[]},{"id":"CVE-2026-11645","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Read and Write Vulnerability","added":"2026-06-09","due":"2026-06-23","ransomware":false,"epss":0.0244,"pct":0.8375,"cvss":[]},{"id":"CVE-2026-7473","kev":true,"vendor":"Arista","product":"Extensible Operating System","name":"Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability","added":"2026-06-09","due":"2026-06-23","ransomware":false,"epss":0.00649,"pct":0.49312,"cvss":[]},{"id":"CVE-2026-20245","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","name":"Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability","added":"2026-06-09","due":"2026-06-23","ransomware":false,"epss":0.25323,"pct":0.97888,"cvss":[]},{"id":"CVE-2026-42271","kev":true,"vendor":"BerriAI","product":"LiteLLM","name":"BerriAI LiteLLM Command Injection Vulnerability","added":"2026-06-08","due":"2026-06-22","ransomware":false,"epss":0.9257,"pct":0.99825,"cvss":[]},{"id":"CVE-2026-50751","kev":true,"vendor":"Check Point","product":"Security Gateway","name":"Check Point Security Gateway Improper Authentication Vulnerability","added":"2026-06-08","due":"2026-06-11","ransomware":true,"epss":0.06416,"pct":0.93495,"cvss":[]},{"id":"CVE-2026-28318","kev":true,"vendor":"SolarWinds","product":"Serv-U","name":"SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability","added":"2026-06-05","due":"2026-06-19","ransomware":false,"epss":0.01942,"pct":0.79448,"cvss":[]},{"id":"CVE-2026-45247","kev":true,"vendor":"Mirasvit","product":"Mirasvit Full Page Cache Warmer","name":"Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability","added":"2026-06-03","due":"2026-06-06","ransomware":false,"epss":0.02085,"pct":0.80911,"cvss":[]},{"id":"CVE-2022-0492","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Improper Authentication Vulnerability","added":"2026-06-02","due":"2026-06-05","ransomware":false,"epss":0.05528,"pct":0.92577,"cvss":[]},{"id":"CVE-2025-48595","kev":true,"vendor":"Android","product":"Framework","name":"Android Framework Integer Overflow Vulnerability","added":"2026-06-02","due":"2026-06-05","ransomware":false,"epss":0.01714,"pct":0.76609,"cvss":[]},{"id":"CVE-2024-21182","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Unspecified Vulnerability","added":"2026-06-01","due":"2026-06-04","ransomware":false,"epss":0.74162,"pct":0.99476,"cvss":[]},{"id":"CVE-2026-0257","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","added":"2026-05-29","due":"2026-06-01","ransomware":true,"epss":0.96382,"pct":0.9988,"cvss":[]},{"id":"CVE-2026-48027","kev":true,"vendor":"Nx","product":"Nx Console","name":"Nx Console Embedded Malicious Code Vulnerability","added":"2026-05-27","due":"2026-06-10","ransomware":true,"epss":0.01336,"pct":0.70243,"cvss":[]},{"id":"CVE-2026-45321","kev":true,"vendor":"TanStack","product":"TanStack","name":"TanStack Unspecified Vulnerability","added":"2026-05-27","due":"2026-06-10","ransomware":true,"epss":0.01054,"pct":0.63188,"cvss":[]},{"id":"CVE-2026-8398","kev":true,"vendor":"Daemon","product":"Daemon Tools Lite","name":"Daemon Tools Lite Embedded Malicious Code Vulnerability","added":"2026-05-27","due":"2026-05-30","ransomware":false,"epss":0.00963,"pct":0.60323,"cvss":[]},{"id":"CVE-2026-48172","kev":true,"vendor":"LiteSpeed","product":"cPanel Plugin","name":"LiteSpeed cPanel Plugin Privilege Escalation Vulnerability","added":"2026-05-26","due":"2026-05-29","ransomware":false,"epss":0.01011,"pct":0.6191,"cvss":[]},{"id":"CVE-2026-9082","kev":true,"vendor":"Drupal","product":"Core","name":"Drupal Core SQL Injection Vulnerability","added":"2026-05-22","due":"2026-05-27","ransomware":false,"epss":0.15701,"pct":0.96766,"cvss":[]},{"id":"CVE-2025-34291","kev":true,"vendor":"Langflow","product":"Langflow","name":"Langflow Origin Validation Error Vulnerability","added":"2026-05-21","due":"2026-06-04","ransomware":false,"epss":0.92808,"pct":0.99828,"cvss":[]},{"id":"CVE-2026-34926","kev":true,"vendor":"Trend Micro","product":"Apex One","name":"Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability","added":"2026-05-21","due":"2026-06-04","ransomware":false,"epss":0.00538,"pct":0.43306,"cvss":[]},{"id":"CVE-2008-4250","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Buffer Overflow Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.98751,"pct":0.99925,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":10,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2008-10-23T22:00:01.357Z","modified":"2026-06-16T22:57:29.393Z"},{"id":"CVE-2009-1537","kev":true,"vendor":"Microsoft","product":"DirectX","name":"Microsoft DirectX NULL Byte Overwrite Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.51207,"pct":0.98906,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2009-05-29T18:30:00.187Z","modified":"2026-06-16T23:07:28.827Z"},{"id":"CVE-2009-3459","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.86583,"pct":0.99735,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2009-10-13T10:30:00.577Z","modified":"2026-06-16T23:11:38.727Z"},{"id":"CVE-2010-0249","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.91939,"pct":0.99817,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2010-01-15T17:30:00.533Z","modified":"2026-06-16T23:15:47.577Z"},{"id":"CVE-2010-0806","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.82241,"pct":0.99649,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2010-03-10T22:30:01.323Z","modified":"2026-06-16T23:16:52.753Z"},{"id":"CVE-2026-41091","kev":true,"vendor":"Microsoft","product":"Defender","name":"Microsoft Defender Link Following Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.00443,"pct":0.36345,"cvss":[]},{"id":"CVE-2026-45498","kev":true,"vendor":"Microsoft","product":"Defender","name":"Microsoft Defender Denial of Service Vulnerability","added":"2026-05-20","due":"2026-06-03","ransomware":false,"epss":0.01267,"pct":0.68758,"cvss":[]},{"id":"CVE-2026-42897","kev":true,"vendor":"Microsoft","product":"Microsoft","name":"Microsoft Exchange Server Cross-Site Scripting Vulnerability","added":"2026-05-15","due":"2026-05-29","ransomware":false,"epss":0.00519,"pct":0.42127,"cvss":[]},{"id":"CVE-2026-20182","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN","name":"Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability","added":"2026-05-14","due":"2026-05-17","ransomware":false,"epss":0.91522,"pct":0.99812,"cvss":[]},{"id":"CVE-2026-42208","kev":true,"vendor":"BerriAI","product":"LiteLLM","name":"BerriAI LiteLLM SQL Injection Vulnerability","added":"2026-05-08","due":"2026-05-11","ransomware":false,"epss":0.05772,"pct":0.92868,"cvss":[]},{"id":"CVE-2026-6973","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability","added":"2026-05-07","due":"2026-05-10","ransomware":false,"epss":0.02537,"pct":0.84412,"cvss":[]},{"id":"CVE-2026-0300","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability","added":"2026-05-06","due":"2026-05-09","ransomware":false,"epss":0.31725,"pct":0.98252,"cvss":[]},{"id":"CVE-2026-31431","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability","added":"2026-05-01","due":"2026-05-15","ransomware":false,"epss":0.03437,"pct":0.88591,"cvss":[]},{"id":"CVE-2026-41940","kev":true,"vendor":"WebPros","product":"cPanel & WHM and WP2 (WordPress Squared)","name":"WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability","added":"2026-04-30","due":"2026-05-03","ransomware":true,"epss":0.98527,"pct":0.9992,"cvss":[]},{"id":"CVE-2024-1708","kev":true,"vendor":"ConnectWise","product":"ScreenConnect","name":"ConnectWise ScreenConnect Path Traversal Vulnerability","added":"2026-04-28","due":"2026-05-12","ransomware":true,"epss":0.95436,"pct":0.99869,"cvss":[]},{"id":"CVE-2026-32202","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Protection Mechanism Failure Vulnerability","added":"2026-04-28","due":"2026-05-12","ransomware":false,"epss":0.04902,"pct":0.91837,"cvss":[]},{"id":"CVE-2025-29635","kev":true,"vendor":"D-Link","product":"DIR-823X","name":"D-Link DIR-823X Command Injection Vulnerability","added":"2026-04-24","due":"2026-05-08","ransomware":false,"epss":0.87944,"pct":0.99762,"cvss":[]},{"id":"CVE-2024-7399","kev":true,"vendor":"Samsung","product":"MagicINFO 9 Server","name":"Samsung MagicINFO 9 Server Path Traversal Vulnerability","added":"2026-04-24","due":"2026-05-08","ransomware":false,"epss":0.91941,"pct":0.99817,"cvss":[]},{"id":"CVE-2024-57728","kev":true,"vendor":"SimpleHelp","product":"SimpleHelp","name":"SimpleHelp Path Traversal Vulnerability","added":"2026-04-24","due":"2026-05-08","ransomware":true,"epss":0.64664,"pct":0.99223,"cvss":[]},{"id":"CVE-2024-57726","kev":true,"vendor":"SimpleHelp","product":"SimpleHelp","name":"SimpleHelp Missing Authorization Vulnerability","added":"2026-04-24","due":"2026-05-08","ransomware":true,"epss":0.66601,"pct":0.9927,"cvss":[]},{"id":"CVE-2026-39987","kev":true,"vendor":"Marimo","product":"Marimo","name":"Marimo Remote Code Execution Vulnerability","added":"2026-04-23","due":"2026-05-07","ransomware":false,"epss":0.37865,"pct":0.98509,"cvss":[]},{"id":"CVE-2026-33825","kev":true,"vendor":"Microsoft","product":"Defender","name":"Microsoft Defender Insufficient Granularity of Access Control Vulnerability","added":"2026-04-22","due":"2026-05-06","ransomware":true,"epss":0.00399,"pct":0.3182,"cvss":[]},{"id":"CVE-2026-20122","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Manger","name":"Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability","added":"2026-04-20","due":"2026-04-23","ransomware":false,"epss":0.24978,"pct":0.9786,"cvss":[]},{"id":"CVE-2026-20133","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","name":"Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability","added":"2026-04-20","due":"2026-04-23","ransomware":false,"epss":0.31829,"pct":0.98256,"cvss":[]},{"id":"CVE-2025-2749","kev":true,"vendor":"Kentico","product":"Kentico Xperience","name":"Kentico Xperience Path Traversal Vulnerability","added":"2026-04-20","due":"2026-05-04","ransomware":false,"epss":0.04054,"pct":0.90349,"cvss":[]},{"id":"CVE-2023-27351","kev":true,"vendor":"PaperCut","product":"NG/MF","name":"PaperCut NG/MF Improper Authentication Vulnerability","added":"2026-04-20","due":"2026-05-04","ransomware":true,"epss":0.78052,"pct":0.99566,"cvss":[]},{"id":"CVE-2025-48700","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability","added":"2026-04-20","due":"2026-04-23","ransomware":false,"epss":0.01713,"pct":0.76591,"cvss":[]},{"id":"CVE-2026-20128","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Manager","name":"Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability","added":"2026-04-20","due":"2026-04-23","ransomware":false,"epss":0.07064,"pct":0.94024,"cvss":[]},{"id":"CVE-2025-32975","kev":true,"vendor":"Quest","product":"KACE Systems Management Appliance (SMA)","name":"Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability","added":"2026-04-20","due":"2026-05-04","ransomware":false,"epss":0.02487,"pct":0.84081,"cvss":[]},{"id":"CVE-2024-27199","kev":true,"vendor":"JetBrains","product":"TeamCity","name":"JetBrains TeamCity Relative Path Traversal Vulnerability","added":"2026-04-20","due":"2026-05-04","ransomware":true,"epss":0.99991,"pct":0.99986,"cvss":[]},{"id":"CVE-2026-34197","kev":true,"vendor":"Apache","product":"ActiveMQ","name":"Apache ActiveMQ Improper Input Validation Vulnerability","added":"2026-04-16","due":"2026-04-30","ransomware":false,"epss":0.15492,"pct":0.96713,"cvss":[]},{"id":"CVE-2009-0238","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Remote Code Execution","added":"2026-04-14","due":"2026-04-28","ransomware":false,"epss":0.43212,"pct":0.9869,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2009-02-25T16:30:00.343Z","modified":"2026-06-16T23:04:33.880Z"},{"id":"CVE-2026-32201","kev":true,"vendor":"Microsoft","product":"SharePoint Server","name":"Microsoft SharePoint Server Improper Input Validation Vulnerability","added":"2026-04-14","due":"2026-04-28","ransomware":false,"epss":0.43378,"pct":0.98696,"cvss":[]},{"id":"CVE-2012-1854","kev":true,"vendor":"Microsoft","product":"Visual Basic for Applications (VBA)","name":"Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability","added":"2026-04-13","due":"2026-04-27","ransomware":false,"epss":0.21028,"pct":0.97509,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":6.9,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2012-07-10T21:55:05.587Z","modified":"2026-06-16T23:40:25.993Z"},{"id":"CVE-2025-60710","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Link Following Vulnerability","added":"2026-04-13","due":"2026-04-27","ransomware":true,"epss":0.04598,"pct":0.91383,"cvss":[]},{"id":"CVE-2023-21529","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability","added":"2026-04-13","due":"2026-04-27","ransomware":true,"epss":0.59294,"pct":0.99096,"cvss":[]},{"id":"CVE-2023-36424","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Out-of-Bounds Read Vulnerability","added":"2026-04-13","due":"2026-04-27","ransomware":false,"epss":0.12184,"pct":0.96051,"cvss":[]},{"id":"CVE-2020-9715","kev":true,"vendor":"Adobe","product":"Acrobat","name":"Adobe Acrobat Use-After-Free Vulnerability","added":"2026-04-13","due":"2026-04-27","ransomware":false,"epss":0.48595,"pct":0.98838,"cvss":[]},{"id":"CVE-2026-21643","kev":true,"vendor":"Fortinet","product":"FortiClient EMS","name":"Fortinet FortiClient EMS SQL Injection Vulnerability","added":"2026-04-13","due":"2026-04-16","ransomware":false,"epss":0.93871,"pct":0.99843,"cvss":[]},{"id":"CVE-2026-34621","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Prototype Pollution Vulnerability","added":"2026-04-13","due":"2026-04-27","ransomware":false,"epss":0.02183,"pct":0.81752,"cvss":[]},{"id":"CVE-2026-1340","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability","added":"2026-04-08","due":"2026-04-11","ransomware":false,"epss":0.98639,"pct":0.99923,"cvss":[]},{"id":"CVE-2026-35616","kev":true,"vendor":"Fortinet","product":"FortiClient EMS","name":"Fortinet FortiClient EMS Improper Access Control Vulnerability","added":"2026-04-06","due":"2026-04-09","ransomware":false,"epss":0.09098,"pct":0.95166,"cvss":[]},{"id":"CVE-2026-3502","kev":true,"vendor":"TrueConf","product":"Client","name":"TrueConf Client Download of Code Without Integrity Check Vulnerability","added":"2026-04-02","due":"2026-04-16","ransomware":false,"epss":0.00329,"pct":0.23726,"cvss":[]},{"id":"CVE-2026-5281","kev":true,"vendor":"Google","product":"Dawn","name":"Google Dawn Use-After-Free Vulnerability","added":"2026-04-01","due":"2026-04-15","ransomware":false,"epss":0.00703,"pct":0.51647,"cvss":[]},{"id":"CVE-2026-3055","kev":true,"vendor":"Citrix","product":"NetScaler","name":"Citrix NetScaler Out-of-Bounds Read Vulnerability","added":"2026-03-30","due":"2026-04-02","ransomware":false,"epss":0.04042,"pct":0.90322,"cvss":[]},{"id":"CVE-2025-53521","kev":true,"vendor":"F5","product":"BIG-IP","name":"F5 BIG-IP Stack-Based Buffer Overflow Vulnerability","added":"2026-03-27","due":"2026-03-30","ransomware":false,"epss":0.02295,"pct":0.82673,"cvss":[]},{"id":"CVE-2026-33634","kev":true,"vendor":"Aquasecurity","product":"Trivy","name":"Aquasecurity Trivy Embedded Malicious Code Vulnerability","added":"2026-03-26","due":"2026-04-09","ransomware":false,"epss":0.01683,"pct":0.76179,"cvss":[]},{"id":"CVE-2026-33017","kev":true,"vendor":"Langflow","product":"Langflow","name":"Langflow Code Injection Vulnerability","added":"2026-03-25","due":"2026-04-08","ransomware":false,"epss":0.24755,"pct":0.97842,"cvss":[]},{"id":"CVE-2025-32432","kev":true,"vendor":"Craft CMS","product":"Craft CMS","name":"Craft CMS Code Injection Vulnerability","added":"2026-03-20","due":"2026-04-03","ransomware":false,"epss":0.99792,"pct":0.99956,"cvss":[]},{"id":"CVE-2025-54068","kev":true,"vendor":"Laravel","product":"Livewire","name":"Laravel Livewire Code Injection Vulnerability","added":"2026-03-20","due":"2026-04-03","ransomware":false,"epss":0.97072,"pct":0.99892,"cvss":[]},{"id":"CVE-2025-43510","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Improper Locking Vulnerability","added":"2026-03-20","due":"2026-04-03","ransomware":false,"epss":0.00355,"pct":0.27007,"cvss":[]},{"id":"CVE-2025-43520","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Classic Buffer Overflow Vulnerability","added":"2026-03-20","due":"2026-04-03","ransomware":false,"epss":0.00425,"pct":0.3458,"cvss":[]},{"id":"CVE-2025-31277","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Buffer Overflow Vulnerability","added":"2026-03-20","due":"2026-04-03","ransomware":false,"epss":0.01604,"pct":0.75007,"cvss":[]},{"id":"CVE-2026-20131","kev":true,"vendor":"Cisco","product":"Secure Firewall Management Center (FMC)","name":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability","added":"2026-03-19","due":"2026-03-22","ransomware":true,"epss":0.43166,"pct":0.98688,"cvss":[]},{"id":"CVE-2025-66376","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability","added":"2026-03-18","due":"2026-04-01","ransomware":false,"epss":0.20227,"pct":0.97401,"cvss":[]},{"id":"CVE-2026-20963","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","added":"2026-03-18","due":"2026-03-21","ransomware":false,"epss":0.29582,"pct":0.98144,"cvss":[]},{"id":"CVE-2025-47813","kev":true,"vendor":"Wing FTP Server","product":"Wing FTP Server","name":"Wing FTP Server Information Disclosure Vulnerability","added":"2026-03-16","due":"2026-03-30","ransomware":false,"epss":0.63107,"pct":0.99184,"cvss":[]},{"id":"CVE-2026-3910","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability","added":"2026-03-13","due":"2026-03-27","ransomware":false,"epss":0.01026,"pct":0.62372,"cvss":[]},{"id":"CVE-2026-3909","kev":true,"vendor":"Google","product":"Skia","name":"Google Skia Out-of-Bounds Write Vulnerability","added":"2026-03-13","due":"2026-03-27","ransomware":false,"epss":0.02301,"pct":0.82723,"cvss":[]},{"id":"CVE-2025-68613","kev":true,"vendor":"n8n","product":"n8n","name":"n8n Improper Control of Dynamically-Managed Code Resources Vulnerability","added":"2026-03-11","due":"2026-03-25","ransomware":false,"epss":0.98994,"pct":0.9993,"cvss":[]},{"id":"CVE-2021-22054","kev":true,"vendor":"Omnissa","product":"Workspace One UEM","name":"Omnissa Workspace ONE Server-Side Request Forgery","added":"2026-03-09","due":"2026-03-23","ransomware":false,"epss":0.99677,"pct":0.9995,"cvss":[]},{"id":"CVE-2025-26399","kev":true,"vendor":"SolarWinds","product":"Web Help Desk","name":"SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability","added":"2026-03-09","due":"2026-03-12","ransomware":true,"epss":0.895,"pct":0.99783,"cvss":[]},{"id":"CVE-2026-1603","kev":true,"vendor":"Ivanti","product":"Endpoint Manager (EPM)","name":"Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability","added":"2026-03-09","due":"2026-03-23","ransomware":false,"epss":0.8794,"pct":0.99761,"cvss":[]},{"id":"CVE-2017-7921","kev":true,"vendor":"Hikvision","product":"Multiple Products","name":"Hikvision Multiple Products Improper Authentication Vulnerability","added":"2026-03-05","due":"2026-03-26","ransomware":false,"epss":0.99998,"pct":0.9999,"cvss":[]},{"id":"CVE-2021-22681","kev":true,"vendor":"Rockwell","product":"Multiple Products","name":"Rockwell Multiple Products Insufficient Protected Credentials Vulnerability","added":"2026-03-05","due":"2026-03-26","ransomware":false,"epss":0.6363,"pct":0.99196,"cvss":[]},{"id":"CVE-2023-43000","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple products Use-After-Free Vulnerability","added":"2026-03-05","due":"2026-03-26","ransomware":false,"epss":0.03898,"pct":0.89951,"cvss":[]},{"id":"CVE-2021-30952","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Integer Overflow or Wraparound Vulnerability","added":"2026-03-05","due":"2026-03-26","ransomware":false,"epss":0.06964,"pct":0.93942,"cvss":[]},{"id":"CVE-2023-41974","kev":true,"vendor":"Apple","product":"iOS and iPadOS","name":"Apple iOS and iPadOS Use-After-Free Vulnerability","added":"2026-03-05","due":"2026-03-26","ransomware":false,"epss":0.01955,"pct":0.7958,"cvss":[]},{"id":"CVE-2026-22719","kev":true,"vendor":"Broadcom","product":"VMware Aria Operations","name":"Broadcom VMware Aria Operations Command Injection Vulnerability","added":"2026-03-03","due":"2026-03-24","ransomware":false,"epss":0.17713,"pct":0.9708,"cvss":[]},{"id":"CVE-2026-21385","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Memory Corruption Vulnerability","added":"2026-03-03","due":"2026-03-24","ransomware":false,"epss":0.01265,"pct":0.68717,"cvss":[]},{"id":"CVE-2022-20775","kev":true,"vendor":"Cisco","product":"SD-WAN","name":"Cisco SD-WAN Path Traversal Vulnerability","added":"2026-02-25","due":"2026-02-27","ransomware":false,"epss":0.12475,"pct":0.96108,"cvss":[]},{"id":"CVE-2026-20127","kev":true,"vendor":"Cisco","product":"Catalyst SD-WAN Controller and Manager","name":"Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability","added":"2026-02-25","due":"2026-02-27","ransomware":false,"epss":0.88476,"pct":0.9977,"cvss":[]},{"id":"CVE-2026-25108","kev":true,"vendor":"Soliton Systems K.K","product":"FileZen","name":"Soliton Systems K.K FileZen OS Command Injection Vulnerability","added":"2026-02-24","due":"2026-03-17","ransomware":false,"epss":0.05177,"pct":0.92208,"cvss":[]},{"id":"CVE-2025-49113","kev":true,"vendor":"Roundcube","product":"Webmail","name":"RoundCube Webmail Deserialization of Untrusted Data Vulnerability","added":"2026-02-20","due":"2026-03-13","ransomware":false,"epss":0.98897,"pct":0.99927,"cvss":[]},{"id":"CVE-2025-68461","kev":true,"vendor":"Roundcube","product":"Webmail","name":"RoundCube Webmail Cross-site Scripting Vulnerability","added":"2026-02-20","due":"2026-03-13","ransomware":false,"epss":0.26842,"pct":0.97981,"cvss":[]},{"id":"CVE-2021-22175","kev":true,"vendor":"GitLab","product":"GitLab","name":"GitLab Server-Side Request Forgery (SSRF) Vulnerability","added":"2026-02-18","due":"2026-03-11","ransomware":false,"epss":0.53372,"pct":0.98959,"cvss":[]},{"id":"CVE-2026-22769","kev":true,"vendor":"Dell","product":"RecoverPoint for Virtual Machines (RP4VMs)","name":"Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability","added":"2026-02-18","due":"2026-02-21","ransomware":false,"epss":0.13345,"pct":0.96308,"cvss":[]},{"id":"CVE-2020-7796","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite","name":"Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability","added":"2026-02-17","due":"2026-03-10","ransomware":false,"epss":0.84418,"pct":0.99695,"cvss":[]},{"id":"CVE-2024-7694","kev":true,"vendor":"TeamT5","product":"ThreatSonar Anti-Ransomware","name":"TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2026-02-17","due":"2026-03-10","ransomware":false,"epss":0.01792,"pct":0.7764,"cvss":[]},{"id":"CVE-2008-0015","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability","added":"2026-02-17","due":"2026-03-10","ransomware":false,"epss":0.76576,"pct":0.9953,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2009-07-07T23:30:00.187Z","modified":"2026-06-16T22:48:45.957Z"},{"id":"CVE-2026-2441","kev":true,"vendor":"Google","product":"Chromium","name":"Google Chromium CSS Use-After-Free Vulnerability","added":"2026-02-17","due":"2026-03-10","ransomware":false,"epss":0.55101,"pct":0.99003,"cvss":[]},{"id":"CVE-2026-1731","kev":true,"vendor":"BeyondTrust","product":"Remote Support (RS) and Privileged Remote Access (PRA)","name":"BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability","added":"2026-02-13","due":"2026-02-16","ransomware":true,"epss":0.90891,"pct":0.99804,"cvss":[]},{"id":"CVE-2026-20700","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Buffer Overflow Vulnerability","added":"2026-02-12","due":"2026-03-05","ransomware":false,"epss":0.01372,"pct":0.71016,"cvss":[]},{"id":"CVE-2024-43468","kev":true,"vendor":"Microsoft","product":"Configuration Manager","name":"Microsoft Configuration Manager SQL Injection Vulnerability","added":"2026-02-12","due":"2026-03-05","ransomware":false,"epss":0.80912,"pct":0.99622,"cvss":[]},{"id":"CVE-2025-15556","kev":true,"vendor":"Notepad++","product":"Notepad++","name":"Notepad++ Download of Code Without Integrity Check Vulnerability","added":"2026-02-12","due":"2026-03-05","ransomware":false,"epss":0.01772,"pct":0.77395,"cvss":[]},{"id":"CVE-2025-40536","kev":true,"vendor":"SolarWinds","product":"Web Help Desk","name":"SolarWinds Web Help Desk Security Control Bypass Vulnerability","added":"2026-02-12","due":"2026-02-15","ransomware":false,"epss":0.73562,"pct":0.99457,"cvss":[]},{"id":"CVE-2026-21513","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability","added":"2026-02-10","due":"2026-03-03","ransomware":false,"epss":0.15642,"pct":0.96754,"cvss":[]},{"id":"CVE-2026-21525","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NULL Pointer Dereference Vulnerability","added":"2026-02-10","due":"2026-03-03","ransomware":false,"epss":0.04797,"pct":0.91682,"cvss":[]},{"id":"CVE-2026-21510","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Shell Protection Mechanism Failure Vulnerability","added":"2026-02-10","due":"2026-03-03","ransomware":false,"epss":0.24226,"pct":0.97797,"cvss":[]},{"id":"CVE-2026-21533","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Improper Privilege Management Vulnerability","added":"2026-02-10","due":"2026-03-03","ransomware":false,"epss":0.04125,"pct":0.90503,"cvss":[]},{"id":"CVE-2026-21519","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Type Confusion Vulnerability","added":"2026-02-10","due":"2026-03-03","ransomware":false,"epss":0.02462,"pct":0.83912,"cvss":[]},{"id":"CVE-2026-21514","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability","added":"2026-02-10","due":"2026-03-03","ransomware":false,"epss":0.01578,"pct":0.74639,"cvss":[]},{"id":"CVE-2025-11953","kev":true,"vendor":"React Native Community","product":"CLI","name":"React Native Community CLI OS Command Injection Vulnerability","added":"2026-02-05","due":"2026-02-26","ransomware":false,"epss":0.9398,"pct":0.99845,"cvss":[]},{"id":"CVE-2026-24423","kev":true,"vendor":"SmarterTools","product":"SmarterMail","name":"SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability","added":"2026-02-05","due":"2026-02-26","ransomware":true,"epss":0.88177,"pct":0.99765,"cvss":[]},{"id":"CVE-2021-39935","kev":true,"vendor":"GitLab","product":"Community and Enterprise Editions","name":"GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability","added":"2026-02-03","due":"2026-02-24","ransomware":false,"epss":0.35649,"pct":0.98421,"cvss":[]},{"id":"CVE-2025-64328","kev":true,"vendor":"Sangoma","product":"FreePBX","name":"Sangoma FreePBX OS Command Injection Vulnerability","added":"2026-02-03","due":"2026-02-24","ransomware":false,"epss":0.84618,"pct":0.99699,"cvss":[]},{"id":"CVE-2019-19006","kev":true,"vendor":"Sangoma","product":"FreePBX","name":"Sangoma FreePBX Improper Authentication Vulnerability","added":"2026-02-03","due":"2026-02-24","ransomware":false,"epss":0.55946,"pct":0.99022,"cvss":[]},{"id":"CVE-2025-40551","kev":true,"vendor":"SolarWinds","product":"Web Help Desk","name":"SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability","added":"2026-02-03","due":"2026-02-06","ransomware":false,"epss":0.84181,"pct":0.99691,"cvss":[]},{"id":"CVE-2026-1281","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability","added":"2026-01-29","due":"2026-02-01","ransomware":false,"epss":0.98688,"pct":0.99924,"cvss":[]},{"id":"CVE-2026-24858","kev":true,"vendor":"Fortinet","product":"Multiple Products","name":"Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability","added":"2026-01-27","due":"2026-01-30","ransomware":false,"epss":0.85796,"pct":0.99723,"cvss":[]},{"id":"CVE-2018-14634","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Integer Overflow Vulnerability","added":"2026-01-26","due":"2026-02-16","ransomware":false,"epss":0.14689,"pct":0.96576,"cvss":[]},{"id":"CVE-2025-52691","kev":true,"vendor":"SmarterTools","product":"SmarterMail","name":"SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2026-01-26","due":"2026-02-16","ransomware":true,"epss":0.85655,"pct":0.9972,"cvss":[]},{"id":"CVE-2026-23760","kev":true,"vendor":"SmarterTools","product":"SmarterMail","name":"SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability","added":"2026-01-26","due":"2026-02-16","ransomware":true,"epss":0.96544,"pct":0.99881,"cvss":[]},{"id":"CVE-2026-24061","kev":true,"vendor":"GNU","product":"InetUtils","name":"GNU InetUtils Argument Injection Vulnerability","added":"2026-01-26","due":"2026-02-16","ransomware":false,"epss":0.98984,"pct":0.9993,"cvss":[]},{"id":"CVE-2026-21509","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Security Feature Bypass Vulnerability","added":"2026-01-26","due":"2026-02-16","ransomware":false,"epss":0.70795,"pct":0.99385,"cvss":[]},{"id":"CVE-2024-37079","kev":true,"vendor":"Broadcom","product":"VMware vCenter Server","name":"Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability","added":"2026-01-23","due":"2026-02-13","ransomware":false,"epss":0.22377,"pct":0.97633,"cvss":[]},{"id":"CVE-2025-68645","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability","added":"2026-01-22","due":"2026-02-12","ransomware":false,"epss":0.48873,"pct":0.98846,"cvss":[]},{"id":"CVE-2025-34026","kev":true,"vendor":"Versa","product":"Concerto","name":"Versa Concerto Improper Authentication Vulnerability","added":"2026-01-22","due":"2026-02-12","ransomware":false,"epss":0.8194,"pct":0.99643,"cvss":[]},{"id":"CVE-2025-31125","kev":true,"vendor":"Vite","product":"Vitejs","name":"Vite Vitejs Improper Access Control Vulnerability","added":"2026-01-22","due":"2026-02-12","ransomware":false,"epss":0.65189,"pct":0.99236,"cvss":[]},{"id":"CVE-2025-54313","kev":true,"vendor":"Prettier","product":"eslint-config-prettier","name":"Prettier eslint-config-prettier Embedded Malicious Code Vulnerability","added":"2026-01-22","due":"2026-02-12","ransomware":false,"epss":0.04522,"pct":0.91249,"cvss":[]},{"id":"CVE-2026-20045","kev":true,"vendor":"Cisco","product":"Unified Communications Manager","name":"Cisco Unified Communications Products Code Injection Vulnerability","added":"2026-01-21","due":"2026-02-11","ransomware":false,"epss":0.04541,"pct":0.9128,"cvss":[]},{"id":"CVE-2026-20805","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Information Disclosure Vulnerability","added":"2026-01-13","due":"2026-02-03","ransomware":false,"epss":0.07203,"pct":0.94132,"cvss":[]},{"id":"CVE-2025-8110","kev":true,"vendor":"Gogs","product":"Gogs","name":"Gogs Path Traversal Vulnerability","added":"2026-01-12","due":"2026-02-02","ransomware":false,"epss":0.85202,"pct":0.99711,"cvss":[]},{"id":"CVE-2009-0556","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office PowerPoint Code Injection Vulnerability","added":"2026-01-07","due":"2026-01-28","ransomware":false,"epss":0.67312,"pct":0.99289,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2009-04-03T18:30:00.610Z","modified":"2026-06-16T23:05:17.900Z"},{"id":"CVE-2025-37164","kev":true,"vendor":"Hewlett Packard Enterprise (HPE)","product":"OneView","name":"Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability","added":"2026-01-07","due":"2026-01-28","ransomware":false,"epss":0.90193,"pct":0.99796,"cvss":[]},{"id":"CVE-2025-14847","kev":true,"vendor":"MongoDB","product":"MongoDB and MongoDB Server","name":"MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability","added":"2025-12-29","due":"2026-01-19","ransomware":false,"epss":0.83218,"pct":0.99672,"cvss":[]},{"id":"CVE-2023-52163","kev":true,"vendor":"Digiever","product":"DS-2105 Pro","name":"Digiever DS-2105 Pro Missing Authorization Vulnerability","added":"2025-12-22","due":"2026-01-12","ransomware":false,"epss":0.96921,"pct":0.99888,"cvss":[]},{"id":"CVE-2025-14733","kev":true,"vendor":"WatchGuard","product":"Firebox","name":"WatchGuard Firebox Out of Bounds Write Vulnerability","added":"2025-12-19","due":"2025-12-26","ransomware":true,"epss":0.2651,"pct":0.97959,"cvss":[]},{"id":"CVE-2025-59374","kev":true,"vendor":"ASUS","product":"Live Update","name":"ASUS Live Update Embedded Malicious Code Vulnerability","added":"2025-12-17","due":"2026-01-07","ransomware":false,"epss":0.01197,"pct":0.67061,"cvss":[]},{"id":"CVE-2025-40602","kev":true,"vendor":"SonicWall","product":"SMA1000 appliance","name":"SonicWall SMA1000 Missing Authorization Vulnerability","added":"2025-12-17","due":"2025-12-24","ransomware":false,"epss":0.02756,"pct":0.85767,"cvss":[]},{"id":"CVE-2025-20393","kev":true,"vendor":"Cisco","product":"Multiple Products","name":"Cisco Multiple Products Improper Input Validation Vulnerability","added":"2025-12-17","due":"2025-12-24","ransomware":false,"epss":0.32392,"pct":0.98289,"cvss":[]},{"id":"CVE-2025-59718","kev":true,"vendor":"Fortinet","product":"Multiple Products","name":"Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability","added":"2025-12-16","due":"2025-12-23","ransomware":false,"epss":0.68293,"pct":0.99315,"cvss":[]},{"id":"CVE-2025-14611","kev":true,"vendor":"Gladinet","product":"CentreStack and Triofox","name":"Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability","added":"2025-12-15","due":"2026-01-05","ransomware":false,"epss":0.53302,"pct":0.98956,"cvss":[]},{"id":"CVE-2025-43529","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Use-After-Free WebKit Vulnerability","added":"2025-12-15","due":"2026-01-05","ransomware":false,"epss":0.08763,"pct":0.95026,"cvss":[]},{"id":"CVE-2018-4063","kev":true,"vendor":"Sierra Wireless","product":"AirLink ALEOS","name":"Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2025-12-12","due":"2026-01-02","ransomware":false,"epss":0.27059,"pct":0.97994,"cvss":[]},{"id":"CVE-2025-14174","kev":true,"vendor":"Google","product":"Chromium","name":"Google Chromium Out of Bounds Memory Access Vulnerability","added":"2025-12-12","due":"2026-01-02","ransomware":false,"epss":0.22327,"pct":0.97626,"cvss":[]},{"id":"CVE-2025-58360","kev":true,"vendor":"OSGeo","product":"GeoServer","name":"OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability","added":"2025-12-11","due":"2026-01-01","ransomware":false,"epss":0.60522,"pct":0.99122,"cvss":[]},{"id":"CVE-2025-6218","kev":true,"vendor":"RARLAB","product":"WinRAR","name":"RARLAB WinRAR Path Traversal Vulnerability","added":"2025-12-09","due":"2025-12-30","ransomware":false,"epss":0.90479,"pct":0.99799,"cvss":[]},{"id":"CVE-2025-62221","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Use After Free Vulnerability","added":"2025-12-09","due":"2025-12-30","ransomware":false,"epss":0.02505,"pct":0.84192,"cvss":[]},{"id":"CVE-2022-37055","kev":true,"vendor":"D-Link","product":"Routers","name":"D-Link Routers Buffer Overflow Vulnerability","added":"2025-12-08","due":"2025-12-29","ransomware":false,"epss":0.55531,"pct":0.99013,"cvss":[]},{"id":"CVE-2025-66644","kev":true,"vendor":"Array Networks","product":"ArrayOS AG","name":"Array Networks ArrayOS AG OS Command Injection Vulnerability","added":"2025-12-08","due":"2025-12-29","ransomware":false,"epss":0.03415,"pct":0.88517,"cvss":[]},{"id":"CVE-2025-55182","kev":true,"vendor":"Meta","product":"React Server Components","name":"Meta React Server Components Remote Code Execution Vulnerability","added":"2025-12-05","due":"2025-12-12","ransomware":true,"epss":0.99802,"pct":0.99957,"cvss":[]},{"id":"CVE-2021-26828","kev":true,"vendor":"OpenPLC","product":"ScadaBR","name":"OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability","added":"2025-12-03","due":"2025-12-24","ransomware":false,"epss":0.39356,"pct":0.98567,"cvss":[]},{"id":"CVE-2025-48633","kev":true,"vendor":"Android","product":"Framework","name":"Android Framework Information Disclosure Vulnerability","added":"2025-12-02","due":"2025-12-23","ransomware":false,"epss":0.00262,"pct":0.16382,"cvss":[]},{"id":"CVE-2025-48572","kev":true,"vendor":"Android","product":"Framework","name":"Android Framework Privilege Escalation Vulnerability","added":"2025-12-02","due":"2025-12-23","ransomware":false,"epss":0.00259,"pct":0.1599,"cvss":[]},{"id":"CVE-2021-26829","kev":true,"vendor":"OpenPLC","product":"ScadaBR","name":"OpenPLC ScadaBR Cross-site Scripting Vulnerability","added":"2025-11-28","due":"2025-12-19","ransomware":false,"epss":0.4805,"pct":0.98824,"cvss":[]},{"id":"CVE-2025-61757","kev":true,"vendor":"Oracle","product":"Fusion Middleware","name":"Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability","added":"2025-11-21","due":"2025-12-12","ransomware":false,"epss":0.88647,"pct":0.99772,"cvss":[]},{"id":"CVE-2025-13223","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2025-11-19","due":"2025-12-10","ransomware":false,"epss":0.05026,"pct":0.92012,"cvss":[]},{"id":"CVE-2025-58034","kev":true,"vendor":"Fortinet","product":"FortiWeb","name":"Fortinet FortiWeb OS Command Injection Vulnerability","added":"2025-11-18","due":"2025-11-25","ransomware":false,"epss":0.5558,"pct":0.99014,"cvss":[]},{"id":"CVE-2025-64446","kev":true,"vendor":"Fortinet","product":"FortiWeb","name":"Fortinet FortiWeb Path Traversal Vulnerability","added":"2025-11-14","due":"2025-11-21","ransomware":false,"epss":0.91838,"pct":0.99815,"cvss":[]},{"id":"CVE-2025-12480","kev":true,"vendor":"Gladinet","product":"Triofox","name":"Gladinet Triofox Improper Access Control Vulnerability","added":"2025-11-12","due":"2025-12-03","ransomware":false,"epss":0.95428,"pct":0.99869,"cvss":[]},{"id":"CVE-2025-62215","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Race Condition Vulnerability","added":"2025-11-12","due":"2025-12-03","ransomware":false,"epss":0.05985,"pct":0.93097,"cvss":[]},{"id":"CVE-2025-9242","kev":true,"vendor":"WatchGuard","product":"Firebox","name":"WatchGuard Firebox Out-of-Bounds Write Vulnerability","added":"2025-11-12","due":"2025-12-03","ransomware":false,"epss":0.913,"pct":0.9981,"cvss":[]},{"id":"CVE-2025-21042","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Out-of-Bounds Write Vulnerability","added":"2025-11-10","due":"2025-12-01","ransomware":false,"epss":0.3317,"pct":0.98324,"cvss":[]},{"id":"CVE-2025-48703","kev":true,"vendor":"CWP","product":"Control Web Panel","name":"CWP Control Web Panel OS Command Injection Vulnerability","added":"2025-11-04","due":"2025-11-25","ransomware":false,"epss":0.99655,"pct":0.99949,"cvss":[]},{"id":"CVE-2025-11371","kev":true,"vendor":"Gladinet","product":"CentreStack and Triofox","name":"Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability","added":"2025-11-04","due":"2025-11-25","ransomware":false,"epss":0.92137,"pct":0.9982,"cvss":[]},{"id":"CVE-2025-41244","kev":true,"vendor":"Broadcom","product":"VMware Aria Operations and VMware Tools","name":"Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability","added":"2025-10-30","due":"2025-11-20","ransomware":false,"epss":0.08438,"pct":0.9485,"cvss":[]},{"id":"CVE-2025-24893","kev":true,"vendor":"XWiki","product":"Platform","name":"XWiki Platform Eval Injection Vulnerability","added":"2025-10-30","due":"2025-11-20","ransomware":false,"epss":0.99864,"pct":0.99962,"cvss":[]},{"id":"CVE-2025-6204","kev":true,"vendor":"Dassault Systèmes","product":"DELMIA Apriso","name":"Dassault Systèmes DELMIA Apriso Code Injection Vulnerability","added":"2025-10-28","due":"2025-11-18","ransomware":false,"epss":0.79342,"pct":0.99593,"cvss":[]},{"id":"CVE-2025-6205","kev":true,"vendor":"Dassault Systèmes","product":"DELMIA Apriso","name":"Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability","added":"2025-10-28","due":"2025-11-18","ransomware":false,"epss":0.73752,"pct":0.99465,"cvss":[]},{"id":"CVE-2025-54236","kev":true,"vendor":"Adobe","product":"Commerce and Magento","name":"Adobe Commerce and Magento Improper Input Validation Vulnerability","added":"2025-10-24","due":"2025-11-14","ransomware":false,"epss":0.94532,"pct":0.99853,"cvss":[]},{"id":"CVE-2025-59287","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability","added":"2025-10-24","due":"2025-11-14","ransomware":false,"epss":0.9998,"pct":0.99981,"cvss":[]},{"id":"CVE-2025-61932","kev":true,"vendor":"Motex","product":"LANSCOPE Endpoint Manager","name":"Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability","added":"2025-10-22","due":"2025-11-12","ransomware":false,"epss":0.02768,"pct":0.85837,"cvss":[]},{"id":"CVE-2022-48503","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Unspecified Vulnerability","added":"2025-10-20","due":"2025-11-10","ransomware":false,"epss":0.03213,"pct":0.8777,"cvss":[]},{"id":"CVE-2025-2746","kev":true,"vendor":"Kentico","product":"Xperience CMS","name":"Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability","added":"2025-10-20","due":"2025-11-10","ransomware":false,"epss":0.7304,"pct":0.99444,"cvss":[]},{"id":"CVE-2025-2747","kev":true,"vendor":"Kentico","product":"Xperience CMS","name":"Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability","added":"2025-10-20","due":"2025-11-10","ransomware":false,"epss":0.97166,"pct":0.99894,"cvss":[]},{"id":"CVE-2025-33073","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SMB Client Improper Access Control Vulnerability","added":"2025-10-20","due":"2025-11-10","ransomware":false,"epss":0.82699,"pct":0.9966,"cvss":[]},{"id":"CVE-2025-61884","kev":true,"vendor":"Oracle","product":"E-Business Suite","name":"Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability","added":"2025-10-20","due":"2025-11-10","ransomware":true,"epss":0.95891,"pct":0.99873,"cvss":[]},{"id":"CVE-2025-54253","kev":true,"vendor":"Adobe","product":"Experience Manager (AEM) Forms","name":"Adobe Experience Manager Forms Code Execution Vulnerability","added":"2025-10-15","due":"2025-11-05","ransomware":false,"epss":0.88262,"pct":0.99767,"cvss":[]},{"id":"CVE-2025-47827","kev":true,"vendor":"IGEL","product":"IGEL OS","name":"IGEL OS Use of a Key Past its Expiration Date Vulnerability","added":"2025-10-14","due":"2025-11-04","ransomware":false,"epss":0.04927,"pct":0.91876,"cvss":[]},{"id":"CVE-2025-24990","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Untrusted Pointer Dereference Vulnerability","added":"2025-10-14","due":"2025-11-04","ransomware":false,"epss":0.06369,"pct":0.93457,"cvss":[]},{"id":"CVE-2025-59230","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Improper Access Control Vulnerability","added":"2025-10-14","due":"2025-11-04","ransomware":false,"epss":0.02657,"pct":0.85176,"cvss":[]},{"id":"CVE-2016-7836","kev":true,"vendor":"SKYSEA","product":"Client View","name":"SKYSEA Client View Improper Authentication Vulnerability","added":"2025-10-14","due":"2025-11-04","ransomware":false,"epss":0.1923,"pct":0.97262,"cvss":[]},{"id":"CVE-2021-43798","kev":true,"vendor":"Grafana Labs","product":"Grafana","name":"Grafana Path Traversal Vulnerability","added":"2025-10-09","due":"2025-10-30","ransomware":false,"epss":0.88503,"pct":0.9977,"cvss":[]},{"id":"CVE-2025-27915","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability","added":"2025-10-07","due":"2025-10-28","ransomware":false,"epss":0.04064,"pct":0.90366,"cvss":[]},{"id":"CVE-2021-22555","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Heap Out-of-Bounds Write Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":false,"epss":0.78684,"pct":0.9958,"cvss":[]},{"id":"CVE-2010-3962","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":false,"epss":0.96831,"pct":0.99887,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.1,"severity":"HIGH"}],"published":"2010-11-05T17:00:02.890Z","modified":"2026-06-16T23:23:53.780Z"},{"id":"CVE-2021-43226","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":true,"epss":0.03098,"pct":0.87313,"cvss":[]},{"id":"CVE-2013-3918","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Out-of-Bounds