{
  "schemaVersion": "1.0",
  "datasetVersion": "2026-08-22.1",
  "retrievedAt": "2026-08-22T19:49:53Z",
  "pagination": {
    "page": 1,
    "pageSize": 50,
    "total": 50,
    "next": null
  },
  "items": [
    {
      "id": "cve:CVE-2026-35273",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-35273/",
      "webUrl": "https://vulns.co/cves/CVE-2026-35273/",
      "record": {
        "id": "CVE-2026-35273",
        "title": "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
        "cvePublishedAt": "2026-06-11",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-06-12",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "oracle",
        "epssProbability": 0.95473,
        "epssPercentile": 0.99864,
        "lastFetchedAt": "2026-08-22T13:17:07.477Z",
        "product": "Oracle  PeopleSoft Enterprise PeopleTools",
        "signal": "",
        "summary": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-35273.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-35273",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-35273",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273"
        ],
        "severity": "critical",
        "epss": 0.95473,
        "published": "2026-06-11",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2024-27199",
      "url": "https://vulns.co/api/v1/cves/CVE-2024-27199/",
      "webUrl": "https://vulns.co/cves/CVE-2024-27199/",
      "record": {
        "id": "CVE-2024-27199",
        "title": "JetBrains TeamCity Relative Path Traversal Vulnerability",
        "cvePublishedAt": "2024-03-04",
        "cveModifiedAt": "2026-04-21",
        "kevAddedAt": "2026-04-20",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 7.3,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
        "severitySource": "JetBrains",
        "epssProbability": 0.99991,
        "epssPercentile": 0.99985,
        "lastFetchedAt": "2026-08-22T13:17:07.680Z",
        "product": "JetBrains TeamCity",
        "signal": "",
        "summary": "JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.",
        "poc": null,
        "nuclei": "http/cves/2024/CVE-2024-27199.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2024-27199",
          "https://nvd.nist.gov/vuln/detail/CVE-2024-27199",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27199"
        ],
        "severity": "high",
        "epss": 0.99991,
        "published": "2024-03-04",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "file-boundary",
          "classLabel": "File boundary",
          "surface": "devops",
          "surfaceLabel": "Build and delivery",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Compare canonical and alternate path representations against one controlled file. Separate read, write, extraction, and execution primitives, and do not cross into sensitive host files."
        }
      }
    },
    {
      "id": "cve:CVE-2026-41940",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-41940/",
      "webUrl": "https://vulns.co/cves/CVE-2026-41940/",
      "record": {
        "id": "CVE-2026-41940",
        "title": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability",
        "cvePublishedAt": "2026-04-29",
        "cveModifiedAt": "2026-08-11",
        "kevAddedAt": "2026-04-30",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
        "severitySource": "VulnCheck",
        "epssProbability": 0.9811,
        "epssPercentile": 0.99909,
        "lastFetchedAt": "2026-08-22T13:17:07.863Z",
        "product": "WebPros cPanel & WHM and WP2 (WordPress Squared)",
        "signal": "",
        "summary": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-41940.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-41940",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-41940",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940"
        ],
        "severity": "critical",
        "epss": 0.9811,
        "published": "2026-04-29",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "cms-hosting",
          "surfaceLabel": "CMS and hosting",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2026-0257",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-0257/",
      "webUrl": "https://vulns.co/cves/CVE-2026-0257/",
      "record": {
        "id": "CVE-2026-0257",
        "title": "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
        "cvePublishedAt": "2026-05-13",
        "cveModifiedAt": "2026-07-14",
        "kevAddedAt": "2026-05-29",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 7.8,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:A/AU:N/R:A/V:D/RE:M/U:Red",
        "severitySource": "palo_alto",
        "epssProbability": 0.93905,
        "epssPercentile": 0.99838,
        "lastFetchedAt": "2026-08-22T13:17:08.027Z",
        "product": "Palo Alto Networks PAN-OS",
        "signal": "",
        "summary": "Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-0257",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-0257",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257"
        ],
        "severity": "high",
        "epss": 0.93905,
        "published": "2026-05-13",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "network-edge",
          "surfaceLabel": "Network edge",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2026-23760",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-23760/",
      "webUrl": "https://vulns.co/cves/CVE-2026-23760/",
      "record": {
        "id": "CVE-2026-23760",
        "title": "SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability",
        "cvePublishedAt": "2026-01-22",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-01-26",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
        "severitySource": "VulnCheck",
        "epssProbability": 0.96268,
        "epssPercentile": 0.99876,
        "lastFetchedAt": "2026-08-22T13:17:08.222Z",
        "product": "SmarterTools SmarterMail",
        "signal": "",
        "summary": "SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-23760.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-23760",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-23760",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-23760"
        ],
        "severity": "critical",
        "epss": 0.96268,
        "published": "2026-01-22",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2024-1708",
      "url": "https://vulns.co/api/v1/cves/CVE-2024-1708/",
      "webUrl": "https://vulns.co/cves/CVE-2024-1708/",
      "record": {
        "id": "CVE-2024-1708",
        "title": "ConnectWise ScreenConnect Path Traversal Vulnerability",
        "cvePublishedAt": "2024-02-21",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-04-28",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 8.4,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
        "severitySource": "cisa-cg",
        "epssProbability": 0.87558,
        "epssPercentile": 0.99746,
        "lastFetchedAt": "2026-08-22T13:17:08.391Z",
        "product": "ConnectWise ScreenConnect",
        "signal": "",
        "summary": "ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2024-1708",
          "https://nvd.nist.gov/vuln/detail/CVE-2024-1708",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-1708"
        ],
        "severity": "high",
        "epss": 0.87558,
        "published": "2024-02-21",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "file-boundary",
          "classLabel": "File boundary",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Compare canonical and alternate path representations against one controlled file. Separate read, write, extraction, and execution primitives, and do not cross into sensitive host files."
