{
"id": "CVE-2021-44228",
"description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
"published": "2021-12-10T10:15:09.143",
"last_modified": "2026-06-17T04:12:05.460",
"status": "Analyzed",
"cwe": [
"CWE-20",
"CWE-400",
"CWE-502",
"CWE-917"
],
"products": [
"siemens:6bk1602-0aa12-0tp0_firmware",
"siemens:6bk1602-0aa12-0tp0",
"siemens:6bk1602-0aa22-0tp0_firmware",
"siemens:6bk1602-0aa22-0tp0",
"siemens:6bk1602-0aa32-0tp0_firmware",
"siemens:6bk1602-0aa32-0tp0",
"siemens:6bk1602-0aa42-0tp0_firmware",
"siemens:6bk1602-0aa42-0tp0",
"siemens:6bk1602-0aa52-0tp0_firmware",
"siemens:6bk1602-0aa52-0tp0",
"apache:log4j",
"siemens:sppa-t3000_ses3000_firmware",
"siemens:sppa-t3000_ses3000",
"siemens:capital",
"siemens:comos",
"siemens:desigo_cc_advanced_reports",
"siemens:desigo_cc_info_center",
"siemens:e-car_operation_center",
"siemens:energy_engage",
"siemens:energyip"
],
"cpe_ranges": [
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0",
"vulnerable": false
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.0.1",
"versionEndExcluding": "2.3.1"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.4.0",
"versionEndExcluding": "2.12.2"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.13.0",
"versionEndExcluding": "2.15.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000_firmware",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"versionEndExcluding": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "comos",
"vulnerable": true,
"versionEndExcluding": "10.4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "3.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "e-car_operation_center",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "energy_engage",
"vulnerable": true,
"version": "3.1"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.5"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.6"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.7"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "9.0"
},
{
"vendor": "siemens",
"product": "energyip_prepay",
"vulnerable": true,
"versionEndExcluding": "3.8.0.12"
},
{
"vendor": "siemens",
"product": "gma-manager",
"vulnerable": true,
"versionEndExcluding": "8.6.2j-398"
},
{
"vendor": "siemens",
"product": "head-end_system_universal_device_integration_system",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "industrial_edge_management",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "industrial_edge_management_hub",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "logo\\!_soft_comfort",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "mendix",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "mindsphere",
"vulnerable": true,
"versionEndExcluding": "2021-12-16"
},
{
"vendor": "siemens",
"product": "navigator",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "nx",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "opcenter_intelligence",
"vulnerable": true,
"versionStartIncluding": "3.2"
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27344/cve+lookup+and+priority+verdict?id=CVE-2021-44228' --header 'Authorization: Bearer YOUR_API_KEY'
{
"total": 7,
"count": 3,
"weaponized": true,
"results": [
{
"id": "CVE-2017-5645",
"description": "In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.",
"published": "2017-04-17T21:59:00.373",
"last_modified": "2026-06-17T01:20:55.043",
"status": "Modified",
"cwe": [
"CWE-502"
],
"products": [
"apache:log4j",
"netapp:oncommand_api_services",
"netapp:oncommand_insight",
"netapp:oncommand_workflow_automation",
"netapp:service_level_manager",
"netapp:snapcenter",
"netapp:storage_automation_store",
"redhat:fuse",
"redhat:enterprise_linux",
"redhat:enterprise_linux_desktop",
"redhat:enterprise_linux_server",
"redhat:enterprise_linux_server_aus",
"redhat:enterprise_linux_server_eus",
"redhat:enterprise_linux_server_tus",
"redhat:enterprise_linux_workstation",
"oracle:api_gateway",
"oracle:application_testing_suite",
"oracle:autovue_vuelink_integration",
"oracle:banking_platform",
"oracle:bi_publisher"
],
"references": [
"http://www.openwall.com/lists/oss-security/2019/12/19/2",
"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html",
"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html",
"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html",
"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