Write Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":false,"epss":0.73693,"pct":0.99462,"cvss":[]},{"id":"CVE-2011-3402","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Remote Code Execution Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":false,"epss":0.78138,"pct":0.99568,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2011-11-04T21:55:04.693Z","modified":"2026-06-16T23:33:14.020Z"},{"id":"CVE-2010-3765","kev":true,"vendor":"Mozilla","product":"Multiple Products","name":"Mozilla Multiple Products Remote Code Execution Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":false,"epss":0.83156,"pct":0.9967,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2010-10-28T00:00:05.237Z","modified":"2026-06-16T23:23:28.500Z"},{"id":"CVE-2025-61882","kev":true,"vendor":"Oracle","product":"E-Business Suite","name":"Oracle E-Business Suite Unspecified Vulnerability","added":"2025-10-06","due":"2025-10-27","ransomware":true,"epss":0.99732,"pct":0.99952,"cvss":[]},{"id":"CVE-2014-6278","kev":true,"vendor":"GNU","product":"GNU Bash","name":"GNU Bash OS Command Injection Vulnerability","added":"2025-10-02","due":"2025-10-23","ransomware":false,"epss":0.99621,"pct":0.99948,"cvss":[]},{"id":"CVE-2017-1000353","kev":true,"vendor":"Jenkins","product":"Jenkins","name":"Jenkins Remote Code Execution Vulnerability","added":"2025-10-02","due":"2025-10-23","ransomware":false,"epss":0.99679,"pct":0.9995,"cvss":[]},{"id":"CVE-2015-7755","kev":true,"vendor":"Juniper","product":"ScreenOS","name":"Juniper ScreenOS Improper Authentication Vulnerability","added":"2025-10-02","due":"2025-10-23","ransomware":false,"epss":0.61139,"pct":0.99138,"cvss":[]},{"id":"CVE-2025-21043","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Out-of-Bounds Write Vulnerability","added":"2025-10-02","due":"2025-10-23","ransomware":false,"epss":0.0214,"pct":0.814,"cvss":[]},{"id":"CVE-2025-4008","kev":true,"vendor":"Smartbedded","product":"Meteobridge","name":"Smartbedded Meteobridge Command Injection Vulnerability","added":"2025-10-02","due":"2025-10-23","ransomware":false,"epss":0.93667,"pct":0.99842,"cvss":[]},{"id":"CVE-2025-32463","kev":true,"vendor":"Sudo","product":"Sudo","name":"Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability","added":"2025-09-29","due":"2025-10-20","ransomware":false,"epss":0.55498,"pct":0.99012,"cvss":[]},{"id":"CVE-2025-59689","kev":true,"vendor":"Libraesva","product":"Email Security Gateway","name":"Libraesva Email Security Gateway Command Injection Vulnerability","added":"2025-09-29","due":"2025-10-20","ransomware":false,"epss":0.01864,"pct":0.78555,"cvss":[]},{"id":"CVE-2025-10035","kev":true,"vendor":"Fortra","product":"GoAnywhere MFT","name":"Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability","added":"2025-09-29","due":"2025-10-20","ransomware":true,"epss":0.99799,"pct":0.99957,"cvss":[]},{"id":"CVE-2025-20352","kev":true,"vendor":"Cisco","product":"IOS and IOS XE","name":"Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability","added":"2025-09-29","due":"2025-10-20","ransomware":false,"epss":0.39447,"pct":0.98571,"cvss":[]},{"id":"CVE-2021-21311","kev":true,"vendor":"Adminer","product":"Adminer","name":"Adminer Server-Side Request Forgery Vulnerability","added":"2025-09-29","due":"2025-10-20","ransomware":false,"epss":0.98464,"pct":0.99918,"cvss":[]},{"id":"CVE-2025-20362","kev":true,"vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense","name":"Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability","added":"2025-09-25","due":"2025-09-26","ransomware":false,"epss":0.87085,"pct":0.99746,"cvss":[]},{"id":"CVE-2025-20333","kev":true,"vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense","name":"Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability","added":"2025-09-25","due":"2025-09-26","ransomware":false,"epss":0.70651,"pct":0.99378,"cvss":[]},{"id":"CVE-2025-10585","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2025-09-23","due":"2025-10-14","ransomware":false,"epss":0.05391,"pct":0.9244,"cvss":[]},{"id":"CVE-2025-5086","kev":true,"vendor":"Dassault Systèmes","product":"DELMIA Apriso","name":"Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability","added":"2025-09-11","due":"2025-10-02","ransomware":false,"epss":0.96915,"pct":0.99888,"cvss":[]},{"id":"CVE-2025-38352","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability","added":"2025-09-04","due":"2025-09-25","ransomware":false,"epss":0.01289,"pct":0.69216,"cvss":[]},{"id":"CVE-2025-48543","kev":true,"vendor":"Android","product":"Runtime","name":"Android Runtime Use-After-Free Vulnerability","added":"2025-09-04","due":"2025-09-25","ransomware":false,"epss":0.00543,"pct":0.4368,"cvss":[]},{"id":"CVE-2025-53690","kev":true,"vendor":"Sitecore","product":"Multiple Products","name":"Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability","added":"2025-09-04","due":"2025-09-25","ransomware":false,"epss":0.51094,"pct":0.98903,"cvss":[]},{"id":"CVE-2023-50224","kev":true,"vendor":"TP-Link","product":"TL-WR841N","name":"TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability","added":"2025-09-03","due":"2025-09-24","ransomware":false,"epss":0.15558,"pct":0.96739,"cvss":[]},{"id":"CVE-2025-9377","kev":true,"vendor":"TP-Link","product":"Multiple Routers","name":"TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability","added":"2025-09-03","due":"2025-09-24","ransomware":false,"epss":0.33524,"pct":0.9834,"cvss":[]},{"id":"CVE-2020-24363","kev":true,"vendor":"TP-Link","product":"TL-WA855RE","name":"TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability","added":"2025-09-02","due":"2025-09-23","ransomware":false,"epss":0.20689,"pct":0.97467,"cvss":[]},{"id":"CVE-2025-55177","kev":true,"vendor":"Meta Platforms","product":"WhatsApp","name":"Meta Platforms WhatsApp Incorrect Authorization Vulnerability","added":"2025-09-02","due":"2025-09-23","ransomware":false,"epss":0.04304,"pct":0.90853,"cvss":[]},{"id":"CVE-2025-57819","kev":true,"vendor":"Sangoma","product":"FreePBX","name":"Sangoma FreePBX Authentication Bypass Vulnerability","added":"2025-08-29","due":"2025-09-19","ransomware":false,"epss":0.85463,"pct":0.99717,"cvss":[]},{"id":"CVE-2025-7775","kev":true,"vendor":"Citrix","product":"NetScaler","name":"Citrix NetScaler Memory Overflow Vulnerability","added":"2025-08-26","due":"2025-08-28","ransomware":false,"epss":0.20284,"pct":0.97408,"cvss":[]},{"id":"CVE-2025-48384","kev":true,"vendor":"Git","product":"Git","name":"Git Link Following Vulnerability","added":"2025-08-25","due":"2025-09-15","ransomware":false,"epss":0.042,"pct":0.90659,"cvss":[]},{"id":"CVE-2024-8068","kev":true,"vendor":"Citrix","product":"Session Recording","name":"Citrix Session Recording Improper Privilege Management Vulnerability","added":"2025-08-25","due":"2025-09-15","ransomware":false,"epss":0.03481,"pct":0.88741,"cvss":[]},{"id":"CVE-2024-8069","kev":true,"vendor":"Citrix","product":"Session Recording","name":"Citrix Session Recording Deserialization of Untrusted Data Vulnerability","added":"2025-08-25","due":"2025-09-15","ransomware":false,"epss":0.14643,"pct":0.96565,"cvss":[]},{"id":"CVE-2025-43300","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability","added":"2025-08-21","due":"2025-09-11","ransomware":false,"epss":0.32498,"pct":0.98295,"cvss":[]},{"id":"CVE-2025-54948","kev":true,"vendor":"Trend Micro","product":"Apex One","name":"Trend Micro Apex One OS Command Injection Vulnerability","added":"2025-08-18","due":"2025-09-08","ransomware":false,"epss":0.23919,"pct":0.97773,"cvss":[]},{"id":"CVE-2025-8876","kev":true,"vendor":"N-able","product":"N-Central","name":"N-able N-Central Command Injection Vulnerability","added":"2025-08-13","due":"2025-08-20","ransomware":false,"epss":0.03448,"pct":0.88633,"cvss":[]},{"id":"CVE-2025-8875","kev":true,"vendor":"N-able","product":"N-Central","name":"N-able N-Central Insecure Deserialization Vulnerability","added":"2025-08-13","due":"2025-08-20","ransomware":false,"epss":0.01899,"pct":0.78959,"cvss":[]},{"id":"CVE-2025-8088","kev":true,"vendor":"RARLAB","product":"WinRAR","name":"RARLAB WinRAR Path Traversal Vulnerability","added":"2025-08-12","due":"2025-09-02","ransomware":true,"epss":0.94051,"pct":0.99846,"cvss":[]},{"id":"CVE-2007-0671","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Excel Remote Code Execution Vulnerability","added":"2025-08-12","due":"2025-09-02","ransomware":false,"epss":0.43241,"pct":0.98691,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2007-02-03T01:28:00.000Z","modified":"2026-06-16T22:36:02.527Z"},{"id":"CVE-2013-3893","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Resource Management Errors Vulnerability","added":"2025-08-12","due":"2025-09-02","ransomware":false,"epss":0.87526,"pct":0.99755,"cvss":[]},{"id":"CVE-2020-25078","kev":true,"vendor":"D-Link","product":"DCS-2530L and DCS-2670L Devices","name":"D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability","added":"2025-08-05","due":"2025-08-26","ransomware":false,"epss":0.97511,"pct":0.999,"cvss":[]},{"id":"CVE-2020-25079","kev":true,"vendor":"D-Link","product":"DCS-2530L and DCS-2670L Devices","name":"D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability","added":"2025-08-05","due":"2025-08-26","ransomware":false,"epss":0.54007,"pct":0.98976,"cvss":[]},{"id":"CVE-2022-40799","kev":true,"vendor":"D-Link","product":"DNR-322L","name":"D-Link DNR-322L Download of Code Without Integrity Check Vulnerability","added":"2025-08-05","due":"2025-08-26","ransomware":false,"epss":0.3365,"pct":0.98345,"cvss":[]},{"id":"CVE-2023-2533","kev":true,"vendor":"PaperCut","product":"NG/MF","name":"PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability","added":"2025-07-28","due":"2025-08-18","ransomware":false,"epss":0.28621,"pct":0.98088,"cvss":[]},{"id":"CVE-2025-20337","kev":true,"vendor":"Cisco","product":"Identity Services Engine","name":"Cisco Identity Services Engine Injection Vulnerability","added":"2025-07-28","due":"2025-08-18","ransomware":false,"epss":0.67825,"pct":0.99302,"cvss":[]},{"id":"CVE-2025-20281","kev":true,"vendor":"Cisco","product":"Identity Services Engine","name":"Cisco Identity Services Engine Injection Vulnerability","added":"2025-07-28","due":"2025-08-18","ransomware":false,"epss":0.97601,"pct":0.99902,"cvss":[]},{"id":"CVE-2025-2775","kev":true,"vendor":"SysAid","product":"SysAid On-Prem","name":"SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability","added":"2025-07-22","due":"2025-08-12","ransomware":false,"epss":0.42612,"pct":0.98675,"cvss":[]},{"id":"CVE-2025-2776","kev":true,"vendor":"SysAid","product":"SysAid On-Prem","name":"SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability","added":"2025-07-22","due":"2025-08-12","ransomware":false,"epss":0.64726,"pct":0.99225,"cvss":[]},{"id":"CVE-2025-6558","kev":true,"vendor":"Google","product":"Chromium","name":"Google Chromium ANGLE and GPU Improper Input Validation Vulnerability","added":"2025-07-22","due":"2025-08-12","ransomware":false,"epss":0.09464,"pct":0.95295,"cvss":[]},{"id":"CVE-2025-54309","kev":true,"vendor":"CrushFTP","product":"CrushFTP","name":"CrushFTP Unprotected Alternate Channel Vulnerability","added":"2025-07-22","due":"2025-08-12","ransomware":false,"epss":0.94905,"pct":0.99859,"cvss":[]},{"id":"CVE-2025-49704","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Code Injection Vulnerability","added":"2025-07-22","due":"2025-07-23","ransomware":true,"epss":0.99995,"pct":0.99988,"cvss":[]},{"id":"CVE-2025-49706","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Improper Authentication Vulnerability","added":"2025-07-22","due":"2025-07-23","ransomware":true,"epss":0.99076,"pct":0.99932,"cvss":[]},{"id":"CVE-2025-53770","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","added":"2025-07-20","due":"2025-07-21","ransomware":true,"epss":0.99998,"pct":0.99991,"cvss":[]},{"id":"CVE-2025-25257","kev":true,"vendor":"Fortinet","product":"FortiWeb","name":"Fortinet FortiWeb SQL Injection Vulnerability","added":"2025-07-18","due":"2025-08-08","ransomware":false,"epss":0.99775,"pct":0.99954,"cvss":[]},{"id":"CVE-2025-47812","kev":true,"vendor":"Wing FTP Server","product":"Wing FTP Server","name":"Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability","added":"2025-07-14","due":"2025-08-04","ransomware":false,"epss":0.93235,"pct":0.99834,"cvss":[]},{"id":"CVE-2025-5777","kev":true,"vendor":"Citrix","product":"NetScaler ADC and Gateway","name":"Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability","added":"2025-07-10","due":"2025-07-11","ransomware":true,"epss":0.99972,"pct":0.99978,"cvss":[]},{"id":"CVE-2019-9621","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability","added":"2025-07-07","due":"2025-07-28","ransomware":false,"epss":0.81037,"pct":0.99625,"cvss":[]},{"id":"CVE-2019-5418","kev":true,"vendor":"Rails","product":"Ruby on Rails","name":"Rails Ruby on Rails Path Traversal Vulnerability","added":"2025-07-07","due":"2025-07-28","ransomware":false,"epss":0.98507,"pct":0.9992,"cvss":[]},{"id":"CVE-2016-10033","kev":true,"vendor":"PHP","product":"PHPMailer","name":"PHPMailer Command Injection Vulnerability","added":"2025-07-07","due":"2025-07-28","ransomware":false,"epss":0.99714,"pct":0.99951,"cvss":[]},{"id":"CVE-2014-3931","kev":true,"vendor":"Looking Glass","product":"Multi-Router Looking Glass (MRLG)","name":"Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability","added":"2025-07-07","due":"2025-07-28","ransomware":false,"epss":0.28978,"pct":0.98112,"cvss":[]},{"id":"CVE-2025-6554","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2025-07-02","due":"2025-07-23","ransomware":false,"epss":0.14142,"pct":0.96477,"cvss":[]},{"id":"CVE-2025-48928","kev":true,"vendor":"TeleMessage","product":"TM SGNL","name":"TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability","added":"2025-07-01","due":"2025-07-22","ransomware":false,"epss":0.00553,"pct":0.4425,"cvss":[]},{"id":"CVE-2025-48927","kev":true,"vendor":"TeleMessage","product":"TM SGNL","name":"TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability","added":"2025-07-01","due":"2025-07-22","ransomware":false,"epss":0.11104,"pct":0.95813,"cvss":[]},{"id":"CVE-2025-6543","kev":true,"vendor":"Citrix","product":"NetScaler ADC and Gateway","name":"Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability","added":"2025-06-30","due":"2025-07-21","ransomware":false,"epss":0.10562,"pct":0.95656,"cvss":[]},{"id":"CVE-2019-6693","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability","added":"2025-06-25","due":"2025-07-16","ransomware":true,"epss":0.05828,"pct":0.92943,"cvss":[]},{"id":"CVE-2024-0769","kev":true,"vendor":"D-Link","product":"DIR-859 Router","name":"D-Link DIR-859 Router Path Traversal Vulnerability","added":"2025-06-25","due":"2025-07-16","ransomware":false,"epss":0.82714,"pct":0.99661,"cvss":[]},{"id":"CVE-2024-54085","kev":true,"vendor":"AMI","product":"MegaRAC SPx","name":"AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability","added":"2025-06-25","due":"2025-07-16","ransomware":false,"epss":0.60747,"pct":0.99127,"cvss":[]},{"id":"CVE-2023-0386","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Improper Ownership Management Vulnerability","added":"2025-06-17","due":"2025-07-08","ransomware":false,"epss":0.0788,"pct":0.94546,"cvss":[]},{"id":"CVE-2023-33538","kev":true,"vendor":"TP-Link","product":"Multiple Routers","name":"TP-Link Multiple Routers Command Injection Vulnerability","added":"2025-06-16","due":"2025-07-07","ransomware":false,"epss":0.41606,"pct":0.98644,"cvss":[]},{"id":"CVE-2025-43200","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Unspecified Vulnerability","added":"2025-06-16","due":"2025-07-07","ransomware":false,"epss":0.01191,"pct":0.66908,"cvss":[]},{"id":"CVE-2025-33053","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows External Control of File Name or Path Vulnerability","added":"2025-06-10","due":"2025-07-01","ransomware":false,"epss":0.87015,"pct":0.99745,"cvss":[]},{"id":"CVE-2025-24016","kev":true,"vendor":"Wazuh","product":"Wazuh Server","name":"Wazuh Server Deserialization of Untrusted Data Vulnerability","added":"2025-06-10","due":"2025-07-01","ransomware":false,"epss":0.9384,"pct":0.99843,"cvss":[]},{"id":"CVE-2024-42009","kev":true,"vendor":"Roundcube","product":"Webmail","name":"RoundCube Webmail Cross-Site Scripting Vulnerability","added":"2025-06-09","due":"2025-06-30","ransomware":false,"epss":0.82882,"pct":0.99665,"cvss":[]},{"id":"CVE-2025-32433","kev":true,"vendor":"Erlang","product":"Erlang/OTP","name":"Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability","added":"2025-06-09","due":"2025-06-30","ransomware":false,"epss":0.98786,"pct":0.99926,"cvss":[]},{"id":"CVE-2025-5419","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Read and Write Vulnerability","added":"2025-06-05","due":"2025-06-26","ransomware":false,"epss":0.07821,"pct":0.94506,"cvss":[]},{"id":"CVE-2025-21479","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability","added":"2025-06-03","due":"2025-06-24","ransomware":false,"epss":0.00843,"pct":0.56507,"cvss":[]},{"id":"CVE-2025-21480","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability","added":"2025-06-03","due":"2025-06-24","ransomware":false,"epss":0.0046,"pct":0.37657,"cvss":[]},{"id":"CVE-2025-27038","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Use-After-Free Vulnerability","added":"2025-06-03","due":"2025-06-24","ransomware":false,"epss":0.01016,"pct":0.62062,"cvss":[]},{"id":"CVE-2021-32030","kev":true,"vendor":"ASUS","product":"Routers","name":"ASUS Routers Improper Authentication Vulnerability","added":"2025-06-02","due":"2025-06-23","ransomware":false,"epss":0.99393,"pct":0.9994,"cvss":[]},{"id":"CVE-2025-3935","kev":true,"vendor":"ConnectWise","product":"ScreenConnect","name":"ConnectWise ScreenConnect Improper Authentication Vulnerability","added":"2025-06-02","due":"2025-06-23","ransomware":false,"epss":0.03507,"pct":0.88825,"cvss":[]},{"id":"CVE-2025-35939","kev":true,"vendor":"Craft CMS","product":"Craft CMS","name":"Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability","added":"2025-06-02","due":"2025-06-23","ransomware":false,"epss":0.01349,"pct":0.70535,"cvss":[]},{"id":"CVE-2024-56145","kev":true,"vendor":"Craft CMS","product":"Craft CMS","name":"Craft CMS Code Injection Vulnerability","added":"2025-06-02","due":"2025-06-23","ransomware":false,"epss":0.97405,"pct":0.99898,"cvss":[]},{"id":"CVE-2023-39780","kev":true,"vendor":"ASUS","product":"RT-AX55 Routers","name":"ASUS RT-AX55 Routers OS Command Injection Vulnerability","added":"2025-06-02","due":"2025-06-23","ransomware":false,"epss":0.39514,"pct":0.98574,"cvss":[]},{"id":"CVE-2025-4632","kev":true,"vendor":"Samsung","product":"MagicINFO 9 Server","name":"Samsung MagicINFO 9 Server Path Traversal Vulnerability","added":"2025-05-22","due":"2025-06-12","ransomware":false,"epss":0.24295,"pct":0.97803,"cvss":[]},{"id":"CVE-2023-38950","kev":true,"vendor":"ZKTeco","product":"BioTime","name":"ZKTeco BioTime Path Traversal Vulnerability","added":"2025-05-19","due":"2025-06-09","ransomware":false,"epss":0.92468,"pct":0.99823,"cvss":[]},{"id":"CVE-2024-27443","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability","added":"2025-05-19","due":"2025-06-09","ransomware":false,"epss":0.23632,"pct":0.97751,"cvss":[]},{"id":"CVE-2025-27920","kev":true,"vendor":"Srimax","product":"Output Messenger","name":"Srimax Output Messenger Directory Traversal Vulnerability","added":"2025-05-19","due":"2025-06-09","ransomware":false,"epss":0.01865,"pct":0.78563,"cvss":[]},{"id":"CVE-2024-11182","kev":true,"vendor":"MDaemon","product":"Email Server","name":"MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability","added":"2025-05-19","due":"2025-06-09","ransomware":false,"epss":0.17591,"pct":0.97066,"cvss":[]},{"id":"CVE-2025-4428","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability","added":"2025-05-19","due":"2025-06-09","ransomware":false,"epss":0.86519,"pct":0.99734,"cvss":[]},{"id":"CVE-2025-4427","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability","added":"2025-05-19","due":"2025-06-09","ransomware":false,"epss":0.99927,"pct":0.99969,"cvss":[]},{"id":"CVE-2025-42999","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Deserialization Vulnerability","added":"2025-05-15","due":"2025-06-05","ransomware":true,"epss":0.13868,"pct":0.96427,"cvss":[]},{"id":"CVE-2024-12987","kev":true,"vendor":"DrayTek","product":"Vigor Routers","name":"DrayTek Vigor Routers OS Command Injection Vulnerability","added":"2025-05-15","due":"2025-06-05","ransomware":false,"epss":0.98163,"pct":0.99913,"cvss":[]},{"id":"CVE-2025-32756","kev":true,"vendor":"Fortinet","product":"Multiple Products","name":"Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability","added":"2025-05-14","due":"2025-06-04","ransomware":false,"epss":0.29812,"pct":0.98155,"cvss":[]},{"id":"CVE-2025-32709","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability","added":"2025-05-13","due":"2025-06-03","ransomware":false,"epss":0.02158,"pct":0.81561,"cvss":[]},{"id":"CVE-2025-30397","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Scripting Engine Type Confusion Vulnerability","added":"2025-05-13","due":"2025-06-03","ransomware":false,"epss":0.26835,"pct":0.97981,"cvss":[]},{"id":"CVE-2025-32706","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability","added":"2025-05-13","due":"2025-06-03","ransomware":false,"epss":0.02313,"pct":0.82817,"cvss":[]},{"id":"CVE-2025-32701","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability","added":"2025-05-13","due":"2025-06-03","ransomware":false,"epss":0.01403,"pct":0.71628,"cvss":[]},{"id":"CVE-2025-30400","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows DWM Core Library Use-After-Free Vulnerability","added":"2025-05-13","due":"2025-06-03","ransomware":false,"epss":0.019,"pct":0.7897,"cvss":[]},{"id":"CVE-2025-47729","kev":true,"vendor":"TeleMessage","product":"TM SGNL","name":"TeleMessage TM SGNL Hidden Functionality Vulnerability","added":"2025-05-12","due":"2025-06-02","ransomware":false,"epss":0.00447,"pct":0.36632,"cvss":[]},{"id":"CVE-2024-11120","kev":true,"vendor":"GeoVision","product":"Multiple Devices","name":"GeoVision Devices OS Command Injection Vulnerability","added":"2025-05-07","due":"2025-05-28","ransomware":false,"epss":0.28386,"pct":0.98076,"cvss":[]},{"id":"CVE-2024-6047","kev":true,"vendor":"GeoVision","product":"Multiple Devices","name":"GeoVision Devices OS Command Injection Vulnerability","added":"2025-05-07","due":"2025-05-28","ransomware":false,"epss":0.10072,"pct":0.95505,"cvss":[]},{"id":"CVE-2025-27363","kev":true,"vendor":"FreeType","product":"FreeType","name":"FreeType Out-of-Bounds Write Vulnerability","added":"2025-05-06","due":"2025-05-27","ransomware":false,"epss":0.27775,"pct":0.98041,"cvss":[]},{"id":"CVE-2025-3248","kev":true,"vendor":"Langflow","product":"Langflow","name":"Langflow Missing Authentication Vulnerability","added":"2025-05-05","due":"2025-05-26","ransomware":true,"epss":0.99993,"pct":0.99987,"cvss":[]},{"id":"CVE-2025-34028","kev":true,"vendor":"Commvault","product":"Command Center","name":"Commvault Command Center Path Traversal Vulnerability","added":"2025-05-02","due":"2025-05-23","ransomware":false,"epss":0.97604,"pct":0.99902,"cvss":[]},{"id":"CVE-2024-58136","kev":true,"vendor":"Yiiframework","product":"Yii","name":"Yiiframework Yii Improper Protection of Alternate Path Vulnerability","added":"2025-05-02","due":"2025-05-23","ransomware":false,"epss":0.87757,"pct":0.99758,"cvss":[]},{"id":"CVE-2024-38475","kev":true,"vendor":"Apache","product":"HTTP Server","name":"Apache HTTP Server Improper Escaping of Output Vulnerability","added":"2025-05-01","due":"2025-05-22","ransomware":false,"epss":0.99957,"pct":0.99975,"cvss":[]},{"id":"CVE-2023-44221","kev":true,"vendor":"SonicWall","product":"SMA100 Appliances","name":"SonicWall SMA100 Appliances OS Command Injection Vulnerability","added":"2025-05-01","due":"2025-05-22","ransomware":false,"epss":0.7625,"pct":0.99524,"cvss":[]},{"id":"CVE-2025-31324","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Unrestricted File Upload Vulnerability","added":"2025-04-29","due":"2025-05-20","ransomware":true,"epss":0.99486,"pct":0.99944,"cvss":[]},{"id":"CVE-2025-1976","kev":true,"vendor":"Broadcom","product":"Brocade Fabric OS","name":"Broadcom Brocade Fabric OS Code Injection Vulnerability","added":"2025-04-28","due":"2025-05-19","ransomware":false,"epss":0.0069,"pct":0.51135,"cvss":[]},{"id":"CVE-2025-42599","kev":true,"vendor":"Qualitia","product":"Active! Mail","name":"Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability","added":"2025-04-28","due":"2025-05-19","ransomware":false,"epss":0.03298,"pct":0.88128,"cvss":[]},{"id":"CVE-2025-3928","kev":true,"vendor":"Commvault","product":"Web Server","name":"Commvault Web Server Unspecified Vulnerability","added":"2025-04-28","due":"2025-05-19","ransomware":false,"epss":0.02299,"pct":0.82706,"cvss":[]},{"id":"CVE-2025-24054","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability","added":"2025-04-17","due":"2025-05-08","ransomware":false,"epss":0.58909,"pct":0.99088,"cvss":[]},{"id":"CVE-2025-31201","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Arbitrary Read and Write Vulnerability","added":"2025-04-17","due":"2025-05-08","ransomware":false,"epss":0.13973,"pct":0.96447,"cvss":[]},{"id":"CVE-2025-31200","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2025-04-17","due":"2025-05-08","ransomware":false,"epss":0.18751,"pct":0.97201,"cvss":[]},{"id":"CVE-2021-20035","kev":true,"vendor":"SonicWall","product":"SMA100 Appliances","name":"SonicWall SMA100 Appliances OS Command Injection Vulnerability","added":"2025-04-16","due":"2025-05-07","ransomware":false,"epss":0.04181,"pct":0.90623,"cvss":[]},{"id":"CVE-2024-53150","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Out-of-Bounds Read Vulnerability","added":"2025-04-09","due":"2025-04-30","ransomware":false,"epss":0.01354,"pct":0.70637,"cvss":[]},{"id":"CVE-2024-53197","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Out-of-Bounds Access Vulnerability","added":"2025-04-09","due":"2025-04-30","ransomware":false,"epss":0.04117,"pct":0.90483,"cvss":[]},{"id":"CVE-2025-29824","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability","added":"2025-04-08","due":"2025-04-29","ransomware":true,"epss":0.13904,"pct":0.96435,"cvss":[]},{"id":"CVE-2025-30406","kev":true,"vendor":"Gladinet","product":"CentreStack","name":"Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability","added":"2025-04-08","due":"2025-04-29","ransomware":false,"epss":0.94343,"pct":0.9985,"cvss":[]},{"id":"CVE-2025-31161","kev":true,"vendor":"CrushFTP","product":"CrushFTP","name":"CrushFTP Authentication Bypass Vulnerability","added":"2025-04-07","due":"2025-04-28","ransomware":true,"epss":0.99966,"pct":0.99976,"cvss":[]},{"id":"CVE-2025-22457","kev":true,"vendor":"Ivanti","product":"Connect Secure, Policy Secure, and ZTA Gateways","name":"Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability","added":"2025-04-04","due":"2025-04-11","ransomware":true,"epss":0.99981,"pct":0.99981,"cvss":[]},{"id":"CVE-2025-24813","kev":true,"vendor":"Apache","product":"Tomcat","name":"Apache Tomcat Path Equivalence Vulnerability","added":"2025-04-01","due":"2025-04-22","ransomware":false,"epss":0.99927,"pct":0.99969,"cvss":[]},{"id":"CVE-2024-20439","kev":true,"vendor":"Cisco","product":"Smart Licensing Utility","name":"Cisco Smart Licensing Utility Static Credential Vulnerability","added":"2025-03-31","due":"2025-04-21","ransomware":false,"epss":0.9709,"pct":0.99892,"cvss":[]},{"id":"CVE-2025-2783","kev":true,"vendor":"Google","product":"Chromium Mojo","name":"Google Chromium Mojo Sandbox Escape Vulnerability","added":"2025-03-27","due":"2025-04-17","ransomware":false,"epss":0.09238,"pct":0.95218,"cvss":[]},{"id":"CVE-2019-9875","kev":true,"vendor":"Sitecore","product":"CMS and Experience Platform (XP)","name":"Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability","added":"2025-03-26","due":"2025-04-16","ransomware":false,"epss":0.13795,"pct":0.96414,"cvss":[]},{"id":"CVE-2019-9874","kev":true,"vendor":"Sitecore","product":"CMS and Experience Platform (XP)","name":"Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability","added":"2025-03-26","due":"2025-04-16","ransomware":false,"epss":0.83736,"pct":0.99684,"cvss":[]},{"id":"CVE-2025-30154","kev":true,"vendor":"reviewdog","product":"action-setup GitHub Action","name":"reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability","added":"2025-03-24","due":"2025-04-14","ransomware":false,"epss":0.02437,"pct":0.83729,"cvss":[]},{"id":"CVE-2017-12637","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Directory Traversal Vulnerability","added":"2025-03-19","due":"2025-04-09","ransomware":false,"epss":0.95111,"pct":0.99863,"cvss":[]},{"id":"CVE-2024-48248","kev":true,"vendor":"NAKIVO","product":"Backup and Replication","name":"NAKIVO Backup and Replication Absolute Path Traversal Vulnerability","added":"2025-03-19","due":"2025-04-09","ransomware":false,"epss":0.94356,"pct":0.99851,"cvss":[]},{"id":"CVE-2025-1316","kev":true,"vendor":"Edimax","product":"IC-7100 IP Camera","name":"Edimax IC-7100 IP Camera OS Command Injection Vulnerability","added":"2025-03-19","due":"2025-04-09","ransomware":false,"epss":0.74482,"pct":0.99484,"cvss":[]},{"id":"CVE-2025-30066","kev":true,"vendor":"tj-actions","product":"changed-files GitHub Action","name":"tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability","added":"2025-03-18","due":"2025-04-08","ransomware":false,"epss":0.72092,"pct":0.99418,"cvss":[]},{"id":"CVE-2025-24472","kev":true,"vendor":"Fortinet","product":"FortiOS and FortiProxy","name":"Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability","added":"2025-03-18","due":"2025-04-08","ransomware":true,"epss":0.07235,"pct":0.94153,"cvss":[]},{"id":"CVE-2025-21590","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability","added":"2025-03-13","due":"2025-04-03","ransomware":false,"epss":0.01749,"pct":0.77063,"cvss":[]},{"id":"CVE-2025-24201","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability","added":"2025-03-13","due":"2025-04-03","ransomware":false,"epss":0.03847,"pct":0.89825,"cvss":[]},{"id":"CVE-2025-24993","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability","added":"2025-03-11","due":"2025-04-01","ransomware":false,"epss":0.02216,"pct":0.82041,"cvss":[]},{"id":"CVE-2025-24991","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability","added":"2025-03-11","due":"2025-04-01","ransomware":false,"epss":0.02018,"pct":0.80252,"cvss":[]},{"id":"CVE-2025-24985","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability","added":"2025-03-11","due":"2025-04-01","ransomware":false,"epss":0.03922,"pct":0.90029,"cvss":[]},{"id":"CVE-2025-24984","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NTFS Information Disclosure Vulnerability","added":"2025-03-11","due":"2025-04-01","ransomware":false,"epss":0.01994,"pct":0.79981,"cvss":[]},{"id":"CVE-2025-24983","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Win32k Use-After-Free Vulnerability","added":"2025-03-11","due":"2025-04-01","ransomware":false,"epss":0.01375,"pct":0.71079,"cvss":[]},{"id":"CVE-2025-26633","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability","added":"2025-03-11","due":"2025-04-01","ransomware":true,"epss":0.30391,"pct":0.98187,"cvss":[]},{"id":"CVE-2024-13161","kev":true,"vendor":"Ivanti","product":"Endpoint Manager (EPM)","name":"Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability","added":"2025-03-10","due":"2025-03-31","ransomware":false,"epss":0.90081,"pct":0.99794,"cvss":[]},{"id":"CVE-2024-13160","kev":true,"vendor":"Ivanti","product":"Endpoint Manager (EPM)","name":"Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability","added":"2025-03-10","due":"2025-03-31","ransomware":false,"epss":0.91247,"pct":0.99808,"cvss":[]},{"id":"CVE-2024-13159","kev":true,"vendor":"Ivanti","product":"Endpoint Manager (EPM)","name":"Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability","added":"2025-03-10","due":"2025-03-31","ransomware":false,"epss":0.99992,"pct":0.99987,"cvss":[]},{"id":"CVE-2024-57968","kev":true,"vendor":"Advantive","product":"VeraCore","name":"Advantive VeraCore Unrestricted File Upload Vulnerability","added":"2025-03-10","due":"2025-03-31","ransomware":false,"epss":0.32284,"pct":0.98281,"cvss":[]},{"id":"CVE-2025-25181","kev":true,"vendor":"Advantive","product":"VeraCore","name":"Advantive VeraCore SQL Injection Vulnerability","added":"2025-03-10","due":"2025-03-31","ransomware":false,"epss":0.55549,"pct":0.99013,"cvss":[]},{"id":"CVE-2025-22226","kev":true,"vendor":"VMware","product":"ESXi, Workstation, and Fusion","name":"VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability","added":"2025-03-04","due":"2025-03-25","ransomware":false,"epss":0.01769,"pct":0.77358,"cvss":[]},{"id":"CVE-2025-22225","kev":true,"vendor":"VMware","product":"ESXi","name":"VMware ESXi Arbitrary Write Vulnerability","added":"2025-03-04","due":"2025-03-25","ransomware":true,"epss":0.01016,"pct":0.62068,"cvss":[]},{"id":"CVE-2025-22224","kev":true,"vendor":"VMware","product":"ESXi and Workstation","name":"VMware ESXi and Workstation TOCTOU Race Condition Vulnerability","added":"2025-03-04","due":"2025-03-25","ransomware":false,"epss":0.01561,"pct":0.74387,"cvss":[]},{"id":"CVE-2024-50302","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Use of Uninitialized Resource Vulnerability","added":"2025-03-04","due":"2025-03-25","ransomware":false,"epss":0.00811,"pct":0.55467,"cvss":[]},{"id":"CVE-2024-4885","kev":true,"vendor":"Progress","product":"WhatsUp Gold","name":"Progress WhatsUp Gold Path Traversal Vulnerability","added":"2025-03-03","due":"2025-03-24","ransomware":false,"epss":0.99288,"pct":0.99937,"cvss":[]},{"id":"CVE-2018-8639","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability","added":"2025-03-03","due":"2025-03-24","ransomware":true,"epss":0.22179,"pct":0.97613,"cvss":[]},{"id":"CVE-2022-43769","kev":true,"vendor":"Hitachi Vantara","product":"Pentaho Business Analytics (BA) Server","name":"Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability","added":"2025-03-03","due":"2025-03-24","ransomware":false,"epss":0.9767,"pct":0.99903,"cvss":[]},{"id":"CVE-2022-43939","kev":true,"vendor":"Hitachi Vantara","product":"Pentaho Business Analytics (BA) Server","name":"Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability","added":"2025-03-03","due":"2025-03-24","ransomware":false,"epss":0.92266,"pct":0.99821,"cvss":[]},{"id":"CVE-2023-20118","kev":true,"vendor":"Cisco","product":"Small Business RV Series Routers","name":"Cisco Small Business RV Series Routers Command Injection Vulnerability","added":"2025-03-03","due":"2025-03-24","ransomware":false,"epss":0.54107,"pct":0.9898,"cvss":[]},{"id":"CVE-2023-34192","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability","added":"2025-02-25","due":"2025-03-18","ransomware":false,"epss":0.77266,"pct":0.99544,"cvss":[]},{"id":"CVE-2024-49035","kev":true,"vendor":"Microsoft","product":"Partner Center","name":"Microsoft Partner Center Improper Access Control Vulnerability","added":"2025-02-25","due":"2025-03-18","ransomware":false,"epss":0.013,"pct":0.69467,"cvss":[]},{"id":"CVE-2024-20953","kev":true,"vendor":"Oracle","product":"Agile Product Lifecycle Management (PLM)","name":"Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability","added":"2025-02-24","due":"2025-03-17","ransomware":false,"epss":0.03934,"pct":0.90067,"cvss":[]},{"id":"CVE-2017-3066","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Deserialization Vulnerability","added":"2025-02-24","due":"2025-03-17","ransomware":false,"epss":0.90597,"pct":0.99801,"cvss":[]},{"id":"CVE-2025-24989","kev":true,"vendor":"Microsoft","product":"Power Pages","name":"Microsoft Power Pages Improper Access Control Vulnerability","added":"2025-02-21","due":"2025-03-14","ransomware":false,"epss":0.01622,"pct":0.75275,"cvss":[]},{"id":"CVE-2025-0111","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS File Read Vulnerability","added":"2025-02-20","due":"2025-03-13","ransomware":false,"epss":0.01999,"pct":0.80028,"cvss":[]},{"id":"CVE-2025-23209","kev":true,"vendor":"Craft CMS","product":"Craft CMS","name":"Craft CMS Code Injection Vulnerability","added":"2025-02-20","due":"2025-03-13","ransomware":false,"epss":0.21776,"pct":0.97578,"cvss":[]},{"id":"CVE-2025-0108","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","added":"2025-02-18","due":"2025-03-11","ransomware":false,"epss":0.98455,"pct":0.99918,"cvss":[]},{"id":"CVE-2024-53704","kev":true,"vendor":"SonicWall","product":"SonicOS","name":"SonicWall SonicOS SSLVPN Improper Authentication Vulnerability","added":"2025-02-18","due":"2025-03-11","ransomware":true,"epss":0.95132,"pct":0.99864,"cvss":[]},{"id":"CVE-2024-57727","kev":true,"vendor":"SimpleHelp","product":"SimpleHelp","name":"SimpleHelp Path Traversal Vulnerability","added":"2025-02-13","due":"2025-03-06","ransomware":true,"epss":0.96576,"pct":0.99882,"cvss":[]},{"id":"CVE-2025-24200","kev":true,"vendor":"Apple","product":"iOS and iPadOS","name":"Apple iOS and iPadOS Incorrect Authorization Vulnerability","added":"2025-02-12","due":"2025-03-05","ransomware":false,"epss":0.0442,"pct":0.91063,"cvss":[]},{"id":"CVE-2024-41710","kev":true,"vendor":"Mitel","product":"SIP Phones","name":"Mitel SIP Phones Argument Injection Vulnerability","added":"2025-02-12","due":"2025-03-05","ransomware":false,"epss":0.41646,"pct":0.98645,"cvss":[]},{"id":"CVE-2024-40891","kev":true,"vendor":"Zyxel","product":"DSL CPE Devices","name":"Zyxel DSL CPE OS Command Injection Vulnerability","added":"2025-02-11","due":"2025-03-04","ransomware":false,"epss":0.21536,"pct":0.97558,"cvss":[]},{"id":"CVE-2024-40890","kev":true,"vendor":"Zyxel","product":"DSL CPE Devices","name":"Zyxel DSL CPE OS Command Injection Vulnerability","added":"2025-02-11","due":"2025-03-04","ransomware":false,"epss":0.20703,"pct":0.97469,"cvss":[]},{"id":"CVE-2025-21418","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability","added":"2025-02-11","due":"2025-03-04","ransomware":false,"epss":0.01568,"pct":0.74487,"cvss":[]},{"id":"CVE-2025-21391","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Storage Link Following Vulnerability","added":"2025-02-11","due":"2025-03-04","ransomware":false,"epss":0.02303,"pct":0.8274,"cvss":[]},{"id":"CVE-2025-0994","kev":true,"vendor":"Trimble","product":"Cityworks","name":"Trimble Cityworks Deserialization Vulnerability","added":"2025-02-07","due":"2025-02-28","ransomware":false,"epss":0.31085,"pct":0.98221,"cvss":[]},{"id":"CVE-2020-15069","kev":true,"vendor":"Sophos","product":"XG Firewall","name":"Sophos XG Firewall Buffer Overflow Vulnerability","added":"2025-02-06","due":"2025-02-27","ransomware":false,"epss":0.10674,"pct":0.95685,"cvss":[]},{"id":"CVE-2020-29574","kev":true,"vendor":"Sophos","product":"CyberoamOS","name":"CyberoamOS (CROS) SQL Injection Vulnerability","added":"2025-02-06","due":"2025-02-27","ransomware":true,"epss":0.04658,"pct":0.91476,"cvss":[]},{"id":"CVE-2024-21413","kev":true,"vendor":"Microsoft","product":"Office Outlook","name":"Microsoft Outlook Improper Input Validation Vulnerability","added":"2025-02-06","due":"2025-02-27","ransomware":false,"epss":0.9466,"pct":0.99856,"cvss":[]},{"id":"CVE-2022-23748","kev":true,"vendor":"Audinate","product":"Dante Discovery","name":"Dante Discovery Process Control Vulnerability","added":"2025-02-06","due":"2025-02-27","ransomware":false,"epss":0.09092,"pct":0.95164,"cvss":[]},{"id":"CVE-2025-0411","kev":true,"vendor":"7-Zip","product":"7-Zip","name":"7-Zip Mark of the Web Bypass Vulnerability","added":"2025-02-06","due":"2025-02-27","ransomware":false,"epss":0.67071,"pct":0.99283,"cvss":[]},{"id":"CVE-2024-53104","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Out-of-Bounds Write Vulnerability","added":"2025-02-05","due":"2025-02-26","ransomware":false,"epss":0.03395,"pct":0.88449,"cvss":[]},{"id":"CVE-2018-19410","kev":true,"vendor":"Paessler","product":"PRTG Network Monitor","name":"Paessler PRTG Network Monitor Local File Inclusion Vulnerability","added":"2025-02-04","due":"2025-02-25","ransomware":false,"epss":0.97939,"pct":0.99909,"cvss":[]},{"id":"CVE-2018-9276","kev":true,"vendor":"Paessler","product":"PRTG Network Monitor","name":"Paessler PRTG Network Monitor OS Command Injection Vulnerability","added":"2025-02-04","due":"2025-02-25","ransomware":false,"epss":0.86996,"pct":0.99744,"cvss":[]},{"id":"CVE-2024-29059","kev":true,"vendor":"Microsoft","product":".NET Framework","name":"Microsoft .NET Framework Information Disclosure Vulnerability","added":"2025-02-04","due":"2025-02-25","ransomware":false,"epss":0.98624,"pct":0.99922,"cvss":[]},{"id":"CVE-2024-45195","kev":true,"vendor":"Apache","product":"OFBiz","name":"Apache OFBiz Forced Browsing Vulnerability","added":"2025-02-04","due":"2025-02-25","ransomware":false,"epss":0.99983,"pct":0.99982,"cvss":[]},{"id":"CVE-2025-24085","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Use-After-Free Vulnerability","added":"2025-01-29","due":"2025-02-19","ransomware":false,"epss":0.1751,"pct":0.97056,"cvss":[]},{"id":"CVE-2025-23006","kev":true,"vendor":"SonicWall","product":"SMA1000 Appliances","name":"SonicWall SMA1000 Appliances Deserialization Vulnerability","added":"2025-01-24","due":"2025-02-14","ransomware":true,"epss":0.23432,"pct":0.97732,"cvss":[]},{"id":"CVE-2020-11023","kev":true,"vendor":"JQuery","product":"JQuery","name":"JQuery Cross-Site Scripting (XSS) Vulnerability","added":"2025-01-23","due":"2025-02-13","ransomware":false,"epss":0.84887,"pct":0.99707,"cvss":[]},{"id":"CVE-2024-50603","kev":true,"vendor":"Aviatrix","product":"Controllers","name":"Aviatrix Controllers OS Command Injection Vulnerability","added":"2025-01-16","due":"2025-02-06","ransomware":false,"epss":0.98545,"pct":0.99921,"cvss":[]},{"id":"CVE-2025-21335","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability","added":"2025-01-14","due":"2025-02-04","ransomware":false,"epss":0.0139,"pct":0.71384,"cvss":[]},{"id":"CVE-2025-21334","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability","added":"2025-01-14","due":"2025-02-04","ransomware":false,"epss":0.01561,"pct":0.74388,"cvss":[]},{"id":"CVE-2025-21333","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability","added":"2025-01-14","due":"2025-02-04","ransomware":false,"epss":0.09988,"pct":0.95478,"cvss":[]},{"id":"CVE-2024-55591","kev":true,"vendor":"Fortinet","product":"FortiOS and FortiProxy","name":"Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability","added":"2025-01-14","due":"2025-01-21","ransomware":true,"epss":0.94149,"pct":0.99847,"cvss":[]},{"id":"CVE-2023-48365","kev":true,"vendor":"Qlik","product":"Sense","name":"Qlik Sense HTTP Tunneling Vulnerability","added":"2025-01-13","due":"2025-02-03","ransomware":true,"epss":0.47453,"pct":0.98811,"cvss":[]},{"id":"CVE-2024-12686","kev":true,"vendor":"BeyondTrust","product":"Privileged Remote Access (PRA) and Remote Support (RS)","name":"BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability","added":"2025-01-13","due":"2025-02-03","ransomware":false,"epss":0.137,"pct":0.96391,"cvss":[]},{"id":"CVE-2025-0282","kev":true,"vendor":"Ivanti","product":"Connect Secure, Policy Secure, and ZTA Gateways","name":"Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability","added":"2025-01-08","due":"2025-01-15","ransomware":true,"epss":0.99979,"pct":0.9998,"cvss":[]},{"id":"CVE-2020-2883","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Unspecified