        }
      }
    },
    {
      "id": "cve:CVE-2025-55182",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-55182/",
      "webUrl": "https://vulns.co/cves/CVE-2025-55182/",
      "record": {
        "id": "CVE-2025-55182",
        "title": "Meta React Server Components Remote Code Execution Vulnerability",
        "cvePublishedAt": "2025-12-03",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-12-05",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "Meta",
        "epssProbability": 0.99616,
        "epssPercentile": 0.99947,
        "lastFetchedAt": "2026-08-22T13:17:08.573Z",
        "product": "Meta React Server Components",
        "signal": "",
        "summary": "Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-55182.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-55182",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-55182",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"
        ],
        "severity": "critical",
        "epss": 0.99616,
        "published": "2025-12-03",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-50751",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-50751/",
      "webUrl": "https://vulns.co/cves/CVE-2026-50751/",
      "record": {
        "id": "CVE-2026-50751",
        "title": "Check Point Security Gateway Improper Authentication Vulnerability",
        "cvePublishedAt": "2026-06-08",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-06-08",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.82554,
        "epssPercentile": 0.9964,
        "lastFetchedAt": "2026-08-22T13:17:08.746Z",
        "product": "Check Point Security Gateway",
        "signal": "",
        "summary": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-50751.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-50751",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-50751",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751"
        ],
        "severity": "critical",
        "epss": 0.82554,
        "published": "2026-06-08",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "network-edge",
          "surfaceLabel": "Network edge",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2025-26399",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-26399/",
      "webUrl": "https://vulns.co/cves/CVE-2025-26399/",
      "record": {
        "id": "CVE-2025-26399",
        "title": "SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
        "cvePublishedAt": "2025-09-23",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-03-09",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "SolarWinds",
        "epssProbability": 0.8833,
        "epssPercentile": 0.99759,
        "lastFetchedAt": "2026-08-22T13:17:08.936Z",
        "product": "SolarWinds Web Help Desk",
        "signal": "",
        "summary": "SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-26399.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-26399",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-26399",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26399"
        ],
        "severity": "critical",
        "epss": 0.8833,
        "published": "2025-09-23",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "injection",
          "classLabel": "Interpreter injection",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Locate each parser boundary before choosing a probe. Vary one delimiter or encoding at a time, use non-destructive canaries, and distinguish interpreter behavior from generic errors."
        }
      }
    },
    {
      "id": "cve:CVE-2026-8037",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-8037/",
      "webUrl": "https://vulns.co/cves/CVE-2026-8037/",
      "record": {
        "id": "CVE-2026-8037",
        "title": "Progress LoadMaster Command Injection Vulnerability",
        "cvePublishedAt": "2026-06-04",
        "cveModifiedAt": "2026-08-08",
        "kevAddedAt": "2026-08-07",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.6,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "ProgressSoftware",
        "epssProbability": 0.99311,
        "epssPercentile": 0.99937,
        "lastFetchedAt": "2026-08-22T13:17:09.136Z",
        "product": "Progress LoadMaster",
        "signal": "trending",
        "summary": "Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-8037.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-8037",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-8037",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037"
        ],
        "severity": "critical",
        "epss": 0.99311,
        "published": "2026-06-04",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-15410",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-15410/",
      "webUrl": "https://vulns.co/cves/CVE-2026-15410/",
      "record": {
        "id": "CVE-2026-15410",
        "title": "SonicWall SMA1000 Appliances Code Injection Vulnerability",
        "cvePublishedAt": "2026-07-14",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-07-14",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 7.2,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.76347,
        "epssPercentile": 0.99498,
        "lastFetchedAt": "2026-08-22T13:17:09.295Z",
        "product": "SonicWall SMA1000 Appliances",
        "signal": "",
        "summary": "SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-15410",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-15410",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410"
        ],
        "severity": "high",
        "epss": 0.76347,
        "published": "2026-07-14",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-61882",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-61882/",
      "webUrl": "https://vulns.co/cves/CVE-2025-61882/",
      "record": {
        "id": "CVE-2025-61882",
        "title": "Oracle E-Business Suite Unspecified Vulnerability",
        "cvePublishedAt": "2025-10-05",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-10-06",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "oracle",
        "epssProbability": 0.99722,
        "epssPercentile": 0.99952,
        "lastFetchedAt": "2026-08-22T13:17:09.485Z",
        "product": "Oracle E-Business Suite",
        "signal": "",
        "summary": "Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-61882.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-61882",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-61882",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61882"
        ],
        "severity": "critical",
        "epss": 0.99722,
        "published": "2025-10-05",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "other",
          "classLabel": "Needs manual classification",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Start with the affected product, reachable component, preconditions, trust boundary, and cheapest non-destructive discriminator. Do not infer exploitability from the CVE label alone."