"http://www.securityfocus.com/bid/97702",
"http://www.securitytracker.com/id/1040200",
"http://www.securitytracker.com/id/1041294",
"https://access.redhat.com/errata/RHSA-2017:1417",
"https://access.redhat.com/errata/RHSA-2017:1801",
"https://access.redhat.com/errata/RHSA-2017:1802",
"https://access.redhat.com/errata/RHSA-2017:2423"
],
"exploit_available": false,
"exploit_refs": [],
"has_patch": true,
"has_mitigation": false,
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.8904,
"epss_percentile": 0.99765,
"kev": false,
"exploitation": {
"weaponized": true,
"metasploit": false,
"nuclei": true,
"exploit_db": false,
"public_exploit": true,
"kev": false
},
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "A working public exploit exists (Metasploit/Nuclei/Exploit-DB); exploit probability 89%.",
"score": 73
}
},
{
"id": "CVE-2021-44228",
"description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
"published": "2021-12-10T10:15:09.143",
"last_modified": "2026-06-17T04:12:05.460",
"status": "Analyzed",
"cwe": [
"CWE-20",
"CWE-400",
"CWE-502",
"CWE-917"
],
"products": [
"siemens:6bk1602-0aa12-0tp0_firmware",
"siemens:6bk1602-0aa12-0tp0",
"siemens:6bk1602-0aa22-0tp0_firmware",
"siemens:6bk1602-0aa22-0tp0",
"siemens:6bk1602-0aa32-0tp0_firmware",
"siemens:6bk1602-0aa32-0tp0",
"siemens:6bk1602-0aa42-0tp0_firmware",
"siemens:6bk1602-0aa42-0tp0",
"siemens:6bk1602-0aa52-0tp0_firmware",
"siemens:6bk1602-0aa52-0tp0",
"apache:log4j",
"siemens:sppa-t3000_ses3000_firmware",
"siemens:sppa-t3000_ses3000",
"siemens:capital",
"siemens:comos",
"siemens:desigo_cc_advanced_reports",
"siemens:desigo_cc_info_center",
"siemens:e-car_operation_center",
"siemens:energy_engage",
"siemens:energyip"
],
"references": [
"http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
"http://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.html",
"http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html",
"http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
"http://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.html",
"http://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.html",
"http://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.html",
"http://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.html",
"http://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.html",
"http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html",
"http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html",
"http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html"
],
"exploit_available": true,
"exploit_refs": [
"http://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.html",
"http://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.html",
"http://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.html",
"http://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.html",
"http://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html",
"http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html"
],
"has_patch": true,
"has_mitigation": true,
"cvss": 10,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"epss": 0.99999,
"epss_percentile": 1,
"kev": true,
"exploitation": {
"weaponized": true,
"metasploit": true,
"nuclei": true,
"exploit_db": true,
"public_exploit": true,
"kev": true,
"exploitdb_ids": [
"51183",
"50592",
"50590"
]
},
"kev_details": {
"date_added": "2021-12-10",
"due_date": "2021-12-24",
"ransomware": true,
"required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available."
},
"priority": {
"tier": "P1",
"label": "Patch now",
"reason": "actively exploited in known ransomware campaigns; exploit probability 100%.",
"score": 100
}
},
{
"id": "CVE-2021-45046"
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27345/search+cves?q=log4j&severity=CRITICAL&limit=20&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY'
{
"days": 7,
"total": 38,
"count": 1,
"weaponized": true,
"results": [
{
"id": "CVE-2026-44596",
"description": "Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.",
"published": "2026-07-16T17:16:55.880",
"last_modified": "2026-07-17T18:44:26.383",
"status": "Analyzed",
"cwe": [
"CWE-307"
],
"products": [
"spaceapplications:yamcs"
],
"references": [
"https://github.com/yamcs/yamcs/commit/309218c651680f79df11a8d0f8628f7033f98a83",