Vulnerability","added":"2025-01-07","due":"2025-01-28","ransomware":false,"epss":0.94928,"pct":0.9986,"cvss":[]},{"id":"CVE-2024-55550","kev":true,"vendor":"Mitel","product":"MiCollab","name":"Mitel MiCollab Path Traversal Vulnerability","added":"2025-01-07","due":"2025-01-28","ransomware":true,"epss":0.38155,"pct":0.98521,"cvss":[]},{"id":"CVE-2024-41713","kev":true,"vendor":"Mitel","product":"MiCollab","name":"Mitel MiCollab Path Traversal Vulnerability","added":"2025-01-07","due":"2025-01-28","ransomware":true,"epss":0.9811,"pct":0.99911,"cvss":[]},{"id":"CVE-2024-3393","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability","added":"2024-12-30","due":"2025-01-20","ransomware":false,"epss":0.2912,"pct":0.98121,"cvss":[]},{"id":"CVE-2021-44207","kev":true,"vendor":"Acclaim Systems","product":"USAHERDS","name":"Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability","added":"2024-12-23","due":"2025-01-13","ransomware":false,"epss":0.17578,"pct":0.97063,"cvss":[]},{"id":"CVE-2024-12356","kev":true,"vendor":"BeyondTrust","product":"Privileged Remote Access (PRA) and Remote Support (RS)","name":"BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability","added":"2024-12-19","due":"2024-12-27","ransomware":false,"epss":0.87258,"pct":0.99749,"cvss":[]},{"id":"CVE-2021-40407","kev":true,"vendor":"Reolink","product":"RLC-410W IP Camera","name":"Reolink RLC-410W IP Camera OS Command Injection Vulnerability","added":"2024-12-18","due":"2025-01-08","ransomware":false,"epss":0.47635,"pct":0.98815,"cvss":[]},{"id":"CVE-2019-11001","kev":true,"vendor":"Reolink","product":"Multiple IP Cameras","name":"Reolink Multiple IP Cameras OS Command Injection Vulnerability","added":"2024-12-18","due":"2025-01-08","ransomware":false,"epss":0.37542,"pct":0.98496,"cvss":[]},{"id":"CVE-2022-23227","kev":true,"vendor":"NUUO","product":"NVRmini2 Devices","name":"NUUO NVRmini2 Devices Missing Authentication Vulnerability","added":"2024-12-18","due":"2025-01-08","ransomware":false,"epss":0.48497,"pct":0.98834,"cvss":[]},{"id":"CVE-2018-14933","kev":true,"vendor":"NUUO","product":"NVRmini Devices","name":"NUUO NVRmini Devices OS Command Injection Vulnerability","added":"2024-12-18","due":"2025-01-08","ransomware":false,"epss":0.94884,"pct":0.99859,"cvss":[]},{"id":"CVE-2024-55956","kev":true,"vendor":"Cleo","product":"Multiple Products","name":"Cleo Multiple Products Unauthenticated File Upload Vulnerability","added":"2024-12-17","due":"2025-01-07","ransomware":true,"epss":0.93968,"pct":0.99845,"cvss":[]},{"id":"CVE-2024-35250","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability","added":"2024-12-16","due":"2025-01-06","ransomware":false,"epss":0.25222,"pct":0.97882,"cvss":[]},{"id":"CVE-2024-20767","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Improper Access Control Vulnerability","added":"2024-12-16","due":"2025-01-06","ransomware":false,"epss":0.98514,"pct":0.9992,"cvss":[]},{"id":"CVE-2024-50623","kev":true,"vendor":"Cleo","product":"Multiple Products","name":"Cleo Multiple Products Unrestricted File Upload Vulnerability","added":"2024-12-13","due":"2025-01-03","ransomware":true,"epss":0.98607,"pct":0.99922,"cvss":[]},{"id":"CVE-2024-49138","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability","added":"2024-12-10","due":"2024-12-31","ransomware":false,"epss":0.26215,"pct":0.97945,"cvss":[]},{"id":"CVE-2024-51378","kev":true,"vendor":"CyberPersons","product":"CyberPanel","name":"CyberPanel Incorrect Default Permissions Vulnerability","added":"2024-12-04","due":"2024-12-25","ransomware":true,"epss":0.94748,"pct":0.99857,"cvss":[]},{"id":"CVE-2024-11667","kev":true,"vendor":"Zyxel","product":"Multiple Firewalls","name":"Zyxel Multiple Firewalls Path Traversal Vulnerability","added":"2024-12-03","due":"2024-12-24","ransomware":true,"epss":0.02929,"pct":0.86618,"cvss":[]},{"id":"CVE-2024-11680","kev":true,"vendor":"ProjectSend","product":"ProjectSend","name":"ProjectSend Improper Authentication Vulnerability","added":"2024-12-03","due":"2024-12-24","ransomware":false,"epss":0.91697,"pct":0.99814,"cvss":[]},{"id":"CVE-2023-45727","kev":true,"vendor":"North Grid","product":"Proself","name":"North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability","added":"2024-12-03","due":"2024-12-24","ransomware":false,"epss":0.03542,"pct":0.88926,"cvss":[]},{"id":"CVE-2023-28461","kev":true,"vendor":"Array Networks","product":"AG/vxAG ArrayOS","name":"Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability","added":"2024-11-25","due":"2024-12-16","ransomware":true,"epss":0.68079,"pct":0.99309,"cvss":[]},{"id":"CVE-2024-21287","kev":true,"vendor":"Oracle","product":"Agile Product Lifecycle Management (PLM)","name":"Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability","added":"2024-11-21","due":"2024-12-12","ransomware":false,"epss":0.01723,"pct":0.76714,"cvss":[]},{"id":"CVE-2024-44309","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability","added":"2024-11-21","due":"2024-12-12","ransomware":false,"epss":0.2259,"pct":0.97658,"cvss":[]},{"id":"CVE-2024-44308","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Code Execution Vulnerability","added":"2024-11-21","due":"2024-12-12","ransomware":false,"epss":0.10075,"pct":0.95506,"cvss":[]},{"id":"CVE-2024-38813","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Privilege Escalation Vulnerability","added":"2024-11-20","due":"2024-12-11","ransomware":false,"epss":0.17355,"pct":0.97037,"cvss":[]},{"id":"CVE-2024-38812","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Heap-Based Buffer Overflow Vulnerability","added":"2024-11-20","due":"2024-12-11","ransomware":false,"epss":0.54571,"pct":0.98992,"cvss":[]},{"id":"CVE-2024-9474","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability","added":"2024-11-18","due":"2024-12-09","ransomware":true,"epss":0.94824,"pct":0.99859,"cvss":[]},{"id":"CVE-2024-0012","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability","added":"2024-11-18","due":"2024-12-09","ransomware":true,"epss":0.99855,"pct":0.99961,"cvss":[]},{"id":"CVE-2024-1212","kev":true,"vendor":"Progress","product":"Kemp LoadMaster","name":"Progress Kemp LoadMaster OS Command Injection Vulnerability","added":"2024-11-18","due":"2024-12-09","ransomware":false,"epss":0.95388,"pct":0.99868,"cvss":[]},{"id":"CVE-2024-9465","kev":true,"vendor":"Palo Alto Networks","product":"Expedition","name":"Palo Alto Networks Expedition SQL Injection Vulnerability","added":"2024-11-14","due":"2024-12-05","ransomware":false,"epss":0.99626,"pct":0.99948,"cvss":[]},{"id":"CVE-2024-9463","kev":true,"vendor":"Palo Alto Networks","product":"Expedition","name":"Palo Alto Networks Expedition OS Command Injection Vulnerability","added":"2024-11-14","due":"2024-12-05","ransomware":false,"epss":0.98546,"pct":0.99921,"cvss":[]},{"id":"CVE-2021-26086","kev":true,"vendor":"Atlassian","product":"Jira Server and Data Center","name":"Atlassian Jira Server and Data Center Path Traversal Vulnerability","added":"2024-11-12","due":"2024-12-03","ransomware":false,"epss":0.99999,"pct":0.99992,"cvss":[]},{"id":"CVE-2014-2120","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","name":"Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability","added":"2024-11-12","due":"2024-12-03","ransomware":false,"epss":0.22558,"pct":0.97654,"cvss":[]},{"id":"CVE-2021-41277","kev":true,"vendor":"Metabase","product":"Metabase","name":"Metabase GeoJSON API Local File Inclusion Vulnerability","added":"2024-11-12","due":"2024-12-03","ransomware":false,"epss":0.97178,"pct":0.99894,"cvss":[]},{"id":"CVE-2024-43451","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability","added":"2024-11-12","due":"2024-12-03","ransomware":false,"epss":0.84108,"pct":0.99689,"cvss":[]},{"id":"CVE-2024-49039","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Task Scheduler Privilege Escalation Vulnerability","added":"2024-11-12","due":"2024-12-03","ransomware":true,"epss":0.14179,"pct":0.96484,"cvss":[]},{"id":"CVE-2019-16278","kev":true,"vendor":"Nostromo","product":"nhttpd","name":"Nostromo nhttpd Directory Traversal Vulnerability","added":"2024-11-07","due":"2024-11-28","ransomware":false,"epss":0.99033,"pct":0.99931,"cvss":[]},{"id":"CVE-2024-51567","kev":true,"vendor":"CyberPersons","product":"CyberPanel","name":"CyberPanel Incorrect Default Permissions Vulnerability","added":"2024-11-07","due":"2024-11-28","ransomware":true,"epss":0.86633,"pct":0.99736,"cvss":[]},{"id":"CVE-2024-43093","kev":true,"vendor":"Android","product":"Framework","name":"Android Framework Privilege Escalation Vulnerability","added":"2024-11-07","due":"2024-11-28","ransomware":false,"epss":0.00709,"pct":0.51883,"cvss":[]},{"id":"CVE-2024-5910","kev":true,"vendor":"Palo Alto Networks","product":"Expedition","name":"Palo Alto Networks Expedition Missing Authentication Vulnerability","added":"2024-11-07","due":"2024-11-28","ransomware":false,"epss":0.91684,"pct":0.99814,"cvss":[]},{"id":"CVE-2024-8956","kev":true,"vendor":"PTZOptics","product":"PT30X-SDI/NDI Cameras","name":"PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability","added":"2024-11-04","due":"2024-11-25","ransomware":false,"epss":0.58787,"pct":0.99084,"cvss":[]},{"id":"CVE-2024-8957","kev":true,"vendor":"PTZOptics","product":"PT30X-SDI/NDI Cameras","name":"PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability","added":"2024-11-04","due":"2024-11-25","ransomware":false,"epss":0.79703,"pct":0.996,"cvss":[]},{"id":"CVE-2024-37383","kev":true,"vendor":"Roundcube","product":"Webmail","name":"RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability","added":"2024-10-24","due":"2024-11-14","ransomware":false,"epss":0.73296,"pct":0.9945,"cvss":[]},{"id":"CVE-2024-20481","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","name":"Cisco ASA and FTD Denial-of-Service Vulnerability","added":"2024-10-24","due":"2024-11-14","ransomware":false,"epss":0.15874,"pct":0.96795,"cvss":[]},{"id":"CVE-2024-47575","kev":true,"vendor":"Fortinet","product":"FortiManager","name":"Fortinet FortiManager Missing Authentication Vulnerability","added":"2024-10-23","due":"2024-11-13","ransomware":false,"epss":0.94766,"pct":0.99858,"cvss":[]},{"id":"CVE-2024-38094","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Deserialization Vulnerability","added":"2024-10-22","due":"2024-11-12","ransomware":true,"epss":0.50892,"pct":0.98898,"cvss":[]},{"id":"CVE-2024-9537","kev":true,"vendor":"ScienceLogic","product":"SL1","name":"ScienceLogic SL1 Unspecified Vulnerability","added":"2024-10-21","due":"2024-11-11","ransomware":false,"epss":0.03826,"pct":0.89766,"cvss":[]},{"id":"CVE-2024-40711","kev":true,"vendor":"Veeam","product":"Backup & Replication","name":"Veeam Backup and Replication Deserialization Vulnerability","added":"2024-10-17","due":"2024-11-07","ransomware":true,"epss":0.90369,"pct":0.99798,"cvss":[]},{"id":"CVE-2024-28987","kev":true,"vendor":"SolarWinds","product":"Web Help Desk","name":"SolarWinds Web Help Desk Hardcoded Credential Vulnerability","added":"2024-10-15","due":"2024-11-05","ransomware":false,"epss":0.93299,"pct":0.99836,"cvss":[]},{"id":"CVE-2024-9680","kev":true,"vendor":"Mozilla","product":"Firefox","name":"Mozilla Firefox Use-After-Free Vulnerability","added":"2024-10-15","due":"2024-11-05","ransomware":true,"epss":0.23184,"pct":0.97711,"cvss":[]},{"id":"CVE-2024-30088","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel TOCTOU Race Condition Vulnerability","added":"2024-10-15","due":"2024-11-05","ransomware":true,"epss":0.68202,"pct":0.99313,"cvss":[]},{"id":"CVE-2024-9380","kev":true,"vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","name":"Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability","added":"2024-10-09","due":"2024-10-30","ransomware":false,"epss":0.59651,"pct":0.99106,"cvss":[]},{"id":"CVE-2024-9379","kev":true,"vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","name":"Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability","added":"2024-10-09","due":"2024-10-30","ransomware":false,"epss":0.43782,"pct":0.98709,"cvss":[]},{"id":"CVE-2024-23113","kev":true,"vendor":"Fortinet","product":"Multiple Products","name":"Fortinet Multiple Products Format String Vulnerability","added":"2024-10-09","due":"2024-10-30","ransomware":false,"epss":0.61725,"pct":0.9915,"cvss":[]},{"id":"CVE-2024-43573","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows MSHTML Platform Spoofing Vulnerability","added":"2024-10-08","due":"2024-10-29","ransomware":false,"epss":0.46109,"pct":0.98777,"cvss":[]},{"id":"CVE-2024-43572","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Management Console Remote Code Execution Vulnerability","added":"2024-10-08","due":"2024-10-29","ransomware":false,"epss":0.66695,"pct":0.99272,"cvss":[]},{"id":"CVE-2024-43047","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Use-After-Free Vulnerability","added":"2024-10-08","due":"2024-10-29","ransomware":false,"epss":0.00674,"pct":0.50452,"cvss":[]},{"id":"CVE-2024-45519","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability","added":"2024-10-03","due":"2024-10-24","ransomware":false,"epss":0.99907,"pct":0.99966,"cvss":[]},{"id":"CVE-2024-29824","kev":true,"vendor":"Ivanti","product":"Endpoint Manager (EPM)","name":"Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability","added":"2024-10-02","due":"2024-10-23","ransomware":false,"epss":0.99938,"pct":0.99972,"cvss":[]},{"id":"CVE-2019-0344","kev":true,"vendor":"SAP","product":"Commerce Cloud","name":"SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability","added":"2024-09-30","due":"2024-10-21","ransomware":false,"epss":0.07079,"pct":0.94038,"cvss":[]},{"id":"CVE-2020-15415","kev":true,"vendor":"DrayTek","product":"Multiple Vigor Routers","name":"DrayTek Multiple Vigor Routers OS Command Injection Vulnerability","added":"2024-09-30","due":"2024-10-21","ransomware":false,"epss":0.8448,"pct":0.99696,"cvss":[]},{"id":"CVE-2023-25280","kev":true,"vendor":"D-Link","product":"DIR-820 Router","name":"D-Link DIR-820 Router OS Command Injection Vulnerability","added":"2024-09-30","due":"2024-10-21","ransomware":false,"epss":0.97864,"pct":0.99908,"cvss":[]},{"id":"CVE-2024-7593","kev":true,"vendor":"Ivanti","product":"Virtual Traffic Manager","name":"Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability","added":"2024-09-24","due":"2024-10-15","ransomware":false,"epss":0.99999,"pct":0.99991,"cvss":[]},{"id":"CVE-2024-8963","kev":true,"vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","name":"Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability","added":"2024-09-19","due":"2024-10-10","ransomware":false,"epss":0.98607,"pct":0.99922,"cvss":[]},{"id":"CVE-2020-14644","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Remote Code Execution Vulnerability","added":"2024-09-18","due":"2024-10-09","ransomware":false,"epss":0.94548,"pct":0.99853,"cvss":[]},{"id":"CVE-2022-21445","kev":true,"vendor":"Oracle","product":"ADF Faces","name":"Oracle ADF Faces Deserialization of Untrusted Data Vulnerability","added":"2024-09-18","due":"2024-10-09","ransomware":false,"epss":0.62478,"pct":0.99168,"cvss":[]},{"id":"CVE-2020-0618","kev":true,"vendor":"Microsoft","product":"SQL Server","name":"Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability","added":"2024-09-18","due":"2024-10-09","ransomware":true,"epss":0.99022,"pct":0.99931,"cvss":[]},{"id":"CVE-2024-27348","kev":true,"vendor":"Apache","product":"HugeGraph-Server","name":"Apache HugeGraph-Server Improper Access Control Vulnerability","added":"2024-09-18","due":"2024-10-09","ransomware":false,"epss":0.9921,"pct":0.99935,"cvss":[]},{"id":"CVE-2014-0502","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Double Free Vulnerablity","added":"2024-09-17","due":"2024-10-08","ransomware":false,"epss":0.24817,"pct":0.97847,"cvss":[]},{"id":"CVE-2013-0648","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Code Execution Vulnerability","added":"2024-09-17","due":"2024-10-08","ransomware":false,"epss":0.11094,"pct":0.95809,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2013-02-27T00:55:01.160Z","modified":"2026-06-16T23:49:50.320Z"},{"id":"CVE-2013-0643","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Incorrect Default Permissions Vulnerability","added":"2024-09-17","due":"2024-10-08","ransomware":false,"epss":0.10533,"pct":0.95646,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2013-02-27T00:55:01.017Z","modified":"2026-06-16T23:49:49.607Z"},{"id":"CVE-2014-0497","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Integer Underflow Vulnerablity","added":"2024-09-17","due":"2024-10-08","ransomware":false,"epss":0.99879,"pct":0.99964,"cvss":[]},{"id":"CVE-2024-6670","kev":true,"vendor":"Progress","product":"WhatsUp Gold","name":"Progress WhatsUp Gold SQL Injection Vulnerability","added":"2024-09-16","due":"2024-10-07","ransomware":true,"epss":0.93,"pct":0.99831,"cvss":[]},{"id":"CVE-2024-43461","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows MSHTML Platform Spoofing Vulnerability","added":"2024-09-16","due":"2024-10-07","ransomware":false,"epss":0.54486,"pct":0.98988,"cvss":[]},{"id":"CVE-2024-8190","kev":true,"vendor":"Ivanti","product":"Cloud Services Appliance","name":"Ivanti Cloud Services Appliance OS Command Injection Vulnerability","added":"2024-09-13","due":"2024-10-04","ransomware":false,"epss":0.88535,"pct":0.99771,"cvss":[]},{"id":"CVE-2024-38217","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability","added":"2024-09-10","due":"2024-10-01","ransomware":false,"epss":0.10026,"pct":0.95489,"cvss":[]},{"id":"CVE-2024-38014","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Installer Improper Privilege Management Vulnerability","added":"2024-09-10","due":"2024-10-01","ransomware":false,"epss":0.06263,"pct":0.93368,"cvss":[]},{"id":"CVE-2024-38226","kev":true,"vendor":"Microsoft","product":"Publisher","name":"Microsoft Publisher Protection Mechanism Failure Vulnerability","added":"2024-09-10","due":"2024-10-01","ransomware":false,"epss":0.02667,"pct":0.85236,"cvss":[]},{"id":"CVE-2024-40766","kev":true,"vendor":"SonicWall","product":"SonicOS","name":"SonicWall SonicOS Improper Access Control Vulnerability","added":"2024-09-09","due":"2024-09-30","ransomware":true,"epss":0.18379,"pct":0.97153,"cvss":[]},{"id":"CVE-2017-1000253","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel PIE Stack Buffer Corruption Vulnerability","added":"2024-09-09","due":"2024-09-30","ransomware":true,"epss":0.10695,"pct":0.95694,"cvss":[]},{"id":"CVE-2016-3714","kev":true,"vendor":"ImageMagick","product":"ImageMagick","name":"ImageMagick Improper Input Validation Vulnerability","added":"2024-09-09","due":"2024-09-30","ransomware":false,"epss":0.97485,"pct":0.999,"cvss":[]},{"id":"CVE-2024-7262","kev":true,"vendor":"Kingsoft","product":"WPS Office","name":"Kingsoft WPS Office Path Traversal Vulnerability","added":"2024-09-03","due":"2024-09-24","ransomware":false,"epss":0.02937,"pct":0.86643,"cvss":[]},{"id":"CVE-2021-20124","kev":true,"vendor":"DrayTek","product":"VigorConnect","name":"Draytek VigorConnect Path Traversal Vulnerability","added":"2024-09-03","due":"2024-09-24","ransomware":false,"epss":0.96308,"pct":0.99879,"cvss":[]},{"id":"CVE-2021-20123","kev":true,"vendor":"DrayTek","product":"VigorConnect","name":"Draytek VigorConnect Path Traversal Vulnerability","added":"2024-09-03","due":"2024-09-24","ransomware":false,"epss":0.90234,"pct":0.99796,"cvss":[]},{"id":"CVE-2024-7965","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Inappropriate Implementation Vulnerability","added":"2024-08-28","due":"2024-09-18","ransomware":false,"epss":0.18528,"pct":0.97176,"cvss":[]},{"id":"CVE-2024-38856","kev":true,"vendor":"Apache","product":"OFBiz","name":"Apache OFBiz Incorrect Authorization Vulnerability","added":"2024-08-27","due":"2024-09-17","ransomware":false,"epss":0.99427,"pct":0.99942,"cvss":[]},{"id":"CVE-2024-7971","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2024-08-26","due":"2024-09-16","ransomware":false,"epss":0.21103,"pct":0.97517,"cvss":[]},{"id":"CVE-2024-39717","kev":true,"vendor":"Versa","product":"Director","name":"Versa Director Dangerous File Type Upload Vulnerability","added":"2024-08-23","due":"2024-09-13","ransomware":false,"epss":0.04006,"pct":0.90247,"cvss":[]},{"id":"CVE-2021-31196","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Information Disclosure Vulnerability","added":"2024-08-21","due":"2024-09-11","ransomware":false,"epss":0.54056,"pct":0.98978,"cvss":[]},{"id":"CVE-2022-0185","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Heap-Based Buffer Overflow Vulnerability","added":"2024-08-21","due":"2024-09-11","ransomware":false,"epss":0.25151,"pct":0.97879,"cvss":[]},{"id":"CVE-2021-33045","kev":true,"vendor":"Dahua","product":"IP Camera Firmware","name":"Dahua IP Camera Authentication Bypass Vulnerability","added":"2024-08-21","due":"2024-09-11","ransomware":false,"epss":0.99593,"pct":0.99946,"cvss":[]},{"id":"CVE-2021-33044","kev":true,"vendor":"Dahua","product":"IP Camera Firmware","name":"Dahua IP Camera Authentication Bypass Vulnerability","added":"2024-08-21","due":"2024-09-11","ransomware":false,"epss":0.99987,"pct":0.99984,"cvss":[]},{"id":"CVE-2024-23897","kev":true,"vendor":"Jenkins","product":"Jenkins Command Line Interface (CLI)","name":"Jenkins Command Line Interface (CLI) Path Traversal Vulnerability","added":"2024-08-19","due":"2024-09-09","ransomware":true,"epss":0.99999,"pct":0.99995,"cvss":[]},{"id":"CVE-2024-28986","kev":true,"vendor":"SolarWinds","product":"Web Help Desk","name":"SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability","added":"2024-08-15","due":"2024-09-05","ransomware":false,"epss":0.84628,"pct":0.997,"cvss":[]},{"id":"CVE-2024-38107","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability","added":"2024-08-13","due":"2024-09-03","ransomware":false,"epss":0.01635,"pct":0.75476,"cvss":[]},{"id":"CVE-2024-38106","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2024-08-13","due":"2024-09-03","ransomware":false,"epss":0.06337,"pct":0.93434,"cvss":[]},{"id":"CVE-2024-38193","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability","added":"2024-08-13","due":"2024-09-03","ransomware":false,"epss":0.28739,"pct":0.98095,"cvss":[]},{"id":"CVE-2024-38213","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SmartScreen Security Feature Bypass Vulnerability","added":"2024-08-13","due":"2024-09-03","ransomware":false,"epss":0.13626,"pct":0.96374,"cvss":[]},{"id":"CVE-2024-38178","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Scripting Engine Memory Corruption Vulnerability","added":"2024-08-13","due":"2024-09-03","ransomware":false,"epss":0.4138,"pct":0.98637,"cvss":[]},{"id":"CVE-2024-38189","kev":true,"vendor":"Microsoft","product":"Project","name":"Microsoft Project Remote Code Execution Vulnerability","added":"2024-08-13","due":"2024-09-03","ransomware":false,"epss":0.08194,"pct":0.94719,"cvss":[]},{"id":"CVE-2024-32113","kev":true,"vendor":"Apache","product":"OFBiz","name":"Apache OFBiz Path Traversal Vulnerability","added":"2024-08-07","due":"2024-08-28","ransomware":false,"epss":0.99919,"pct":0.99968,"cvss":[]},{"id":"CVE-2024-36971","kev":true,"vendor":"Android","product":"Kernel","name":"Android Kernel Remote Code Execution Vulnerability","added":"2024-08-07","due":"2024-08-28","ransomware":false,"epss":0.02701,"pct":0.85438,"cvss":[]},{"id":"CVE-2018-0824","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability","added":"2024-08-05","due":"2024-08-26","ransomware":false,"epss":0.73185,"pct":0.99446,"cvss":[]},{"id":"CVE-2024-37085","kev":true,"vendor":"VMware","product":"ESXi","name":"VMware ESXi Authentication Bypass Vulnerability","added":"2024-07-30","due":"2024-08-20","ransomware":true,"epss":0.2677,"pct":0.97977,"cvss":[]},{"id":"CVE-2023-45249","kev":true,"vendor":"Acronis","product":"Cyber Infrastructure (ACI)","name":"Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability","added":"2024-07-29","due":"2024-08-19","ransomware":false,"epss":0.53255,"pct":0.98955,"cvss":[]},{"id":"CVE-2024-5217","kev":true,"vendor":"ServiceNow","product":"Utah, Vancouver, and Washington DC Now Platform","name":"ServiceNow Incomplete List of Disallowed Inputs Vulnerability","added":"2024-07-29","due":"2024-08-19","ransomware":false,"epss":0.99628,"pct":0.99948,"cvss":[]},{"id":"CVE-2024-4879","kev":true,"vendor":"ServiceNow","product":"Utah, Vancouver, and Washington DC Now Platform","name":"ServiceNow Improper Input Validation Vulnerability","added":"2024-07-29","due":"2024-08-19","ransomware":false,"epss":0.99976,"pct":0.99979,"cvss":[]},{"id":"CVE-2024-39891","kev":true,"vendor":"Twilio","product":"Authy","name":"Twilio Authy Information Disclosure Vulnerability","added":"2024-07-23","due":"2024-08-13","ransomware":false,"epss":0.01669,"pct":0.75971,"cvss":[]},{"id":"CVE-2012-4792","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2024-07-23","due":"2024-08-13","ransomware":false,"epss":0.78823,"pct":0.99584,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2012-12-30T18:55:01.477Z","modified":"2026-06-16T23:45:43.277Z"},{"id":"CVE-2022-22948","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Incorrect Default File Permissions Vulnerability","added":"2024-07-17","due":"2024-08-07","ransomware":false,"epss":0.13282,"pct":0.96286,"cvss":[]},{"id":"CVE-2024-28995","kev":true,"vendor":"SolarWinds","product":"Serv-U","name":"SolarWinds Serv-U Path Traversal Vulnerability","added":"2024-07-17","due":"2024-08-07","ransomware":false,"epss":0.99614,"pct":0.99947,"cvss":[]},{"id":"CVE-2024-34102","kev":true,"vendor":"Adobe","product":"Commerce and Magento Open Source","name":"Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability","added":"2024-07-17","due":"2024-08-07","ransomware":false,"epss":0.99994,"pct":0.99988,"cvss":[]},{"id":"CVE-2024-36401","kev":true,"vendor":"OSGeo","product":"GeoServer","name":"OSGeo GeoServer GeoTools Eval Injection Vulnerability","added":"2024-07-15","due":"2024-08-05","ransomware":false,"epss":0.99813,"pct":0.99958,"cvss":[]},{"id":"CVE-2024-23692","kev":true,"vendor":"Rejetto","product":"HTTP File Server","name":"Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability","added":"2024-07-09","due":"2024-07-30","ransomware":true,"epss":0.99485,"pct":0.99944,"cvss":[]},{"id":"CVE-2024-38080","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Hyper-V Privilege Escalation Vulnerability","added":"2024-07-09","due":"2024-07-30","ransomware":false,"epss":0.07115,"pct":0.94066,"cvss":[]},{"id":"CVE-2024-38112","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows MSHTML Platform Spoofing Vulnerability","added":"2024-07-09","due":"2024-07-30","ransomware":false,"epss":0.84225,"pct":0.99692,"cvss":[]},{"id":"CVE-2024-20399","kev":true,"vendor":"Cisco","product":"NX-OS","name":"Cisco NX-OS Command Injection Vulnerability","added":"2024-07-02","due":"2024-07-23","ransomware":false,"epss":0.04306,"pct":0.90857,"cvss":[]},{"id":"CVE-2020-13965","kev":true,"vendor":"Roundcube","product":"Webmail","name":"Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability","added":"2024-06-26","due":"2024-07-17","ransomware":false,"epss":0.76596,"pct":0.99531,"cvss":[]},{"id":"CVE-2022-2586","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Use-After-Free Vulnerability","added":"2024-06-26","due":"2024-07-17","ransomware":false,"epss":0.10202,"pct":0.95544,"cvss":[]},{"id":"CVE-2022-24816","kev":true,"vendor":"OSGeo","product":"JAI-EXT","name":"OSGeo GeoServer JAI-EXT Code Injection Vulnerability","added":"2024-06-26","due":"2024-07-17","ransomware":false,"epss":0.99911,"pct":0.99967,"cvss":[]},{"id":"CVE-2024-4358","kev":true,"vendor":"Progress","product":"Telerik Report Server","name":"Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability","added":"2024-06-13","due":"2024-07-04","ransomware":false,"epss":0.97482,"pct":0.999,"cvss":[]},{"id":"CVE-2024-26169","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability","added":"2024-06-13","due":"2024-07-04","ransomware":true,"epss":0.04014,"pct":0.90265,"cvss":[]},{"id":"CVE-2024-32896","kev":true,"vendor":"Android","product":"Pixel","name":"Android Pixel Privilege Escalation Vulnerability","added":"2024-06-13","due":"2024-07-04","ransomware":false,"epss":0.02985,"pct":0.86853,"cvss":[]},{"id":"CVE-2024-4577","kev":true,"vendor":"PHP Group","product":"PHP","name":"PHP-CGI OS Command Injection Vulnerability","added":"2024-06-12","due":"2024-07-03","ransomware":true,"epss":0.99987,"pct":0.99984,"cvss":[]},{"id":"CVE-2024-4610","kev":true,"vendor":"Arm","product":"Mali GPU Kernel Driver","name":"Arm Mali GPU Kernel Driver Use-After-Free Vulnerability","added":"2024-06-12","due":"2024-07-03","ransomware":false,"epss":0.00764,"pct":0.5387,"cvss":[]},{"id":"CVE-2017-3506","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server OS Command Injection Vulnerability","added":"2024-06-03","due":"2024-06-24","ransomware":false,"epss":0.96281,"pct":0.99879,"cvss":[]},{"id":"CVE-2024-1086","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Use-After-Free Vulnerability","added":"2024-05-30","due":"2024-06-20","ransomware":true,"epss":0.28058,"pct":0.98059,"cvss":[]},{"id":"CVE-2024-24919","kev":true,"vendor":"Check Point","product":"Quantum Security Gateways","name":"Check Point Quantum Security Gateways Information Disclosure Vulnerability","added":"2024-05-30","due":"2024-06-20","ransomware":true,"epss":0.99978,"pct":0.9998,"cvss":[]},{"id":"CVE-2024-4978","kev":true,"vendor":"Justice AV Solutions","product":"Viewer","name":"Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability","added":"2024-05-29","due":"2024-06-19","ransomware":false,"epss":0.26937,"pct":0.97987,"cvss":[]},{"id":"CVE-2024-5274","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2024-05-28","due":"2024-06-18","ransomware":false,"epss":0.07472,"pct":0.94296,"cvss":[]},{"id":"CVE-2020-17519","kev":true,"vendor":"Apache","product":"Flink","name":"Apache Flink Improper Access Control Vulnerability","added":"2024-05-23","due":"2024-06-13","ransomware":false,"epss":0.97809,"pct":0.99906,"cvss":[]},{"id":"CVE-2024-4947","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2024-05-20","due":"2024-06-10","ransomware":false,"epss":0.15236,"pct":0.9667,"cvss":[]},{"id":"CVE-2023-43208","kev":true,"vendor":"NextGen Healthcare","product":"Mirth Connect","name":"NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability","added":"2024-05-20","due":"2024-06-10","ransomware":true,"epss":0.82708,"pct":0.99661,"cvss":[]},{"id":"CVE-2024-4761","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Memory Write Vulnerability","added":"2024-05-16","due":"2024-06-06","ransomware":false,"epss":0.11007,"pct":0.95785,"cvss":[]},{"id":"CVE-2021-40655","kev":true,"vendor":"D-Link","product":"DIR-605 Router","name":"D-Link DIR-605 Router Information Disclosure Vulnerability","added":"2024-05-16","due":"2024-06-06","ransomware":false,"epss":0.86659,"pct":0.99737,"cvss":[]},{"id":"CVE-2014-100005","kev":true,"vendor":"D-Link","product":"DIR-600 Router","name":"D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability","added":"2024-05-16","due":"2024-06-06","ransomware":false,"epss":0.43456,"pct":0.98703,"cvss":[]},{"id":"CVE-2024-30040","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability","added":"2024-05-14","due":"2024-06-04","ransomware":false,"epss":0.03939,"pct":0.90076,"cvss":[]},{"id":"CVE-2024-30051","kev":true,"vendor":"Microsoft","product":"DWM Core Library","name":"Microsoft DWM Core Library Privilege Escalation Vulnerability","added":"2024-05-14","due":"2024-06-04","ransomware":true,"epss":0.05687,"pct":0.92769,"cvss":[]},{"id":"CVE-2024-4671","kev":true,"vendor":"Google","product":"Chromium","name":"Google Chromium Visuals Use-After-Free Vulnerability","added":"2024-05-13","due":"2024-06-03","ransomware":false,"epss":0.08348,"pct":0.94804,"cvss":[]},{"id":"CVE-2023-7028","kev":true,"vendor":"GitLab","product":"GitLab CE/EE","name":"GitLab Community and Enterprise Editions Improper Access Control Vulnerability","added":"2024-05-01","due":"2024-05-22","ransomware":false,"epss":0.94647,"pct":0.99855,"cvss":[]},{"id":"CVE-2024-29988","kev":true,"vendor":"Microsoft","product":"SmartScreen Prompt","name":"Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability","added":"2024-04-30","due":"2024-05-21","ransomware":false,"epss":0.44875,"pct":0.98741,"cvss":[]},{"id":"CVE-2024-4040","kev":true,"vendor":"CrushFTP","product":"CrushFTP","name":"CrushFTP VFS Sandbox Escape Vulnerability","added":"2024-04-24","due":"2024-05-01","ransomware":false,"epss":0.99539,"pct":0.99945,"cvss":[]},{"id":"CVE-2024-20359","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","name":"Cisco ASA and FTD Privilege Escalation Vulnerability","added":"2024-04-24","due":"2024-05-01","ransomware":false,"epss":0.19434,"pct":0.97295,"cvss":[]},{"id":"CVE-2024-20353","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","name":"Cisco ASA and FTD Denial of Service Vulnerability","added":"2024-04-24","due":"2024-05-01","ransomware":false,"epss":0.70686,"pct":0.99381,"cvss":[]},{"id":"CVE-2022-38028","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Print Spooler Privilege Escalation Vulnerability","added":"2024-04-23","due":"2024-05-14","ransomware":false,"epss":0.14949,"pct":0.96619,"cvss":[]},{"id":"CVE-2024-3400","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Command Injection Vulnerability","added":"2024-04-12","due":"2024-04-19","ransomware":true,"epss":0.99999,"pct":1,"cvss":[]},{"id":"CVE-2024-3273","kev":true,"vendor":"D-Link","product":"Multiple NAS Devices","name":"D-Link Multiple NAS Devices Command Injection Vulnerability","added":"2024-04-11","due":"2024-05-02","ransomware":false,"epss":0.99997,"pct":0.99989,"cvss":[]},{"id":"CVE-2024-3272","kev":true,"vendor":"D-Link","product":"Multiple NAS Devices","name":"D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability","added":"2024-04-11","due":"2024-05-02","ransomware":false,"epss":0.98038,"pct":0.9991,"cvss":[]},{"id":"CVE-2024-29748","kev":true,"vendor":"Android","product":"Pixel","name":"Android Pixel Privilege Escalation Vulnerability","added":"2024-04-04","due":"2024-04-25","ransomware":false,"epss":0.0067,"pct":0.50272,"cvss":[]},{"id":"CVE-2024-29745","kev":true,"vendor":"Android","product":"Pixel","name":"Android Pixel Information Disclosure Vulnerability","added":"2024-04-04","due":"2024-04-25","ransomware":false,"epss":0.00482,"pct":0.3941,"cvss":[]},{"id":"CVE-2023-24955","kev":true,"vendor":"Microsoft","product":"SharePoint Server","name":"Microsoft SharePoint Server Code Injection Vulnerability","added":"2024-03-26","due":"2024-04-16","ransomware":true,"epss":0.84974,"pct":0.99708,"cvss":[]},{"id":"CVE-2019-7256","kev":true,"vendor":"Nice","product":"Linear eMerge E3-Series","name":"Nice Linear eMerge E3-Series OS Command Injection Vulnerability","added":"2024-03-25","due":"2024-04-15","ransomware":false,"epss":0.97081,"pct":0.99892,"cvss":[]},{"id":"CVE-2021-44529","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Cloud Service Appliance (EPM CSA)","name":"Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability","added":"2024-03-25","due":"2024-04-15","ransomware":true,"epss":0.99105,"pct":0.99933,"cvss":[]},{"id":"CVE-2023-48788","kev":true,"vendor":"Fortinet","product":"FortiClient EMS","name":"Fortinet FortiClient EMS SQL Injection Vulnerability","added":"2024-03-25","due":"2024-04-15","ransomware":true,"epss":0.98446,"pct":0.99917,"cvss":[]},{"id":"CVE-2024-27198","kev":true,"vendor":"JetBrains","product":"TeamCity","name":"JetBrains TeamCity Authentication Bypass Vulnerability","added":"2024-03-07","due":"2024-03-28","ransomware":true,"epss":0.99938,"pct":0.99972,"cvss":[]},{"id":"CVE-2024-23225","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2024-03-06","due":"2024-03-27","ransomware":false,"epss":0.01481,"pct":0.7305,"cvss":[]},{"id":"CVE-2024-23296","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2024-03-06","due":"2024-03-27","ransomware":false,"epss":0.01411,"pct":0.71758,"cvss":[]},{"id":"CVE-2023-21237","kev":true,"vendor":"Android","product":"Pixel","name":"Android Pixel Information Disclosure Vulnerability","added":"2024-03-05","due":"2024-03-26","ransomware":false,"epss":0.00266,"pct":0.16802,"cvss":[]},{"id":"CVE-2021-36380","kev":true,"vendor":"Sunhillo","product":"SureLine","name":"Sunhillo SureLine OS Command Injection Vulnerablity","added":"2024-03-05","due":"2024-03-26","ransomware":false,"epss":0.97647,"pct":0.99903,"cvss":[]},{"id":"CVE-2024-21338","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability","added":"2024-03-04","due":"2024-03-25","ransomware":true,"epss":0.5981,"pct":0.99109,"cvss":[]},{"id":"CVE-2023-29360","kev":true,"vendor":"Microsoft","product":"Streaming Service","name":"Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability","added":"2024-02-29","due":"2024-03-21","ransomware":false,"epss":0.2162,"pct":0.97565,"cvss":[]},{"id":"CVE-2024-1709","kev":true,"vendor":"ConnectWise","product":"ScreenConnect","name":"ConnectWise ScreenConnect Authentication Bypass Vulnerability","added":"2024-02-22","due":"2024-02-29","ransomware":true,"epss":0.9998,"pct":0.99981,"cvss":[]},{"id":"CVE-2020-3259","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","name":"Cisco ASA and FTD Information Disclosure Vulnerability","added":"2024-02-15","due":"2024-03-07","ransomware":true,"epss":0.71789,"pct":0.99411,"cvss":[]},{"id":"CVE-2024-21410","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Privilege Escalation Vulnerability","added":"2024-02-15","due":"2024-03-07","ransomware":false,"epss":0.12561,"pct":0.96127,"cvss":[]},{"id":"CVE-2024-21412","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability","added":"2024-02-13","due":"2024-03-05","ransomware":true,"epss":0.9941,"pct":0.99941,"cvss":[]},{"id":"CVE-2024-21351","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SmartScreen Security Feature Bypass Vulnerability","added":"2024-02-13","due":"2024-03-05","ransomware":false,"epss":0.27798,"pct":0.98043,"cvss":[]},{"id":"CVE-2023-43770","kev":true,"vendor":"Roundcube","product":"Webmail","name":"Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability","added":"2024-02-12","due":"2024-03-04","ransomware":false,"epss":0.6366,"pct":0.99197,"cvss":[]},{"id":"CVE-2024-21762","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Out-of-Bound Write Vulnerability","added":"2024-02-09","due":"2024-02-16","ransomware":true,"epss":0.83428,"pct":0.99677,"cvss":[]},{"id":"CVE-2023-4762","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2024-02-06","due":"2024-02-27","ransomware":false,"epss":0.41375,"pct":0.98636,"cvss":[]},{"id":"CVE-2022-48618","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2024-01-31","due":"2024-02-21","ransomware":false,"epss":0.00487,"pct":0.3977,"cvss":[]},{"id":"CVE-2024-21893","kev":true,"vendor":"Ivanti","product":"Connect Secure, Policy Secure, and Neurons","name":"Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability","added":"2024-01-31","due":"2024-02-02","ransomware":true,"epss":0.99999,"pct":0.99999,"cvss":[]},{"id":"CVE-2023-22527","kev":true,"vendor":"Atlassian","product":"Confluence Data Center and Server","name":"Atlassian Confluence Data Center and Server Template Injection Vulnerability","added":"2024-01-24","due":"2024-02-14","ransomware":true,"epss":0.99984,"pct":0.99982,"cvss":[]},{"id":"CVE-2024-23222","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Type Confusion Vulnerability","added":"2024-01-23","due":"2024-02-13","ransomware":false,"epss":0.10593,"pct":0.95663,"cvss":[]},{"id":"CVE-2023-34048","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Out-of-Bounds Write Vulnerability","added":"2024-01-22","due":"2024-02-12","ransomware":false,"epss":0.99428,"pct":0.99942,"cvss":[]},{"id":"CVE-2023-35082","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM) and MobileIron Core","name":"Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability","added":"2024-01-18","due":"2024-02-08","ransomware":true,"epss":0.99999,"pct":0.99996,"cvss":[]},{"id":"CVE-2024-0519","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Memory Access Vulnerability","added":"2024-01-17","due":"2024-02-07","ransomware":false,"epss":0.03802,"pct":0.89694,"cvss":[]},{"id":"CVE-2023-6549","kev":true,"vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","name":"Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability","added":"2024-01-17","due":"2024-02-07","ransomware":false,"epss":0.57633,"pct":0.9906,"cvss":[]},{"id":"CVE-2023-6548","kev":true,"vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","name":"Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability","added":"2024-01-17","due":"2024-01-24","ransomware":false,"epss":0.03191,"pct":0.87673,"cvss":[]},{"id":"CVE-2018-15133","kev":true,"vendor":"Laravel","product":"Laravel Framework","name":"Laravel Deserialization of Untrusted Data Vulnerability","added":"2024-01-16","due":"2024-02-06","ransomware":false,"epss":0.76814,"pct":0.99536,"cvss":[]},{"id":"CVE-2023-29357","kev":true,"vendor":"Microsoft","product":"SharePoint Server","name":"Microsoft SharePoint Server Privilege Escalation Vulnerability","added":"2024-01-10","due":"2024-01-31","ransomware":true,"epss":0.99984,"pct":0.99982,"cvss":[]},{"id":"CVE-2023-46805","kev":true,"vendor":"Ivanti","product":"Connect Secure and Policy Secure","name":"Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability","added":"2024-01-10","due":"2024-01-22","ransomware":true,"epss":0.99986,"pct":0.99983,"cvss":[]},{"id":"CVE-2024-21887","kev":true,"vendor":"Ivanti","product":"Connect Secure and Policy Secure","name":"Ivanti Connect Secure and Policy Secure Command Injection Vulnerability","added":"2024-01-10","due":"2024-01-22","ransomware":true,"epss":0.99999,"pct":0.99999,"cvss":[]},{"id":"CVE-2023-23752","kev":true,"vendor":"Joomla!","product":"Joomla!","name":"Joomla! Improper Access Control Vulnerability","added":"2024-01-08","due":"2024-01-29","ransomware":false,"epss":0.99827,"pct":0.9996,"cvss":[]},{"id":"CVE-2016-20017","kev":true,"vendor":"D-Link","product":"DSL-2750B Devices","name":"D-Link DSL-2750B Devices Command Injection Vulnerability","added":"2024-01-08","due":"2024-01-29","ransomware":false,"epss":0.64238,"pct":0.99211,"cvss":[]},{"id":"CVE-2023-41990","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Code Execution Vulnerability","added":"2024-01-08","due":"2024-01-29","ransomware":false,"epss":0.01388,"pct":0.71326,"cvss":[]},{"id":"CVE-2023-27524","kev":true,"vendor":"Apache","product":"Superset","name":"Apache Superset Insecure Default Initialization of Resource Vulnerability","added":"2024-01-08","due":"2024-01-29","ransomware":false,"epss":0.97405,"pct":0.99899,"cvss":[]},{"id":"CVE-2023-29300","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Deserialization of Untrusted Data Vulnerability","added":"2024-01-08","due":"2024-01-29","ransomware":true,"epss":0.99991,"pct":0.99986,"cvss":[]},{"id":"CVE-2023-38203","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Deserialization of Untrusted Data Vulnerability","added":"2024-01-08","due":"2024-01-29","ransomware":true,"epss":0.97074,"pct":0.99892,"cvss":[]},{"id":"CVE-2023-7101","kev":true,"vendor":"Spreadsheet::ParseExcel","product":"Spreadsheet::ParseExcel","name":"Spreadsheet::ParseExcel Remote Code Execution Vulnerability","added":"2024-01-02","due":"2024-01-23","ransomware":false,"epss":0.19106,"pct":0.97248,"cvss":[]},{"id":"CVE-2023-7024","kev":true,"vendor":"Google","product":"Chromium WebRTC","name":"Google Chromium