        }
      }
    },
    {
      "id": "cve:CVE-2026-1731",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-1731/",
      "webUrl": "https://vulns.co/cves/CVE-2026-1731/",
      "record": {
        "id": "CVE-2026-1731",
        "title": "BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability",
        "cvePublishedAt": "2026-02-06",
        "cveModifiedAt": "2026-02-26",
        "kevAddedAt": "2026-02-13",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 9.9,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L",
        "severitySource": "BT",
        "epssProbability": 0.88586,
        "epssPercentile": 0.99763,
        "lastFetchedAt": "2026-08-22T13:17:09.637Z",
        "product": "BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)",
        "signal": "",
        "summary": "BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-1731",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-1731",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1731"
        ],
        "severity": "critical",
        "epss": 0.88586,
        "published": "2026-02-06",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-61884",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-61884/",
      "webUrl": "https://vulns.co/cves/CVE-2025-61884/",
      "record": {
        "id": "CVE-2025-61884",
        "title": "Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
        "cvePublishedAt": "2025-10-12",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-10-20",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 7.5,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
        "severitySource": "oracle",
        "epssProbability": 0.97788,
        "epssPercentile": 0.99901,
        "lastFetchedAt": "2026-08-22T13:17:09.825Z",
        "product": "Oracle E-Business Suite",
        "signal": "",
        "summary": "Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-61884.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-61884",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-61884",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-61884"
        ],
        "severity": "high",
        "epss": 0.97788,
        "published": "2025-10-12",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2025-10035",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-10035/",
      "webUrl": "https://vulns.co/cves/CVE-2025-10035/",
      "record": {
        "id": "CVE-2025-10035",
        "title": "Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
        "cvePublishedAt": "2025-09-18",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-09-29",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "Fortra",
        "epssProbability": 0.9958,
        "epssPercentile": 0.99945,
        "lastFetchedAt": "2026-08-22T13:17:10.013Z",
        "product": "Fortra GoAnywhere MFT",
        "signal": "",
        "summary": "Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-10035.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-10035",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-10035",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-10035"
        ],
        "severity": "critical",
        "epss": 0.9958,
        "published": "2025-09-18",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-15409",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-15409/",
      "webUrl": "https://vulns.co/cves/CVE-2026-15409/",
      "record": {
        "id": "CVE-2026-15409",
        "title": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
        "cvePublishedAt": "2026-07-14",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-07-14",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.74218,
        "epssPercentile": 0.99447,
        "lastFetchedAt": "2026-08-22T13:17:10.172Z",
        "product": "SonicWall SMA1000 Appliances",
        "signal": "",
        "summary": "SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-15409",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-15409",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409"
        ],
        "severity": "critical",
        "epss": 0.74218,
        "published": "2026-07-14",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "request-boundary",
          "classLabel": "Request boundary",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Map URL parsing, redirect, DNS, proxy, and destination controls as separate gates. Use an owned callback endpoint and a negative destination control when the program permits server-side fetch testing."
        }
      }
    },
    {
      "id": "cve:CVE-2026-24423",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-24423/",
      "webUrl": "https://vulns.co/cves/CVE-2026-24423/",
      "record": {
        "id": "CVE-2026-24423",
        "title": "SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability",
        "cvePublishedAt": "2026-01-23",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2026-02-05",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
        "severitySource": "VulnCheck",
        "epssProbability": 0.87693,
        "epssPercentile": 0.99748,
        "lastFetchedAt": "2026-08-22T13:17:10.361Z",
        "product": "SmarterTools SmarterMail",
        "signal": "",
        "summary": "SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. ",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-24423.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-24423",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-24423",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24423"
        ],
        "severity": "critical",
        "epss": 0.87693,
        "published": "2026-01-23",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-48282",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-48282/",
      "webUrl": "https://vulns.co/cves/CVE-2026-48282/",
      "record": {
        "id": "CVE-2026-48282",
        "title": "Adobe ColdFusion Path Traversal Vulnerability",
        "cvePublishedAt": "2026-06-30",
        "cveModifiedAt": "2026-07-08",
        "kevAddedAt": "2026-07-07",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "adobe",
        "epssProbability": 0.99241,
        "epssPercentile": 0.99933,
        "lastFetchedAt": "2026-08-22T13:17:10.531Z",
        "product": "Adobe ColdFusion",
        "signal": "",
        "summary": "Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-48282.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-48282",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-48282",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282"
        ],
        "severity": "critical",
        "epss": 0.99241,
        "published": "2026-06-30",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-10520",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-10520/",
      "webUrl": "https://vulns.co/cves/CVE-2026-10520/",
      "record": {
        "id": "CVE-2026-10520",
        "title": "Ivanti Sentry OS Command Injection Vulnerability",
        "cvePublishedAt": "2026-06-09",
        "cveModifiedAt": "2026-06-12",
        "kevAddedAt": "2026-06-11",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "ivanti",
        "epssProbability": 0.99902,
        "epssPercentile": 0.99966,
        "lastFetchedAt": "2026-08-22T13:17:10.720Z",
        "product": "Ivanti Sentry",
        "signal": "",
        "summary": "Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-10520.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-10520",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-10520",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520"
        ],
        "severity": "critical",
        "epss": 0.99902,
        "published": "2026-06-09",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-63030",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-63030/",
      "webUrl": "https://vulns.co/cves/CVE-2026-63030/",
      "record": {
        "id": "CVE-2026-63030",
        "title": "WordPress Core Interpretation Conflict Vulnerability",
        "cvePublishedAt": "2026-07-17",
        "cveModifiedAt": "2026-07-22",
        "kevAddedAt": "2026-07-21",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "WPScan",
        "epssProbability": 0.95605,
        "epssPercentile": 0.99865,
        "lastFetchedAt": "2026-08-22T13:17:10.897Z",
        "product": "WordPress Core",
        "signal": "",
        "summary": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-63030.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-63030",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-63030",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63030"