"https://github.com/yamcs/yamcs/commit/64392df531fbcbc65f19ee5724c4c23d289f49fc",
"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4"
],
"exploit_available": true,
"exploit_refs": [
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4"
],
"has_patch": true,
"has_mitigation": false,
"cvss": 6.5,
"severity": "MEDIUM",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"epss": 0.0177,
"epss_percentile": 0.75706,
"kev": false,
"exploitation": {
"weaponized": true,
"metasploit": false,
"nuclei": false,
"exploit_db": true,
"public_exploit": true,
"kev": false,
"exploitdb_ids": [
"52605"
]
},
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "A working public exploit exists (Metasploit/Nuclei/Exploit-DB); exploit probability 2%.",
"score": 39
}
}
]
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27346/recently+published+cves?days=7&severity=CRITICAL&limit=1&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY'
{
"ecosystem": "PyPI",
"package": "django",
"version": "3.0",
"vulnerable": true,
"vuln_count": 31,
"highest_priority": "P2",
"vulnerabilities": [
{
"id": "GHSA-frmv-pr5f-9mcr",
"cve": "CVE-2025-64459",
"aliases": [
"BIT-django-2025-64459",
"CVE-2025-64459",
"PYSEC-2025-108"
],
"summary": "Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.",
"published": "2025-11-05T15:31:07Z",
"modified": "2026-06-05T14:45:52.053173828Z",
"fixed_versions": [
"4.2.26",
"5.1.14",
"5.2.8"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2025-64459",
"https://github.com/django/django/commit/06dd38324ac3d60d83d9f3adabf0dcdf423d2a85",
"https://github.com/django/django/commit/59ae82e67053d281ff4562a24bbba21299f0a7d4",
"https://github.com/django/django/commit/6703f364d767e949c5b0e4016433ef75063b4f9b",
"https://github.com/django/django/commit/72d2c87431f2ae0431d65d0ec792047f078c8241",
"https://docs.djangoproject.com/en/dev/releases/security",
"https://github.com/django/django",
"https://github.com/omarkurt/django-connector-CVE-2025-64459-testbed"
],
"cvss": 9.1,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"epss": 0.19396,
"epss_percentile": 0.9706,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "Critical severity (CVSS 9.1); exploit probability 19%."
}
},
{
"id": "GHSA-hmr4-m2h5-33qx",
"cve": "CVE-2020-7471",
"aliases": [
"BIT-django-2020-7471",
"CVE-2020-7471",
"PYSEC-2020-35"
],
"summary": "SQL injection in Django",
"published": "2020-02-11T21:03:20Z",
"modified": "2025-02-21T06:12:43.981276Z",
"fixed_versions": [
"1.11.28",
"2.2.10",
"3.0.3"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2020-7471",
"https://github.com/django/django/commit/001b0634cd309e372edb6d7d95d083d02b8e37bd",
"https://github.com/django/django/commit/505826b469b16ab36693360da9e11fd13213421b",
"https://github.com/django/django/commit/c67a368c16e4680b324b4f385398d638db4d8147",
"https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136",
"https://www.openwall.com/lists/oss-security/2020/02/03/1",
"https://www.djangoproject.com/weblog/2020/feb/03/security-releases",
"https://www.debian.org/security/2020/dsa-4629"
],
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.65336,
"epss_percentile": 0.99173,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "High exploit probability (65%) though not yet on KEV."
}
},
{
"id": "GHSA-vfq6-hq5r-27r6",
"cve": "CVE-2019-19844",
"aliases": [
"CVE-2019-19844",
"PYSEC-2019-16"
],
"summary": "Django Potential account hijack via password reset form",
"published": "2020-01-16T22:35:12Z",
"modified": "2024-09-20T15:24:05.816291Z",
"fixed_versions": [
"1.11.27",
"2.2.9",
"3.0.1"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2019-19844",
"https://github.com/django/django/commit/302a4ff1e8b1c798aab97673909c7a3dfda42c26",
"https://github.com/django/django/commit/4d334bea06cac63dc1272abcec545b85136cca0e",
"https://github.com/django/django/commit/5b1fbcef7a8bec991ebe7b2a18b5d5a95d72cb70",
"https://github.com/django/django/commit/f4cff43bf921fcea6a29b726eb66767f67753fa2",
"https://www.djangoproject.com/weblog/2019/dec/18/security-releases",
"https://www.debian.org/security/2020/dsa-4598",
"https://usn.ubuntu.com/4224-1"
],
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.3481,
"epss_percentile": 0.98255,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "Critical severity (CVSS 9.8); exploit probability 35%."