WebRTC Heap Buffer Overflow Vulnerability","added":"2024-01-02","due":"2024-01-23","ransomware":false,"epss":0.06671,"pct":0.93701,"cvss":[]},{"id":"CVE-2023-49897","kev":true,"vendor":"FXC","product":"AE1021, AE1021PE","name":"FXC AE1021, AE1021PE OS Command Injection Vulnerability","added":"2023-12-21","due":"2024-01-11","ransomware":false,"epss":0.50447,"pct":0.98883,"cvss":[]},{"id":"CVE-2023-47565","kev":true,"vendor":"QNAP","product":"VioStor NVR","name":"QNAP VioStor NVR OS Command Injection Vulnerability","added":"2023-12-21","due":"2024-01-11","ransomware":false,"epss":0.73277,"pct":0.99449,"cvss":[]},{"id":"CVE-2023-6448","kev":true,"vendor":"Unitronics","product":"Vision PLC and HMI","name":"Unitronics Vision PLC and HMI Insecure Default Password Vulnerability","added":"2023-12-11","due":"2023-12-18","ransomware":false,"epss":0.02072,"pct":0.80783,"cvss":[]},{"id":"CVE-2023-41266","kev":true,"vendor":"Qlik","product":"Sense","name":"Qlik Sense Path Traversal Vulnerability","added":"2023-12-07","due":"2023-12-28","ransomware":true,"epss":0.84843,"pct":0.99706,"cvss":[]},{"id":"CVE-2023-41265","kev":true,"vendor":"Qlik","product":"Sense","name":"Qlik Sense HTTP Tunneling Vulnerability","added":"2023-12-07","due":"2023-12-28","ransomware":true,"epss":0.88215,"pct":0.99766,"cvss":[]},{"id":"CVE-2023-33107","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Integer Overflow Vulnerability","added":"2023-12-05","due":"2023-12-26","ransomware":false,"epss":0.00739,"pct":0.5299,"cvss":[]},{"id":"CVE-2023-33106","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability","added":"2023-12-05","due":"2023-12-26","ransomware":false,"epss":0.00788,"pct":0.54671,"cvss":[]},{"id":"CVE-2023-33063","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Use-After-Free Vulnerability","added":"2023-12-05","due":"2023-12-26","ransomware":false,"epss":0.0058,"pct":0.45779,"cvss":[]},{"id":"CVE-2022-22071","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Use-After-Free Vulnerability","added":"2023-12-05","due":"2023-12-26","ransomware":false,"epss":0.00455,"pct":0.37288,"cvss":[]},{"id":"CVE-2023-42917","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Memory Corruption Vulnerability","added":"2023-12-04","due":"2023-12-25","ransomware":false,"epss":0.09295,"pct":0.95235,"cvss":[]},{"id":"CVE-2023-42916","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability","added":"2023-12-04","due":"2023-12-25","ransomware":false,"epss":0.17823,"pct":0.97091,"cvss":[]},{"id":"CVE-2023-6345","kev":true,"vendor":"Google","product":"Chromium Skia","name":"Google Skia Integer Overflow Vulnerability","added":"2023-11-30","due":"2023-12-21","ransomware":false,"epss":0.16468,"pct":0.96903,"cvss":[]},{"id":"CVE-2023-49103","kev":true,"vendor":"ownCloud","product":"ownCloud graphapi","name":"ownCloud graphapi Information Disclosure Vulnerability","added":"2023-11-30","due":"2023-12-21","ransomware":false,"epss":0.78428,"pct":0.99573,"cvss":[]},{"id":"CVE-2023-4911","kev":true,"vendor":"GNU","product":"GNU C Library","name":"GNU C Library Buffer Overflow Vulnerability","added":"2023-11-21","due":"2023-12-12","ransomware":false,"epss":0.63769,"pct":0.99201,"cvss":[]},{"id":"CVE-2023-36584","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability","added":"2023-11-16","due":"2023-12-07","ransomware":false,"epss":0.03055,"pct":0.87148,"cvss":[]},{"id":"CVE-2023-1671","kev":true,"vendor":"Sophos","product":"Web Appliance","name":"Sophos Web Appliance Command Injection Vulnerability","added":"2023-11-16","due":"2023-12-07","ransomware":false,"epss":0.99999,"pct":0.99992,"cvss":[]},{"id":"CVE-2020-2551","kev":true,"vendor":"Oracle","product":"Fusion Middleware","name":"Oracle Fusion Middleware Unspecified Vulnerability","added":"2023-11-16","due":"2023-12-07","ransomware":false,"epss":0.93217,"pct":0.99833,"cvss":[]},{"id":"CVE-2023-36033","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability","added":"2023-11-14","due":"2023-12-05","ransomware":false,"epss":0.10945,"pct":0.9577,"cvss":[]},{"id":"CVE-2023-36025","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SmartScreen Security Feature Bypass Vulnerability","added":"2023-11-14","due":"2023-12-05","ransomware":false,"epss":0.88085,"pct":0.99763,"cvss":[]},{"id":"CVE-2023-36036","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability","added":"2023-11-14","due":"2023-12-05","ransomware":false,"epss":0.1667,"pct":0.96943,"cvss":[]},{"id":"CVE-2023-47246","kev":true,"vendor":"SysAid","product":"SysAid Server","name":"SysAid Server Path Traversal Vulnerability","added":"2023-11-13","due":"2023-12-04","ransomware":true,"epss":0.98851,"pct":0.99927,"cvss":[]},{"id":"CVE-2023-36844","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS EX Series PHP External Variable Modification Vulnerability","added":"2023-11-13","due":"2023-11-17","ransomware":false,"epss":0.89958,"pct":0.99792,"cvss":[]},{"id":"CVE-2023-36845","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability","added":"2023-11-13","due":"2023-11-17","ransomware":false,"epss":0.9507,"pct":0.99862,"cvss":[]},{"id":"CVE-2023-36846","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability","added":"2023-11-13","due":"2023-11-17","ransomware":false,"epss":0.93473,"pct":0.99839,"cvss":[]},{"id":"CVE-2023-36847","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability","added":"2023-11-13","due":"2023-11-17","ransomware":false,"epss":0.83455,"pct":0.99678,"cvss":[]},{"id":"CVE-2023-36851","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability","added":"2023-11-13","due":"2023-11-17","ransomware":false,"epss":0.01123,"pct":0.65088,"cvss":[]},{"id":"CVE-2023-29552","kev":true,"vendor":"IETF","product":"Service Location Protocol (SLP)","name":"Service Location Protocol (SLP) Denial-of-Service Vulnerability","added":"2023-11-08","due":"2023-11-29","ransomware":false,"epss":0.63975,"pct":0.99204,"cvss":[]},{"id":"CVE-2023-22518","kev":true,"vendor":"Atlassian","product":"Confluence Data Center and Server","name":"Atlassian Confluence Data Center and Server Improper Authorization Vulnerability","added":"2023-11-07","due":"2023-11-28","ransomware":true,"epss":0.99999,"pct":0.99996,"cvss":[]},{"id":"CVE-2023-46604","kev":true,"vendor":"Apache","product":"ActiveMQ","name":"Apache ActiveMQ Deserialization of Untrusted Data Vulnerability","added":"2023-11-02","due":"2023-11-23","ransomware":true,"epss":0.99891,"pct":0.99965,"cvss":[]},{"id":"CVE-2023-46748","kev":true,"vendor":"F5","product":"BIG-IP Configuration Utility","name":"F5 BIG-IP Configuration Utility SQL Injection Vulnerability","added":"2023-10-31","due":"2023-11-21","ransomware":false,"epss":0.04468,"pct":0.91158,"cvss":[]},{"id":"CVE-2023-46747","kev":true,"vendor":"F5","product":"BIG-IP Configuration Utility","name":"F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability","added":"2023-10-31","due":"2023-11-21","ransomware":true,"epss":0.96515,"pct":0.99881,"cvss":[]},{"id":"CVE-2023-5631","kev":true,"vendor":"Roundcube","product":"Webmail","name":"Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability","added":"2023-10-26","due":"2023-11-16","ransomware":false,"epss":0.75873,"pct":0.99515,"cvss":[]},{"id":"CVE-2023-20273","kev":true,"vendor":"Cisco","product":"Cisco IOS XE Web UI","name":"Cisco IOS XE Web UI Command Injection Vulnerability","added":"2023-10-23","due":"2023-10-27","ransomware":false,"epss":0.89634,"pct":0.99786,"cvss":[]},{"id":"CVE-2023-4966","kev":true,"vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","name":"Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability","added":"2023-10-18","due":"2023-11-08","ransomware":true,"epss":0.99999,"pct":0.99997,"cvss":[]},{"id":"CVE-2023-20198","kev":true,"vendor":"Cisco","product":"IOS XE Web UI","name":"Cisco IOS XE Web UI Privilege Escalation Vulnerability","added":"2023-10-16","due":"2023-10-20","ransomware":false,"epss":0.99571,"pct":0.99946,"cvss":[]},{"id":"CVE-2023-21608","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Use-After-Free Vulnerability","added":"2023-10-10","due":"2023-10-31","ransomware":false,"epss":0.61475,"pct":0.99144,"cvss":[]},{"id":"CVE-2023-20109","kev":true,"vendor":"Cisco","product":"IOS and IOS XE","name":"Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability","added":"2023-10-10","due":"2023-10-31","ransomware":false,"epss":0.02484,"pct":0.84053,"cvss":[]},{"id":"CVE-2023-41763","kev":true,"vendor":"Microsoft","product":"Skype for Business","name":"Microsoft Skype for Business Privilege Escalation Vulnerability","added":"2023-10-10","due":"2023-10-31","ransomware":false,"epss":0.90353,"pct":0.99797,"cvss":[]},{"id":"CVE-2023-36563","kev":true,"vendor":"Microsoft","product":"WordPad","name":"Microsoft WordPad Information Disclosure Vulnerability","added":"2023-10-10","due":"2023-10-31","ransomware":false,"epss":0.20719,"pct":0.97471,"cvss":[]},{"id":"CVE-2023-44487","kev":true,"vendor":"IETF","product":"HTTP/2","name":"HTTP/2 Rapid Reset Attack Vulnerability","added":"2023-10-10","due":"2023-10-31","ransomware":false,"epss":0.99999,"pct":0.99998,"cvss":[]},{"id":"CVE-2023-22515","kev":true,"vendor":"Atlassian","product":"Confluence Data Center and Server","name":"Atlassian Confluence Data Center and Server Broken Access Control Vulnerability","added":"2023-10-05","due":"2023-10-13","ransomware":true,"epss":0.99235,"pct":0.99936,"cvss":[]},{"id":"CVE-2023-40044","kev":true,"vendor":"Progress","product":"WS_FTP Server","name":"Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability","added":"2023-10-05","due":"2023-10-26","ransomware":true,"epss":0.90355,"pct":0.99798,"cvss":[]},{"id":"CVE-2023-42824","kev":true,"vendor":"Apple","product":"iOS and iPadOS","name":"Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability","added":"2023-10-05","due":"2023-10-26","ransomware":false,"epss":0.01095,"pct":0.6439,"cvss":[]},{"id":"CVE-2023-42793","kev":true,"vendor":"JetBrains","product":"TeamCity","name":"JetBrains TeamCity Authentication Bypass Vulnerability","added":"2023-10-04","due":"2023-10-25","ransomware":true,"epss":0.99987,"pct":0.99984,"cvss":[]},{"id":"CVE-2023-28229","kev":true,"vendor":"Microsoft","product":"Windows CNG Key Isolation Service","name":"Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability","added":"2023-10-04","due":"2023-10-25","ransomware":false,"epss":0.01671,"pct":0.76003,"cvss":[]},{"id":"CVE-2023-4211","kev":true,"vendor":"Arm","product":"Mali GPU Kernel Driver","name":"Arm Mali GPU Kernel Driver Use-After-Free Vulnerability","added":"2023-10-03","due":"2023-10-24","ransomware":false,"epss":0.01098,"pct":0.6448,"cvss":[]},{"id":"CVE-2023-5217","kev":true,"vendor":"Google","product":"Chromium libvpx","name":"Google Chromium libvpx Heap Buffer Overflow Vulnerability","added":"2023-10-02","due":"2023-10-23","ransomware":false,"epss":0.49013,"pct":0.98851,"cvss":[]},{"id":"CVE-2018-14667","kev":true,"vendor":"Red Hat","product":"JBoss RichFaces Framework","name":"Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability","added":"2023-09-28","due":"2023-10-19","ransomware":false,"epss":0.74202,"pct":0.99477,"cvss":[]},{"id":"CVE-2023-41991","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Improper Certificate Validation Vulnerability","added":"2023-09-25","due":"2023-10-16","ransomware":false,"epss":0.1338,"pct":0.96315,"cvss":[]},{"id":"CVE-2023-41992","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Kernel Privilege Escalation Vulnerability","added":"2023-09-25","due":"2023-10-16","ransomware":false,"epss":0.09515,"pct":0.95315,"cvss":[]},{"id":"CVE-2023-41993","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Code Execution Vulnerability","added":"2023-09-25","due":"2023-10-16","ransomware":false,"epss":0.24349,"pct":0.97807,"cvss":[]},{"id":"CVE-2023-41179","kev":true,"vendor":"Trend Micro","product":"Apex One and Worry-Free Business Security","name":"Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability","added":"2023-09-21","due":"2023-10-12","ransomware":false,"epss":0.04251,"pct":0.90758,"cvss":[]},{"id":"CVE-2023-28434","kev":true,"vendor":"MinIO","product":"MinIO","name":"MinIO Security Feature Bypass Vulnerability","added":"2023-09-19","due":"2023-10-10","ransomware":false,"epss":0.07917,"pct":0.94562,"cvss":[]},{"id":"CVE-2022-22265","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Use-After-Free Vulnerability","added":"2023-09-18","due":"2023-10-09","ransomware":false,"epss":0.00392,"pct":0.30973,"cvss":[]},{"id":"CVE-2014-8361","kev":true,"vendor":"Realtek","product":"SDK","name":"Realtek SDK Improper Input Validation Vulnerability","added":"2023-09-18","due":"2023-10-09","ransomware":false,"epss":0.99975,"pct":0.99979,"cvss":[]},{"id":"CVE-2017-6884","kev":true,"vendor":"Zyxel","product":"EMG2926 Routers","name":"Zyxel EMG2926 Routers Command Injection Vulnerability","added":"2023-09-18","due":"2023-10-09","ransomware":true,"epss":0.34607,"pct":0.98381,"cvss":[]},{"id":"CVE-2021-3129","kev":true,"vendor":"Laravel","product":"Ignition","name":"Laravel Ignition File Upload Vulnerability","added":"2023-09-18","due":"2023-10-09","ransomware":true,"epss":0.99943,"pct":0.99973,"cvss":[]},{"id":"CVE-2023-26369","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability","added":"2023-09-14","due":"2023-10-05","ransomware":false,"epss":0.06746,"pct":0.93775,"cvss":[]},{"id":"CVE-2023-35674","kev":true,"vendor":"Android","product":"Framework","name":"Android Framework Privilege Escalation Vulnerability","added":"2023-09-13","due":"2023-10-04","ransomware":false,"epss":0.02615,"pct":0.84911,"cvss":[]},{"id":"CVE-2023-20269","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance and Firepower Threat Defense","name":"Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability","added":"2023-09-13","due":"2023-10-04","ransomware":true,"epss":0.25453,"pct":0.97896,"cvss":[]},{"id":"CVE-2023-4863","kev":true,"vendor":"Google","product":"Chromium WebP","name":"Google Chromium WebP Heap-Based Buffer Overflow Vulnerability","added":"2023-09-13","due":"2023-10-04","ransomware":false,"epss":0.99979,"pct":0.9998,"cvss":[]},{"id":"CVE-2023-36761","kev":true,"vendor":"Microsoft","product":"Word","name":"Microsoft Word Information Disclosure Vulnerability","added":"2023-09-12","due":"2023-10-03","ransomware":false,"epss":0.1957,"pct":0.97312,"cvss":[]},{"id":"CVE-2023-36802","kev":true,"vendor":"Microsoft","product":"Streaming Service Proxy","name":"Microsoft Streaming Service Proxy Privilege Escalation Vulnerability","added":"2023-09-12","due":"2023-10-03","ransomware":false,"epss":0.27909,"pct":0.9805,"cvss":[]},{"id":"CVE-2023-41064","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability","added":"2023-09-11","due":"2023-10-02","ransomware":false,"epss":0.53403,"pct":0.9896,"cvss":[]},{"id":"CVE-2023-41061","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and watchOS","name":"Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability","added":"2023-09-11","due":"2023-10-02","ransomware":false,"epss":0.04373,"pct":0.90989,"cvss":[]},{"id":"CVE-2023-33246","kev":true,"vendor":"Apache","product":"RocketMQ","name":"Apache RocketMQ Command Execution Vulnerability","added":"2023-09-06","due":"2023-09-27","ransomware":false,"epss":0.96568,"pct":0.99882,"cvss":[]},{"id":"CVE-2023-38831","kev":true,"vendor":"RARLAB","product":"WinRAR","name":"RARLAB WinRAR Code Execution Vulnerability","added":"2023-08-24","due":"2023-09-14","ransomware":true,"epss":0.99815,"pct":0.99959,"cvss":[]},{"id":"CVE-2023-32315","kev":true,"vendor":"Ignite Realtime","product":"Openfire","name":"Ignite Realtime Openfire Path Traversal Vulnerability","added":"2023-08-24","due":"2023-09-14","ransomware":false,"epss":0.99999,"pct":0.99993,"cvss":[]},{"id":"CVE-2023-38035","kev":true,"vendor":"Ivanti","product":"Sentry","name":"Ivanti Sentry Authentication Bypass Vulnerability","added":"2023-08-22","due":"2023-09-12","ransomware":true,"epss":0.9995,"pct":0.99974,"cvss":[]},{"id":"CVE-2023-27532","kev":true,"vendor":"Veeam","product":"Backup & Replication","name":"Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability","added":"2023-08-22","due":"2023-09-12","ransomware":true,"epss":0.81326,"pct":0.99629,"cvss":[]},{"id":"CVE-2023-26359","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Deserialization of Untrusted Data Vulnerability","added":"2023-08-21","due":"2023-09-11","ransomware":false,"epss":0.16988,"pct":0.96987,"cvss":[]},{"id":"CVE-2023-24489","kev":true,"vendor":"Citrix","product":"Content Collaboration","name":"Citrix Content Collaboration ShareFile Improper Access Control Vulnerability","added":"2023-08-16","due":"2023-09-06","ransomware":false,"epss":0.97343,"pct":0.99898,"cvss":[]},{"id":"CVE-2023-38180","kev":true,"vendor":"Microsoft","product":".NET Core and Visual Studio","name":"Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability","added":"2023-08-09","due":"2023-08-30","ransomware":false,"epss":0.14016,"pct":0.96456,"cvss":[]},{"id":"CVE-2017-18368","kev":true,"vendor":"Zyxel","product":"P660HN-T1A Routers","name":"Zyxel P660HN-T1A Routers Command Injection Vulnerability","added":"2023-08-07","due":"2023-08-28","ransomware":false,"epss":0.94425,"pct":0.99851,"cvss":[]},{"id":"CVE-2023-35081","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability","added":"2023-07-31","due":"2023-08-21","ransomware":false,"epss":0.63577,"pct":0.99194,"cvss":[]},{"id":"CVE-2023-37580","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability","added":"2023-07-27","due":"2023-08-17","ransomware":false,"epss":0.49083,"pct":0.98853,"cvss":[]},{"id":"CVE-2023-38606","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Kernel Unspecified Vulnerability","added":"2023-07-26","due":"2023-08-16","ransomware":false,"epss":0.02899,"pct":0.8648,"cvss":[]},{"id":"CVE-2023-35078","kev":true,"vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","name":"Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability","added":"2023-07-25","due":"2023-08-15","ransomware":true,"epss":0.99999,"pct":0.99998,"cvss":[]},{"id":"CVE-2023-29298","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Improper Access Control Vulnerability","added":"2023-07-20","due":"2023-08-10","ransomware":false,"epss":0.9979,"pct":0.99955,"cvss":[]},{"id":"CVE-2023-38205","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Improper Access Control Vulnerability","added":"2023-07-20","due":"2023-08-10","ransomware":false,"epss":0.99764,"pct":0.99954,"cvss":[]},{"id":"CVE-2023-3519","kev":true,"vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","name":"Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability","added":"2023-07-19","due":"2023-08-09","ransomware":true,"epss":0.99749,"pct":0.99953,"cvss":[]},{"id":"CVE-2023-36884","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Search Remote Code Execution Vulnerability","added":"2023-07-17","due":"2023-08-29","ransomware":true,"epss":0.98932,"pct":0.99928,"cvss":[]},{"id":"CVE-2022-29303","kev":true,"vendor":"SolarView","product":"Compact","name":"SolarView Compact Command Injection Vulnerability","added":"2023-07-13","due":"2023-08-03","ransomware":false,"epss":0.97997,"pct":0.99909,"cvss":[]},{"id":"CVE-2023-37450","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Code Execution Vulnerability","added":"2023-07-13","due":"2023-08-03","ransomware":false,"epss":0.1895,"pct":0.97226,"cvss":[]},{"id":"CVE-2023-32046","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability","added":"2023-07-11","due":"2023-08-01","ransomware":false,"epss":0.10049,"pct":0.95495,"cvss":[]},{"id":"CVE-2023-32049","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability","added":"2023-07-11","due":"2023-08-01","ransomware":false,"epss":0.04156,"pct":0.90569,"cvss":[]},{"id":"CVE-2023-35311","kev":true,"vendor":"Microsoft","product":"Outlook","name":"Microsoft Outlook Security Feature Bypass Vulnerability","added":"2023-07-11","due":"2023-08-01","ransomware":false,"epss":0.15522,"pct":0.96717,"cvss":[]},{"id":"CVE-2023-36874","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability","added":"2023-07-11","due":"2023-08-01","ransomware":false,"epss":0.42564,"pct":0.98672,"cvss":[]},{"id":"CVE-2022-31199","kev":true,"vendor":"Netwrix","product":"Auditor","name":"Netwrix Auditor Insecure Object Deserialization Vulnerability","added":"2023-07-11","due":"2023-08-01","ransomware":true,"epss":0.36009,"pct":0.98434,"cvss":[]},{"id":"CVE-2021-29256","kev":true,"vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","name":"Arm Mali GPU Kernel Driver Use-After-Free Vulnerability","added":"2023-07-07","due":"2023-07-28","ransomware":false,"epss":0.02988,"pct":0.86864,"cvss":[]},{"id":"CVE-2019-17621","kev":true,"vendor":"D-Link","product":"DIR-859 Router","name":"D-Link DIR-859 Router Command Execution Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.89624,"pct":0.99785,"cvss":[]},{"id":"CVE-2019-20500","kev":true,"vendor":"D-Link","product":"DWL-2600AP Access Point","name":"D-Link DWL-2600AP Access Point Command Injection Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.97109,"pct":0.99893,"cvss":[]},{"id":"CVE-2021-25487","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Out-of-Bounds Read Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.00635,"pct":0.48641,"cvss":[]},{"id":"CVE-2021-25489","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Improper Input Validation Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.00531,"pct":0.42874,"cvss":[]},{"id":"CVE-2021-25394","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Race Condition Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.00401,"pct":0.32068,"cvss":[]},{"id":"CVE-2021-25395","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Race Condition Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.00366,"pct":0.28208,"cvss":[]},{"id":"CVE-2021-25371","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Unspecified Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.00802,"pct":0.55135,"cvss":[]},{"id":"CVE-2021-25372","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Improper Boundary Check Vulnerability","added":"2023-06-29","due":"2023-07-20","ransomware":false,"epss":0.00804,"pct":0.55242,"cvss":[]},{"id":"CVE-2023-32434","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Integer Overflow Vulnerability","added":"2023-06-23","due":"2023-07-14","ransomware":false,"epss":0.51517,"pct":0.98914,"cvss":[]},{"id":"CVE-2023-32435","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Memory Corruption Vulnerability","added":"2023-06-23","due":"2023-07-14","ransomware":false,"epss":0.22951,"pct":0.97691,"cvss":[]},{"id":"CVE-2023-32439","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Type Confusion Vulnerability","added":"2023-06-23","due":"2023-07-14","ransomware":false,"epss":0.23968,"pct":0.97777,"cvss":[]},{"id":"CVE-2023-20867","kev":true,"vendor":"VMware","product":"Tools","name":"VMware Tools Authentication Bypass Vulnerability","added":"2023-06-23","due":"2023-07-14","ransomware":false,"epss":0.1353,"pct":0.96349,"cvss":[]},{"id":"CVE-2023-27992","kev":true,"vendor":"Zyxel","product":"Multiple Network-Attached Storage (NAS) Devices","name":"Zyxel Multiple NAS Devices Command Injection Vulnerability","added":"2023-06-23","due":"2023-07-14","ransomware":false,"epss":0.82828,"pct":0.99664,"cvss":[]},{"id":"CVE-2023-20887","kev":true,"vendor":"VMware","product":"Aria Operations for Networks","name":"Vmware Aria Operations for Networks Command Injection Vulnerability","added":"2023-06-22","due":"2023-07-13","ransomware":false,"epss":0.98281,"pct":0.99915,"cvss":[]},{"id":"CVE-2020-35730","kev":true,"vendor":"Roundcube","product":"Roundcube Webmail","name":"Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability","added":"2023-06-22","due":"2023-07-13","ransomware":false,"epss":0.3292,"pct":0.98314,"cvss":[]},{"id":"CVE-2020-12641","kev":true,"vendor":"Roundcube","product":"Roundcube Webmail","name":"Roundcube Webmail Remote Code Execution Vulnerability","added":"2023-06-22","due":"2023-07-13","ransomware":false,"epss":0.84336,"pct":0.99694,"cvss":[]},{"id":"CVE-2021-44026","kev":true,"vendor":"Roundcube","product":"Roundcube Webmail","name":"Roundcube Webmail SQL Injection Vulnerability","added":"2023-06-22","due":"2023-07-13","ransomware":false,"epss":0.69882,"pct":0.99357,"cvss":[]},{"id":"CVE-2016-9079","kev":true,"vendor":"Mozilla","product":"Firefox, Firefox ESR, and Thunderbird","name":"Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability","added":"2023-06-22","due":"2023-07-13","ransomware":false,"epss":0.87423,"pct":0.99754,"cvss":[]},{"id":"CVE-2016-0165","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2023-06-22","due":"2023-07-13","ransomware":false,"epss":0.13732,"pct":0.96403,"cvss":[]},{"id":"CVE-2023-27997","kev":true,"vendor":"Fortinet","product":"FortiOS and FortiProxy SSL-VPN","name":"Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability","added":"2023-06-13","due":"2023-07-04","ransomware":true,"epss":0.85689,"pct":0.9972,"cvss":[]},{"id":"CVE-2023-3079","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2023-06-07","due":"2023-06-28","ransomware":false,"epss":0.3211,"pct":0.98272,"cvss":[]},{"id":"CVE-2023-33009","kev":true,"vendor":"Zyxel","product":"Multiple Firewalls","name":"Zyxel Multiple Firewalls Buffer Overflow Vulnerability","added":"2023-06-05","due":"2023-06-26","ransomware":false,"epss":0.28144,"pct":0.98062,"cvss":[]},{"id":"CVE-2023-33010","kev":true,"vendor":"Zyxel","product":"Multiple Firewalls","name":"Zyxel Multiple Firewalls Buffer Overflow Vulnerability","added":"2023-06-05","due":"2023-06-26","ransomware":false,"epss":0.29024,"pct":0.98115,"cvss":[]},{"id":"CVE-2023-34362","kev":true,"vendor":"Progress","product":"MOVEit Transfer","name":"Progress MOVEit Transfer SQL Injection Vulnerability","added":"2023-06-02","due":"2023-06-23","ransomware":true,"epss":0.99934,"pct":0.9997,"cvss":[]},{"id":"CVE-2023-28771","kev":true,"vendor":"Zyxel","product":"Multiple Firewalls","name":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","added":"2023-05-31","due":"2023-06-21","ransomware":false,"epss":0.99284,"pct":0.99937,"cvss":[]},{"id":"CVE-2023-2868","kev":true,"vendor":"Barracuda Networks","product":"Email Security Gateway (ESG) Appliance","name":"Barracuda Networks ESG Appliance Improper Input Validation Vulnerability","added":"2023-05-26","due":"2023-06-16","ransomware":false,"epss":0.87691,"pct":0.99757,"cvss":[]},{"id":"CVE-2023-32409","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Sandbox Escape Vulnerability","added":"2023-05-22","due":"2023-06-12","ransomware":false,"epss":0.1653,"pct":0.9692,"cvss":[]},{"id":"CVE-2023-28204","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability","added":"2023-05-22","due":"2023-06-12","ransomware":false,"epss":0.14292,"pct":0.96506,"cvss":[]},{"id":"CVE-2023-32373","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Use-After-Free Vulnerability","added":"2023-05-22","due":"2023-06-12","ransomware":false,"epss":0.12172,"pct":0.96048,"cvss":[]},{"id":"CVE-2004-1464","kev":true,"vendor":"Cisco","product":"IOS","name":"Cisco IOS Denial-of-Service Vulnerability","added":"2023-05-19","due":"2023-06-09","ransomware":false,"epss":0.0484,"pct":0.91745,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":5.9,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":5.9,"severity":"MEDIUM"}],"published":"2004-12-31T05:00:00.000Z","modified":"2026-06-16T22:07:45.380Z"},{"id":"CVE-2016-6415","kev":true,"vendor":"Cisco","product":"IOS, IOS XR, and IOS XE","name":"Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability","added":"2023-05-19","due":"2023-06-09","ransomware":false,"epss":0.87687,"pct":0.99757,"cvss":[]},{"id":"CVE-2023-21492","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability","added":"2023-05-19","due":"2023-06-09","ransomware":false,"epss":0.02554,"pct":0.84526,"cvss":[]},{"id":"CVE-2023-25717","kev":true,"vendor":"Ruckus Wireless","product":"Multiple Products","name":"Multiple Ruckus Wireless Products CSRF and RCE Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.98069,"pct":0.99911,"cvss":[]},{"id":"CVE-2021-3560","kev":true,"vendor":"Red Hat","product":"Polkit","name":"Red Hat Polkit Incorrect Authorization Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.23708,"pct":0.97759,"cvss":[]},{"id":"CVE-2014-0196","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Race Condition Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.22475,"pct":0.97645,"cvss":[]},{"id":"CVE-2010-3904","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Improper Input Validation Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.15737,"pct":0.96772,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-12-06T20:13:00.513Z","modified":"2026-06-16T23:23:47.610Z"},{"id":"CVE-2015-5317","kev":true,"vendor":"Jenkins","product":"Jenkins User Interface (UI)","name":"Jenkins User Interface (UI) Information Disclosure Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.23003,"pct":0.97695,"cvss":[]},{"id":"CVE-2016-3427","kev":true,"vendor":"Oracle","product":"Java SE and JRockit","name":"Oracle Java SE and JRockit Unspecified Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.92334,"pct":0.99821,"cvss":[]},{"id":"CVE-2016-8735","kev":true,"vendor":"Apache","product":"Tomcat","name":"Apache Tomcat Remote Code Execution Vulnerability","added":"2023-05-12","due":"2023-06-02","ransomware":false,"epss":0.90338,"pct":0.99797,"cvss":[]},{"id":"CVE-2023-29336","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32K Privilege Escalation Vulnerability","added":"2023-05-09","due":"2023-05-30","ransomware":false,"epss":0.41185,"pct":0.9863,"cvss":[]},{"id":"CVE-2023-1389","kev":true,"vendor":"TP-Link","product":"Archer AX21","name":"TP-Link Archer AX-21 Command Injection Vulnerability","added":"2023-05-01","due":"2023-05-22","ransomware":false,"epss":0.99999,"pct":0.99992,"cvss":[]},{"id":"CVE-2021-45046","kev":true,"vendor":"Apache","product":"Log4j2","name":"Apache Log4j2 Deserialization of Untrusted Data Vulnerability","added":"2023-05-01","due":"2023-05-22","ransomware":true,"epss":0.99977,"pct":0.9998,"cvss":[]},{"id":"CVE-2023-21839","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Unspecified Vulnerability","added":"2023-05-01","due":"2023-05-22","ransomware":false,"epss":0.999,"pct":0.99965,"cvss":[]},{"id":"CVE-2023-28432","kev":true,"vendor":"MinIO","product":"MinIO","name":"MinIO Information Disclosure Vulnerability","added":"2023-04-21","due":"2023-05-12","ransomware":false,"epss":0.83957,"pct":0.99688,"cvss":[]},{"id":"CVE-2023-27350","kev":true,"vendor":"PaperCut","product":"MF/NG","name":"PaperCut MF/NG Improper Access Control Vulnerability","added":"2023-04-21","due":"2023-05-12","ransomware":true,"epss":0.99999,"pct":0.99995,"cvss":[]},{"id":"CVE-2023-2136","kev":true,"vendor":"Google","product":"Chromium Skia","name":"Google Chrome Skia Integer Overflow Vulnerability","added":"2023-04-21","due":"2023-05-12","ransomware":false,"epss":0.05739,"pct":0.92833,"cvss":[]},{"id":"CVE-2017-6742","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2023-04-19","due":"2023-05-10","ransomware":false,"epss":0.21424,"pct":0.97547,"cvss":[]},{"id":"CVE-2019-8526","kev":true,"vendor":"Apple","product":"macOS","name":"Apple macOS Use-After-Free Vulnerability","added":"2023-04-17","due":"2023-05-08","ransomware":false,"epss":0.00701,"pct":0.51583,"cvss":[]},{"id":"CVE-2023-2033","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2023-04-17","due":"2023-05-08","ransomware":false,"epss":0.40798,"pct":0.98616,"cvss":[]},{"id":"CVE-2023-20963","kev":true,"vendor":"Android","product":"Framework","name":"Android Framework Privilege Escalation Vulnerability","added":"2023-04-13","due":"2023-05-04","ransomware":false,"epss":0.01465,"pct":0.72779,"cvss":[]},{"id":"CVE-2023-29492","kev":true,"vendor":"Novi Survey","product":"Novi Survey","name":"Novi Survey Insecure Deserialization Vulnerability","added":"2023-04-13","due":"2023-05-04","ransomware":false,"epss":0.0269,"pct":0.85377,"cvss":[]},{"id":"CVE-2023-28252","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability","added":"2023-04-11","due":"2023-05-02","ransomware":true,"epss":0.48973,"pct":0.98849,"cvss":[]},{"id":"CVE-2023-28205","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Use-After-Free Vulnerability","added":"2023-04-10","due":"2023-05-01","ransomware":false,"epss":0.27076,"pct":0.97996,"cvss":[]},{"id":"CVE-2023-28206","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability","added":"2023-04-10","due":"2023-05-01","ransomware":false,"epss":0.23215,"pct":0.97714,"cvss":[]},{"id":"CVE-2021-27876","kev":true,"vendor":"Veritas","product":"Backup Exec Agent","name":"Veritas Backup Exec Agent File Access Vulnerability","added":"2023-04-07","due":"2023-04-28","ransomware":true,"epss":0.13518,"pct":0.96346,"cvss":[]},{"id":"CVE-2021-27877","kev":true,"vendor":"Veritas","product":"Backup Exec Agent","name":"Veritas Backup Exec Agent Improper Authentication Vulnerability","added":"2023-04-07","due":"2023-04-28","ransomware":true,"epss":0.6491,"pct":0.9923,"cvss":[]},{"id":"CVE-2021-27878","kev":true,"vendor":"Veritas","product":"Backup Exec Agent","name":"Veritas Backup Exec Agent Command Execution Vulnerability","added":"2023-04-07","due":"2023-04-28","ransomware":true,"epss":0.23952,"pct":0.97776,"cvss":[]},{"id":"CVE-2019-1388","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability","added":"2023-04-07","due":"2023-04-28","ransomware":true,"epss":0.08589,"pct":0.94932,"cvss":[]},{"id":"CVE-2023-26083","kev":true,"vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","name":"Arm Mali GPU Kernel Driver Information Disclosure Vulnerability","added":"2023-04-07","due":"2023-04-28","ransomware":false,"epss":0.01218,"pct":0.67592,"cvss":[]},{"id":"CVE-2022-27926","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability","added":"2023-04-03","due":"2023-04-24","ransomware":false,"epss":0.17634,"pct":0.97072,"cvss":[]},{"id":"CVE-2013-3163","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.70676,"pct":0.9938,"cvss":[]},{"id":"CVE-2017-7494","kev":true,"vendor":"Samba","product":"Samba","name":"Samba Remote Code Execution Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":true,"epss":0.99448,"pct":0.99943,"cvss":[]},{"id":"CVE-2022-42948","kev":true,"vendor":"Fortra","product":"Cobalt Strike","name":"Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.02706,"pct":0.85468,"cvss":[]},{"id":"CVE-2022-39197","kev":true,"vendor":"Fortra","product":"Cobalt Strike","name":"Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.46446,"pct":0.98786,"cvss":[]},{"id":"CVE-2021-30900","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.05204,"pct":0.92241,"cvss":[]},{"id":"CVE-2022-38181","kev":true,"vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","name":"Arm Mali GPU Kernel Driver Use-After-Free Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.14093,"pct":0.96466,"cvss":[]},{"id":"CVE-2023-0266","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Use-After-Free Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.03702,"pct":0.89408,"cvss":[]},{"id":"CVE-2022-3038","kev":true,"vendor":"Google","product":"Chromium Network Service","name":"Google Chromium Network Service Use-After-Free Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.24925,"pct":0.97856,"cvss":[]},{"id":"CVE-2022-22706","kev":true,"vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","name":"Arm Mali GPU Kernel Driver Unspecified Vulnerability","added":"2023-03-30","due":"2023-04-20","ransomware":false,"epss":0.01062,"pct":0.63417,"cvss":[]},{"id":"CVE-2023-26360","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Deserialization of Untrusted Data Vulnerability","added":"2023-03-15","due":"2023-04-05","ransomware":false,"epss":0.97339,"pct":0.99897,"cvss":[]},{"id":"CVE-2023-23397","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Outlook Privilege Escalation Vulnerability","added":"2023-03-14","due":"2023-04-04","ransomware":false,"epss":0.97159,"pct":0.99894,"cvss":[]},{"id":"CVE-2023-24880","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SmartScreen Security Feature Bypass Vulnerability","added":"2023-03-14","due":"2023-04-04","ransomware":true,"epss":0.78005,"pct":0.99565,"cvss":[]},{"id":"CVE-2022-41328","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Path Traversal Vulnerability","added":"2023-03-14","due":"2023-04-04","ransomware":false,"epss":0.10682,"pct":0.95689,"cvss":[]},{"id":"CVE-2021-39144","kev":true,"vendor":"XStream","product":"XStream","name":"XStream Remote Code Execution Vulnerability","added":"2023-03-10","due":"2023-03-31","ransomware":false,"epss":0.98124,"pct":0.99912,"cvss":[]},{"id":"CVE-2020-5741","kev":true,"vendor":"Plex","product":"Media Server","name":"Plex Media Server Remote Code Execution Vulnerability","added":"2023-03-10","due":"2023-03-31","ransomware":false,"epss":0.72936,"pct":0.9944,"cvss":[]},{"id":"CVE-2022-28810","kev":true,"vendor":"Zoho","product":"ManageEngine","name":"Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability","added":"2023-03-07","due":"2023-03-28","ransomware":false,"epss":0.70966,"pct":0.99389,"cvss":[]},{"id":"CVE-2022-33891","kev":true,"vendor":"Apache","product":"Spark","name":"Apache Spark Command Injection Vulnerability","added":"2023-03-07","due":"2023-03-28","ransomware":false,"epss":0.93244,"pct":0.99834,"cvss":[]},{"id":"CVE-2022-35914","kev":true,"vendor":"Teclib","product":"GLPI","name":"Teclib GLPI Remote Code Execution Vulnerability","added":"2023-03-07","due":"2023-03-28","ransomware":false,"epss":0.9988,"pct":0.99964,"cvss":[]},{"id":"CVE-2022-36537","kev":true,"vendor":"ZK Framework","product":"AuUploader","name":"ZK Framework AuUploader Unspecified Vulnerability","added":"2023-02-27","due":"2023-03-20","ransomware":true,"epss":0.95397,"pct":0.99868,"cvss":[]},{"id":"CVE-2022-47986","kev":true,"vendor":"IBM","product":"Aspera Faspex","name":"IBM Aspera Faspex Code Execution Vulnerability","added":"2023-02-21","due":"2023-03-14","ransomware":true,"epss":0.99968,"pct":0.99977,"cvss":[]},{"id":"CVE-2022-41223","kev":true,"vendor":"Mitel","product":"MiVoice Connect","name":"Mitel MiVoice Connect Code Injection Vulnerability","added":"2023-02-21","due":"2023-03-14","ransomware":true,"epss":0.10657,"pct":0.9568,"cvss":[]},{"id":"CVE-2022-40765","kev":true,"vendor":"Mitel","product":"MiVoice Connect","name":"Mitel MiVoice Connect Command Injection Vulnerability","added":"2023-02-21","due":"2023-03-14","ransomware":true,"epss":0.10566,"pct":0.95657,"cvss":[]},{"id":"CVE-2022-46169","kev":true,"vendor":"Cacti","product":"Cacti","name":"Cacti Command Injection Vulnerability","added":"2023-02-16","due":"2023-03-09","ransomware":false,"epss":0.99826,"pct":0.9996,"cvss":[]},{"id":"CVE-2023-21715","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Publisher Security Feature Bypass Vulnerability","added":"2023-02-14","due":"2023-03-07","ransomware":false,"epss":0.12011,"pct":0.96021,"cvss":[]},{"id":"CVE-2023-23376","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability","added":"2023-02-14","due":"2023-03-07","ransomware":true,"epss":0.10853,"pct":0.95738,"cvss":[]},{"id":"CVE-2023-23529","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Type Confusion Vulnerability","added":"2023-02-14","due":"2023-03-07","ransomware":false,"epss":0.09502,"pct":0.9531,"cvss":[]},{"id":"CVE-2023-21823","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Graphic Component Privilege Escalation Vulnerability","added":"2023-02-14","due":"2023-03-07","ransomware":false,"epss":0.05563,"pct":0.92623,"cvss":[]},{"id":"CVE-2015-2291","kev":true,"vendor":"Intel","product":"Ethernet Diagnostics Driver for Windows","name":"Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability","added":"2023-02-10","due":"2023-03-03","ransomware":true,"epss":0.09011,"pct":0.95135,"cvss":[]},{"id":"CVE-2022-24990","kev":true,"vendor":"TerraMaster","product":"TerraMaster OS","name":"TerraMaster OS Remote Command Execution Vulnerability","added":"2023-02-10","due":"2023-03-03","ransomware":true,"epss":0.83166,"pct":0.99671,"cvss":[]},{"id":"CVE-2023-0669","kev":true,"vendor":"Fortra","product":"GoAnywhere MFT","name":"Fortra GoAnywhere MFT Remote Code Execution Vulnerability","added":"2023-02-10","due":"2023-03-03","ransomware":true,"epss":0.99999,"pct":0.99996,"cvss":[]},{"id":"CVE-2022-21587","kev":true,"vendor":"Oracle","product":"E-Business Suite","name":"Oracle E-Business Suite Unspecified Vulnerability","added":"2023-02-02","due":"2023-02-23","ransomware":true,"epss":0.98342,"pct":0.99917,"cvss":[]},{"id":"CVE-2023-22952","kev":true,"vendor":"SugarCRM","product":"Multiple Products","name":"Multiple SugarCRM Products Remote Code Execution Vulnerability","added":"2023-02-02","due":"2023-02-23","ransomware":false,"epss":0.80139,"pct":0.99609,"cvss":[]},{"id":"CVE-2017-11357","kev":true,"vendor":"Telerik","product":"User Interface (UI) for ASP.NET AJAX","name":"Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability","added":"2023-01-26","due":"2023-02-16","ransomware":true,"epss":0.77679,"pct":0.99556,"cvss":[]},{"id":"CVE-2022-47966","kev":true,"vendor":"Zoho","product":"ManageEngine","name":"Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability","added":"2023-01-23","due":"2023-02-13","ransomware":true,"epss":0.99753,"pct":0.99954,"cvss":[]},{"id":"CVE-2022-44877","kev":true,"vendor":"CWP","product":"Control Web Panel","name":"CWP Control Web Panel OS Command Injection Vulnerability","added":"2023-01-17","due":"2023-02-07","ransomware":false,"epss":0.99995,"pct":0.99988,"cvss":[]},{"id":"CVE-2022-41080","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Privilege Escalation Vulnerability","added":"2023-01-10","due":"2023-01-31","ransomware":true,"epss":0.77326,"pct":0.99546,"cvss":[]},{"id":"CVE-2023-21674","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability","added":"2023-01-10","due":"2023-01-31","ransomware":false,"epss":0.40987,"pct":0.98622,"cvss":[]},{"id":"CVE-2018-5430","kev":true,"vendor":"TIBCO","product":"JasperReports","name":"TIBCO JasperReports Server Information Disclosure Vulnerability","added":"2022-12-29","due":"2023-01-19","ransomware":false,"epss":0.48986,"pct":0.9885,"cvss":[]},{"id":"CVE-2018-18809","kev":true,"vendor":"TIBCO","product":"JasperReports","name":"TIBCO JasperReports Library Directory Traversal Vulnerability","added":"2022-12-29","due":"2023-01-19","ransomware":false,"epss":0.79064,"pct":0.99589,"cvss":[]},{"id":"CVE-2022-42856","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS Type Confusion Vulnerability","added":"2022-12-14","due":"2023-01-04","ransomware":false,"epss":0.08523,"pct":0.94897,"cvss":[]},{"id":"CVE-2022-42475","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability","added":"2022-12-13","due":"2023-01-03","ransomware":true,"epss":0.99474,"pct":0.99943,"cvss":[]},{"id":"CVE-2022-44698","kev":true,"vendor":"Microsoft","product":"Defender","name":"Microsoft Defender SmartScreen Security Feature Bypass Vulnerability","added":"2022-12-13","due":"2023-01-03","ransomware":true,"epss":0.76267,"pct":0.99524,"cvss":[]},{"id":"CVE-2022-27518","kev":true,"vendor":"Citrix","product":"Application Delivery Controller (ADC) and Gateway","name":"Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability","added":"2022-12-13","due":"2023-01-03","ransomware":false,"epss":0.06683,"pct":0.9371,"cvss":[]},{"id":"CVE-2022-26500","kev":true,"vendor":"Veeam","product":"Backup & Replication","name":"Veeam Backup & Replication Remote Code Execution