        ],
        "severity": "critical",
        "epss": 0.95605,
        "published": "2026-07-17",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "cms-hosting",
          "surfaceLabel": "CMS and hosting",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-52691",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-52691/",
      "webUrl": "https://vulns.co/cves/CVE-2025-52691/",
      "record": {
        "id": "CVE-2025-52691",
        "title": "SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability",
        "cvePublishedAt": "2025-12-29",
        "cveModifiedAt": "2026-02-26",
        "kevAddedAt": "2026-01-26",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "CSA",
        "epssProbability": 0.85457,
        "epssPercentile": 0.99704,
        "lastFetchedAt": "2026-08-22T13:17:11.067Z",
        "product": "SmarterTools SmarterMail",
        "signal": "",
        "summary": "SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-52691.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-52691",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-52691",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691"
        ],
        "severity": "critical",
        "epss": 0.85457,
        "published": "2025-12-29",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2023-27351",
      "url": "https://vulns.co/api/v1/cves/CVE-2023-27351/",
      "webUrl": "https://vulns.co/cves/CVE-2023-27351/",
      "record": {
        "id": "CVE-2023-27351",
        "title": "PaperCut NG/MF Improper Authentication Vulnerability",
        "cvePublishedAt": "2023-04-20",
        "cveModifiedAt": "2026-04-21",
        "kevAddedAt": "2026-04-20",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.0",
        "cvssScore": 8.2,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
        "severitySource": "zdi",
        "epssProbability": 0.77388,
        "epssPercentile": 0.99521,
        "lastFetchedAt": "2026-08-22T13:17:11.238Z",
        "product": "PaperCut NG/MF",
        "signal": "",
        "summary": "PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.",
        "poc": null,
        "nuclei": "http/cves/2023/CVE-2023-27351.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2023-27351",
          "https://nvd.nist.gov/vuln/detail/CVE-2023-27351",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27351"
        ],
        "severity": "high",
        "epss": 0.77388,
        "published": "2023-04-20",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2026-20253",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-20253/",
      "webUrl": "https://vulns.co/cves/CVE-2026-20253/",
      "record": {
        "id": "CVE-2026-20253",
        "title": "Splunk Enterprise Missing Authentication for Critical Function Vulnerability",
        "cvePublishedAt": "2026-06-10",
        "cveModifiedAt": "2026-06-19",
        "kevAddedAt": "2026-06-18",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "cisco",
        "epssProbability": 0.96939,
        "epssPercentile": 0.99887,
        "lastFetchedAt": "2026-08-22T13:17:11.425Z",
        "product": "Splunk Enterprise",
        "signal": "",
        "summary": "Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-20253.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-20253",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-20253",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20253"
        ],
        "severity": "critical",
        "epss": 0.96939,
        "published": "2026-06-10",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2025-49704",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-49704/",
      "webUrl": "https://vulns.co/cves/CVE-2025-49704/",
      "record": {
        "id": "CVE-2025-49704",
        "title": "Microsoft SharePoint Code Injection Vulnerability",
        "cvePublishedAt": "2025-07-08",
        "cveModifiedAt": "2026-02-13",
        "kevAddedAt": "2025-07-22",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 8.8,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
        "severitySource": "microsoft",
        "epssProbability": 0.99983,
        "epssPercentile": 0.99982,
        "lastFetchedAt": "2026-08-22T13:17:11.599Z",
        "product": "Microsoft SharePoint",
        "signal": "",
        "summary": "Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-49704",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-49704",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49704"
        ],
        "severity": "high",
        "epss": 0.99983,
        "published": "2025-07-08",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-49706",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-49706/",
      "webUrl": "https://vulns.co/cves/CVE-2025-49706/",
      "record": {
        "id": "CVE-2025-49706",
        "title": "Microsoft SharePoint Improper Authentication Vulnerability",
        "cvePublishedAt": "2025-07-08",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-07-22",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 6.5,
        "cvssSeverity": "medium",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C",
        "severitySource": "microsoft",
        "epssProbability": 0.99865,
        "epssPercentile": 0.99963,
        "lastFetchedAt": "2026-08-22T13:17:11.801Z",
        "product": "Microsoft SharePoint",
        "signal": "",
        "summary": "Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-49706.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-49706",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-49706",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49706"
        ],
        "severity": "medium",
        "epss": 0.99865,
        "published": "2025-07-08",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2025-53770",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-53770/",
      "webUrl": "https://vulns.co/cves/CVE-2025-53770/",
      "record": {
        "id": "CVE-2025-53770",
        "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
        "cvePublishedAt": "2025-07-20",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-07-20",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:W/RC:C",
        "severitySource": "microsoft",
        "epssProbability": 0.99982,
        "epssPercentile": 0.99982,
        "lastFetchedAt": "2026-08-22T13:17:11.996Z",
        "product": "Microsoft SharePoint",
        "signal": "",
        "summary": "Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-53770.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-53770",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-53770",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-53770"
        ],
        "severity": "critical",
        "epss": 0.99982,
        "published": "2025-07-20",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "injection",
          "classLabel": "Interpreter injection",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Locate each parser boundary before choosing a probe. Vary one delimiter or encoding at a time, use non-destructive canaries, and distinguish interpreter behavior from generic errors."
        }
      }
    },
    {
      "id": "cve:CVE-2008-4250",
      "url": "https://vulns.co/api/v1/cves/CVE-2008-4250/",
      "webUrl": "https://vulns.co/cves/CVE-2008-4250/",
      "record": {
        "id": "CVE-2008-4250",
        "title": "Microsoft Windows Buffer Overflow Vulnerability",
        "cvePublishedAt": "2008-10-23",
        "cveModifiedAt": "2026-05-21",
        "kevAddedAt": "2026-05-20",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.98751,
        "epssPercentile": 0.99923,
        "lastFetchedAt": "2026-08-22T13:17:12.165Z",
        "product": "Microsoft Windows",
        "signal": "",
        "summary": "Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2008-4250",
          "https://nvd.nist.gov/vuln/detail/CVE-2008-4250",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2008-4250"
        ],
        "severity": "critical",
        "epss": 0.98751,
        "published": "2008-10-23",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "memory-safety",
          "classLabel": "Memory safety",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Confirm product, build, reachable protocol, and affected component first. Prefer version and code-path evidence; do not reproduce crashes or corrupt production state."