Vulnerability","added":"2022-12-13","due":"2023-01-03","ransomware":true,"epss":0.05828,"pct":0.92943,"cvss":[]},{"id":"CVE-2022-26501","kev":true,"vendor":"Veeam","product":"Backup & Replication","name":"Veeam Backup & Replication Remote Code Execution Vulnerability","added":"2022-12-13","due":"2023-01-03","ransomware":true,"epss":0.04104,"pct":0.90458,"cvss":[]},{"id":"CVE-2022-4262","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2022-12-05","due":"2022-12-26","ransomware":false,"epss":0.2351,"pct":0.9774,"cvss":[]},{"id":"CVE-2021-35587","kev":true,"vendor":"Oracle","product":"Fusion Middleware","name":"Oracle Fusion Middleware Unspecified Vulnerability","added":"2022-11-28","due":"2022-12-19","ransomware":false,"epss":0.96284,"pct":0.99879,"cvss":[]},{"id":"CVE-2022-4135","kev":true,"vendor":"Google","product":"Chromium GPU","name":"Google Chromium GPU Heap Buffer Overflow Vulnerability","added":"2022-11-28","due":"2022-12-19","ransomware":false,"epss":0.31864,"pct":0.98259,"cvss":[]},{"id":"CVE-2022-41049","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability","added":"2022-11-14","due":"2022-12-09","ransomware":false,"epss":0.02491,"pct":0.8411,"cvss":[]},{"id":"CVE-2022-41091","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability","added":"2022-11-08","due":"2022-12-09","ransomware":true,"epss":0.01806,"pct":0.77827,"cvss":[]},{"id":"CVE-2022-41073","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Print Spooler Privilege Escalation Vulnerability","added":"2022-11-08","due":"2022-12-09","ransomware":true,"epss":0.02278,"pct":0.82538,"cvss":[]},{"id":"CVE-2022-41125","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability","added":"2022-11-08","due":"2022-12-09","ransomware":false,"epss":0.03046,"pct":0.871,"cvss":[]},{"id":"CVE-2022-41128","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Scripting Languages Remote Code Execution Vulnerability","added":"2022-11-08","due":"2022-12-09","ransomware":false,"epss":0.24623,"pct":0.97827,"cvss":[]},{"id":"CVE-2021-25337","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Improper Access Control Vulnerability","added":"2022-11-08","due":"2022-11-29","ransomware":false,"epss":0.02807,"pct":0.86031,"cvss":[]},{"id":"CVE-2021-25369","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Improper Access Control Vulnerability","added":"2022-11-08","due":"2022-11-29","ransomware":false,"epss":0.01079,"pct":0.63889,"cvss":[]},{"id":"CVE-2021-25370","kev":true,"vendor":"Samsung","product":"Mobile Devices","name":"Samsung Mobile Devices Memory Corruption Vulnerability","added":"2022-11-08","due":"2022-11-29","ransomware":false,"epss":0.0089,"pct":0.57977,"cvss":[]},{"id":"CVE-2022-3723","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2022-10-28","due":"2022-11-18","ransomware":false,"epss":0.07921,"pct":0.94564,"cvss":[]},{"id":"CVE-2022-42827","kev":true,"vendor":"Apple","product":"iOS and iPadOS","name":"Apple iOS and iPadOS Out-of-Bounds Write Vulnerability","added":"2022-10-25","due":"2022-11-15","ransomware":false,"epss":0.01048,"pct":0.63006,"cvss":[]},{"id":"CVE-2020-3433","kev":true,"vendor":"Cisco","product":"AnyConnect Secure","name":"Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability","added":"2022-10-24","due":"2022-11-14","ransomware":true,"epss":0.10049,"pct":0.95495,"cvss":[]},{"id":"CVE-2020-3153","kev":true,"vendor":"Cisco","product":"AnyConnect Secure","name":"Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability","added":"2022-10-24","due":"2022-11-14","ransomware":true,"epss":0.28307,"pct":0.98071,"cvss":[]},{"id":"CVE-2018-19323","kev":true,"vendor":"GIGABYTE","product":"Multiple Products","name":"GIGABYTE Multiple Products Privilege Escalation Vulnerability","added":"2022-10-24","due":"2022-11-14","ransomware":true,"epss":0.08296,"pct":0.9477,"cvss":[]},{"id":"CVE-2018-19322","kev":true,"vendor":"GIGABYTE","product":"Multiple Products","name":"GIGABYTE Multiple Products Code Execution Vulnerability","added":"2022-10-24","due":"2022-11-14","ransomware":true,"epss":0.01801,"pct":0.77757,"cvss":[]},{"id":"CVE-2018-19321","kev":true,"vendor":"GIGABYTE","product":"Multiple Products","name":"GIGABYTE Multiple Products Privilege Escalation Vulnerability","added":"2022-10-24","due":"2022-11-14","ransomware":true,"epss":0.03671,"pct":0.89315,"cvss":[]},{"id":"CVE-2018-19320","kev":true,"vendor":"GIGABYTE","product":"Multiple Products","name":"GIGABYTE Multiple Products Unspecified Vulnerability","added":"2022-10-24","due":"2022-11-14","ransomware":true,"epss":0.03597,"pct":0.891,"cvss":[]},{"id":"CVE-2022-41352","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability","added":"2022-10-20","due":"2022-11-10","ransomware":true,"epss":0.95478,"pct":0.99869,"cvss":[]},{"id":"CVE-2021-3493","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Privilege Escalation Vulnerability","added":"2022-10-20","due":"2022-11-10","ransomware":false,"epss":0.49166,"pct":0.98854,"cvss":[]},{"id":"CVE-2022-40684","kev":true,"vendor":"Fortinet","product":"Multiple Products","name":"Fortinet Multiple Products Authentication Bypass Vulnerability","added":"2022-10-11","due":"2022-11-01","ransomware":true,"epss":0.99984,"pct":0.99983,"cvss":[]},{"id":"CVE-2022-41033","kev":true,"vendor":"Microsoft","product":"Windows COM+ Event System Service","name":"Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability","added":"2022-10-11","due":"2022-11-01","ransomware":false,"epss":0.01696,"pct":0.76356,"cvss":[]},{"id":"CVE-2022-41082","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2022-09-30","due":"2022-10-21","ransomware":true,"epss":0.9997,"pct":0.99978,"cvss":[]},{"id":"CVE-2022-41040","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Server-Side Request Forgery Vulnerability","added":"2022-09-30","due":"2022-10-21","ransomware":true,"epss":0.99956,"pct":0.99974,"cvss":[]},{"id":"CVE-2022-36804","kev":true,"vendor":"Atlassian","product":"Bitbucket Server and Data Center","name":"Atlassian Bitbucket Server and Data Center Command Injection Vulnerability","added":"2022-09-30","due":"2022-10-21","ransomware":false,"epss":0.99174,"pct":0.99934,"cvss":[]},{"id":"CVE-2022-3236","kev":true,"vendor":"Sophos","product":"Firewall","name":"Sophos Firewall Code Injection Vulnerability","added":"2022-09-23","due":"2022-10-14","ransomware":false,"epss":0.98905,"pct":0.99927,"cvss":[]},{"id":"CVE-2022-35405","kev":true,"vendor":"Zoho","product":"ManageEngine","name":"Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability","added":"2022-09-22","due":"2022-10-13","ransomware":false,"epss":0.99924,"pct":0.99969,"cvss":[]},{"id":"CVE-2022-40139","kev":true,"vendor":"Trend Micro","product":"Apex One and Apex One as a Service","name":"Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability","added":"2022-09-15","due":"2022-10-06","ransomware":false,"epss":0.03291,"pct":0.881,"cvss":[]},{"id":"CVE-2013-6282","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Improper Input Validation Vulnerability","added":"2022-09-15","due":"2022-10-06","ransomware":false,"epss":0.39711,"pct":0.98582,"cvss":[]},{"id":"CVE-2013-2597","kev":true,"vendor":"Code Aurora","product":"ACDB Audio Driver","name":"Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability","added":"2022-09-15","due":"2022-10-06","ransomware":false,"epss":0.01503,"pct":0.73438,"cvss":[]},{"id":"CVE-2013-2596","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Integer Overflow Vulnerability","added":"2022-09-15","due":"2022-10-06","ransomware":false,"epss":0.03212,"pct":0.87762,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2013-04-13T02:59:46.627Z","modified":"2026-06-16T23:53:41.450Z"},{"id":"CVE-2013-2094","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Privilege Escalation Vulnerability","added":"2022-09-15","due":"2022-10-06","ransomware":false,"epss":0.47709,"pct":0.98817,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":7.2,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.4,"severity":"HIGH"}],"published":"2013-05-14T20:55:01.527Z","modified":"2026-06-16T23:52:44.150Z"},{"id":"CVE-2010-2568","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Remote Code Execution Vulnerability","added":"2022-09-15","due":"2022-10-06","ransomware":false,"epss":0.91324,"pct":0.9981,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-07-22T05:43:49.703Z","modified":"2026-06-16T23:20:59.973Z"},{"id":"CVE-2022-37969","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability","added":"2022-09-14","due":"2022-10-05","ransomware":true,"epss":0.28275,"pct":0.9807,"cvss":[]},{"id":"CVE-2022-32917","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability","added":"2022-09-14","due":"2022-10-05","ransomware":false,"epss":0.05603,"pct":0.92678,"cvss":[]},{"id":"CVE-2022-3075","kev":true,"vendor":"Google","product":"Chromium Mojo","name":"Google Chromium Mojo Insufficient Data Validation Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.05806,"pct":0.92914,"cvss":[]},{"id":"CVE-2022-27593","kev":true,"vendor":"QNAP","product":"Photo Station","name":"QNAP Photo Station Externally Controlled Reference Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":true,"epss":0.87908,"pct":0.9976,"cvss":[]},{"id":"CVE-2022-26258","kev":true,"vendor":"D-Link","product":"DIR-820L","name":"D-Link DIR-820L Remote Code Execution Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.91981,"pct":0.99818,"cvss":[]},{"id":"CVE-2020-9934","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS Input Validation Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.03208,"pct":0.87744,"cvss":[]},{"id":"CVE-2018-7445","kev":true,"vendor":"MikroTik","product":"RouterOS","name":"MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.60809,"pct":0.99128,"cvss":[]},{"id":"CVE-2018-6530","kev":true,"vendor":"D-Link","product":"Multiple Routers","name":"D-Link Multiple Routers OS Command Injection Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":true,"epss":0.96682,"pct":0.99885,"cvss":[]},{"id":"CVE-2018-2628","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Unspecified Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.99958,"pct":0.99975,"cvss":[]},{"id":"CVE-2018-13374","kev":true,"vendor":"Fortinet","product":"FortiOS and FortiADC","name":"Fortinet FortiOS and FortiADC Improper Access Control Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":true,"epss":0.37832,"pct":0.98507,"cvss":[]},{"id":"CVE-2017-5521","kev":true,"vendor":"NETGEAR","product":"Multiple Devices","name":"NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.89245,"pct":0.99779,"cvss":[]},{"id":"CVE-2011-4723","kev":true,"vendor":"D-Link","product":"DIR-300 Router","name":"D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.03064,"pct":0.87184,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":6.8,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":5.7,"severity":"MEDIUM"}],"published":"2011-12-20T11:55:08.413Z","modified":"2026-06-16T23:35:18.387Z"},{"id":"CVE-2011-1823","kev":true,"vendor":"Android","product":"Android OS","name":"Android OS Privilege Escalation Vulnerability","added":"2022-09-08","due":"2022-09-29","ransomware":false,"epss":0.41367,"pct":0.98636,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2011-06-09T10:36:27.680Z","modified":"2026-06-16T23:30:11.197Z"},{"id":"CVE-2022-26352","kev":true,"vendor":"dotCMS","product":"dotCMS","name":"dotCMS Unrestricted Upload of File Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":true,"epss":0.91248,"pct":0.99808,"cvss":[]},{"id":"CVE-2022-24706","kev":true,"vendor":"Apache","product":"CouchDB","name":"Apache CouchDB Insecure Default Initialization of Resource Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.9251,"pct":0.99825,"cvss":[]},{"id":"CVE-2022-24112","kev":true,"vendor":"Apache","product":"APISIX","name":"Apache APISIX Authentication Bypass Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.96069,"pct":0.99876,"cvss":[]},{"id":"CVE-2022-22963","kev":true,"vendor":"VMware Tanzu","product":"Spring Cloud","name":"VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.99938,"pct":0.99971,"cvss":[]},{"id":"CVE-2022-2294","kev":true,"vendor":"WebRTC","product":"WebRTC","name":"WebRTC Heap Buffer Overflow Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":true,"epss":0.70461,"pct":0.99374,"cvss":[]},{"id":"CVE-2021-39226","kev":true,"vendor":"Grafana Labs","product":"Grafana","name":"Grafana Authentication Bypass Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.99933,"pct":0.9997,"cvss":[]},{"id":"CVE-2021-38406","kev":true,"vendor":"Delta Electronics","product":"DOPSoft 2","name":"Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.76428,"pct":0.99528,"cvss":[]},{"id":"CVE-2021-31010","kev":true,"vendor":"Apple","product":"iOS, macOS, watchOS","name":"Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.03673,"pct":0.89325,"cvss":[]},{"id":"CVE-2020-36193","kev":true,"vendor":"PEAR","product":"Archive_Tar","name":"PEAR Archive_Tar Improper Link Resolution Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.70595,"pct":0.99377,"cvss":[]},{"id":"CVE-2020-28949","kev":true,"vendor":"PEAR","product":"Archive_Tar","name":"PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability","added":"2022-08-25","due":"2022-09-15","ransomware":false,"epss":0.84554,"pct":0.99697,"cvss":[]},{"id":"CVE-2022-0028","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability","added":"2022-08-22","due":"2022-09-12","ransomware":false,"epss":0.02542,"pct":0.84452,"cvss":[]},{"id":"CVE-2022-22536","kev":true,"vendor":"SAP","product":"Multiple Products","name":"SAP Multiple Products HTTP Request Smuggling Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.97945,"pct":0.99909,"cvss":[]},{"id":"CVE-2022-32894","kev":true,"vendor":"Apple","product":"iOS and macOS","name":"Apple iOS and macOS Out-of-Bounds Write Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.03286,"pct":0.88075,"cvss":[]},{"id":"CVE-2022-32893","kev":true,"vendor":"Apple","product":"iOS and macOS","name":"Apple iOS and macOS Out-of-Bounds Write Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.09931,"pct":0.95462,"cvss":[]},{"id":"CVE-2022-2856","kev":true,"vendor":"Google","product":"Chromium Intents","name":"Google Chromium Intents Insufficient Input Validation Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.0453,"pct":0.91265,"cvss":[]},{"id":"CVE-2022-26923","kev":true,"vendor":"Microsoft","product":"Active Directory","name":"Microsoft Active Directory Domain Services Privilege Escalation Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.835,"pct":0.99678,"cvss":[]},{"id":"CVE-2022-21971","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Runtime Remote Code Execution Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.53934,"pct":0.98974,"cvss":[]},{"id":"CVE-2017-15944","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Remote Code Execution Vulnerability","added":"2022-08-18","due":"2022-09-08","ransomware":false,"epss":0.98303,"pct":0.99916,"cvss":[]},{"id":"CVE-2022-27925","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability","added":"2022-08-11","due":"2022-09-01","ransomware":true,"epss":0.98676,"pct":0.99923,"cvss":[]},{"id":"CVE-2022-37042","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability","added":"2022-08-11","due":"2022-09-01","ransomware":true,"epss":0.91893,"pct":0.99816,"cvss":[]},{"id":"CVE-2022-34713","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability","added":"2022-08-09","due":"2022-08-30","ransomware":false,"epss":0.67757,"pct":0.99301,"cvss":[]},{"id":"CVE-2022-30333","kev":true,"vendor":"RARLAB","product":"UnRAR","name":"RARLAB UnRAR Directory Traversal Vulnerability","added":"2022-08-09","due":"2022-08-30","ransomware":true,"epss":0.99233,"pct":0.99936,"cvss":[]},{"id":"CVE-2022-27924","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability","added":"2022-08-04","due":"2022-08-25","ransomware":true,"epss":0.93908,"pct":0.99844,"cvss":[]},{"id":"CVE-2022-26138","kev":true,"vendor":"Atlassian","product":"Confluence","name":"Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability","added":"2022-07-29","due":"2022-08-19","ransomware":false,"epss":0.9817,"pct":0.99914,"cvss":[]},{"id":"CVE-2022-22047","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability","added":"2022-07-12","due":"2022-08-02","ransomware":false,"epss":0.18765,"pct":0.97203,"cvss":[]},{"id":"CVE-2022-26925","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows LSA Spoofing Vulnerability","added":"2022-07-01","due":"2022-07-22","ransomware":false,"epss":0.10476,"pct":0.95629,"cvss":[]},{"id":"CVE-2022-29499","kev":true,"vendor":"Mitel","product":"MiVoice Connect","name":"Mitel MiVoice Connect Data Validation Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":true,"epss":0.55242,"pct":0.99005,"cvss":[]},{"id":"CVE-2021-30533","kev":true,"vendor":"Google","product":"Chromium PopupBlocker","name":"Google Chromium PopupBlocker Security Bypass Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":false,"epss":0.16742,"pct":0.96954,"cvss":[]},{"id":"CVE-2021-4034","kev":true,"vendor":"Red Hat","product":"Polkit","name":"Red Hat Polkit Out-of-Bounds Read and Write Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":true,"epss":0.94345,"pct":0.9985,"cvss":[]},{"id":"CVE-2021-30983","kev":true,"vendor":"Apple","product":"iOS and iPadOS","name":"Apple iOS and iPadOS Buffer Overflow Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":false,"epss":0.02923,"pct":0.86589,"cvss":[]},{"id":"CVE-2020-3837","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":false,"epss":0.14839,"pct":0.96601,"cvss":[]},{"id":"CVE-2020-9907","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":false,"epss":0.03199,"pct":0.87705,"cvss":[]},{"id":"CVE-2019-8605","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Use-After-Free Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":false,"epss":0.17609,"pct":0.97069,"cvss":[]},{"id":"CVE-2018-4344","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2022-06-27","due":"2022-07-18","ransomware":false,"epss":0.02374,"pct":0.83269,"cvss":[]},{"id":"CVE-2022-30190","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability","added":"2022-06-14","due":"2022-07-05","ransomware":true,"epss":0.99163,"pct":0.99933,"cvss":[]},{"id":"CVE-2021-38163","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Unrestricted File Upload Vulnerability","added":"2022-06-09","due":"2022-06-30","ransomware":false,"epss":0.36898,"pct":0.9847,"cvss":[]},{"id":"CVE-2016-2386","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver SQL Injection Vulnerability","added":"2022-06-09","due":"2022-06-30","ransomware":false,"epss":0.71522,"pct":0.99403,"cvss":[]},{"id":"CVE-2016-2388","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Information Disclosure Vulnerability","added":"2022-06-09","due":"2022-06-30","ransomware":false,"epss":0.52206,"pct":0.98929,"cvss":[]},{"id":"CVE-2019-7195","kev":true,"vendor":"QNAP","product":"Photo Station","name":"QNAP Photo Station Path Traversal Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":true,"epss":0.89681,"pct":0.99786,"cvss":[]},{"id":"CVE-2019-7194","kev":true,"vendor":"QNAP","product":"Photo Station","name":"QNAP Photo Station Path Traversal Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":true,"epss":0.83124,"pct":0.99669,"cvss":[]},{"id":"CVE-2019-7193","kev":true,"vendor":"QNAP","product":"QTS","name":"QNAP QTS Improper Input Validation Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":true,"epss":0.14367,"pct":0.96522,"cvss":[]},{"id":"CVE-2019-7192","kev":true,"vendor":"QNAP","product":"Photo Station","name":"QNAP Photo Station Improper Access Control Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":true,"epss":0.88102,"pct":0.99764,"cvss":[]},{"id":"CVE-2019-5825","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Write Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.55925,"pct":0.99021,"cvss":[]},{"id":"CVE-2019-15271","kev":true,"vendor":"Cisco","product":"RV Series Routers","name":"Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.05488,"pct":0.92537,"cvss":[]},{"id":"CVE-2018-6065","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Integer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.60304,"pct":0.99118,"cvss":[]},{"id":"CVE-2018-4990","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Double Free Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.36228,"pct":0.9844,"cvss":[]},{"id":"CVE-2018-17480","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Write Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.3564,"pct":0.9842,"cvss":[]},{"id":"CVE-2018-17463","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Remote Code Execution Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.84564,"pct":0.99698,"cvss":[]},{"id":"CVE-2017-6862","kev":true,"vendor":"NETGEAR","product":"Multiple Devices","name":"NETGEAR Multiple Devices Buffer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.45748,"pct":0.98766,"cvss":[]},{"id":"CVE-2017-5070","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.32071,"pct":0.98269,"cvss":[]},{"id":"CVE-2017-5030","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Memory Corruption Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.40635,"pct":0.98613,"cvss":[]},{"id":"CVE-2016-5198","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Memory Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.34164,"pct":0.98363,"cvss":[]},{"id":"CVE-2016-1646","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Read Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.4811,"pct":0.98825,"cvss":[]},{"id":"CVE-2013-1331","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Buffer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.79822,"pct":0.99603,"cvss":[]},{"id":"CVE-2012-5054","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Integer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.21194,"pct":0.97525,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2012-09-24T17:55:07.217Z","modified":"2026-06-16T23:46:05.460Z"},{"id":"CVE-2012-4969","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.8025,"pct":0.99612,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.1,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.1,"severity":"HIGH"}],"published":"2012-09-18T10:39:14.147Z","modified":"2026-06-16T23:45:58.897Z"},{"id":"CVE-2012-1889","kev":true,"vendor":"Microsoft","product":"XML Core Services","name":"Microsoft XML Core Services Memory Corruption Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.83516,"pct":0.99679,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2012-06-13T04:46:46.190Z","modified":"2026-06-16T23:40:29.923Z"},{"id":"CVE-2012-0767","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.06187,"pct":0.93296,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":6.1,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":6.1,"severity":"MEDIUM"}],"published":"2012-02-16T19:55:01.303Z","modified":"2026-06-16T23:38:13.193Z"},{"id":"CVE-2012-0754","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Memory Corruption Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.91085,"pct":0.99806,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.1,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2012-02-16T19:55:01.130Z","modified":"2026-06-16T23:38:11.620Z"},{"id":"CVE-2012-0151","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.87719,"pct":0.99758,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2012-04-10T21:55:01.597Z","modified":"2026-06-16T23:36:47.550Z"},{"id":"CVE-2011-2462","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.88881,"pct":0.99775,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2011-12-07T19:55:01.673Z","modified":"2026-06-16T23:31:23.203Z"},{"id":"CVE-2011-0609","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Unspecified Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.63507,"pct":0.99192,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2011-03-15T17:55:03.827Z","modified":"2026-06-16T23:27:44.460Z"},{"id":"CVE-2010-2883","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.81376,"pct":0.99631,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.3,"severity":"HIGH"}],"published":"2010-09-09T22:00:02.250Z","modified":"2026-06-16T23:21:41.330Z"},{"id":"CVE-2010-2572","kev":true,"vendor":"Microsoft","product":"PowerPoint","name":"Microsoft PowerPoint Buffer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.58646,"pct":0.99081,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-11-10T03:00:01.850Z","modified":"2026-06-16T23:21:00.513Z"},{"id":"CVE-2010-1297","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Memory Corruption Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.82531,"pct":0.99658,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-06-08T18:30:10.007Z","modified":"2026-06-16T23:18:02.793Z"},{"id":"CVE-2009-4324","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Use-After-Free Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.8188,"pct":0.99641,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2009-12-15T02:30:00.217Z","modified":"2026-06-16T23:13:26.803Z"},{"id":"CVE-2009-3953","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.83219,"pct":0.99672,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2010-01-13T19:30:00.343Z","modified":"2026-06-16T23:12:41.597Z"},{"id":"CVE-2009-1862","kev":true,"vendor":"Adobe","product":"Acrobat and Reader, Flash Player","name":"Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.21198,"pct":0.97526,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2009-07-23T20:30:00.233Z","modified":"2026-06-16T23:08:13.467Z"},{"id":"CVE-2009-0563","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Buffer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.62828,"pct":0.99176,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2009-06-10T18:00:00.313Z","modified":"2026-06-16T23:05:18.980Z"},{"id":"CVE-2009-0557","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Object Record Corruption Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.53,"pct":0.98948,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2009-06-10T18:30:00.203Z","modified":"2026-06-16T23:05:18.140Z"},{"id":"CVE-2008-0655","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Unspecified Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.37871,"pct":0.98509,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2008-02-07T21:00:00.000Z","modified":"2026-06-16T22:50:04.270Z"},{"id":"CVE-2007-5659","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Buffer Overflow Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.87423,"pct":0.99754,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2008-02-12T19:00:00.000Z","modified":"2026-06-16T22:46:35.347Z"},{"id":"CVE-2006-2492","kev":true,"vendor":"Microsoft","product":"Word","name":"Microsoft Word Malformed Object Pointer Vulnerability","added":"2022-06-08","due":"2022-06-22","ransomware":false,"epss":0.48107,"pct":0.98825,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2006-05-20T00:02:00.000Z","modified":"2026-06-16T22:25:09.880Z"},{"id":"CVE-2022-26134","kev":true,"vendor":"Atlassian","product":"Confluence Server/Data Center","name":"Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability","added":"2022-06-02","due":"2022-06-06","ransomware":true,"epss":0.99999,"pct":0.99994,"cvss":[]},{"id":"CVE-2019-3010","kev":true,"vendor":"Oracle","product":"Solaris","name":"Oracle Solaris Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.13399,"pct":0.96319,"cvss":[]},{"id":"CVE-2016-3393","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.68465,"pct":0.99319,"cvss":[]},{"id":"CVE-2016-7256","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Open Type Font Remote Code Execution Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.64591,"pct":0.99221,"cvss":[]},{"id":"CVE-2016-1010","kev":true,"vendor":"Adobe","product":"Flash Player and AIR","name":"Adobe Flash Player and AIR Integer Overflow Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.19333,"pct":0.97274,"cvss":[]},{"id":"CVE-2016-0984","kev":true,"vendor":"Adobe","product":"Flash Player and AIR","name":"Adobe Flash Player and AIR Use-After-Free Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.54544,"pct":0.98991,"cvss":[]},{"id":"CVE-2016-0034","kev":true,"vendor":"Microsoft","product":"Silverlight","name":"Microsoft Silverlight Runtime Remote Code Execution Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.69397,"pct":0.99344,"cvss":[]},{"id":"CVE-2015-0310","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player ASLR Bypass Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.15097,"pct":0.96643,"cvss":[]},{"id":"CVE-2015-0016","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows TS WebProxy Directory Traversal Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.75777,"pct":0.99512,"cvss":[]},{"id":"CVE-2015-0071","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer ASLR Bypass Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.33581,"pct":0.98343,"cvss":[]},{"id":"CVE-2015-2360","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.1484,"pct":0.96602,"cvss":[]},{"id":"CVE-2015-2425","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.44727,"pct":0.98735,"cvss":[]},{"id":"CVE-2015-1769","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Mount Manager Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.04078,"pct":0.90399,"cvss":[]},{"id":"CVE-2015-4495","kev":true,"vendor":"Mozilla","product":"Firefox","name":"Mozilla Firefox Security Feature Bypass Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.68558,"pct":0.99322,"cvss":[]},{"id":"CVE-2015-8651","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Integer Overflow Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.67698,"pct":0.993,"cvss":[]},{"id":"CVE-2015-6175","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.05127,"pct":0.92144,"cvss":[]},{"id":"CVE-2015-1671","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Remote Code Execution Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.48986,"pct":0.9885,"cvss":[]},{"id":"CVE-2014-4148","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Remote Code Execution Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.5985,"pct":0.99109,"cvss":[]},{"id":"CVE-2014-8439","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Dereferenced Pointer Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.20369,"pct":0.97421,"cvss":[]},{"id":"CVE-2014-4123","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.47133,"pct":0.98802,"cvss":[]},{"id":"CVE-2014-0546","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Sandbox Bypass Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.2233,"pct":0.97627,"cvss":[]},{"id":"CVE-2014-2817","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.26349,"pct":0.97952,"cvss":[]},{"id":"CVE-2014-4077","kev":true,"vendor":"Microsoft","product":"Input Method Editor (IME) Japanese","name":"Microsoft IME Japanese Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.54577,"pct":0.98992,"cvss":[]},{"id":"CVE-2014-3153","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Privilege Escalation Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.37233,"pct":0.98485,"cvss":[]},{"id":"CVE-2013-7331","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Information Disclosure Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.5021,"pct":0.98877,"cvss":[]},{"id":"CVE-2013-3993","kev":true,"vendor":"IBM","product":"InfoSphere BigInsights","name":"IBM InfoSphere BigInsights Invalid Input Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.04766,"pct":0.91639,"cvss":[]},{"id":"CVE-2013-3896","kev":true,"vendor":"Microsoft","product":"Silverlight","name":"Microsoft Silverlight Information Disclosure Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.67959,"pct":0.99306,"cvss":[]},{"id":"CVE-2013-2423","kev":true,"vendor":"Oracle","product":"Java Runtime Environment (JRE)","name":"Oracle JRE Unspecified Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.85215,"pct":0.99712,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":4.3,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":3.7,"severity":"LOW"}],"published":"2013-04-17T18:55:07.087Z","modified":"2026-06-16T23:53:20.027Z"},{"id":"CVE-2013-0431","kev":true,"vendor":"Oracle","product":"Java Runtime Environment (JRE)","name":"Oracle JRE Sandbox Bypass Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.9015,"pct":0.99795,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":5,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":3.7,"severity":"LOW"}],"published":"2013-01-31T14:55:01.327Z","modified":"2026-10-02T14:55:14.407Z"},{"id":"CVE-2013-0422","kev":true,"vendor":"Oracle","product":"Java Runtime Environment (JRE)","name":"Oracle JRE Remote Code Execution Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.97024,"pct":0.99891,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":10,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2013-01-10T21:55:00.777Z","modified":"2026-06-16T23:49:24.963Z"},{"id":"CVE-2013-0074","kev":true,"vendor":"Microsoft","product":"Silverlight","name":"Microsoft Silverlight Double Dereference Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.78885,"pct":0.99585,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2013-03-13T00:55:01.137Z","modified":"2026-08-14T05:16:52.040Z"},{"id":"CVE-2012-1710","kev":true,"vendor":"Oracle","product":"Fusion Middleware","name":"Oracle Fusion Middleware Unspecified Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.07826,"pct":0.94509,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-05-03T22:55:02.967Z","modified":"2026-10-01T20:17:14.953Z"},{"id":"CVE-2010-1428","kev":true,"vendor":"Red Hat","product":"JBoss","name":"Red Hat JBoss Information Disclosure Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.61487,"pct":0.99145,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":5.9,"severity":"MEDIUM"}],"published":"2010-04-28T22:30:00.793Z","modified":"2026-10-02T14:55:25.677Z"},{"id":"CVE-2010-0840","kev":true,"vendor":"Oracle","product":"Java Runtime Environment (JRE)","name":"Oracle JRE Unspecified Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":false,"epss":0.96319,"pct":0.9988,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2010-04-01T16:30:00.907Z","modified":"2026-06-16T23:16:57.020Z"},{"id":"CVE-2010-0738","kev":true,"vendor":"Red Hat","product":"JBoss","name":"Red Hat JBoss Authentication Bypass Vulnerability","added":"2022-05-25","due":"2022-06-15","ransomware":true,"epss":0.7958,"pct":0.99597,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":5.3,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":3.7,"severity":"LOW"}],"published":"2010-04-28T22:30:00.447Z","modified":"2026-10-02T14:55:30.687Z"},{"id":"CVE-2018-8611","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.04196,"pct":0.90652,"cvss":[]},{"id":"CVE-2018-19953","kev":true,"vendor":"QNAP","product":"Network Attached Storage (NAS)","name":"QNAP NAS File Station Cross-Site Scripting Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":true,"epss":0.28771,"pct":0.98098,"cvss":[]},{"id":"CVE-2018-19949","kev":true,"vendor":"QNAP","product":"Network Attached Storage (NAS)","name":"QNAP NAS File Station Command Injection Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":true,"epss":0.28421,"pct":0.98078,"cvss":[]},{"id":"CVE-2018-19943","kev":true,"vendor":"QNAP","product":"Network Attached Storage (NAS)","name":"QNAP NAS File Station Cross-Site Scripting Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":true,"epss":0.21476,"pct":0.97552,"cvss":[]},{"id":"CVE-2017-0147","kev":true,"vendor":"Microsoft","product":"SMBv1 server","name":"Microsoft Windows SMBv1 Information Disclosure Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":true,"epss":0.99693,"pct":0.9995,"cvss":[]},{"id":"CVE-2017-0022","kev":true,"vendor":"Microsoft","product":"XML Core Services","name":"Microsoft XML Core Services Information Disclosure Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.18069,"pct":0.97118,"cvss":[]},{"id":"CVE-2017-0005","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.11022,"pct":0.9579,"cvss":[]},{"id":"CVE-2017-0149","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.29178,"pct":0.98124,"cvss":[]},{"id":"CVE-2017-0210","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Privilege Escalation Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.22334,"pct":0.97628,"cvss":[]},{"id":"CVE-2017-8291","kev":true,"vendor":"Artifex","product":"Ghostscript","name":"Artifex Ghostscript Type Confusion Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.96968,"pct":0.9989,"cvss":[]},{"id":"CVE-2017-8543","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Search Remote Code Execution Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.74164,"pct":0.99476,"cvss":[]},{"id":"CVE-2017-18362","kev":true,"vendor":"Kaseya","product":"Virtual System/Server Administrator (VSA)","name":"Kaseya VSA SQL Injection Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":true,"epss":0.8682,"pct":0.99741,"cvss":[]},{"id":"CVE-2016-0162","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Information Disclosure Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.22012,"pct":0.97601,"cvss":[]},{"id":"CVE-2016-3351","kev":true,"vendor":"Microsoft","product":"Internet Explorer and Edge","name":"Microsoft Internet Explorer and Edge Information Disclosure Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":true,"epss":0.26286,"pct":0.97949,"cvss":[]},{"id":"CVE-2016-4655","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS Information Disclosure Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.33353,"pct":0.98333,"cvss":[]},{"id":"CVE-2016-4656","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS Memory Corruption Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.23626,"pct":0.9775,"cvss":[]},{"id":"CVE-2016-4657","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS Webkit Memory Corruption Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.66788,"pct":0.99274,"cvss":[]},{"id":"CVE-2016-6366","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","name":"Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.87565,"pct":0.99756,"cvss":[]},{"id":"CVE-2016-6367","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","name":"Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.22583,"pct":0.97657,"cvss":[]},{"id":"CVE-2016-3298","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability","added":"2022-05-24","due":"2022-06-14","ransomware":false,"epss":0.33332,"pct":0.9833,"cvss":[]},{"id":"CVE-2022-20821","kev":true,"vendor":"Cisco","product":"IOS XR","name":"Cisco IOS XR Open Port Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.11471,"pct":0.95902,"cvss":[]},{"id":"CVE-2021-1048","kev":true,"vendor":"Android","product":"Kernel","name":"Android Kernel Use-After-Free Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.01,"pct":0.61536,"cvss":[]},{"id":"CVE-2021-0920","kev":true,"vendor":"Android","product":"Kernel","name":"Android Kernel Race Condition Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.0082,"pct":0.55784,"cvss":[]},{"id":"CVE-2021-30883","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.14721,"pct":0.96582,"cvss":[]},{"id":"CVE-2020-1027","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.04547,"pct":0.91302,"cvss":[]},{"id":"CVE-2020-0638","kev":true,"vendor":"Microsoft","product":"Update Notification Manager","name":"Microsoft Update Notification Manager Privilege Escalation Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":true,"epss":0.02351,"pct":0.83113,"cvss":[]},{"id":"CVE-2019-7286","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.15939,"pct":0.96807,"cvss":[]},{"id":"CVE-2019-7287","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS Memory Corruption Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.04579,"pct":0.91354,"cvss":[]},{"id":"CVE-2019-0676","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Information Disclosure Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.0811,"pct":0.94672,"cvss":[]},{"id":"CVE-2019-5786","kev":true,"vendor":"Google","product":"Chrome Blink","name":"Google Chrome Blink Use-After-Free Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.61085,"pct":0.99136,"cvss":[]},{"id":"CVE-2019-0703","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SMB Information Disclosure Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.0964,"pct":0.95357,"cvss":[]},{"id":"CVE-2019-0880","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.02289,"pct":0.82621,"cvss":[]},{"id":"CVE-2019-13720","kev":true,"vendor":"Google","product":"Chrome WebAudio","name":"Google Chrome WebAudio Use-After-Free Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.4914,"pct":0.98853,"cvss":[]},{"id":"CVE-2019-11707","kev":true,"vendor":"Mozilla","product":"Firefox and Thunderbird","name":"Mozilla Firefox and Thunderbird Type Confusion Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.37696,"pct":0.98502,"cvss":[]},{"id":"CVE-2019-11708","kev":true,"vendor":"Mozilla","product":"Firefox and Thunderbird","name":"Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.55874,"pct":0.99019,"cvss":[]},{"id":"CVE-2019-8720","kev":true,"vendor":"WebKitGTK","product":"WebKitGTK","name":"WebKitGTK Memory Corruption Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.01556,"pct":0.74319,"cvss":[]},{"id":"CVE-2019-18426","kev":true,"vendor":"Meta Platforms","product":"WhatsApp","name":"WhatsApp Cross-Site Scripting Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.67859,"pct":0.99304,"cvss":[]},{"id":"CVE-2019-1385","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":true,"epss":0.03604,"pct":0.89121,"cvss":[]},{"id":"CVE-2019-1130","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":true,"epss":0.01705,"pct":0.76488,"cvss":[]},{"id":"CVE-2018-5002","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Stack-based Buffer Overflow Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.25059,"pct":0.97867,"cvss":[]},{"id":"CVE-2018-8589","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-05-23","due":"2022-06-13","ransomware":false,"epss":0.03023,"pct":0.87013,"cvss":[]},{"id":"CVE-2022-30525","kev":true,"vendor":"Zyxel","product":"Multiple Firewalls","name":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","added":"2022-05-16","due":"2022-06-06","ransomware":false,"epss":0.99944,"pct":0.99973,"cvss":[]},{"id":"CVE-2022-22947","kev":true,"vendor":"VMware","product":"Spring Cloud Gateway","name":"VMware Spring Cloud Gateway Code Injection Vulnerability","added":"2022-05-16","due":"2022-06-06","ransomware":false,"epss":0.98253,"pct":0.99915,"cvss":[]},{"id":"CVE-2022-1388","kev":true,"vendor":"F5","product":"BIG-IP","name":"F5 BIG-IP Missing Authentication Vulnerability","added":"2022-05-10","due":"2022-05-31","ransomware":true,"epss":0.99954,"pct":0.99974,"cvss":[]},{"id":"CVE-2021-1789","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Type Confusion Vulnerability","added":"2022-05-04","due":"2022-05-25","ransomware":false,"epss":0.13975,"pct":0.96448,"cvss":[]},{"id":"CVE-2019-8506","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Type Confusion Vulnerability","added":"2022-05-04","due":"2022-05-25","ransomware":false,"epss":0.16159,"pct":0.96846,"cvss":[]},{"id":"CVE-2014-4113","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-05-04","due":"2022-05-25","ransomware":false,"epss":0.86928,"pct":0.99744,"cvss":[]},{"id":"CVE-2014-0322","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2022-05-04","due":"2022-05-25","ransomware":false,"epss":0.85122,"pct":0.9971,"cvss":[]},{"id":"CVE-2014-0160","kev":true,"vendor":"OpenSSL","product":"OpenSSL","name":"OpenSSL