        }
      }
    },
    {
      "id": "cve:CVE-2026-31431",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-31431/",
      "webUrl": "https://vulns.co/cves/CVE-2026-31431/",
      "record": {
        "id": "CVE-2026-31431",
        "title": "Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability",
        "cvePublishedAt": "2026-04-22",
        "cveModifiedAt": "2026-08-21",
        "kevAddedAt": "2026-05-01",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 7.8,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "Linux",
        "epssProbability": 0.99907,
        "epssPercentile": 0.99967,
        "lastFetchedAt": "2026-08-22T13:17:12.335Z",
        "product": "Linux Kernel",
        "signal": "",
        "summary": "Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-31431",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-31431",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431"
        ],
        "severity": "high",
        "epss": 0.99907,
        "published": "2026-04-22",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2025-5777",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-5777/",
      "webUrl": "https://vulns.co/cves/CVE-2025-5777/",
      "record": {
        "id": "CVE-2025-5777",
        "title": "Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability",
        "cvePublishedAt": "2025-06-17",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-07-10",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
        "severitySource": "Citrix",
        "epssProbability": 0.99962,
        "epssPercentile": 0.99976,
        "lastFetchedAt": "2026-08-22T13:17:12.534Z",
        "product": "Citrix NetScaler ADC and Gateway",
        "signal": "",
        "summary": "Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-5777.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-5777",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-5777",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5777"
        ],
        "severity": "critical",
        "epss": 0.99962,
        "published": "2025-06-17",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "memory-safety",
          "classLabel": "Memory safety",
          "surface": "network-edge",
          "surfaceLabel": "Network edge",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Confirm product, build, reachable protocol, and affected component first. Prefer version and code-path evidence; do not reproduce crashes or corrupt production state."
        }
      }
    },
    {
      "id": "cve:CVE-2026-39808",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-39808/",
      "webUrl": "https://vulns.co/cves/CVE-2026-39808/",
      "record": {
        "id": "CVE-2026-39808",
        "title": "Fortinet FortiSandbox OS Command Injection Vulnerability",
        "cvePublishedAt": "2026-04-14",
        "cveModifiedAt": "2026-07-17",
        "kevAddedAt": "2026-07-16",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.1,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
        "severitySource": "fortinet",
        "epssProbability": 0.9121,
        "epssPercentile": 0.99801,
        "lastFetchedAt": "2026-08-22T13:17:12.712Z",
        "product": "Fortinet FortiSandbox",
        "signal": "",
        "summary": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-39808.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-39808",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-39808",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808"
        ],
        "severity": "critical",
        "epss": 0.9121,
        "published": "2026-04-14",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "network-edge",
          "surfaceLabel": "Network edge",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-8088",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-8088/",
      "webUrl": "https://vulns.co/cves/CVE-2025-8088/",
      "record": {
        "id": "CVE-2025-8088",
        "title": "RARLAB WinRAR Path Traversal Vulnerability",
        "cvePublishedAt": "2025-08-08",
        "cveModifiedAt": "2026-08-11",
        "kevAddedAt": "2025-08-12",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "4.0",
        "cvssScore": 8.4,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
        "severitySource": "ESET",
        "epssProbability": 0.94551,
        "epssPercentile": 0.99848,
        "lastFetchedAt": "2026-08-22T13:17:12.883Z",
        "product": "RARLAB WinRAR",
        "signal": "",
        "summary": "RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-8088",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-8088",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088"
        ],
        "severity": "high",
        "epss": 0.94551,
        "published": "2025-08-08",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-32432",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-32432/",
      "webUrl": "https://vulns.co/cves/CVE-2025-32432/",
      "record": {
        "id": "CVE-2025-32432",
        "title": "Craft CMS Code Injection Vulnerability",
        "cvePublishedAt": "2025-04-25",
        "cveModifiedAt": "2026-03-21",
        "kevAddedAt": "2026-03-20",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L",
        "severitySource": "GitHub_M",
        "epssProbability": 0.99837,
        "epssPercentile": 0.99961,
        "lastFetchedAt": "2026-08-22T13:17:13.071Z",
        "product": "Craft CMS Craft CMS",
        "signal": "",
        "summary": "Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-32432.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-32432",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-32432",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32432"
        ],
        "severity": "critical",
        "epss": 0.99837,
        "published": "2025-04-25",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-34197",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-34197/",
      "webUrl": "https://vulns.co/cves/CVE-2026-34197/",
      "record": {
        "id": "CVE-2026-34197",
        "title": "Apache ActiveMQ Improper Input Validation Vulnerability",
        "cvePublishedAt": "2026-04-07",
        "cveModifiedAt": "2026-08-17",
        "kevAddedAt": "2026-04-16",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 8.8,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.9722,
        "epssPercentile": 0.9989,
        "lastFetchedAt": "2026-08-22T13:17:13.265Z",
        "product": "Apache ActiveMQ",
        "signal": "",
        "summary": "Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-34197.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-34197",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-34197",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34197"
        ],
        "severity": "high",
        "epss": 0.9722,
        "published": "2026-04-07",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "server-framework",
          "surfaceLabel": "Server and framework",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-39987",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-39987/",
      "webUrl": "https://vulns.co/cves/CVE-2026-39987/",
      "record": {
        "id": "CVE-2026-39987",
        "title": "Marimo Remote Code Execution Vulnerability",
        "cvePublishedAt": "2026-04-09",
        "cveModifiedAt": "2026-04-24",
        "kevAddedAt": "2026-04-23",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "4.0",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
        "severitySource": "GitHub_M",
        "epssProbability": 0.96576,
        "epssPercentile": 0.9988,
        "lastFetchedAt": "2026-08-22T13:17:13.449Z",
        "product": "Marimo Marimo",