Information Disclosure Vulnerability","added":"2022-05-04","due":"2022-05-25","ransomware":false,"epss":0.99999,"pct":0.99997,"cvss":[]},{"id":"CVE-2022-29464","kev":true,"vendor":"WSO2","product":"Multiple Products","name":"WSO2 Multiple Products Unrestrictive Upload of File Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":true,"epss":0.99999,"pct":0.99992,"cvss":[]},{"id":"CVE-2022-26904","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows User Profile Service Privilege Escalation Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":false,"epss":0.16948,"pct":0.96982,"cvss":[]},{"id":"CVE-2022-21919","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows User Profile Service Privilege Escalation Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":false,"epss":0.02434,"pct":0.83714,"cvss":[]},{"id":"CVE-2022-0847","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Privilege Escalation Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":false,"epss":0.92795,"pct":0.99828,"cvss":[]},{"id":"CVE-2021-41357","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":false,"epss":0.01582,"pct":0.74696,"cvss":[]},{"id":"CVE-2021-40450","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":false,"epss":0.01582,"pct":0.74697,"cvss":[]},{"id":"CVE-2019-1003029","kev":true,"vendor":"Jenkins","product":"Script Security Plugin","name":"Jenkins Script Security Plugin Sandbox Bypass Vulnerability","added":"2022-04-25","due":"2022-05-16","ransomware":false,"epss":0.7444,"pct":0.99483,"cvss":[]},{"id":"CVE-2018-6882","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability","added":"2022-04-19","due":"2022-05-10","ransomware":true,"epss":0.29761,"pct":0.98153,"cvss":[]},{"id":"CVE-2019-3568","kev":true,"vendor":"Meta Platforms","product":"WhatsApp","name":"WhatsApp VOIP Stack Buffer Overflow Vulnerability","added":"2022-04-19","due":"2022-05-10","ransomware":false,"epss":0.30076,"pct":0.98169,"cvss":[]},{"id":"CVE-2022-22718","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Print Spooler Privilege Escalation Vulnerability","added":"2022-04-19","due":"2022-05-10","ransomware":false,"epss":0.18464,"pct":0.97167,"cvss":[]},{"id":"CVE-2022-22960","kev":true,"vendor":"VMware","product":"Multiple Products","name":"VMware Multiple Products Privilege Escalation Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.35519,"pct":0.98414,"cvss":[]},{"id":"CVE-2022-1364","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.1372,"pct":0.96401,"cvss":[]},{"id":"CVE-2019-3929","kev":true,"vendor":"Crestron","product":"Multiple Products","name":"Crestron Multiple Products Command Injection Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.98952,"pct":0.99929,"cvss":[]},{"id":"CVE-2019-16057","kev":true,"vendor":"D-Link","product":"DNS-320 Storage Device","name":"D-Link DNS-320 Remote Code Execution Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":true,"epss":0.86491,"pct":0.99733,"cvss":[]},{"id":"CVE-2018-7841","kev":true,"vendor":"Schneider Electric","product":"U.motion Builder","name":"Schneider Electric U.motion Builder SQL Injection Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.72675,"pct":0.99432,"cvss":[]},{"id":"CVE-2016-4523","kev":true,"vendor":"Trihedral","product":"VTScada (formerly VTS)","name":"Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.31167,"pct":0.98226,"cvss":[]},{"id":"CVE-2014-0780","kev":true,"vendor":"InduSoft","product":"Web Studio","name":"InduSoft Web Studio NTWebServer Directory Traversal Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.74679,"pct":0.99491,"cvss":[]},{"id":"CVE-2010-5330","kev":true,"vendor":"Ubiquiti","product":"AirOS","name":"Ubiquiti AirOS Command Injection Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.39362,"pct":0.98567,"cvss":[]},{"id":"CVE-2007-3010","kev":true,"vendor":"Alcatel","product":"OmniPCX Enterprise","name":"Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability","added":"2022-04-15","due":"2022-05-06","ransomware":false,"epss":0.97385,"pct":0.99898,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2007-09-18T21:17:00.000Z","modified":"2026-06-16T22:40:52.660Z"},{"id":"CVE-2022-22954","kev":true,"vendor":"VMware","product":"Workspace ONE Access and Identity Manager","name":"VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability","added":"2022-04-14","due":"2022-05-05","ransomware":true,"epss":0.99998,"pct":0.9999,"cvss":[]},{"id":"CVE-2022-24521","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows CLFS Driver Privilege Escalation Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":true,"epss":0.07076,"pct":0.94036,"cvss":[]},{"id":"CVE-2018-7602","kev":true,"vendor":"Drupal","product":"Core","name":"Drupal Core Remote Code Execution Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":true,"epss":0.99172,"pct":0.99933,"cvss":[]},{"id":"CVE-2018-20753","kev":true,"vendor":"Kaseya","product":"Virtual System/Server Administrator (VSA)","name":"Kaseya VSA Remote Code Execution Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":true,"epss":0.29336,"pct":0.98131,"cvss":[]},{"id":"CVE-2015-5123","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.1883,"pct":0.97209,"cvss":[]},{"id":"CVE-2015-5122","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.93978,"pct":0.99845,"cvss":[]},{"id":"CVE-2015-3113","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Heap-Based Buffer Overflow Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.99812,"pct":0.99958,"cvss":[]},{"id":"CVE-2015-2502","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.51001,"pct":0.98901,"cvss":[]},{"id":"CVE-2015-0313","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.95266,"pct":0.99865,"cvss":[]},{"id":"CVE-2015-0311","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Remote Code Execution Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.85589,"pct":0.99719,"cvss":[]},{"id":"CVE-2014-9163","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Stack-Based Buffer Overflow Vulnerability","added":"2022-04-13","due":"2022-05-04","ransomware":false,"epss":0.20724,"pct":0.97472,"cvss":[]},{"id":"CVE-2022-23176","kev":true,"vendor":"WatchGuard","product":"Firebox and XTM","name":"WatchGuard Firebox and XTM Privilege Escalation Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":false,"epss":0.10805,"pct":0.95727,"cvss":[]},{"id":"CVE-2021-42287","kev":true,"vendor":"Microsoft","product":"Active Directory","name":"Microsoft Active Directory Domain Services Privilege Escalation Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":true,"epss":0.7717,"pct":0.99542,"cvss":[]},{"id":"CVE-2021-42278","kev":true,"vendor":"Microsoft","product":"Active Directory","name":"Microsoft Active Directory Domain Services Privilege Escalation Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":true,"epss":0.73297,"pct":0.9945,"cvss":[]},{"id":"CVE-2021-39793","kev":true,"vendor":"Google","product":"Pixel","name":"Google Pixel Out-of-Bounds Write Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":false,"epss":0.00685,"pct":0.50946,"cvss":[]},{"id":"CVE-2021-27852","kev":true,"vendor":"Checkbox","product":"Checkbox Survey","name":"Checkbox Survey Deserialization of Untrusted Data Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":false,"epss":0.30258,"pct":0.98178,"cvss":[]},{"id":"CVE-2021-22600","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Privilege Escalation Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":false,"epss":0.06586,"pct":0.93645,"cvss":[]},{"id":"CVE-2020-2509","kev":true,"vendor":"QNAP","product":"QNAP Network-Attached Storage (NAS)","name":"QNAP Network-Attached Storage (NAS) Command Injection Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":false,"epss":0.33987,"pct":0.98357,"cvss":[]},{"id":"CVE-2017-11317","kev":true,"vendor":"Telerik","product":"User Interface (UI) for ASP.NET AJAX","name":"Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability","added":"2022-04-11","due":"2022-05-02","ransomware":false,"epss":0.84175,"pct":0.9969,"cvss":[]},{"id":"CVE-2021-3156","kev":true,"vendor":"Sudo","product":"Sudo","name":"Sudo Heap-Based Buffer Overflow Vulnerability","added":"2022-04-06","due":"2022-04-27","ransomware":false,"epss":0.99962,"pct":0.99976,"cvss":[]},{"id":"CVE-2021-31166","kev":true,"vendor":"Microsoft","product":"HTTP Protocol Stack","name":"Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability","added":"2022-04-06","due":"2022-04-27","ransomware":false,"epss":0.99867,"pct":0.99962,"cvss":[]},{"id":"CVE-2017-0148","kev":true,"vendor":"Microsoft","product":"SMBv1 server","name":"Microsoft SMBv1 Server Remote Code Execution Vulnerability","added":"2022-04-06","due":"2022-04-27","ransomware":true,"epss":0.99356,"pct":0.9994,"cvss":[]},{"id":"CVE-2022-22965","kev":true,"vendor":"VMware","product":"Spring Framework","name":"Spring Framework JDK 9+ Remote Code Execution Vulnerability","added":"2022-04-04","due":"2022-04-25","ransomware":false,"epss":0.99638,"pct":0.99949,"cvss":[]},{"id":"CVE-2022-22675","kev":true,"vendor":"Apple","product":"macOS","name":"Apple macOS Out-of-Bounds Write Vulnerability","added":"2022-04-04","due":"2022-04-25","ransomware":false,"epss":0.12492,"pct":0.96113,"cvss":[]},{"id":"CVE-2022-22674","kev":true,"vendor":"Apple","product":"macOS","name":"Apple macOS Out-of-Bounds Read Vulnerability","added":"2022-04-04","due":"2022-04-25","ransomware":false,"epss":0.01133,"pct":0.65314,"cvss":[]},{"id":"CVE-2021-45382","kev":true,"vendor":"D-Link","product":"Multiple Routers","name":"D-Link Multiple Routers Remote Code Execution Vulnerability","added":"2022-04-04","due":"2022-04-25","ransomware":false,"epss":0.97836,"pct":0.99906,"cvss":[]},{"id":"CVE-2022-26871","kev":true,"vendor":"Trend Micro","product":"Apex Central","name":"Trend Micro Apex Central Arbitrary File Upload Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":false,"epss":0.19481,"pct":0.97302,"cvss":[]},{"id":"CVE-2022-1040","kev":true,"vendor":"Sophos","product":"Firewall","name":"Sophos Firewall Authentication Bypass Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":false,"epss":0.99796,"pct":0.99956,"cvss":[]},{"id":"CVE-2021-34484","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows User Profile Service Privilege Escalation Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":false,"epss":0.21827,"pct":0.97581,"cvss":[]},{"id":"CVE-2021-28799","kev":true,"vendor":"QNAP","product":"Network Attached Storage (NAS)","name":"QNAP NAS Improper Authorization Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":true,"epss":0.7825,"pct":0.99569,"cvss":[]},{"id":"CVE-2021-21551","kev":true,"vendor":"Dell","product":"dbutil Driver","name":"Dell dbutil Driver Insufficient Access Control Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":false,"epss":0.79249,"pct":0.99591,"cvss":[]},{"id":"CVE-2018-10562","kev":true,"vendor":"Dasan","product":"Gigabit Passive Optical Network (GPON) Routers","name":"Dasan GPON Routers Command Injection Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":true,"epss":0.99949,"pct":0.99973,"cvss":[]},{"id":"CVE-2018-10561","kev":true,"vendor":"Dasan","product":"Gigabit Passive Optical Network (GPON) Routers","name":"Dasan GPON Routers Authentication Bypass Vulnerability","added":"2022-03-31","due":"2022-04-21","ransomware":false,"epss":0.92893,"pct":0.9983,"cvss":[]},{"id":"CVE-2022-1096","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.24205,"pct":0.97795,"cvss":[]},{"id":"CVE-2022-0543","kev":true,"vendor":"Redis","product":"Debian-specific Redis Servers","name":"Debian-specific Redis Server Lua Sandbox Escape Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.99351,"pct":0.99939,"cvss":[]},{"id":"CVE-2021-38646","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.07987,"pct":0.94599,"cvss":[]},{"id":"CVE-2021-34486","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Event Tracing Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.09253,"pct":0.95222,"cvss":[]},{"id":"CVE-2021-26085","kev":true,"vendor":"Atlassian","product":"Confluence Server","name":"Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.99937,"pct":0.99971,"cvss":[]},{"id":"CVE-2021-20028","kev":true,"vendor":"SonicWall","product":"Secure Remote Access (SRA)","name":"SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.30084,"pct":0.98171,"cvss":[]},{"id":"CVE-2019-7483","kev":true,"vendor":"SonicWall","product":"SMA100","name":"SonicWall SMA100 Directory Traversal Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.0401,"pct":0.90257,"cvss":[]},{"id":"CVE-2018-8440","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.18386,"pct":0.97155,"cvss":[]},{"id":"CVE-2018-8406","kev":true,"vendor":"Microsoft","product":"DirectX Graphics Kernel (DXGKRNL)","name":"Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.03444,"pct":0.88623,"cvss":[]},{"id":"CVE-2018-8405","kev":true,"vendor":"Microsoft","product":"DirectX Graphics Kernel (DXGKRNL)","name":"Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.03444,"pct":0.88622,"cvss":[]},{"id":"CVE-2017-0213","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.84138,"pct":0.9969,"cvss":[]},{"id":"CVE-2017-0059","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Information Disclosure Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.61968,"pct":0.99156,"cvss":[]},{"id":"CVE-2017-0037","kev":true,"vendor":"Microsoft","product":"Edge and Internet Explorer","name":"Microsoft Edge and Internet Explorer Type Confusion Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.80386,"pct":0.99614,"cvss":[]},{"id":"CVE-2016-7201","kev":true,"vendor":"Microsoft","product":"Edge","name":"Microsoft Edge Memory Corruption Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.80004,"pct":0.99606,"cvss":[]},{"id":"CVE-2016-7200","kev":true,"vendor":"Microsoft","product":"Edge","name":"Microsoft Edge Memory Corruption Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.82779,"pct":0.99662,"cvss":[]},{"id":"CVE-2016-0189","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.94062,"pct":0.99846,"cvss":[]},{"id":"CVE-2016-0151","kev":true,"vendor":"Microsoft","product":"Client-Server Run-time Subsystem (CSRSS)","name":"Microsoft Windows CSRSS Security Feature Bypass Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.62943,"pct":0.99179,"cvss":[]},{"id":"CVE-2016-0040","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.24467,"pct":0.97817,"cvss":[]},{"id":"CVE-2015-2426","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.86576,"pct":0.99735,"cvss":[]},{"id":"CVE-2015-2419","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.53127,"pct":0.98952,"cvss":[]},{"id":"CVE-2015-1770","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Uninitialized Memory Use Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.34995,"pct":0.98396,"cvss":[]},{"id":"CVE-2013-3660","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.39318,"pct":0.98566,"cvss":[]},{"id":"CVE-2013-2729","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.66555,"pct":0.99268,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2013-05-16T11:45:31.263Z","modified":"2026-06-16T23:53:52.700Z"},{"id":"CVE-2013-2551","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.73918,"pct":0.99469,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2013-03-11T10:55:01.070Z","modified":"2026-06-16T23:53:36.980Z"},{"id":"CVE-2013-2465","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE Unspecified Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":true,"epss":0.98802,"pct":0.99926,"cvss":[]},{"id":"CVE-2013-1690","kev":true,"vendor":"Mozilla","product":"Firefox and Thunderbird","name":"Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.69021,"pct":0.99335,"cvss":[]},{"id":"CVE-2012-5076","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE Sandbox Bypass Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.9125,"pct":0.99808,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":10,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-10-16T21:55:02.073Z","modified":"2026-06-16T23:46:10.790Z"},{"id":"CVE-2012-2539","kev":true,"vendor":"Microsoft","product":"Word","name":"Microsoft Word Remote Code Execution Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.53033,"pct":0.98949,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":9.3,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2012-12-12T00:55:01.060Z","modified":"2026-06-16T23:41:39.477Z"},{"id":"CVE-2012-2034","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Memory Corruption Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.078,"pct":0.94496,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.5,"severity":"HIGH"}],"published":"2012-06-09T00:55:00.987Z","modified":"2026-06-16T23:40:50.083Z"},{"id":"CVE-2012-0518","kev":true,"vendor":"Oracle","product":"Fusion Middleware","name":"Oracle Fusion Middleware Unspecified Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.04685,"pct":0.91514,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":4.7,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":4.7,"severity":"MEDIUM"}],"published":"2012-10-16T23:55:03.087Z","modified":"2026-06-16T23:37:27.830Z"},{"id":"CVE-2011-2005","kev":true,"vendor":"Microsoft","product":"Ancillary Function Driver (afd.sys)","name":"Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability","added":"2022-03-28","due":"2022-04-18","ransomware":false,"epss":0.31534,"pct":0.98242,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2011-10-12T02:52:43.910Z","modified":"2026-06-16T23:30:35.373Z"},{"id":"CVE-2010-4398","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability","added":"2022-03-28","due":"2022-04-21","ransomware":false,"epss":0.08661,"pct":0.94975,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-12-06T13:44:54.863Z","modified":"2026-06-16T23:24:42.707Z"},{"id":"CVE-2022-26318","kev":true,"vendor":"WatchGuard","product":"Firebox and XTM Appliances","name":"WatchGuard Firebox and XTM Appliances Arbitrary Code Execution","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.78157,"pct":0.99568,"cvss":[]},{"id":"CVE-2022-26143","kev":true,"vendor":"Mitel","product":"MiCollab, MiVoice Business Express","name":"MiCollab, MiVoice Business Express Access Control Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.87325,"pct":0.99751,"cvss":[]},{"id":"CVE-2022-21999","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Print Spooler Privilege Escalation Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.41007,"pct":0.98623,"cvss":[]},{"id":"CVE-2021-42237","kev":true,"vendor":"Sitecore","product":"XP","name":"Sitecore XP Remote Command Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.97566,"pct":0.99901,"cvss":[]},{"id":"CVE-2021-22941","kev":true,"vendor":"Citrix","product":"ShareFile","name":"Citrix ShareFile Improper Access Control Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.53585,"pct":0.98965,"cvss":[]},{"id":"CVE-2020-9377","kev":true,"vendor":"D-Link","product":"DIR-610 Devices","name":"D-Link DIR-610 Devices Remote Command Execution","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.21338,"pct":0.97539,"cvss":[]},{"id":"CVE-2020-9054","kev":true,"vendor":"Zyxel","product":"Multiple Network-Attached Storage (NAS) Devices","name":"Zyxel Multiple NAS Devices OS Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99988,"pct":0.99985,"cvss":[]},{"id":"CVE-2020-7247","kev":true,"vendor":"OpenBSD","product":"OpenSMTPD","name":"OpenSMTPD Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.98972,"pct":0.99929,"cvss":[]},{"id":"CVE-2020-5410","kev":true,"vendor":"VMware Tanzu","product":"Spring Cloud Configuration (Config) Server","name":"VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.95586,"pct":0.9987,"cvss":[]},{"id":"CVE-2020-25223","kev":true,"vendor":"Sophos","product":"SG UTM","name":"Sophos SG UTM Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.96753,"pct":0.99887,"cvss":[]},{"id":"CVE-2020-2506","kev":true,"vendor":"QNAP Systems","product":"Helpdesk","name":"QNAP Helpdesk Improper Access Control Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.01982,"pct":0.79847,"cvss":[]},{"id":"CVE-2020-2021","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.04362,"pct":0.90962,"cvss":[]},{"id":"CVE-2020-1956","kev":true,"vendor":"Apache","product":"Kylin","name":"Apache Kylin OS Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.97337,"pct":0.99897,"cvss":[]},{"id":"CVE-2020-1631","kev":true,"vendor":"Juniper","product":"Junos OS","name":"Juniper Junos OS Path Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.04843,"pct":0.91748,"cvss":[]},{"id":"CVE-2019-6340","kev":true,"vendor":"Drupal","product":"Core","name":"Drupal Core Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.92017,"pct":0.99819,"cvss":[]},{"id":"CVE-2019-2616","kev":true,"vendor":"Oracle","product":"BI Publisher (Formerly XML Publisher)","name":"Oracle BI Publisher Unauthorized Access Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.92183,"pct":0.9982,"cvss":[]},{"id":"CVE-2019-16920","kev":true,"vendor":"D-Link","product":"Multiple Routers","name":"D-Link Multiple Routers Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99996,"pct":0.99989,"cvss":[]},{"id":"CVE-2019-15107","kev":true,"vendor":"Webmin","product":"Webmin","name":"Webmin Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.9971,"pct":0.99951,"cvss":[]},{"id":"CVE-2019-12991","kev":true,"vendor":"Citrix","product":"SD-WAN and NetScaler","name":"Citrix SD-WAN and NetScaler Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.74052,"pct":0.99474,"cvss":[]},{"id":"CVE-2019-12989","kev":true,"vendor":"Citrix","product":"SD-WAN and NetScaler","name":"Citrix SD-WAN and NetScaler SQL Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.94957,"pct":0.99861,"cvss":[]},{"id":"CVE-2019-11043","kev":true,"vendor":"PHP","product":"FastCGI Process Manager (FPM)","name":"PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.9978,"pct":0.99955,"cvss":[]},{"id":"CVE-2019-10068","kev":true,"vendor":"Kentico","product":"Xperience","name":"Kentico Xperience Deserialization of Untrusted Data Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.95074,"pct":0.99862,"cvss":[]},{"id":"CVE-2019-1003030","kev":true,"vendor":"Jenkins","product":"Matrix Project Plugin","name":"Jenkins Matrix Project Plugin Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.97058,"pct":0.99891,"cvss":[]},{"id":"CVE-2019-0903","kev":true,"vendor":"Microsoft","product":"Graphics Device Interface (GDI)","name":"Microsoft GDI Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.21713,"pct":0.97573,"cvss":[]},{"id":"CVE-2018-8414","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Shell Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.72912,"pct":0.99439,"cvss":[]},{"id":"CVE-2018-8373","kev":true,"vendor":"Microsoft","product":"Internet Explorer Scripting Engine","name":"Microsoft Scripting Engine Memory Corruption Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.61912,"pct":0.99154,"cvss":[]},{"id":"CVE-2018-6961","kev":true,"vendor":"VMware","product":"SD-WAN Edge","name":"VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.86252,"pct":0.99729,"cvss":[]},{"id":"CVE-2018-14839","kev":true,"vendor":"LG","product":"N1A1 NAS","name":"LG N1A1 NAS Remote Command Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.89354,"pct":0.99781,"cvss":[]},{"id":"CVE-2018-1273","kev":true,"vendor":"VMware Tanzu","product":"Spring Data Commons","name":"VMware Tanzu Spring Data Commons Property Binder Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.96956,"pct":0.99889,"cvss":[]},{"id":"CVE-2018-11138","kev":true,"vendor":"Quest","product":"KACE System Management Appliance","name":"Quest KACE System Management Appliance Remote Command Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.91778,"pct":0.99815,"cvss":[]},{"id":"CVE-2018-0147","kev":true,"vendor":"Cisco","product":"Secure Access Control System (ACS)","name":"Cisco Secure Access Control System Java Deserialization Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.18212,"pct":0.97135,"cvss":[]},{"id":"CVE-2018-0125","kev":true,"vendor":"Cisco","product":"VPN Routers","name":"Cisco VPN Routers Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.55186,"pct":0.99005,"cvss":[]},{"id":"CVE-2017-6334","kev":true,"vendor":"NETGEAR","product":"DGN2200 Devices","name":"NETGEAR DGN2200 Devices OS Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.7264,"pct":0.99431,"cvss":[]},{"id":"CVE-2017-6316","kev":true,"vendor":"Citrix","product":"NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server","name":"Citrix Multiple Products Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.7303,"pct":0.99443,"cvss":[]},{"id":"CVE-2017-3881","kev":true,"vendor":"Cisco","product":"IOS and IOS XE","name":"Cisco IOS and IOS XE Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.9895,"pct":0.99929,"cvss":[]},{"id":"CVE-2017-12617","kev":true,"vendor":"Apache","product":"Tomcat","name":"Apache Tomcat Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99968,"pct":0.99977,"cvss":[]},{"id":"CVE-2017-12615","kev":true,"vendor":"Apache","product":"Tomcat","name":"Apache Tomcat on Windows Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.99641,"pct":0.99949,"cvss":[]},{"id":"CVE-2017-0146","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SMB Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.89862,"pct":0.9979,"cvss":[]},{"id":"CVE-2016-7892","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.18786,"pct":0.97206,"cvss":[]},{"id":"CVE-2016-4171","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.20055,"pct":0.97378,"cvss":[]},{"id":"CVE-2016-1555","kev":true,"vendor":"NETGEAR","product":"Wireless Access Point (WAP) Devices","name":"NETGEAR Multiple WAP Devices Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.98288,"pct":0.99915,"cvss":[]},{"id":"CVE-2016-11021","kev":true,"vendor":"D-Link","product":"DCS-930L Devices","name":"D-Link DCS-930L Devices OS Command Injection Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.6887,"pct":0.99331,"cvss":[]},{"id":"CVE-2016-10174","kev":true,"vendor":"NETGEAR","product":"WNR2000v5 Router","name":"NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.83328,"pct":0.99673,"cvss":[]},{"id":"CVE-2016-0752","kev":true,"vendor":"Rails","product":"Ruby on Rails","name":"Ruby on Rails Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.95537,"pct":0.9987,"cvss":[]},{"id":"CVE-2015-4068","kev":true,"vendor":"Arcserve","product":"Unified Data Protection (UDP)","name":"Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.63643,"pct":0.99196,"cvss":[]},{"id":"CVE-2015-3035","kev":true,"vendor":"TP-Link","product":"Multiple Archer Devices","name":"TP-Link Multiple Archer Devices Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.83948,"pct":0.99687,"cvss":[]},{"id":"CVE-2015-1427","kev":true,"vendor":"Elastic","product":"Elasticsearch","name":"Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99906,"pct":0.99966,"cvss":[]},{"id":"CVE-2015-1187","kev":true,"vendor":"D-Link and TRENDnet","product":"Multiple Devices","name":"D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.82863,"pct":0.99664,"cvss":[]},{"id":"CVE-2015-0666","kev":true,"vendor":"Cisco","product":"Prime Data Center Network Manager (DCNM)","name":"Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.40379,"pct":0.98606,"cvss":[]},{"id":"CVE-2014-6332","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.94918,"pct":0.9986,"cvss":[]},{"id":"CVE-2014-6324","kev":true,"vendor":"Microsoft","product":"Kerberos Key Distribution Center (KDC)","name":"Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.87335,"pct":0.99752,"cvss":[]},{"id":"CVE-2014-6287","kev":true,"vendor":"Rejetto","product":"HTTP File Server (HFS)","name":"Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99323,"pct":0.99939,"cvss":[]},{"id":"CVE-2014-3120","kev":true,"vendor":"Elastic","product":"Elasticsearch","name":"Elasticsearch Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.88559,"pct":0.99772,"cvss":[]},{"id":"CVE-2014-0130","kev":true,"vendor":"Rails","product":"Ruby on Rails","name":"Ruby on Rails Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.53703,"pct":0.98969,"cvss":[]},{"id":"CVE-2013-5223","kev":true,"vendor":"D-Link","product":"DSL-2760U","name":"D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.50833,"pct":0.98896,"cvss":[]},{"id":"CVE-2013-4810","kev":true,"vendor":"Hewlett Packard (HP)","product":"ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management","name":"HP Multiple Products Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.79468,"pct":0.99595,"cvss":[]},{"id":"CVE-2013-2251","kev":true,"vendor":"Apache","product":"Struts","name":"Apache Struts Improper Input Validation Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99998,"pct":0.9999,"cvss":[]},{"id":"CVE-2012-1823","kev":true,"vendor":"PHP","product":"PHP","name":"PHP-CGI Query String Parameter Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.99998,"pct":0.9999,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-05-11T10:15:48.043Z","modified":"2026-06-16T23:40:22.147Z"},{"id":"CVE-2010-4345","kev":true,"vendor":"Exim","product":"Exim","name":"Exim Privilege Escalation Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.17965,"pct":0.97108,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-12-14T16:00:04.257Z","modified":"2026-06-16T23:24:36.353Z"},{"id":"CVE-2010-4344","kev":true,"vendor":"Exim","product":"Exim","name":"Exim Heap-Based Buffer Overflow Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.71706,"pct":0.99408,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2010-12-14T16:00:04.163Z","modified":"2026-06-16T23:24:36.107Z"},{"id":"CVE-2010-3035","kev":true,"vendor":"Cisco","product":"IOS XR","name":"Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.05668,"pct":0.92754,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.5,"severity":"HIGH"}],"published":"2010-08-30T21:00:12.203Z","modified":"2026-06-16T23:22:00.630Z"},{"id":"CVE-2010-2861","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Directory Traversal Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":true,"epss":0.99747,"pct":0.99953,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.5,"severity":"HIGH"}],"published":"2010-08-11T18:47:51.157Z","modified":"2026-10-02T14:55:20.233Z"},{"id":"CVE-2009-2055","kev":true,"vendor":"Cisco","product":"IOS XR","name":"Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.03314,"pct":0.88187,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":4.3,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":5.9,"severity":"MEDIUM"}],"published":"2009-08-19T17:30:01.047Z","modified":"2026-06-16T23:08:40.190Z"},{"id":"CVE-2009-1151","kev":true,"vendor":"phpMyAdmin","product":"phpMyAdmin","name":"phpMyAdmin Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.96565,"pct":0.99882,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2009-03-26T14:30:00.267Z","modified":"2026-06-16T23:06:36.970Z"},{"id":"CVE-2009-0927","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.96632,"pct":0.99884,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2009-03-19T10:30:00.420Z","modified":"2026-06-16T23:06:07.490Z"},{"id":"CVE-2005-2773","kev":true,"vendor":"Hewlett Packard (HP)","product":"OpenView Network Node Manager","name":"HP OpenView Network Node Manager Remote Code Execution Vulnerability","added":"2022-03-25","due":"2022-04-15","ransomware":false,"epss":0.74592,"pct":0.99487,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2005-09-02T23:03:00.000Z","modified":"2026-06-16T22:15:39.213Z"},{"id":"CVE-2020-5135","kev":true,"vendor":"SonicWall","product":"SonicOS","name":"SonicWall SonicOS Buffer Overflow Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.26869,"pct":0.97983,"cvss":[]},{"id":"CVE-2019-1405","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.2995,"pct":0.98162,"cvss":[]},{"id":"CVE-2019-1322","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.19205,"pct":0.9726,"cvss":[]},{"id":"CVE-2019-1315","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.03478,"pct":0.8873,"cvss":[]},{"id":"CVE-2019-1253","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.11616,"pct":0.95932,"cvss":[]},{"id":"CVE-2019-1132","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":false,"epss":0.09788,"pct":0.95412,"cvss":[]},{"id":"CVE-2019-1129","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.01782,"pct":0.77515,"cvss":[]},{"id":"CVE-2019-1069","kev":true,"vendor":"Microsoft","product":"Task Scheduler","name":"Microsoft Task Scheduler Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.06117,"pct":0.93228,"cvss":[]},{"id":"CVE-2019-1064","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.06886,"pct":0.93881,"cvss":[]},{"id":"CVE-2019-0841","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.414,"pct":0.98638,"cvss":[]},{"id":"CVE-2019-0543","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.04718,"pct":0.91561,"cvss":[]},{"id":"CVE-2018-8120","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.73434,"pct":0.99454,"cvss":[]},{"id":"CVE-2017-0101","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Transaction Manager Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.57482,"pct":0.99058,"cvss":[]},{"id":"CVE-2016-3309","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.20467,"pct":0.97442,"cvss":[]},{"id":"CVE-2015-2546","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Memory Corruption Vulnerability","added":"2022-03-15","due":"2022-04-05","ransomware":true,"epss":0.10107,"pct":0.95516,"cvss":[]},{"id":"CVE-2022-26486","kev":true,"vendor":"Mozilla","product":"Firefox","name":"Mozilla Firefox Use-After-Free Vulnerability","added":"2022-03-07","due":"2022-03-21","ransomware":false,"epss":0.02351,"pct":0.8312,"cvss":[]},{"id":"CVE-2022-26485","kev":true,"vendor":"Mozilla","product":"Firefox","name":"Mozilla Firefox Use-After-Free Vulnerability","added":"2022-03-07","due":"2022-03-21","ransomware":false,"epss":0.14261,"pct":0.96501,"cvss":[]},{"id":"CVE-2021-21973","kev":true,"vendor":"VMware","product":"vCenter Server and Cloud Foundation","name":"VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability","added":"2022-03-07","due":"2022-03-21","ransomware":false,"epss":0.88012,"pct":0.99762,"cvss":[]},{"id":"CVE-2020-8218","kev":true,"vendor":"Pulse Secure","product":"Pulse Connect Secure","name":"Pulse Connect Secure Code Injection Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.3225,"pct":0.9828,"cvss":[]},{"id":"CVE-2019-11581","kev":true,"vendor":"Atlassian","product":"Jira Server and Data Center","name":"Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.84621,"pct":0.997,"cvss":[]},{"id":"CVE-2017-6077","kev":true,"vendor":"NETGEAR","product":"Wireless Router DGN2200","name":"NETGEAR DGN2200 Remote Code Execution Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.68712,"pct":0.99326,"cvss":[]},{"id":"CVE-2016-6277","kev":true,"vendor":"NETGEAR","product":"Multiple Routers","name":"NETGEAR Multiple Routers Remote Code Execution Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.99803,"pct":0.99957,"cvss":[]},{"id":"CVE-2013-0631","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Information Disclosure Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.66413,"pct":0.99265,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.5,"severity":"HIGH"}],"published":"2013-01-09T01:55:03.617Z","modified":"2026-06-16T23:49:47.907Z"},{"id":"CVE-2013-0629","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Directory Traversal Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.65795,"pct":0.9925,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.5,"severity":"HIGH"}],"published":"2013-01-09T01:55:03.553Z","modified":"2026-06-16T23:49:47.607Z"},{"id":"CVE-2013-0625","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Authentication Bypass Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":false,"epss":0.93758,"pct":0.99843,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2013-01-09T01:55:00.803Z","modified":"2026-06-16T23:49:47.163Z"},{"id":"CVE-2009-3960","kev":true,"vendor":"Adobe","product":"BlazeDS","name":"Adobe BlazeDS Information Disclosure Vulnerability","added":"2022-03-07","due":"2022-09-07","ransomware":true,"epss":0.90118,"pct":0.99794,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":6.5,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":6.5,"severity":"MEDIUM"}],"published":"2010-02-15T18:30:00.407Z","modified":"2026-08-06T05:16:33.473Z"},{"id":"CVE-2022-20708","kev":true,"vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","name":"Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.14863,"pct":0.96605,"cvss":[]},{"id":"CVE-2022-20703","kev":true,"vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","name":"Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.09203,"pct":0.952,"cvss":[]},{"id":"CVE-2022-20701","kev":true,"vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","name":"Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.09747,"pct":0.95395,"cvss":[]},{"id":"CVE-2022-20700","kev":true,"vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","name":"Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.05655,"pct":0.92742,"cvss":[]},{"id":"CVE-2022-20699","kev":true,"vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","name":"Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.72458,"pct":0.99428,"cvss":[]},{"id":"CVE-2021-41379","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Installer Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":true,"epss":0.19452,"pct":0.973,"cvss":[]},{"id":"CVE-2020-1938","kev":true,"vendor":"Apache","product":"Tomcat","name":"Apache Tomcat Improper Privilege Management Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.9927,"pct":0.99937,"cvss":[]},{"id":"CVE-2020-11899","kev":true,"vendor":"Treck TCP/IP stack","product":"IPv6","name":"Treck TCP/IP stack Out-of-Bounds Read Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.1842,"pct":0.97159,"cvss":[]},{"id":"CVE-2019-16928","kev":true,"vendor":"Exim","product":"Exim Internet Mailer","name":"Exim Out-of-bounds Write Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.41638,"pct":0.98645,"cvss":[]},{"id":"CVE-2019-1652","kev":true,"vendor":"Cisco","product":"Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers","name":"Cisco Small Business Routers Improper Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.95923,"pct":0.99874,"cvss":[]},{"id":"CVE-2019-1297","kev":true,"vendor":"Microsoft","product":"Excel","name":"Microsoft Excel Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.21805,"pct":0.97578,"cvss":[]},{"id":"CVE-2018-8581","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":true,"epss":0.27355,"pct":0.98009,"cvss":[]},{"id":"CVE-2018-8298","kev":true,"vendor":"ChakraCore","product":"ChakraCore scripting engine","name":"ChakraCore Scripting Engine Type Confusion Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.74694,"pct":0.99491,"cvss":[]},{"id":"CVE-2018-0180","kev":true,"vendor":"Cisco","product":"IOS Software","name":"Cisco IOS Software Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.04935,"pct":0.91885,"cvss":[]},{"id":"CVE-2018-0179","kev":true,"vendor":"Cisco","product":"IOS Software","name":"Cisco IOS Software Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.04935,"pct":0.91886,"cvss":[]},{"id":"CVE-2018-0175","kev":true,"vendor":"Cisco","product":"IOS, XR, and XE Software","name":"Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.03478,"pct":0.88731,"cvss":[]},{"id":"CVE-2018-0174","kev":true,"vendor":"Cisco","product":"IOS XE Software","name":"Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.07608,"pct":0.94382,"cvss":[]},{"id":"CVE-2018-0173","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software Improper Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.07608,"pct":0.94382,"cvss":[]},{"id":"CVE-2018-0172","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software Improper Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.0782,"pct":0.94506,"cvss":[]},{"id":"CVE-2018-0167","kev":true,"vendor":"Cisco","product":"IOS, XR, and XE Software","name":"Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.03354,"pct":0.88318,"cvss":[]},{"id":"CVE-2018-0161","kev":true,"vendor":"Cisco","product":"IOS Software","name":"Cisco IOS Software Resource Management Errors Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.04116,"pct":0.90482,"cvss":[]},{"id":"CVE-2018-0159","kev":true,"vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","name":"Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.0687,"pct":0.93866,"cvss":[]},{"id":"CVE-2018-0158","kev":true,"vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","name":"Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.0719,"pct":0.94126,"cvss":[]},{"id":"CVE-2018-0156","kev":true,"vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","name":"Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.0936,"pct":0.95257,"cvss":[]},{"id":"CVE-2018-0155","kev":true,"vendor":"Cisco","product":"Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches","name":"Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.07742,"pct":0.94462,"cvss":[]},{"id":"CVE-2018-0154","kev":true,"vendor":"Cisco","product":"IOS Software","name":"Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.0707,"pct":0.94031,"cvss":[]},{"id":"CVE-2018-0151","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-17","ransomware":false,"epss":0.14197,"pct":0.96487,"cvss":[]},{"id":"CVE-2017-8540","kev":true,"vendor":"Microsoft","product":"Malware Protection Engine","name":"Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.71874,"pct":0.99412,"cvss":[]},{"id":"CVE-2017-6744","kev":true,"vendor":"Cisco","product":"IOS software","name":"Cisco IOS Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.07292,"pct":0.94191,"cvss":[]},{"id":"CVE-2017-6743","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.10855,"pct":0.95741,"cvss":[]},{"id":"CVE-2017-6740","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.111,"pct":0.95812,"cvss":[]},{"id":"CVE-2017-6739","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.10855,"pct":0.95741,"cvss":[]},{"id":"CVE-2017-6738","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.10855,"pct":0.9574,"cvss":[]},{"id":"CVE-2017-6737","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.4524,"pct":0.98752,"cvss":[]},{"id":"CVE-2017-6736","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.70354,"pct":0.9937,"cvss":[]},{"id":"CVE-2017-6663","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.02117,"pct":0.81198,"cvss":[]},{"id":"CVE-2017-6627","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.06158,"pct":0.93273,"cvss":[]},{"id":"CVE-2017-12319","kev":true,"vendor":"Cisco","product":"IOS XE Software","name":"Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.05243,"pct":0.92287,"cvss":[]},{"id":"CVE-2017-12240","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.13773,"pct":0.96411,"cvss":[]},{"id":"CVE-2017-12238","kev":true,"vendor":"Cisco","product":"Catalyst 6800 Series Switches","name":"Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.02017,"pct":0.8024,"cvss":[]},{"id":"CVE-2017-12237","kev":true,"vendor":"Cisco","product":"IOS and IOS XE Software","name":"Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.0707,"pct":0.94032,"cvss":[]},{"id":"CVE-2017-12235","kev":true,"vendor":"Cisco","product":"IOS software","name":"Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.0707,"pct":0.94031,"cvss":[]},{"id":"CVE-2017-12234","kev":true,"vendor":"Cisco","product":"IOS