        "signal": "",
        "summary": "Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-39987",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-39987",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39987"
        ],
        "severity": "critical",
        "epss": 0.96576,
        "published": "2026-04-09",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2017-7921",
      "url": "https://vulns.co/api/v1/cves/CVE-2017-7921/",
      "webUrl": "https://vulns.co/cves/CVE-2017-7921/",
      "record": {
        "id": "CVE-2017-7921",
        "title": "Hikvision Multiple Products Improper Authentication Vulnerability",
        "cvePublishedAt": "2017-05-06",
        "cveModifiedAt": "2026-03-06",
        "kevAddedAt": "2026-03-05",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.99998,
        "epssPercentile": 0.9999,
        "lastFetchedAt": "2026-08-22T13:17:13.635Z",
        "product": "Hikvision Multiple Products",
        "signal": "",
        "summary": "Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.",
        "poc": null,
        "nuclei": "http/cves/2017/CVE-2017-7921.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2017-7921",
          "https://nvd.nist.gov/vuln/detail/CVE-2017-7921",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-7921"
        ],
        "severity": "critical",
        "epss": 0.99998,
        "published": "2017-05-06",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2025-3248",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-3248/",
      "webUrl": "https://vulns.co/cves/CVE-2025-3248/",
      "record": {
        "id": "CVE-2025-3248",
        "title": "Langflow Missing Authentication Vulnerability",
        "cvePublishedAt": "2025-04-07",
        "cveModifiedAt": "2026-07-14",
        "kevAddedAt": "2025-05-05",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "VulnCheck",
        "epssProbability": 0.99996,
        "epssPercentile": 0.99988,
        "lastFetchedAt": "2026-08-22T13:17:13.831Z",
        "product": "Langflow Langflow",
        "signal": "",
        "summary": "Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-3248.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-3248",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-3248",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248"
        ],
        "severity": "critical",
        "epss": 0.99996,
        "published": "2025-04-07",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2026-48908",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-48908/",
      "webUrl": "https://vulns.co/cves/CVE-2026-48908/",
      "record": {
        "id": "CVE-2026-48908",
        "title": "JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability",
        "cvePublishedAt": "2026-06-20",
        "cveModifiedAt": "2026-08-12",
        "kevAddedAt": "2026-07-07",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "4.0",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red",
        "severitySource": "Joomla",
        "epssProbability": 0.8813,
        "epssPercentile": 0.99755,
        "lastFetchedAt": "2026-08-22T13:17:14.006Z",
        "product": "JoomShaper SP Page Builder",
        "signal": "",
        "summary": "JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-48908",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-48908",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48908"
        ],
        "severity": "critical",
        "epss": 0.8813,
        "published": "2026-06-20",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "other",
          "classLabel": "Needs manual classification",
          "surface": "server-framework",
          "surfaceLabel": "Server and framework",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Start with the affected product, reachable component, preconditions, trust boundary, and cheapest non-destructive discriminator. Do not infer exploitability from the CVE label alone."
        }
      }
    },
    {
      "id": "cve:CVE-2025-68613",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-68613/",
      "webUrl": "https://vulns.co/cves/CVE-2025-68613/",
      "record": {
        "id": "CVE-2025-68613",
        "title": "n8n Improper Control of Dynamically-Managed Code Resources Vulnerability",
        "cvePublishedAt": "2025-12-19",
        "cveModifiedAt": "2026-03-12",
        "kevAddedAt": "2026-03-11",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "GitHub_M",
        "epssProbability": 0.9795,
        "epssPercentile": 0.99906,
        "lastFetchedAt": "2026-08-22T13:17:14.194Z",
        "product": "n8n n8n",
        "signal": "",
        "summary": "n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-68613.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-68613",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-68613",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68613"
        ],
        "severity": "critical",
        "epss": 0.9795,
        "published": "2025-12-19",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2010-0249",
      "url": "https://vulns.co/api/v1/cves/CVE-2010-0249/",
      "webUrl": "https://vulns.co/cves/CVE-2010-0249/",
      "record": {
        "id": "CVE-2010-0249",
        "title": "Microsoft Internet Explorer Use-After-Free Vulnerability",
        "cvePublishedAt": "2010-01-15",
        "cveModifiedAt": "2026-05-21",
        "kevAddedAt": "2026-05-20",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 8.8,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.91885,
        "epssPercentile": 0.9981,
        "lastFetchedAt": "2026-08-22T13:17:14.360Z",
        "product": "Microsoft Internet Explorer",
        "signal": "",
        "summary": "Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2010-0249",
          "https://nvd.nist.gov/vuln/detail/CVE-2010-0249",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0249"
        ],
        "severity": "high",
        "epss": 0.91885,
        "published": "2010-01-15",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "memory-safety",
          "classLabel": "Memory safety",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Confirm product, build, reachable protocol, and affected component first. Prefer version and code-path evidence; do not reproduce crashes or corrupt production state."
        }
      }
    },
    {
      "id": "cve:CVE-2025-31324",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-31324/",
      "webUrl": "https://vulns.co/cves/CVE-2025-31324/",
      "record": {
        "id": "CVE-2025-31324",
        "title": "SAP NetWeaver Unrestricted File Upload Vulnerability",
        "cvePublishedAt": "2025-04-24",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-04-29",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "sap",
        "epssProbability": 0.99512,
        "epssPercentile": 0.99942,
        "lastFetchedAt": "2026-08-22T13:17:14.574Z",
        "product": "SAP NetWeaver",
        "signal": "",
        "summary": "SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-31324.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-31324",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-31324",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324"
        ],
        "severity": "critical",
        "epss": 0.99512,
        "published": "2025-04-24",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "file-boundary",
          "classLabel": "File boundary",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Compare canonical and alternate path representations against one controlled file. Separate read, write, extraction, and execution primitives, and do not cross into sensitive host files."
        }
      }
    },
    {
      "id": "cve:CVE-2026-33017",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-33017/",
      "webUrl": "https://vulns.co/cves/CVE-2026-33017/",
      "record": {
        "id": "CVE-2026-33017",
        "title": "Langflow Code Injection Vulnerability",
        "cvePublishedAt": "2026-03-20",
        "cveModifiedAt": "2026-05-21",
        "kevAddedAt": "2026-03-25",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "4.0",
        "cvssScore": 9.3,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",
        "severitySource": "GitHub_M",
        "epssProbability": 0.96177,
        "epssPercentile": 0.99875,
        "lastFetchedAt": "2026-08-22T13:17:14.761Z",
        "product": "Langflow Langflow",
        "signal": "",
        "summary": "Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-33017.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-33017",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-33017",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33017"
        ],
        "severity": "critical",
        "epss": 0.96177,
        "published": "2026-03-20",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2021-22054",
      "url": "https://vulns.co/api/v1/cves/CVE-2021-22054/",
      "webUrl": "https://vulns.co/cves/CVE-2021-22054/",
      "record": {
        "id": "CVE-2021-22054",
        "title": "Omnissa Workspace ONE Server-Side Request Forgery",
        "cvePublishedAt": "2021-12-17",
        "cveModifiedAt": "2026-03-11",
        "kevAddedAt": "2026-03-09",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 7.5,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
        "severitySource": "CISA-ADP",
        "epssProbability": 0.97369,
        "epssPercentile": 0.99893,
        "lastFetchedAt": "2026-08-22T13:17:14.967Z",
        "product": "Omnissa Workspace One UEM",
        "signal": "",
        "summary": "Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.",
        "poc": null,
        "nuclei": "http/cves/2021/CVE-2021-22054.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2021-22054",
          "https://nvd.nist.gov/vuln/detail/CVE-2021-22054",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22054"
        ],
        "severity": "high",
        "epss": 0.97369,
        "published": "2021-12-17",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2026-20182",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-20182/",
      "webUrl": "https://vulns.co/cves/CVE-2026-20182/",
      "record": {
        "id": "CVE-2026-20182",
        "title": "Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability",
        "cvePublishedAt": "2026-05-14",
        "cveModifiedAt": "2026-06-16",
        "kevAddedAt": "2026-05-14",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "cisco",
        "epssProbability": 0.91522,
        "epssPercentile": 0.99806,
        "lastFetchedAt": "2026-08-22T13:17:15.139Z",
        "product": "Cisco Catalyst SD-WAN",
        "signal": "",
        "summary": "Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-20182",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-20182",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20182"
        ],
        "severity": "critical",
        "epss": 0.91522,
        "published": "2026-05-14",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2026-21643",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-21643/",
      "webUrl": "https://vulns.co/cves/CVE-2026-21643/",
      "record": {
        "id": "CVE-2026-21643",
        "title": "Fortinet FortiClient EMS SQL Injection Vulnerability",
        "cvePublishedAt": "2026-02-06",
        "cveModifiedAt": "2026-04-14",
        "kevAddedAt": "2026-04-13",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.1,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C",
        "severitySource": "fortinet",
        "epssProbability": 0.94085,
        "epssPercentile": 0.99839,
        "lastFetchedAt": "2026-08-22T13:17:15.307Z",
        "product": "Fortinet FortiClient EMS",
        "signal": "",
        "summary": "Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-21643.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-21643",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-21643",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21643"
        ],
        "severity": "critical",
        "epss": 0.94085,
        "published": "2026-02-06",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "injection",
          "classLabel": "Interpreter injection",
          "surface": "network-edge",
          "surfaceLabel": "Network edge",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Locate each parser boundary before choosing a probe. Vary one delimiter or encoding at a time, use non-destructive canaries, and distinguish interpreter behavior from generic errors."
        }
      }
    },
    {
      "id": "cve:CVE-2025-54068",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-54068/",
      "webUrl": "https://vulns.co/cves/CVE-2025-54068/",
      "record": {
        "id": "CVE-2025-54068",
        "title": "Laravel Livewire Code Injection Vulnerability",
        "cvePublishedAt": "2025-07-17",
        "cveModifiedAt": "2026-03-23",
        "kevAddedAt": "2026-03-20",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "4.0",
        "cvssScore": 9.2,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
        "severitySource": "GitHub_M",
        "epssProbability": 0.95805,
        "epssPercentile": 0.99869,
        "lastFetchedAt": "2026-08-22T13:17:15.496Z",
        "product": "Laravel Livewire",
        "signal": "",
        "summary": "Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-54068.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-54068",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-54068",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54068"
        ],
        "severity": "critical",
        "epss": 0.95805,
        "published": "2025-07-17",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-49113",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-49113/",
      "webUrl": "https://vulns.co/cves/CVE-2025-49113/",
      "record": {
        "id": "CVE-2025-49113",
        "title": "RoundCube Webmail Deserialization of Untrusted Data Vulnerability",
        "cvePublishedAt": "2025-06-02",
        "cveModifiedAt": "2026-02-21",
        "kevAddedAt": "2026-02-20",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 9.9,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "mitre",
        "epssProbability": 0.97694,
        "epssPercentile": 0.999,
        "lastFetchedAt": "2026-08-22T13:17:15.682Z",
        "product": "Roundcube Webmail",
        "signal": "",
        "summary": "RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-49113.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-49113",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-49113",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113"
        ],
        "severity": "critical",
        "epss": 0.97694,
        "published": "2025-06-02",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "server-framework",
          "surfaceLabel": "Server and framework",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-31161",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-31161/",
      "webUrl": "https://vulns.co/cves/CVE-2025-31161/",
      "record": {
        "id": "CVE-2025-31161",
        "title": "CrushFTP Authentication Bypass Vulnerability",
        "cvePublishedAt": "2025-04-03",
        "cveModifiedAt": "2025-10-21",
        "kevAddedAt": "2025-04-07",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9.8,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "mitre",
        "epssProbability": 0.99947,
        "epssPercentile": 0.99974,
        "lastFetchedAt": "2026-08-22T13:17:15.893Z",
        "product": "CrushFTP CrushFTP",
        "signal": "",
        "summary": "CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise. ",
        "poc": null,
        "nuclei": "http/cves/2025/CVE-2025-31161.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-31161",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-31161",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31161"
        ],
        "severity": "critical",
        "epss": 0.99947,
        "published": "2025-04-03",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "identity",
          "classLabel": "Identity boundary",
          "surface": "identity-service",
          "surfaceLabel": "Identity service",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Diagram the identity state machine. Compare two controlled identities across alternate routes, token audiences, role changes, recovery flows, and session rotation. Change one property per request."