software","name":"Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.0707,"pct":0.94031,"cvss":[]},{"id":"CVE-2017-12233","kev":true,"vendor":"Cisco","product":"IOS software","name":"Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.0707,"pct":0.9403,"cvss":[]},{"id":"CVE-2017-12232","kev":true,"vendor":"Cisco","product":"IOS software","name":"Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.02153,"pct":0.8152,"cvss":[]},{"id":"CVE-2017-12231","kev":true,"vendor":"Cisco","product":"IOS software","name":"Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.0707,"pct":0.94031,"cvss":[]},{"id":"CVE-2017-11826","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.81158,"pct":0.99627,"cvss":[]},{"id":"CVE-2017-11292","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Type Confusion Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.11885,"pct":0.9599,"cvss":[]},{"id":"CVE-2017-0261","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Use-After-Free Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.7813,"pct":0.99567,"cvss":[]},{"id":"CVE-2017-0001","kev":true,"vendor":"Microsoft","product":"Graphics Device Interface (GDI)","name":"Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.03114,"pct":0.87371,"cvss":[]},{"id":"CVE-2016-8562","kev":true,"vendor":"Siemens","product":"SIMATIC CP","name":"Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.0361,"pct":0.89138,"cvss":[]},{"id":"CVE-2016-7855","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.25198,"pct":0.97881,"cvss":[]},{"id":"CVE-2016-7262","kev":true,"vendor":"Microsoft","product":"Excel","name":"Microsoft Office Security Feature Bypass Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.57733,"pct":0.99062,"cvss":[]},{"id":"CVE-2016-7193","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.57582,"pct":0.99059,"cvss":[]},{"id":"CVE-2016-5195","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Race Condition Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.83524,"pct":0.99679,"cvss":[]},{"id":"CVE-2016-4117","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.94354,"pct":0.99851,"cvss":[]},{"id":"CVE-2016-1019","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.22316,"pct":0.97625,"cvss":[]},{"id":"CVE-2016-0099","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.37045,"pct":0.98477,"cvss":[]},{"id":"CVE-2015-7645","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.65339,"pct":0.99241,"cvss":[]},{"id":"CVE-2015-5119","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.99326,"pct":0.99939,"cvss":[]},{"id":"CVE-2015-4902","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE Integrity Check Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.13603,"pct":0.96365,"cvss":[]},{"id":"CVE-2015-3043","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.73862,"pct":0.99468,"cvss":[]},{"id":"CVE-2015-2590","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.25469,"pct":0.97898,"cvss":[]},{"id":"CVE-2015-2545","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Malformed EPS File Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.85937,"pct":0.99724,"cvss":[]},{"id":"CVE-2015-2424","kev":true,"vendor":"Microsoft","product":"PowerPoint","name":"Microsoft PowerPoint Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.40388,"pct":0.98606,"cvss":[]},{"id":"CVE-2015-2387","kev":true,"vendor":"Microsoft","product":"ATM Font Driver","name":"Microsoft ATM Font Driver Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.34878,"pct":0.98393,"cvss":[]},{"id":"CVE-2015-1701","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.55923,"pct":0.99021,"cvss":[]},{"id":"CVE-2015-1642","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.53087,"pct":0.98951,"cvss":[]},{"id":"CVE-2014-4114","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.81628,"pct":0.99635,"cvss":[]},{"id":"CVE-2014-0496","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Use-After-Free Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.3998,"pct":0.98591,"cvss":[]},{"id":"CVE-2013-5065","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.34651,"pct":0.98382,"cvss":[]},{"id":"CVE-2013-3897","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Use-After-Free Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.7731,"pct":0.99546,"cvss":[]},{"id":"CVE-2013-3346","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.78913,"pct":0.99585,"cvss":[]},{"id":"CVE-2013-1675","kev":true,"vendor":"Mozilla","product":"Firefox","name":"Mozilla Firefox Information Disclosure Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.06696,"pct":0.93721,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":6.5,"severity":"MEDIUM"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":6.5,"severity":"MEDIUM"}],"published":"2013-05-16T11:45:30.877Z","modified":"2026-06-16T23:51:53.300Z"},{"id":"CVE-2013-1347","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.7774,"pct":0.99558,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2013-05-05T11:07:00.527Z","modified":"2026-06-16T23:51:15.717Z"},{"id":"CVE-2013-0641","kev":true,"vendor":"Adobe","product":"Reader","name":"Adobe Reader Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.32346,"pct":0.98284,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2013-02-14T01:55:02.070Z","modified":"2026-06-16T23:49:49.270Z"},{"id":"CVE-2013-0640","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.86927,"pct":0.99743,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2013-02-14T01:55:02.023Z","modified":"2026-06-16T23:49:49.060Z"},{"id":"CVE-2013-0632","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Authentication Bypass Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.93603,"pct":0.99841,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2013-01-17T00:55:01.200Z","modified":"2026-06-16T23:49:48.073Z"},{"id":"CVE-2012-4681","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.98536,"pct":0.99921,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-08-28T00:55:01.860Z","modified":"2026-08-06T05:16:34.310Z"},{"id":"CVE-2012-1856","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.72032,"pct":0.99416,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2012-08-15T01:55:01.490Z","modified":"2026-06-16T23:40:26.290Z"},{"id":"CVE-2012-1723","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.93688,"pct":0.99842,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":10,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-06-16T21:55:03.500Z","modified":"2026-08-06T05:16:33.940Z"},{"id":"CVE-2012-1535","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.70384,"pct":0.99371,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2012-08-15T10:31:40.677Z","modified":"2026-06-16T23:39:42.360Z"},{"id":"CVE-2012-0507","kev":true,"vendor":"Oracle","product":"Java SE","name":"Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.98113,"pct":0.99912,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"2.0","score":10,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-06-07T22:55:17.883Z","modified":"2026-08-14T05:16:51.643Z"},{"id":"CVE-2011-3544","kev":true,"vendor":"Oracle","product":"Java SE JDK and JRE","name":"Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.96653,"pct":0.99884,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2011-10-19T21:55:01.097Z","modified":"2026-06-16T23:33:27.053Z"},{"id":"CVE-2011-1889","kev":true,"vendor":"Microsoft","product":"Forefront Threat Management Gateway (TMG)","name":"Microsoft Forefront TMG Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.4902,"pct":0.98851,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2011-06-16T20:55:02.543Z","modified":"2026-06-16T23:30:18.967Z"},{"id":"CVE-2011-0611","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Remote Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.9941,"pct":0.99941,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2011-04-13T14:55:01.217Z","modified":"2026-06-16T23:27:44.830Z"},{"id":"CVE-2010-3333","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Stack-based Buffer Overflow Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.89497,"pct":0.99783,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-11-10T03:00:02.087Z","modified":"2026-06-16T23:22:36.323Z"},{"id":"CVE-2010-0232","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Exception Handler Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.28735,"pct":0.98094,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-01-21T19:30:00.900Z","modified":"2026-06-16T23:15:45.537Z"},{"id":"CVE-2010-0188","kev":true,"vendor":"Adobe","product":"Reader and Acrobat","name":"Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.88246,"pct":0.99767,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2010-02-22T13:00:02.127Z","modified":"2026-08-14T05:16:49.797Z"},{"id":"CVE-2009-3129","kev":true,"vendor":"Microsoft","product":"Excel","name":"Microsoft Excel Featheader Record Memory Corruption Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.84034,"pct":0.99688,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2009-11-11T19:30:00.530Z","modified":"2026-06-16T23:11:00.237Z"},{"id":"CVE-2009-1123","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Improper Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.04878,"pct":0.91801,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2009-06-10T18:30:00.327Z","modified":"2026-06-16T23:06:33.440Z"},{"id":"CVE-2008-3431","kev":true,"vendor":"Oracle","product":"VirtualBox","name":"Oracle VirtualBox Insufficient Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.06876,"pct":0.93871,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2008-08-05T19:41:00.000Z","modified":"2026-06-16T22:55:48.933Z"},{"id":"CVE-2008-2992","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Reader and Acrobat Input Validation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":true,"epss":0.98482,"pct":0.99919,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2008-11-04T18:29:47.667Z","modified":"2026-06-16T22:54:53.110Z"},{"id":"CVE-2004-0210","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.07214,"pct":0.94141,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2004-08-06T04:00:00.000Z","modified":"2026-06-16T22:05:10.397Z"},{"id":"CVE-2002-0367","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2022-03-03","due":"2022-03-24","ransomware":false,"epss":0.04919,"pct":0.91861,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.8,"severity":"HIGH"}],"published":"2002-06-25T04:00:00.000Z","modified":"2026-06-16T21:57:17.883Z"},{"id":"CVE-2022-24682","kev":true,"vendor":"Synacor","product":"Zimbra Collaborate Suite (ZCS)","name":"Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability","added":"2022-02-25","due":"2022-03-11","ransomware":true,"epss":0.30931,"pct":0.98214,"cvss":[]},{"id":"CVE-2017-8570","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Remote Code Execution Vulnerability","added":"2022-02-25","due":"2022-08-25","ransomware":false,"epss":0.89889,"pct":0.9979,"cvss":[]},{"id":"CVE-2017-0222","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Remote Code Execution Vulnerability","added":"2022-02-25","due":"2022-08-25","ransomware":false,"epss":0.29645,"pct":0.98148,"cvss":[]},{"id":"CVE-2014-6352","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Code Injection Vulnerability","added":"2022-02-25","due":"2022-08-25","ransomware":false,"epss":0.77485,"pct":0.9955,"cvss":[]},{"id":"CVE-2022-23131","kev":true,"vendor":"Zabbix","product":"Frontend","name":"Zabbix Frontend Authentication Bypass Vulnerability","added":"2022-02-22","due":"2022-03-08","ransomware":false,"epss":0.95683,"pct":0.99871,"cvss":[]},{"id":"CVE-2022-23134","kev":true,"vendor":"Zabbix","product":"Frontend","name":"Zabbix Frontend Improper Access Control Vulnerability","added":"2022-02-22","due":"2022-03-08","ransomware":false,"epss":0.9526,"pct":0.99865,"cvss":[]},{"id":"CVE-2022-24086","kev":true,"vendor":"Adobe","product":"Commerce and Magento Open Source","name":"Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability","added":"2022-02-15","due":"2022-03-01","ransomware":false,"epss":0.99199,"pct":0.99934,"cvss":[]},{"id":"CVE-2022-0609","kev":true,"vendor":"Google","product":"Chromium Animation","name":"Google Chromium Animation Use-After-Free Vulnerability","added":"2022-02-15","due":"2022-03-01","ransomware":false,"epss":0.22933,"pct":0.97689,"cvss":[]},{"id":"CVE-2019-0752","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Type Confusion Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":true,"epss":0.81551,"pct":0.99634,"cvss":[]},{"id":"CVE-2018-8174","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":true,"epss":0.88332,"pct":0.99768,"cvss":[]},{"id":"CVE-2018-20250","kev":true,"vendor":"RARLAB","product":"WinRAR","name":"WinRAR Absolute Path Traversal Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":true,"epss":0.96004,"pct":0.99875,"cvss":[]},{"id":"CVE-2018-15982","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":true,"epss":0.89581,"pct":0.99785,"cvss":[]},{"id":"CVE-2017-9841","kev":true,"vendor":"PHPUnit","product":"PHPUnit","name":"PHPUnit Command Injection Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":false,"epss":0.99999,"pct":0.99994,"cvss":[]},{"id":"CVE-2014-1761","kev":true,"vendor":"Microsoft","product":"Word","name":"Microsoft Word Memory Corruption Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":false,"epss":0.7746,"pct":0.99549,"cvss":[]},{"id":"CVE-2013-3906","kev":true,"vendor":"Microsoft","product":"Graphics Component","name":"Microsoft Graphics Component Memory Corruption Vulnerability","added":"2022-02-15","due":"2022-08-15","ransomware":false,"epss":0.84853,"pct":0.99706,"cvss":[]},{"id":"CVE-2022-22620","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability","added":"2022-02-11","due":"2022-02-25","ransomware":false,"epss":0.16342,"pct":0.96878,"cvss":[]},{"id":"CVE-2021-36934","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows SAM Local Privilege Escalation Vulnerability","added":"2022-02-10","due":"2022-02-24","ransomware":false,"epss":0.67252,"pct":0.99287,"cvss":[]},{"id":"CVE-2020-0796","kev":true,"vendor":"Microsoft","product":"SMBv3","name":"Microsoft SMBv3 Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":true,"epss":0.9981,"pct":0.99958,"cvss":[]},{"id":"CVE-2018-1000861","kev":true,"vendor":"Jenkins","product":"Jenkins Stapler Web Framework","name":"Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.98326,"pct":0.99916,"cvss":[]},{"id":"CVE-2017-9791","kev":true,"vendor":"Apache","product":"Struts 1","name":"Apache Struts 1 Improper Input Validation Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.98908,"pct":0.99927,"cvss":[]},{"id":"CVE-2017-8464","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.90026,"pct":0.99792,"cvss":[]},{"id":"CVE-2017-10271","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle Corporation WebLogic Server Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":true,"epss":0.9999,"pct":0.99985,"cvss":[]},{"id":"CVE-2017-0263","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.10034,"pct":0.95491,"cvss":[]},{"id":"CVE-2017-0262","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.81005,"pct":0.99624,"cvss":[]},{"id":"CVE-2017-0145","kev":true,"vendor":"Microsoft","product":"SMBv1","name":"Microsoft SMBv1 Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":true,"epss":0.8985,"pct":0.99789,"cvss":[]},{"id":"CVE-2017-0144","kev":true,"vendor":"Microsoft","product":"SMBv1","name":"Microsoft SMBv1 Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":true,"epss":0.9923,"pct":0.99936,"cvss":[]},{"id":"CVE-2016-3088","kev":true,"vendor":"Apache","product":"ActiveMQ","name":"Apache ActiveMQ Improper Input Validation Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.98518,"pct":0.9992,"cvss":[]},{"id":"CVE-2015-2051","kev":true,"vendor":"D-Link","product":"DIR-645 Router","name":"D-Link DIR-645 Router Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.97101,"pct":0.99893,"cvss":[]},{"id":"CVE-2015-1635","kev":true,"vendor":"Microsoft","product":"HTTP.sys","name":"Microsoft HTTP.sys Remote Code Execution Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.99999,"pct":0.99998,"cvss":[]},{"id":"CVE-2015-1130","kev":true,"vendor":"Apple","product":"OS X","name":"Apple OS X Authentication Bypass Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.09887,"pct":0.95445,"cvss":[]},{"id":"CVE-2014-4404","kev":true,"vendor":"Apple","product":"OS X","name":"Apple OS X Heap-Based Buffer Overflow Vulnerability","added":"2022-02-10","due":"2022-08-10","ransomware":false,"epss":0.48923,"pct":0.98848,"cvss":[]},{"id":"CVE-2022-21882","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-02-04","due":"2022-02-18","ransomware":true,"epss":0.59205,"pct":0.99094,"cvss":[]},{"id":"CVE-2022-22587","kev":true,"vendor":"Apple","product":"iOS and macOS","name":"Apple Memory Corruption Vulnerability","added":"2022-01-28","due":"2022-02-11","ransomware":false,"epss":0.11638,"pct":0.95938,"cvss":[]},{"id":"CVE-2021-20038","kev":true,"vendor":"SonicWall","product":"SMA 100 Appliances","name":"SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability","added":"2022-01-28","due":"2022-02-11","ransomware":true,"epss":0.99912,"pct":0.99967,"cvss":[]},{"id":"CVE-2020-5722","kev":true,"vendor":"Grandstream","product":"UCM6200","name":"Grandstream Networks UCM6200 Series SQL Injection Vulnerability","added":"2022-01-28","due":"2022-07-28","ransomware":false,"epss":0.84406,"pct":0.99695,"cvss":[]},{"id":"CVE-2020-0787","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability","added":"2022-01-28","due":"2022-07-28","ransomware":true,"epss":0.42524,"pct":0.98669,"cvss":[]},{"id":"CVE-2017-5689","kev":true,"vendor":"Intel","product":"Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability","name":"Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability","added":"2022-01-28","due":"2022-07-28","ransomware":false,"epss":0.92189,"pct":0.99821,"cvss":[]},{"id":"CVE-2014-1776","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2022-01-28","due":"2022-07-28","ransomware":false,"epss":0.82682,"pct":0.9966,"cvss":[]},{"id":"CVE-2014-6271","kev":true,"vendor":"GNU","product":"Bourne-Again Shell (Bash)","name":"GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability","added":"2022-01-28","due":"2022-07-28","ransomware":false,"epss":0.99999,"pct":0.99993,"cvss":[]},{"id":"CVE-2014-7169","kev":true,"vendor":"GNU","product":"Bourne-Again Shell (Bash)","name":"GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability","added":"2022-01-28","due":"2022-07-28","ransomware":false,"epss":0.9994,"pct":0.99972,"cvss":[]},{"id":"CVE-2006-1547","kev":true,"vendor":"Apache","product":"Struts 1","name":"Apache Struts 1 ActionForm Denial-of-Service Vulnerability","added":"2022-01-21","due":"2022-07-21","ransomware":false,"epss":0.54635,"pct":0.98993,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":7.5,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":7.5,"severity":"HIGH"}],"published":"2006-03-30T22:02:00.000Z","modified":"2026-06-16T22:23:10.577Z"},{"id":"CVE-2012-0391","kev":true,"vendor":"Apache","product":"Struts 2","name":"Apache Struts 2 Improper Input Validation Vulnerability","added":"2022-01-21","due":"2022-07-21","ransomware":false,"epss":0.75599,"pct":0.99508,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.8,"severity":"CRITICAL"}],"published":"2012-01-08T15:55:01.217Z","modified":"2026-06-16T23:37:12.150Z"},{"id":"CVE-2018-8453","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-01-21","due":"2022-07-21","ransomware":true,"epss":0.70042,"pct":0.99361,"cvss":[]},{"id":"CVE-2021-35247","kev":true,"vendor":"SolarWinds","product":"Serv-U","name":"SolarWinds Serv-U Improper Input Validation Vulnerability","added":"2022-01-21","due":"2022-02-04","ransomware":false,"epss":0.03453,"pct":0.88646,"cvss":[]},{"id":"CVE-2021-32648","kev":true,"vendor":"October CMS","product":"October CMS","name":"October CMS Improper Authentication","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.90418,"pct":0.99799,"cvss":[]},{"id":"CVE-2021-25296","kev":true,"vendor":"Nagios","product":"Nagios XI","name":"Nagios XI OS Command Injection","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.72182,"pct":0.99421,"cvss":[]},{"id":"CVE-2021-25297","kev":true,"vendor":"Nagios","product":"Nagios XI","name":"Nagios XI OS Command Injection","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.56659,"pct":0.99039,"cvss":[]},{"id":"CVE-2021-25298","kev":true,"vendor":"Nagios","product":"Nagios XI","name":"Nagios XI OS Command Injection","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.75148,"pct":0.99499,"cvss":[]},{"id":"CVE-2021-40870","kev":true,"vendor":"Aviatrix","product":"Aviatrix Controller","name":"Aviatrix Controller Unrestricted Upload of File","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.93019,"pct":0.99831,"cvss":[]},{"id":"CVE-2021-33766","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Information Disclosure","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.98176,"pct":0.99914,"cvss":[]},{"id":"CVE-2021-21975","kev":true,"vendor":"VMware","product":"vRealize Operations Manager API","name":"VMware Server Side Request Forgery in vRealize Operations Manager API","added":"2022-01-18","due":"2022-02-01","ransomware":true,"epss":0.77853,"pct":0.99562,"cvss":[]},{"id":"CVE-2021-21315","kev":true,"vendor":"Npm package","product":"System Information Library for Node.JS","name":"System Information Library for Node.JS Command Injection","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.90675,"pct":0.99802,"cvss":[]},{"id":"CVE-2021-22991","kev":true,"vendor":"F5","product":"BIG-IP Traffic Management Microkernel","name":"F5 BIG-IP Traffic Management Microkernel Buffer Overflow","added":"2022-01-18","due":"2022-02-01","ransomware":false,"epss":0.61064,"pct":0.99136,"cvss":[]},{"id":"CVE-2020-14864","kev":true,"vendor":"Oracle","product":"Intelligence Enterprise Edition","name":"Oracle Business Intelligence Enterprise Edition Path Transversal","added":"2022-01-18","due":"2022-07-18","ransomware":false,"epss":0.97233,"pct":0.99895,"cvss":[]},{"id":"CVE-2020-13671","kev":true,"vendor":"Drupal","product":"Drupal core","name":"Drupal core Un-restricted Upload of File","added":"2022-01-18","due":"2022-07-18","ransomware":false,"epss":0.3535,"pct":0.98407,"cvss":[]},{"id":"CVE-2020-11978","kev":true,"vendor":"Apache","product":"Airflow","name":"Apache Airflow Command Injection","added":"2022-01-18","due":"2022-07-18","ransomware":false,"epss":0.99189,"pct":0.99934,"cvss":[]},{"id":"CVE-2020-13927","kev":true,"vendor":"Apache","product":"Airflow's Experimental API","name":"Apache Airflow's Experimental API Authentication Bypass","added":"2022-01-18","due":"2022-07-18","ransomware":false,"epss":0.99778,"pct":0.99955,"cvss":[]},{"id":"CVE-2021-22017","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Improper Access Control","added":"2022-01-10","due":"2022-01-24","ransomware":false,"epss":0.49177,"pct":0.98854,"cvss":[]},{"id":"CVE-2021-36260","kev":true,"vendor":"Hikvision","product":"Security cameras web server","name":"Hikvision Improper Input Validation","added":"2022-01-10","due":"2022-01-24","ransomware":false,"epss":0.99869,"pct":0.99963,"cvss":[]},{"id":"CVE-2020-6572","kev":true,"vendor":"Google","product":"Chrome Media","name":"Google Chrome Media Use-After-Free Vulnerability","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.10586,"pct":0.95662,"cvss":[]},{"id":"CVE-2019-1458","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2022-01-10","due":"2022-07-10","ransomware":true,"epss":0.74263,"pct":0.99479,"cvss":[]},{"id":"CVE-2013-3900","kev":true,"vendor":"Microsoft","product":"WinVerifyTrust function","name":"Microsoft WinVerifyTrust function Remote Code Execution","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.44647,"pct":0.98734,"cvss":[]},{"id":"CVE-2019-2725","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server, Injection","added":"2022-01-10","due":"2022-07-10","ransomware":true,"epss":0.99964,"pct":0.99976,"cvss":[]},{"id":"CVE-2019-9670","kev":true,"vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","name":"Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.99986,"pct":0.99983,"cvss":[]},{"id":"CVE-2018-13382","kev":true,"vendor":"Fortinet","product":"FortiOS and FortiProxy","name":"Fortinet FortiOS and FortiProxy Improper Authorization","added":"2022-01-10","due":"2022-07-10","ransomware":true,"epss":0.81691,"pct":0.99636,"cvss":[]},{"id":"CVE-2018-13383","kev":true,"vendor":"Fortinet","product":"FortiOS and FortiProxy","name":"Fortinet FortiOS and FortiProxy Out-of-bounds Write","added":"2022-01-10","due":"2022-07-10","ransomware":true,"epss":0.33647,"pct":0.98345,"cvss":[]},{"id":"CVE-2019-1579","kev":true,"vendor":"Palo Alto Networks","product":"PAN-OS","name":"Palo Alto Networks PAN-OS Remote Code Execution Vulnerability","added":"2022-01-10","due":"2022-07-10","ransomware":true,"epss":0.46239,"pct":0.98781,"cvss":[]},{"id":"CVE-2019-10149","kev":true,"vendor":"Exim","product":"Mail Transfer Agent (MTA)","name":"Exim Mail Transfer Agent (MTA) Improper Input Validation","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.99961,"pct":0.99975,"cvss":[]},{"id":"CVE-2015-7450","kev":true,"vendor":"IBM","product":"WebSphere Application Server and Server Hypervisor Edition","name":"IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.97764,"pct":0.99905,"cvss":[]},{"id":"CVE-2017-1000486","kev":true,"vendor":"Primetek","product":"Primefaces Application","name":"Primetek Primefaces Remote Code Execution Vulnerability","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.94104,"pct":0.99847,"cvss":[]},{"id":"CVE-2019-7609","kev":true,"vendor":"Elastic","product":"Kibana","name":"Kibana Arbitrary Code Execution","added":"2022-01-10","due":"2022-07-10","ransomware":false,"epss":0.95338,"pct":0.99866,"cvss":[]},{"id":"CVE-2021-27860","kev":true,"vendor":"FatPipe","product":"WARP, IPVPN, and MPVPN software","name":"FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit","added":"2022-01-10","due":"2022-01-24","ransomware":false,"epss":0.39824,"pct":0.98586,"cvss":[]},{"id":"CVE-2021-43890","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows AppX Installer Spoofing Vulnerability","added":"2021-12-15","due":"2021-12-29","ransomware":true,"epss":0.10295,"pct":0.95571,"cvss":[]},{"id":"CVE-2021-4102","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Use-After-Free Vulnerability","added":"2021-12-15","due":"2021-12-29","ransomware":false,"epss":0.07836,"pct":0.94515,"cvss":[]},{"id":"CVE-2021-44515","kev":true,"vendor":"Zoho","product":"Desktop Central","name":"Zoho Desktop Central Authentication Bypass Vulnerability","added":"2021-12-10","due":"2021-12-24","ransomware":false,"epss":0.99871,"pct":0.99963,"cvss":[]},{"id":"CVE-2019-13272","kev":true,"vendor":"Linux","product":"Kernel","name":"Linux Kernel Improper Privilege Management Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.52199,"pct":0.98929,"cvss":[]},{"id":"CVE-2021-35394","kev":true,"vendor":"Realtek","product":"Jungle Software Development Kit (SDK)","name":"Realtek Jungle SDK Remote Code Execution Vulnerability","added":"2021-12-10","due":"2021-12-24","ransomware":false,"epss":0.99861,"pct":0.99962,"cvss":[]},{"id":"CVE-2019-7238","kev":true,"vendor":"Sonatype","product":"Nexus Repository Manager","name":"Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.77146,"pct":0.99542,"cvss":[]},{"id":"CVE-2019-0193","kev":true,"vendor":"Apache","product":"Solr","name":"Apache Solr DataImportHandler Code Injection Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.83547,"pct":0.9968,"cvss":[]},{"id":"CVE-2021-44168","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Arbitrary File Download","added":"2021-12-10","due":"2021-12-24","ransomware":false,"epss":0.00865,"pct":0.57238,"cvss":[]},{"id":"CVE-2017-17562","kev":true,"vendor":"Embedthis","product":"GoAhead","name":"Embedthis GoAhead Remote Code Execution Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.96262,"pct":0.99878,"cvss":[]},{"id":"CVE-2017-12149","kev":true,"vendor":"Red Hat","product":"JBoss Application Server","name":"Red Hat JBoss Application Server Remote Code Execution Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":true,"epss":0.90713,"pct":0.99802,"cvss":[]},{"id":"CVE-2010-1871","kev":true,"vendor":"Red Hat","product":"JBoss Seam 2","name":"Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.83397,"pct":0.99675,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2010-08-05T13:23:09.477Z","modified":"2026-06-16T23:19:29.840Z"},{"id":"CVE-2020-17463","kev":true,"vendor":"Fuel CMS","product":"Fuel CMS","name":"Fuel CMS SQL Injection Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.89689,"pct":0.99787,"cvss":[]},{"id":"CVE-2020-8816","kev":true,"vendor":"Pi-hole","product":"AdminLTE","name":"Pi-Hole AdminLTE Remote Code Execution Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.7819,"pct":0.99569,"cvss":[]},{"id":"CVE-2019-10758","kev":true,"vendor":"MongoDB","product":"mongo-express","name":"MongoDB mongo-express Remote Code Execution Vulnerability","added":"2021-12-10","due":"2022-06-10","ransomware":false,"epss":0.84726,"pct":0.99702,"cvss":[]},{"id":"CVE-2021-44228","kev":true,"vendor":"Apache","product":"Log4j2","name":"Apache Log4j2 Remote Code Execution Vulnerability","added":"2021-12-10","due":"2021-12-24","ransomware":true,"epss":0.99999,"pct":1,"cvss":[]},{"id":"CVE-2020-11261","kev":true,"vendor":"Qualcomm","product":"Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables","name":"Qualcomm Multiple Chipsets Improper Input Validation Vulnerability","added":"2021-12-01","due":"2022-06-01","ransomware":false,"epss":0.01604,"pct":0.75018,"cvss":[]},{"id":"CVE-2018-14847","kev":true,"vendor":"MikroTik","product":"RouterOS","name":"MikroTik Router OS Directory Traversal Vulnerability","added":"2021-12-01","due":"2022-06-01","ransomware":false,"epss":0.96087,"pct":0.99877,"cvss":[]},{"id":"CVE-2021-37415","kev":true,"vendor":"Zoho","product":"ManageEngine ServiceDesk Plus (SDP)","name":"Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability","added":"2021-12-01","due":"2021-12-15","ransomware":false,"epss":0.99825,"pct":0.99959,"cvss":[]},{"id":"CVE-2021-40438","kev":true,"vendor":"Apache","product":"Apache","name":"Apache HTTP Server-Side Request Forgery (SSRF)","added":"2021-12-01","due":"2021-12-15","ransomware":true,"epss":0.99999,"pct":0.99997,"cvss":[]},{"id":"CVE-2021-44077","kev":true,"vendor":"Zoho","product":"ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus","name":"Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability","added":"2021-12-01","due":"2021-12-15","ransomware":false,"epss":0.93298,"pct":0.99835,"cvss":[]},{"id":"CVE-2021-22204","kev":true,"vendor":"Perl","product":"Exiftool","name":"ExifTool Remote Code Execution Vulnerability","added":"2021-11-17","due":"2021-12-01","ransomware":false,"epss":0.99981,"pct":0.99981,"cvss":[]},{"id":"CVE-2021-40449","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Win32k Privilege Escalation Vulnerability","added":"2021-11-17","due":"2021-12-01","ransomware":true,"epss":0.74129,"pct":0.99475,"cvss":[]},{"id":"CVE-2021-42321","kev":true,"vendor":"Microsoft","product":"Exchange","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-17","due":"2021-12-01","ransomware":true,"epss":0.91737,"pct":0.99814,"cvss":[]},{"id":"CVE-2021-42292","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Excel Security Feature Bypass","added":"2021-11-17","due":"2021-12-01","ransomware":false,"epss":0.43005,"pct":0.98685,"cvss":[]},{"id":"CVE-2021-27104","kev":true,"vendor":"Accellion","product":"FTA","name":"Accellion FTA OS Command Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.56686,"pct":0.99039,"cvss":[]},{"id":"CVE-2021-27102","kev":true,"vendor":"Accellion","product":"FTA","name":"Accellion FTA OS Command Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.03654,"pct":0.8927,"cvss":[]},{"id":"CVE-2021-27101","kev":true,"vendor":"Accellion","product":"FTA","name":"Accellion FTA SQL Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.05998,"pct":0.93113,"cvss":[]},{"id":"CVE-2021-27103","kev":true,"vendor":"Accellion","product":"FTA","name":"Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.11406,"pct":0.95884,"cvss":[]},{"id":"CVE-2021-21017","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.86326,"pct":0.9973,"cvss":[]},{"id":"CVE-2021-28550","kev":true,"vendor":"Adobe","product":"Acrobat and Reader","name":"Adobe Acrobat and Reader Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.51851,"pct":0.9892,"cvss":[]},{"id":"CVE-2018-4939","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Deserialization of Untrusted Data Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.61987,"pct":0.99157,"cvss":[]},{"id":"CVE-2018-15961","kev":true,"vendor":"Adobe","product":"ColdFusion","name":"Adobe ColdFusion Unrestricted File Upload Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.9995,"pct":0.99974,"cvss":[]},{"id":"CVE-2018-4878","kev":true,"vendor":"Adobe","product":"Flash Player","name":"Adobe Flash Player Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.89532,"pct":0.99784,"cvss":[]},{"id":"CVE-2020-5735","kev":true,"vendor":"Amcrest","product":"Cameras and Network Video Recorder (NVR)","name":"Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.36217,"pct":0.98439,"cvss":[]},{"id":"CVE-2019-2215","kev":true,"vendor":"Android","product":"Android Kernel","name":"Android Kernel Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.72105,"pct":0.99418,"cvss":[]},{"id":"CVE-2020-0041","kev":true,"vendor":"Android","product":"Android Kernel","name":"Android Kernel Out-of-Bounds Write Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.03145,"pct":0.87495,"cvss":[]},{"id":"CVE-2020-0069","kev":true,"vendor":"MediaTek","product":"Multiple Chipsets","name":"Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.0137,"pct":0.70974,"cvss":[]},{"id":"CVE-2017-9805","kev":true,"vendor":"Apache","product":"Struts","name":"Apache Struts Deserialization of Untrusted Data Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99396,"pct":0.99941,"cvss":[]},{"id":"CVE-2021-42013","kev":true,"vendor":"Apache","product":"HTTP Server","name":"Apache HTTP Server Path Traversal Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99964,"pct":0.99976,"cvss":[]},{"id":"CVE-2021-41773","kev":true,"vendor":"Apache","product":"HTTP Server","name":"Apache HTTP Server Path Traversal Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99992,"pct":0.99986,"cvss":[]},{"id":"CVE-2019-0211","kev":true,"vendor":"Apache","product":"HTTP Server","name":"Apache HTTP Server Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.65005,"pct":0.99233,"cvss":[]},{"id":"CVE-2016-4437","kev":true,"vendor":"Apache","product":"Shiro","name":"Apache Shiro Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.93039,"pct":0.99832,"cvss":[]},{"id":"CVE-2019-17558","kev":true,"vendor":"Apache","product":"Solr","name":"Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.98567,"pct":0.99922,"cvss":[]},{"id":"CVE-2020-17530","kev":true,"vendor":"Apache","product":"Struts","name":"Apache Struts Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.95931,"pct":0.99874,"cvss":[]},{"id":"CVE-2017-5638","kev":true,"vendor":"Apache","product":"Struts","name":"Apache Struts Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99999,"pct":0.99994,"cvss":[]},{"id":"CVE-2018-11776","kev":true,"vendor":"Apache","product":"Struts","name":"Apache Struts Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99991,"pct":0.99986,"cvss":[]},{"id":"CVE-2021-30858","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, macOS Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.13379,"pct":0.96315,"cvss":[]},{"id":"CVE-2019-6223","kev":true,"vendor":"Apple","product":"iOS and macOS","name":"Apple iOS and macOS Group Facetime Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.02629,"pct":0.84999,"cvss":[]},{"id":"CVE-2021-30860","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Integer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.75994,"pct":0.99518,"cvss":[]},{"id":"CVE-2020-27930","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.22009,"pct":0.97601,"cvss":[]},{"id":"CVE-2021-30807","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Corruption Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.28839,"pct":0.98104,"cvss":[]},{"id":"CVE-2020-27950","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Memory Initialization Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.1652,"pct":0.96913,"cvss":[]},{"id":"CVE-2020-27932","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Type Confusion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.10337,"pct":0.95585,"cvss":[]},{"id":"CVE-2020-9818","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and watchOS","name":"Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.02286,"pct":0.82602,"cvss":[]},{"id":"CVE-2020-9819","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and watchOS","name":"Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.02178,"pct":0.81711,"cvss":[]},{"id":"CVE-2021-30762","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS WebKit Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.10986,"pct":0.9578,"cvss":[]},{"id":"CVE-2021-1782","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Race Condition Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.02222,"pct":0.82096,"cvss":[]},{"id":"CVE-2021-1870","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.0771,"pct":0.94443,"cvss":[]},{"id":"CVE-2021-1871","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.07002,"pct":0.9398,"cvss":[]},{"id":"CVE-2021-1879","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and watchOS","name":"Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.07082,"pct":0.94041,"cvss":[]},{"id":"CVE-2021-30661","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Storage Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.04491,"pct":0.91196,"cvss":[]},{"id":"CVE-2021-30666","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS WebKit Buffer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.02998,"pct":0.86909,"cvss":[]},{"id":"CVE-2021-30713","kev":true,"vendor":"Apple","product":"macOS","name":"Apple macOS Unspecified Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.07038,"pct":0.94005,"cvss":[]},{"id":"CVE-2021-30657","kev":true,"vendor":"Apple","product":"macOS","name":"Apple macOS Unspecified Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.68531,"pct":0.9932,"cvss":[]},{"id":"CVE-2021-30665","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Memory Corruption Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.03706,"pct":0.89415,"cvss":[]},{"id":"CVE-2021-30663","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products WebKit Integer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.03521,"pct":0.88863,"cvss":[]},{"id":"CVE-2021-30761","kev":true,"vendor":"Apple","product":"iOS","name":"Apple iOS WebKit Memory Corruption Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.10545,"pct":0.9565,"cvss":[]},{"id":"CVE-2021-30869","kev":true,"vendor":"Apple","product":"iOS, iPadOS, and macOS","name":"Apple iOS, iPadOS, and macOS Type Confusion Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.04135,"pct":0.9053,"cvss":[]},{"id":"CVE-2020-9859","kev":true,"vendor":"Apple","product":"Multiple Products","name":"Apple Multiple Products Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.00829,"pct":0.56066,"cvss":[]},{"id":"CVE-2021-20090","kev":true,"vendor":"Arcadyan","product":"Buffalo Firmware","name":"Arcadyan Buffalo Firmware Path Traversal Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.99983,"pct":0.99982,"cvss":[]},{"id":"CVE-2021-27562","kev":true,"vendor":"Arm","product":"Trusted Firmware","name":"Arm Trusted Firmware Out-of-Bounds Write Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.03093,"pct":0.87296,"cvss":[]},{"id":"CVE-2021-28664","kev":true,"vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","name":"Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.05407,"pct":0.92454,"cvss":[]},{"id":"CVE-2021-28663","kev":true,"vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","name":"Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.12084,"pct":0.96034,"cvss":[]},{"id":"CVE-2019-3398","kev":true,"vendor":"Atlassian","product":"Confluence Server and Data Center","name":"Atlassian Confluence Server and Data Center Path Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.97028,"pct":0.99891,"cvss":[]},{"id":"CVE-2021-26084","kev":true,"vendor":"Atlassian","product":"Confluence Server and Data Center","name":"Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99999,"pct":0.99993,"cvss":[]},{"id":"CVE-2019-11580","kev":true,"vendor":"Atlassian","product":"Crowd and Crowd Data Center","name":"Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.95355,"pct":0.99867,"cvss":[]},{"id":"CVE-2019-3396","kev":true,"vendor":"Atlassian","product":"Confluence Server and Data Server","name":"Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99913,"pct":0.99967,"cvss":[]},{"id":"CVE-2021-42258","kev":true,"vendor":"BQE","product":"BillQuick Web Suite","name":"BQE BillQuick Web Suite SQL Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.74426,"pct":0.99482,"cvss":[]},{"id":"CVE-2020-3452","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","name":"Cisco ASA and FTD Read-Only Path Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99992,"pct":0.99987,"cvss":[]},{"id":"CVE-2020-3580","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","name":"Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.85575,"pct":0.99719,"cvss":[]},{"id":"CVE-2021-1497","kev":true,"vendor":"Cisco","product":"HyperFlex HX","name":"Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.9993,"pct":0.99969,"cvss":[]},{"id":"CVE-2021-1498","kev":true,"vendor":"Cisco","product":"HyperFlex HX","name":"Cisco HyperFlex HX Data Platform Command Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.99999,"pct":0.99991,"cvss":[]},{"id":"CVE-2018-0171","kev":true,"vendor":"Cisco","product":"IOS and IOS XE","name":"Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99479,"pct":0.99943,"cvss":[]},{"id":"CVE-2020-3118","kev":true,"vendor":"Cisco","product":"IOS XR","name":"Cisco IOS XR Software Discovery Protocol Format String Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.11685,"pct":0.95947,"cvss":[]},{"id":"CVE-2020-3566","kev":true,"vendor":"Cisco","product":"IOS XR","name":"Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.03702,"pct":0.89407,"cvss":[]},{"id":"CVE-2020-3569","kev":true,"vendor":"Cisco","product":"IOS XR","name":"Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.0332,"pct":0.88206,"cvss":[]},{"id":"CVE-2020-3161","kev":true,"vendor":"Cisco","product":"Cisco IP Phones","name":"Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.83855,"pct":0.99685,"cvss":[]},{"id":"CVE-2019-1653","kev":true,"vendor":"Cisco","product":"Small Business RV320 and RV325 Routers","name":"Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99876,"pct":0.99963,"cvss":[]},{"id":"CVE-2018-0296","kev":true,"vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","name":"Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99913,"pct":0.99967,"cvss":[]},{"id":"CVE-2019-13608","kev":true,"vendor":"Citrix","product":"StoreFront Server","name":"Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.30041,"pct":0.98166,"cvss":[]},{"id":"CVE-2020-8193","kev":true,"vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","name":"Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.88411,"pct":0.99769,"cvss":[]},{"id":"CVE-2020-8195","kev":true,"vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","name":"Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.33029,"pct":0.98318,"cvss":[]},{"id":"CVE-2020-8196","kev":true,"vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","name":"Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.26333,"pct":0.97951,"cvss":[]},{"id":"CVE-2019-19781","kev":true,"vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","name":"Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99999,"pct":0.99998,"cvss":[]},{"id":"CVE-2019-11634","kev":true,"vendor":"Citrix","product":"Workspace Application and Receiver for Windows","name":"Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.08026,"pct":0.94619,"cvss":[]},{"id":"CVE-2020-29557","kev":true,"vendor":"D-Link","product":"DIR-825 R1 Devices","name":"D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.5432,"pct":0.98984,"cvss":[]},{"id":"CVE-2020-25506","kev":true,"vendor":"D-Link","product":"DNS-320 Device","name":"D-Link DNS-320 Device Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99968,"pct":0.99978,"cvss":[]},{"id":"CVE-2018-15811","kev":true,"vendor":"DotNetNuke (DNN)","product":"DotNetNuke (DNN)","name":"DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.76143,"pct":0.99522,"cvss":[]},{"id":"CVE-2018-18325","kev":true,"vendor":"DotNetNuke (DNN)","product":"DotNetNuke (DNN)","name":"DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.7387,"pct":0.99469,"cvss":[]},{"id":"CVE-2017-9822","kev":true,"vendor":"DotNetNuke (DNN)","product":"DotNetNuke (DNN)","name":"DotNetNuke (DNN) Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.94789,"pct":0.99858,"cvss":[]},{"id":"CVE-2019-15752","kev":true,"vendor":"Docker","product":"Desktop Community Edition","name":"Docker Desktop Community Edition Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.48628,"pct":0.98839,"cvss":[]},{"id":"CVE-2020-8515","kev":true,"vendor":"DrayTek","product":"Multiple Vigor Routers","name":"Multiple DrayTek Vigor Routers Web Management Page Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99993,"pct":0.99987,"cvss":[]},{"id":"CVE-2018-7600","kev":true,"vendor":"Drupal","product":"Drupal Core","name":"Drupal Core Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99991,"pct":0.99985,"cvss":[]},{"id":"CVE-2021-22205","kev":true,"vendor":"GitLab","product":"Community and Enterprise Editions","name":"GitLab Community and Enterprise Editions Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99731,"pct":0.99952,"cvss":[]},{"id":"CVE-2018-6789","kev":true,"vendor":"Exim","product":"Exim","name":"Exim Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.82137,"pct":0.99648,"cvss":[]},{"id":"CVE-2020-8657","kev":true,"vendor":"EyesOfNetwork","product":"EyesOfNetwork","name":"EyesOfNetwork Use of Hard-Coded Credentials Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.91874,"pct":0.99816,"cvss":[]},{"id":"CVE-2020-8655","kev":true,"vendor":"EyesOfNetwork","product":"EyesOfNetwork","name":"EyesOfNetwork Improper Privilege Management Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.60075,"pct":0.99112,"cvss":[]},{"id":"CVE-2020-5902","kev":true,"vendor":"F5","product":"BIG-IP","name":"F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99999,"pct":1,"cvss":[]},{"id":"CVE-2021-22986","kev":true,"vendor":"F5","product":"BIG-IP and BIG-IQ Centralized Management","name":"F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99898,"pct":0.99965,"cvss":[]},{"id":"CVE-2021-35464","kev":true,"vendor":"ForgeRock","product":"Access Management (AM)","name":"ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99999,"pct":0.99994,"cvss":[]},{"id":"CVE-2019-5591","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS Default Configuration Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.18422,"pct":0.97162,"cvss":[]},{"id":"CVE-2020-12812","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS SSL VPN Improper Authentication Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.45379,"pct":0.98755,"cvss":[]},{"id":"CVE-2018-13379","kev":true,"vendor":"Fortinet","product":"FortiOS","name":"Fortinet FortiOS SSL VPN Path Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99999,"pct":0.99995,"cvss":[]},{"id":"CVE-2020-16010","kev":true,"vendor":"Google","product":"Chrome for Android UI","name":"Google Chrome for Android UI Heap Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.06363,"pct":0.93452,"cvss":[]},{"id":"CVE-2020-15999","kev":true,"vendor":"Google","product":"Chrome FreeType","name":"Google Chrome FreeType Heap Buffer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.63894,"pct":0.99203,"cvss":[]},{"id":"CVE-2021-21166","kev":true,"vendor":"Google","product":"Chromium","name":"Google Chromium Race Condition Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.24027,"pct":0.97782,"cvss":[]},{"id":"CVE-2020-16017","kev":true,"vendor":"Google","product":"Chrome","name":"Google Chrome Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.0273,"pct":0.85592,"cvss":[]},{"id":"CVE-2021-37976","kev":true,"vendor":"Google","product":"Chromium","name":"Google Chromium Information Disclosure Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.19901,"pct":0.97357,"cvss":[]},{"id":"CVE-2020-16009","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.48293,"pct":0.98831,"cvss":[]},{"id":"CVE-2021-30632","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Out-of-Bounds Write Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.6319,"pct":0.99185,"cvss":[]},{"id":"CVE-2020-16013","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Incorrect Implementation Vulnerabililty","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.02756,"pct":0.85766,"cvss":[]},{"id":"CVE-2021-30633","kev":true,"vendor":"Google","product":"Chromium Indexed DB API","name":"Google Chromium Indexed DB API Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.3318,"pct":0.98325,"cvss":[]},{"id":"CVE-2021-21148","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Heap Buffer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.19968,"pct":0.97369,"cvss":[]},{"id":"CVE-2021-37973","kev":true,"vendor":"Google","product":"Chromium Portals","name":"Google Chromium Portals Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.11735,"pct":0.95958,"cvss":[]},{"id":"CVE-2021-30551","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.64701,"pct":0.99225,"cvss":[]},{"id":"CVE-2021-37975","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.34887,"pct":0.98393,"cvss":[]},{"id":"CVE-2020-6418","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.78808,"pct":0.99583,"cvss":[]},{"id":"CVE-2021-30554","kev":true,"vendor":"Google","product":"Chromium WebGL","name":"Google Chromium WebGL Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.07367,"pct":0.9424,"cvss":[]},{"id":"CVE-2021-21206","kev":true,"vendor":"Google","product":"Chromium Blink","name":"Google Chromium Blink Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.09307,"pct":0.9524,"cvss":[]},{"id":"CVE-2021-38000","kev":true,"vendor":"Google","product":"Chromium Intents","name":"Google Chromium Intents Improper Input Validation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.04948,"pct":0.91906,"cvss":[]},{"id":"CVE-2021-38003","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Memory Corruption Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.38573,"pct":0.98539,"cvss":[]},{"id":"CVE-2021-21224","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.84173,"pct":0.9969,"cvss":[]},{"id":"CVE-2021-21193","kev":true,"vendor":"Google","product":"Chromium Blink","name":"Google Chromium Blink Use-After-Free Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.0987,"pct":0.9544,"cvss":[]},{"id":"CVE-2021-21220","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Improper Input Validation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.70435,"pct":0.99374,"cvss":[]},{"id":"CVE-2021-30563","kev":true,"vendor":"Google","product":"Chromium V8","name":"Google Chromium V8 Type Confusion Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.09,"pct":0.95132,"cvss":[]},{"id":"CVE-2020-4430","kev":true,"vendor":"IBM","product":"Data Risk Manager","name":"IBM Data Risk Manager Directory Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.68544,"pct":0.99321,"cvss":[]},{"id":"CVE-2020-4427","kev":true,"vendor":"IBM","product":"Data Risk Manager","name":"IBM Data Risk Manager Security Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.70031,"pct":0.9936,"cvss":[]},{"id":"CVE-2020-4428","kev":true,"vendor":"IBM","product":"Data Risk Manager","name":"IBM Data Risk Manager Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.61692,"pct":0.9915,"cvss":[]},{"id":"CVE-2019-4716","kev":true,"vendor":"IBM","product":"Planning Analytics","name":"IBM Planning Analytics Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.86441,"pct":0.99732,"cvss":[]},{"id":"CVE-2016-3715","kev":true,"vendor":"ImageMagick","product":"ImageMagick","name":"ImageMagick Arbitrary File Deletion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.75307,"pct":0.99502,"cvss":[]},{"id":"CVE-2016-3718","kev":true,"vendor":"ImageMagick","product":"ImageMagick","name":"ImageMagick Server-Side Request Forgery (SSRF) Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.76741,"pct":0.99534,"cvss":[]},{"id":"CVE-2020-15505","kev":true,"vendor":"Ivanti","product":"MobileIron Multiple Products","name":"Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99737,"pct":0.99953,"cvss":[]},{"id":"CVE-2021-30116","kev":true,"vendor":"Kaseya","product":"Virtual System/Server Administrator (VSA)","name":"Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.85735,"pct":0.99721,"cvss":[]},{"id":"CVE-2020-7961","kev":true,"vendor":"Liferay","product":"Liferay Portal","name":"Liferay Portal Deserialization of Untrusted Data Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99905,"pct":0.99965,"cvss":[]},{"id":"CVE-2021-23874","kev":true,"vendor":"McAfee","product":"McAfee Total Protection (MTP)","name":"McAfee Total Protection (MTP) Improper Privilege Management Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.01026,"pct":0.62365,"cvss":[]},{"id":"CVE-2021-22506","kev":true,"vendor":"Micro Focus","product":"Micro Focus Access Manager","name":"Micro Focus Access Manager Information Leakage Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.25695,"pct":0.97912,"cvss":[]},{"id":"CVE-2021-22502","kev":true,"vendor":"Micro Focus","product":"Operation Bridge Reporter (OBR)","name":"Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.9674,"pct":0.99886,"cvss":[]},{"id":"CVE-2014-1812","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.64876,"pct":0.9923,"cvss":[]},{"id":"CVE-2021-38647","kev":true,"vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","name":"Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99933,"pct":0.9997,"cvss":[]},{"id":"CVE-2016-0167","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.05683,"pct":0.92766,"cvss":[]},{"id":"CVE-2020-0878","kev":true,"vendor":"Microsoft","product":"Edge and Internet Explorer","name":"Microsoft Edge and Internet Explorer Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.02696,"pct":0.85417,"cvss":[]},{"id":"CVE-2021-31955","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Information Disclosure Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.81107,"pct":0.99626,"cvss":[]},{"id":"CVE-2021-1647","kev":true,"vendor":"Microsoft","product":"Defender","name":"Microsoft Defender Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.39392,"pct":0.98568,"cvss":[]},{"id":"CVE-2021-33739","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.06555,"pct":0.93616,"cvss":[]},{"id":"CVE-2016-0185","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Media Center Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.69846,"pct":0.99356,"cvss":[]},{"id":"CVE-2020-0683","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Installer Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.07605,"pct":0.9438,"cvss":[]},{"id":"CVE-2020-17087","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.05431,"pct":0.92476,"cvss":[]},{"id":"CVE-2021-33742","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.59407,"pct":0.99098,"cvss":[]},{"id":"CVE-2021-31199","kev":true,"vendor":"Microsoft","product":"Enhanced Cryptographic Provider","name":"Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.02954,"pct":0.86721,"cvss":[]},{"id":"CVE-2021-33771","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.10172,"pct":0.95535,"cvss":[]},{"id":"CVE-2021-31956","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows NTFS Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.22273,"pct":0.97622,"cvss":[]},{"id":"CVE-2021-31201","kev":true,"vendor":"Microsoft","product":"Enhanced Cryptographic Provider","name":"Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.02617,"pct":0.84927,"cvss":[]},{"id":"CVE-2021-31979","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.0454,"pct":0.91278,"cvss":[]},{"id":"CVE-2020-0938","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.6895,"pct":0.99333,"cvss":[]},{"id":"CVE-2020-17144","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.36514,"pct":0.98453,"cvss":[]},{"id":"CVE-2020-0986","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Kernel Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.16277,"pct":0.96867,"cvss":[]},{"id":"CVE-2020-1020","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.65037,"pct":0.99234,"cvss":[]},{"id":"CVE-2021-38645","kev":true,"vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","name":"Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.02727,"pct":0.85576,"cvss":[]},{"id":"CVE-2021-34523","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.9999,"pct":0.99985,"cvss":[]},{"id":"CVE-2017-7269","kev":true,"vendor":"Microsoft","product":"Internet Information Services (IIS)","name":"Microsoft Windows Server Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99823,"pct":0.99959,"cvss":[]},{"id":"CVE-2021-36948","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Update Medic Service Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.2327,"pct":0.97719,"cvss":[]},{"id":"CVE-2021-38649","kev":true,"vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","name":"Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.02887,"pct":0.86416,"cvss":[]},{"id":"CVE-2020-0688","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99962,"pct":0.99975,"cvss":[]},{"id":"CVE-2017-0143","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.93307,"pct":0.99836,"cvss":[]},{"id":"CVE-2016-7255","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.80968,"pct":0.99624,"cvss":[]},{"id":"CVE-2019-0708","kev":true,"vendor":"Microsoft","product":"Remote Desktop Services","name":"Microsoft Remote Desktop Services Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99999,"pct":0.99999,"cvss":[]},{"id":"CVE-2021-34473","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99999,"pct":0.99996,"cvss":[]},{"id":"CVE-2020-1464","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Spoofing Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.38946,"pct":0.98551,"cvss":[]},{"id":"CVE-2021-1732","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.78376,"pct":0.99573,"cvss":[]},{"id":"CVE-2021-34527","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Print Spooler Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99792,"pct":0.99956,"cvss":[]},{"id":"CVE-2021-31207","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Security Feature Bypass Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99782,"pct":0.99955,"cvss":[]},{"id":"CVE-2019-0803","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.44954,"pct":0.98743,"cvss":[]},{"id":"CVE-2020-1040","kev":true,"vendor":"Microsoft","product":"Hyper-V RemoteFX","name":"Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.07393,"pct":0.94255,"cvss":[]},{"id":"CVE-2021-28310","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.0833,"pct":0.94797,"cvss":[]},{"id":"CVE-2020-1350","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows DNS Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.96721,"pct":0.99885,"cvss":[]},{"id":"CVE-2021-26411","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Memory Corruption Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.80765,"pct":0.9962,"cvss":[]},{"id":"CVE-2019-0859","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.04151,"pct":0.9056,"cvss":[]},{"id":"CVE-2021-40444","kev":true,"vendor":"Microsoft","product":"MSHTML","name":"Microsoft MSHTML Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.9745,"pct":0.999,"cvss":[]},{"id":"CVE-2017-8759","kev":true,"vendor":"Microsoft","product":".NET Framework","name":"Microsoft .NET Framework Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.88698,"pct":0.99773,"cvss":[]},{"id":"CVE-2018-8653","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.29606,"pct":0.98145,"cvss":[]},{"id":"CVE-2019-0797","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.0189,"pct":0.78848,"cvss":[]},{"id":"CVE-2021-36942","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.66023,"pct":0.99256,"cvss":[]},{"id":"CVE-2019-1215","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.19254,"pct":0.97265,"cvss":[]},{"id":"CVE-2018-0798","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.95121,"pct":0.99864,"cvss":[]},{"id":"CVE-2018-0802","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.93289,"pct":0.99835,"cvss":[]},{"id":"CVE-2012-0158","kev":true,"vendor":"Microsoft","product":"MSCOMCTL.OCX","name":"Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99976,"pct":0.99979,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":8.8,"severity":"HIGH"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":8.8,"severity":"HIGH"}],"published":"2012-04-10T21:55:01.687Z","modified":"2026-06-16T23:36:48.343Z"},{"id":"CVE-2015-1641","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.96698,"pct":0.99885,"cvss":[]},{"id":"CVE-2021-27085","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.05448,"pct":0.92494,"cvss":[]},{"id":"CVE-2019-0541","kev":true,"vendor":"Microsoft","product":"MSHTML","name":"Microsoft MSHTML Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.53202,"pct":0.98953,"cvss":[]},{"id":"CVE-2017-11882","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99945,"pct":0.99973,"cvss":[]},{"id":"CVE-2020-0674","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.86863,"pct":0.99742,"cvss":[]},{"id":"CVE-2021-27059","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.06076,"pct":0.93192,"cvss":[]},{"id":"CVE-2019-1367","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.52449,"pct":0.98934,"cvss":[]},{"id":"CVE-2017-0199","kev":true,"vendor":"Microsoft","product":"Office and WordPad","name":"Microsoft Office and WordPad Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99497,"pct":0.99944,"cvss":[]},{"id":"CVE-2020-1380","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.24188,"pct":0.97794,"cvss":[]},{"id":"CVE-2019-1429","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.7729,"pct":0.99545,"cvss":[]},{"id":"CVE-2017-11774","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office Outlook Security Feature Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.59627,"pct":0.99105,"cvss":[]},{"id":"CVE-2020-0968","kev":true,"vendor":"Microsoft","product":"Internet Explorer","name":"Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.30676,"pct":0.982,"cvss":[]},{"id":"CVE-2020-1472","kev":true,"vendor":"Microsoft","product":"Netlogon","name":"Microsoft Netlogon Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99389,"pct":0.9994,"cvss":[]},{"id":"CVE-2021-26855","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99996,"pct":0.99988,"cvss":[]},{"id":"CVE-2021-26858","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.93651,"pct":0.99842,"cvss":[]},{"id":"CVE-2021-27065","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99876,"pct":0.99963,"cvss":[]},{"id":"CVE-2020-1054","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.54158,"pct":0.98981,"cvss":[]},{"id":"CVE-2021-1675","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Print Spooler Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.85305,"pct":0.99713,"cvss":[]},{"id":"CVE-2021-34448","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Scripting Engine Memory Corruption Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.40062,"pct":0.98595,"cvss":[]},{"id":"CVE-2020-0601","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows CryptoAPI Spoofing Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.89436,"pct":0.99782,"cvss":[]},{"id":"CVE-2019-0604","kev":true,"vendor":"Microsoft","product":"SharePoint","name":"Microsoft SharePoint Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99913,"pct":0.99968,"cvss":[]},{"id":"CVE-2020-0646","kev":true,"vendor":"Microsoft","product":".NET Framework","name":"Microsoft .NET Framework Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99222,"pct":0.99935,"cvss":[]},{"id":"CVE-2019-0808","kev":true,"vendor":"Microsoft","product":"Win32k","name":"Microsoft Win32k Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.53017,"pct":0.98948,"cvss":[]},{"id":"CVE-2021-26857","kev":true,"vendor":"Microsoft","product":"Exchange Server","name":"Microsoft Exchange Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.95762,"pct":0.99872,"cvss":[]},{"id":"CVE-2020-1147","kev":true,"vendor":"Microsoft","product":".NET Framework, SharePoint, Visual Studio","name":"Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.93966,"pct":0.99844,"cvss":[]},{"id":"CVE-2019-1214","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.01419,"pct":0.71904,"cvss":[]},{"id":"CVE-2016-3235","kev":true,"vendor":"Microsoft","product":"Office","name":"Microsoft Office OLE DLL Side Loading Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.43308,"pct":0.98694,"cvss":[]},{"id":"CVE-2019-0863","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.05207,"pct":0.92249,"cvss":[]},{"id":"CVE-2021-36955","kev":true,"vendor":"Microsoft","product":"Windows","name":"Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.04071,"pct":0.90382,"cvss":[]},{"id":"CVE-2021-38648","kev":true,"vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","name":"Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.11424,"pct":0.9589,"cvss":[]},{"id":"CVE-2020-6819","kev":true,"vendor":"Mozilla","product":"Firefox and Thunderbird","name":"Mozilla Firefox And Thunderbird Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.03039,"pct":0.87072,"cvss":[]},{"id":"CVE-2020-6820","kev":true,"vendor":"Mozilla","product":"Firefox and Thunderbird","name":"Mozilla Firefox And Thunderbird Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.07063,"pct":0.94024,"cvss":[]},{"id":"CVE-2019-17026","kev":true,"vendor":"Mozilla","product":"Firefox and Thunderbird","name":"Mozilla Firefox And Thunderbird Type Confusion Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.46311,"pct":0.98783,"cvss":[]},{"id":"CVE-2019-15949","kev":true,"vendor":"Nagios","product":"Nagios XI","name":"Nagios XI Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.77039,"pct":0.99539,"cvss":[]},{"id":"CVE-2020-26919","kev":true,"vendor":"NETGEAR","product":"JGS516PE Devices","name":"Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.57468,"pct":0.99057,"cvss":[]},{"id":"CVE-2019-19356","kev":true,"vendor":"Netis","product":"WF2419 Devices","name":"Netis WF2419 Devices Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.28168,"pct":0.98063,"cvss":[]},{"id":"CVE-2020-2555","kev":true,"vendor":"Oracle","product":"Multiple Products","name":"Oracle Multiple Products Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.97116,"pct":0.99893,"cvss":[]},{"id":"CVE-2012-3152","kev":true,"vendor":"Oracle","product":"Fusion Middleware","name":"Oracle Fusion Middleware Unspecified Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.98793,"pct":0.99926,"cvss":[{"source":"nvd@nist.gov","type":"Primary","version":"3.1","score":9.1,"severity":"CRITICAL"},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","version":"3.1","score":9.1,"severity":"CRITICAL"}],"published":"2012-10-16T23:55:03.823Z","modified":"2026-06-16T23:42:40.677Z"},{"id":"CVE-2020-14871","kev":true,"vendor":"Oracle","product":"Solaris and Zettabyte File System (ZFS)","name":"Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.80157,"pct":0.99609,"cvss":[]},{"id":"CVE-2015-4852","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.96032,"pct":0.99876,"cvss":[]},{"id":"CVE-2020-14750","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.9927,"pct":0.99936,"cvss":[]},{"id":"CVE-2020-14882","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99997,"pct":0.99989,"cvss":[]},{"id":"CVE-2020-14883","kev":true,"vendor":"Oracle","product":"WebLogic Server","name":"Oracle WebLogic Server Unspecified Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.97929,"pct":0.99909,"cvss":[]},{"id":"CVE-2020-8644","kev":true,"vendor":"PlaySMS","product":"PlaySMS","name":"PlaySMS Server-Side Template Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.86689,"pct":0.99738,"cvss":[]},{"id":"CVE-2019-18935","kev":true,"vendor":"Progress","product":"Telerik UI for ASP.NET AJAX","name":"Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99737,"pct":0.99953,"cvss":[]},{"id":"CVE-2021-22893","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.47172,"pct":0.98803,"cvss":[]},{"id":"CVE-2020-8243","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.90759,"pct":0.99803,"cvss":[]},{"id":"CVE-2021-22900","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.14146,"pct":0.96478,"cvss":[]},{"id":"CVE-2021-22894","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.41284,"pct":0.98632,"cvss":[]},{"id":"CVE-2020-8260","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.9648,"pct":0.99881,"cvss":[]},{"id":"CVE-2021-22899","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.22915,"pct":0.97687,"cvss":[]},{"id":"CVE-2019-11510","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure","name":"Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99999,"pct":1,"cvss":[]},{"id":"CVE-2019-11539","kev":true,"vendor":"Ivanti","product":"Pulse Connect Secure and Pulse Policy Secure","name":"Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.98544,"pct":0.99921,"cvss":[]},{"id":"CVE-2021-1906","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.0052,"pct":0.42141,"cvss":[]},{"id":"CVE-2021-1905","kev":true,"vendor":"Qualcomm","product":"Multiple Chipsets","name":"Qualcomm Multiple Chipsets Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.01543,"pct":0.74099,"cvss":[]},{"id":"CVE-2020-10221","kev":true,"vendor":"rConfig","product":"rConfig","name":"rConfig OS Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.77123,"pct":0.99541,"cvss":[]},{"id":"CVE-2021-35395","kev":true,"vendor":"Realtek","product":"AP-Router SDK","name":"Realtek AP-Router SDK Buffer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.981,"pct":0.99911,"cvss":[]},{"id":"CVE-2017-16651","kev":true,"vendor":"Roundcube","product":"Roundcube Webmail","name":"Roundcube Webmail File Disclosure Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.45742,"pct":0.98765,"cvss":[]},{"id":"CVE-2020-11652","kev":true,"vendor":"SaltStack","product":"Salt","name":"SaltStack Salt Path Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.86178,"pct":0.99727,"cvss":[]},{"id":"CVE-2020-11651","kev":true,"vendor":"SaltStack","product":"Salt","name":"SaltStack Salt Authentication Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.96614,"pct":0.99883,"cvss":[]},{"id":"CVE-2020-16846","kev":true,"vendor":"SaltStack","product":"Salt","name":"SaltStack Salt Shell Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99585,"pct":0.99946,"cvss":[]},{"id":"CVE-2018-2380","kev":true,"vendor":"SAP","product":"Customer Relationship Management (CRM)","name":"SAP Customer Relationship Management (CRM) Path Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.28934,"pct":0.98109,"cvss":[]},{"id":"CVE-2010-5326","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.1777,"pct":0.97086,"cvss":[]},{"id":"CVE-2016-9563","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver XML External Entity (XXE) Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.24226,"pct":0.97797,"cvss":[]},{"id":"CVE-2020-6287","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Missing Authentication for Critical Function Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.94719,"pct":0.99857,"cvss":[]},{"id":"CVE-2020-6207","kev":true,"vendor":"SAP","product":"Solution Manager","name":"SAP Solution Manager Missing Authentication for Critical Function Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.98135,"pct":0.99912,"cvss":[]},{"id":"CVE-2016-3976","kev":true,"vendor":"SAP","product":"NetWeaver","name":"SAP NetWeaver Directory Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.47252,"pct":0.98805,"cvss":[]},{"id":"CVE-2019-16256","kev":true,"vendor":"SIMalliance","product":"Toolbox Browser","name":"SIMalliance Toolbox Browser Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.04949,"pct":0.91909,"cvss":[]},{"id":"CVE-2020-10148","kev":true,"vendor":"SolarWinds","product":"Orion","name":"SolarWinds Orion Authentication Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.9198,"pct":0.99818,"cvss":[]},{"id":"CVE-2021-35211","kev":true,"vendor":"SolarWinds","product":"Serv-U","name":"SolarWinds Serv-U Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.9116,"pct":0.99807,"cvss":[]},{"id":"CVE-2016-3643","kev":true,"vendor":"SolarWinds","product":"Virtualization Manager","name":"SolarWinds Virtualization Manager Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.03674,"pct":0.89325,"cvss":[]},{"id":"CVE-2020-10199","kev":true,"vendor":"Sonatype","product":"Nexus Repository","name":"Sonatype Nexus Repository Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99064,"pct":0.99932,"cvss":[]},{"id":"CVE-2021-20021","kev":true,"vendor":"SonicWall","product":"SonicWall Email Security","name":"SonicWall Email Security Improper Privilege Management Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.8867,"pct":0.99773,"cvss":[]},{"id":"CVE-2019-7481","kev":true,"vendor":"SonicWall","product":"SMA100","name":"SonicWall SMA100 SQL Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.99906,"pct":0.99966,"cvss":[]},{"id":"CVE-2021-20022","kev":true,"vendor":"SonicWall","product":"SonicWall Email Security","name":"SonicWall Email Security Unrestricted Upload of File Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.16509,"pct":0.96911,"cvss":[]},{"id":"CVE-2021-20023","kev":true,"vendor":"SonicWall","product":"SonicWall Email Security","name":"SonicWall Email Security Path Traversal Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.51407,"pct":0.98911,"cvss":[]},{"id":"CVE-2021-20016","kev":true,"vendor":"SonicWall","product":"SSLVPN SMA100","name":"SonicWall SSLVPN SMA100 SQL Injection Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.40038,"pct":0.98593,"cvss":[]},{"id":"CVE-2020-12271","kev":true,"vendor":"Sophos","product":"SFOS","name":"Sophos SFOS SQL Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.42434,"pct":0.98667,"cvss":[]},{"id":"CVE-2020-10181","kev":true,"vendor":"Sumavision","product":"Enhanced Multimedia Router (EMR)","name":"Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.14666,"pct":0.9657,"cvss":[]},{"id":"CVE-2017-6327","kev":true,"vendor":"Symantec","product":"Symantec Messaging Gateway","name":"Symantec Messaging Gateway Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.35911,"pct":0.98431,"cvss":[]},{"id":"CVE-2019-18988","kev":true,"vendor":"TeamViewer","product":"Desktop","name":"TeamViewer Desktop Bypass Remote Login Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.04707,"pct":0.91546,"cvss":[]},{"id":"CVE-2017-9248","kev":true,"vendor":"Progress","product":"ASP.NET AJAX and Sitefinity","name":"Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.75098,"pct":0.99498,"cvss":[]},{"id":"CVE-2021-31755","kev":true,"vendor":"Tenda","product":"AC11 Router","name":"Tenda AC11 Router Stack Buffer Overflow Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.86891,"pct":0.99743,"cvss":[]},{"id":"CVE-2020-10987","kev":true,"vendor":"Tenda","product":"AC1900 Router AC15 Model","name":"Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.7981,"pct":0.99602,"cvss":[]},{"id":"CVE-2018-14558","kev":true,"vendor":"Tenda","product":"AC7, AC9, and AC10 Routers","name":"Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.08742,"pct":0.95013,"cvss":[]},{"id":"CVE-2018-20062","kev":true,"vendor":"ThinkPHP","product":"noneCms","name":"ThinkPHP \"noneCms\" Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.9953,"pct":0.99945,"cvss":[]},{"id":"CVE-2019-9082","kev":true,"vendor":"ThinkPHP","product":"ThinkPHP","name":"ThinkPHP Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.97419,"pct":0.99899,"cvss":[]},{"id":"CVE-2019-18187","kev":true,"vendor":"Trend Micro","product":"OfficeScan","name":"Trend Micro OfficeScan Directory Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.25125,"pct":0.97876,"cvss":[]},{"id":"CVE-2020-8467","kev":true,"vendor":"Trend Micro","product":"Apex One and OfficeScan","name":"Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.109,"pct":0.95755,"cvss":[]},{"id":"CVE-2020-8468","kev":true,"vendor":"Trend Micro","product":"Apex One, OfficeScan and Worry-Free Business Security Agents","name":"Trend Micro Multiple Products Content Validation Escape Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.06165,"pct":0.93277,"cvss":[]},{"id":"CVE-2020-24557","kev":true,"vendor":"Trend Micro","product":"Apex One, OfficeScan, and Worry-Free Business Security","name":"Trend Micro Multiple Products Improper Access Control Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.02666,"pct":0.85229,"cvss":[]},{"id":"CVE-2020-8599","kev":true,"vendor":"Trend Micro","product":"Apex One and OfficeScan","name":"Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.11858,"pct":0.95983,"cvss":[]},{"id":"CVE-2021-36742","kev":true,"vendor":"Trend Micro","product":"Apex One, Apex One as a Service, and Worry-Free Business Security","name":"Trend Micro Multiple Products Improper Input Validation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.01482,"pct":0.73073,"cvss":[]},{"id":"CVE-2021-36741","kev":true,"vendor":"Trend Micro","product":"Apex One, Apex One as a Service, and Worry-Free Business Security","name":"Trend Micro Multiple Products Improper Input Validation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.04951,"pct":0.91914,"cvss":[]},{"id":"CVE-2019-20085","kev":true,"vendor":"TVT","product":"NVMS-1000","name":"TVT NVMS-1000 Directory Traversal Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.96071,"pct":0.99877,"cvss":[]},{"id":"CVE-2020-5849","kev":true,"vendor":"Unraid","product":"Unraid","name":"Unraid Authentication Bypass Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.93243,"pct":0.99834,"cvss":[]},{"id":"CVE-2020-5847","kev":true,"vendor":"Unraid","product":"Unraid","name":"Unraid Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.95844,"pct":0.99873,"cvss":[]},{"id":"CVE-2019-16759","kev":true,"vendor":"vBulletin","product":"vBulletin","name":"vBulletin PHP Module Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99728,"pct":0.99952,"cvss":[]},{"id":"CVE-2020-17496","kev":true,"vendor":"vBulletin","product":"vBulletin","name":"vBulletin PHP Module Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.87366,"pct":0.99753,"cvss":[]},{"id":"CVE-2019-5544","kev":true,"vendor":"VMware","product":"VMware ESXi and Horizon DaaS","name":"VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.97258,"pct":0.99896,"cvss":[]},{"id":"CVE-2020-3992","kev":true,"vendor":"VMware","product":"ESXi","name":"VMware ESXi OpenSLP Use-After-Free Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":true,"epss":0.83015,"pct":0.99667,"cvss":[]},{"id":"CVE-2020-3950","kev":true,"vendor":"VMware","product":"Multiple Products","name":"VMware Multiple Products Privilege Escalation Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.07254,"pct":0.94166,"cvss":[]},{"id":"CVE-2021-22005","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server File Upload Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99999,"pct":0.99997,"cvss":[]},{"id":"CVE-2020-3952","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Information Disclosure Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.90384,"pct":0.99798,"cvss":[]},{"id":"CVE-2021-21972","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Remote Code Execution Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99865,"pct":0.99962,"cvss":[]},{"id":"CVE-2021-21985","kev":true,"vendor":"VMware","product":"vCenter Server","name":"VMware vCenter Server Improper Input Validation Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.99999,"pct":0.99993,"cvss":[]},{"id":"CVE-2020-4006","kev":true,"vendor":"VMware","product":"Multiple Products","name":"Multiple VMware Products Command Injection Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.17302,"pct":0.97029,"cvss":[]},{"id":"CVE-2020-25213","kev":true,"vendor":"WordPress","product":"File Manager Plugin","name":"WordPress File Manager Plugin Remote Code Execution Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.97328,"pct":0.99897,"cvss":[]},{"id":"CVE-2020-11738","kev":true,"vendor":"WordPress","product":"Snap Creek Duplicator Plugin","name":"WordPress Snap Creek Duplicator Plugin File Download Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.97822,"pct":0.99906,"cvss":[]},{"id":"CVE-2019-9978","kev":true,"vendor":"WordPress","product":"Social Warfare Plugin","name":"WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.72946,"pct":0.9944,"cvss":[]},{"id":"CVE-2021-27561","kev":true,"vendor":"Yealink","product":"Device Management","name":"Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":false,"epss":0.82865,"pct":0.99664,"cvss":[]},{"id":"CVE-2021-40539","kev":true,"vendor":"Zoho","product":"ManageEngine","name":"Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability","added":"2021-11-03","due":"2021-11-17","ransomware":true,"epss":0.9896,"pct":0.99929,"cvss":[]},{"id":"CVE-2020-10189","kev":true,"vendor":"Zoho","product":"ManageEngine","name":"Zoho ManageEngine Desktop Central File Upload Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.99941,"pct":0.99972,"cvss":[]},{"id":"CVE-2019-8394","kev":true,"vendor":"Zoho","product":"ManageEngine","name":"Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.63336,"pct":0.99187,"cvss":[]},{"id":"CVE-2020-29583","kev":true,"vendor":"Zyxel","product":"Multiple Products","name":"Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability","added":"2021-11-03","due":"2022-05-03","ransomware":false,"epss":0.90155,"pct":0.99795,"cvss":[]},{"id":"CVE-2026-105134","kev":false,"vendor":null,"product":null,"name":null,"desc":"A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack rem…","epss":0.01843,"pct":0.78284,"cvss":[{"source":"cna@vuldb.com","type":"Primary","version":"3.1","score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","score":9.3,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-04T07:16:33.480Z","modified":"2026-10-04T07:16:33.480Z","cwes":["CWE-77","CWE-78"],"assigner":"cna@vuldb.com"},{"id":"CVE-2026-105135","kev":false,"vendor":null,"product":null,"name":null,"desc":"A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit h…","epss":0.0077,"pct":0.54074,"cvss":[{"source":"cna@vuldb.com","type":"Primary","version":"3.1","score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","score":9.3,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-04T07:16:33.693Z","modified":"2026-10-04T07:16:33.693Z","cwes":["CWE-74","CWE-94"],"assigner":"cna@vuldb.com"},{"id":"CVE-2026-105207","kev":false,"vendor":null,"product":null,"name":null,"desc":"ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated at…","epss":0.0031,"pct":0.21722,"cvss":[{"source":"disclosure@vulncheck.com","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","score":9.3,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-04T15:16:31.677Z","modified":"2026-10-04T15:16:31.793Z","cwes":["CWE-306"],"assigner":"disclosure@vulncheck.com"},{"id":"CVE-2026-105209","kev":false,"vendor":null,"product":null,"name":null,"desc":"ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one org…","epss":0.0022,"pct":0.11449,"cvss":[{"source":"disclosure@vulncheck.com","type":"Primary","version":"3.1","score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","score":9.3,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-04T15:16:32.007Z","modified":"2026-10-04T15:16:32.127Z","cwes":["CWE-862"],"assigner":"disclosure@vulncheck.com"},{"id":"CVE-2026-105215","kev":false,"vendor":null,"product":null,"name":null,"desc":"ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPCon…","epss":0.00339,"pct":0.25095,"cvss":[{"source":"disclosure@vulncheck.com","type":"Primary","version":"3.1","score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},{"source":"disclosure@vulncheck.com","type":"Secondary","version":"4.0","score":9.3,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-04T15:16:32.993Z","modified":"2026-10-04T15:16:33.107Z","cwes":["CWE-290"],"assigner":"disclosure@vulncheck.com"},{"id":"CVE-2026-105484","kev":false,"vendor":null,"product":null,"name":null,"desc":"A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attac…","epss":null,"pct":null,"cvss":[{"source":"cna@vuldb.com","type":"Primary","version":"3.1","score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","score":10,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-06T02:17:04.040Z","modified":"2026-10-06T02:17:04.040Z","cwes":["CWE-77","CWE-78"],"assigner":"cna@vuldb.com"},{"id":"CVE-2026-105778","kev":false,"vendor":null,"product":null,"name":null,"desc":"A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotel…","epss":null,"pct":null,"cvss":[{"source":"cna@vuldb.com","type":"Primary","version":"3.1","score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"source":"cna@vuldb.com","type":"Secondary","version":"4.0","score":8.6,"severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-06T07:16:56.547Z","modified":"2026-10-06T07:16:56.547Z","cwes":["CWE-119","CWE-121"],"assigner":"cna@vuldb.com"},{"id":"CVE-2026-86345","kev":false,"vendor":null,"product":null,"name":null,"desc":"A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in pl…","epss":null,"pct":null,"cvss":[{"source":"secalert@redhat.com","type":"Primary","version":"3.1","score":9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}],"published":"2026-10-02T00:17:04.180Z","modified":"2026-10-02T18:44:11.270Z","cwes":["CWE-923"],"assigner":"secalert@redhat.com"},{"id":"CVE-2026-94293","kev":false,"vendor":null,"product":null,"name":null,"desc":"An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.","epss":null,"pct":null,"cvss":[{"source":"info@cert.vde.com","type":"Primary","version":"3.1","score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"source":"info@cert.vde.com","type":"Secondary","version":"4.0","score":9.3,"severity":"CRITICAL","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}],"published":"2026-10-06T07:17:00.193Z","modified":"2026-10-06T07:17:00.193Z","cwes":["CWE-306"],"assigner":"info@cert.vde.com"}]}