        }
      }
    },
    {
      "id": "cve:CVE-2026-34910",
      "url": "https://vulns.co/api/v1/cves/CVE-2026-34910/",
      "webUrl": "https://vulns.co/cves/CVE-2026-34910/",
      "record": {
        "id": "CVE-2026-34910",
        "title": "Ubiquiti UniFi OS Improper Input Validation Vulnerability",
        "cvePublishedAt": "2026-05-22",
        "cveModifiedAt": "2026-06-24",
        "kevAddedAt": "2026-06-23",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 10,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "hackerone",
        "epssProbability": 0.86958,
        "epssPercentile": 0.99732,
        "lastFetchedAt": "2026-08-22T13:17:16.072Z",
        "product": "Ubiquiti UniFi OS",
        "signal": "",
        "summary": "Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.",
        "poc": null,
        "nuclei": "http/cves/2026/CVE-2026-34910.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2026-34910",
          "https://nvd.nist.gov/vuln/detail/CVE-2026-34910",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910"
        ],
        "severity": "critical",
        "epss": 0.86958,
        "published": "2026-05-22",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "code-execution",
          "classLabel": "Code execution",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement."
        }
      }
    },
    {
      "id": "cve:CVE-2025-22457",
      "url": "https://vulns.co/api/v1/cves/CVE-2025-22457/",
      "webUrl": "https://vulns.co/cves/CVE-2025-22457/",
      "record": {
        "id": "CVE-2025-22457",
        "title": "Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
        "cvePublishedAt": "2025-04-03",
        "cveModifiedAt": "2026-08-04",
        "kevAddedAt": "2025-04-04",
        "isInKev": true,
        "knownRansomwareUse": "known",
        "cvssVersion": "3.1",
        "cvssScore": 9,
        "cvssSeverity": "critical",
        "cvssVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
        "severitySource": "ivanti",
        "epssProbability": 0.9999,
        "epssPercentile": 0.99985,
        "lastFetchedAt": "2026-08-22T13:17:16.233Z",
        "product": "Ivanti Connect Secure, Policy Secure, and ZTA Gateways",
        "signal": "",
        "summary": "Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. ",
        "poc": null,
        "nuclei": "",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2025-22457",
          "https://nvd.nist.gov/vuln/detail/CVE-2025-22457",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-22457"
        ],
        "severity": "critical",
        "epss": 0.9999,
        "published": "2025-04-03",
        "kev": true,
        "ransomware": true,
        "vulnsAnalysis": {
          "class": "memory-safety",
          "classLabel": "Memory safety",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "ransomware-linked",
          "attentionLabel": "Known exploited with confirmed ransomware use",
          "attentionRank": 4,
          "hunterPivot": "Confirm product, build, reachable protocol, and affected component first. Prefer version and code-path evidence; do not reproduce crashes or corrupt production state."
        }
      }
    },
    {
      "id": "cve:CVE-2024-7399",
      "url": "https://vulns.co/api/v1/cves/CVE-2024-7399/",
      "webUrl": "https://vulns.co/cves/CVE-2024-7399/",
      "record": {
        "id": "CVE-2024-7399",
        "title": "Samsung MagicINFO 9 Server Path Traversal Vulnerability",
        "cvePublishedAt": "2024-08-09",
        "cveModifiedAt": "2026-04-25",
        "kevAddedAt": "2026-04-24",
        "isInKev": true,
        "knownRansomwareUse": "unknown",
        "cvssVersion": "3.1",
        "cvssScore": 8.8,
        "cvssSeverity": "high",
        "cvssVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "severitySource": "samsung.tv_appliance",
        "epssProbability": 0.91941,
        "epssPercentile": 0.99811,
        "lastFetchedAt": "2026-08-22T13:17:16.420Z",
        "product": "Samsung MagicINFO 9 Server",
        "signal": "",
        "summary": "Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.",
        "poc": null,
        "nuclei": "http/cves/2024/CVE-2024-7399.yaml",
        "refs": [
          "https://www.cve.org/CVERecord?id=CVE-2024-7399",
          "https://nvd.nist.gov/vuln/detail/CVE-2024-7399",
          "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7399"
        ],
        "severity": "high",
        "epss": 0.91941,
        "published": "2024-08-09",
        "kev": true,
        "ransomware": false,
        "vulnsAnalysis": {
          "class": "file-boundary",
          "classLabel": "File boundary",
          "surface": "enterprise-app",
          "surfaceLabel": "Enterprise application",
          "attention": "known-exploited",
          "attentionLabel": "Known exploited, ransomware use unknown",
          "attentionRank": 3,
          "hunterPivot": "Compare canonical and alternate path representations against one controlled file. Separate read, write, extraction, and execution primitives, and do not cross into sensitive host files."
        }
      }
    }
  ]
}