}
},
{
"id": "GHSA-xpfp-f569-q3p2",
"cve": "CVE-2021-35042",
"aliases": [
"BIT-django-2021-35042",
"CVE-2021-35042",
"PYSEC-2021-109"
],
"summary": "SQL Injection in Django",
"published": "2021-09-22T17:34:49Z",
"modified": "2025-02-21T05:30:56.014475Z",
"fixed_versions": [
"3.1.13",
"3.2.5"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2021-35042",
"https://github.com/django/django/commit/0bd57a879a0d54920bb9038a732645fb917040e9",
"https://github.com/django/django/commit/a34a5f724c5d5adb2109374ba3989ebb7b11f81f",
"https://github.com/django/django/commit/dae83a24519d6f284c74414e0b81d64d9b5a0db4",
"https://docs.djangoproject.com/en/3.2/releases/security",
"https://github.com/advisories/GHSA-xpfp-f569-q3p2",
"https://github.com/django/django",
"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-109.yaml"
],
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.44369,
"epss_percentile": 0.98627,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "Critical severity (CVSS 9.8); exploit probability 44%."
}
},
{
"id": "PYSEC-2020-35",
"cve": "CVE-2020-7471",
"aliases": [
"BIT-django-2020-7471",
"CVE-2020-7471",
"GHSA-hmr4-m2h5-33qx"
],
"summary": null,
"published": "2020-02-03T12:15:00Z",
"modified": "2023-12-06T01:00:38.606116Z",
"fixed_versions": [
"1.11.28",
"2.2.10",
"3.0.3",
"eb31d845323618d688ad429479c6dda973056136"
],
"references": [
"https://www.openwall.com/lists/oss-security/2020/02/03/1",
"https://docs.djangoproject.com/en/3.0/releases/security/",
"https://groups.google.com/forum/#!topic/django-announce/X45S86X5bZI",
"https://www.djangoproject.com/weblog/2020/feb/03/security-releases/",
"http://www.openwall.com/lists/oss-security/2020/02/03/1",
"https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136",
"https://usn.ubuntu.com/4264-1/",
"https://seclists.org/bugtraq/2020/Feb/30"
],
"cvss": null,
"severity": null,
"cvss_version": null,
"vector": null,
"epss": 0.65336,
"epss_percentile": 0.99173,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "High exploit probability (65%) though not yet on KEV."
}
},
{
"id": "GHSA-3gh2-xw74-jmcw",
"cve": "CVE-2020-9402",
"aliases": [
"BIT-django-2020-9402",
"CVE-2020-9402",
"PYSEC-2020-36"
],
"summary": "SQL injection in Django",
"published": "2020-06-05T14:52:07Z",
"modified": "2026-07-09T16:56:16.012032693Z",
"fixed_versions": [
"1.11.29",
"2.2.11",
"3.0.4"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2020-9402",
"https://github.com/django/django/commit/6695d29b1c1ce979725816295a26ecc64ae0e927",
"https://www.djangoproject.com/weblog/2020/mar/04/security-releases",
"https://www.debian.org/security/2020/dsa-4705",
"https://usn.ubuntu.com/4296-1"
]
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27347/package+and+dependency+vulnerabilities?ecosystem=PyPI&name=django&version=3.0' --header 'Authorization: Bearer YOUR_API_KEY'
{
"id": "GHSA-jfh8-c2jp-5v3q",
"cve": "CVE-2021-44228",
"aliases": [
"CVE-2021-44228"
],
"summary": "Remote code injection in Log4j",
"published": "2021-12-10T00:40:56Z",
"modified": "2025-10-22T19:37:02.616807Z",
"fixed_versions": [],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
"https://github.com/apache/logging-log4j2/pull/608",
"https://github.com/github/advisory-database/pull/5501",
"https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
"https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
"https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
"https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
"https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
],
"cvss": 10,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
"epss": 0.99999,
"epss_percentile": 1,
"kev": true,
"kev_details": {
"date_added": "2021-12-10",
"due_date": "2021-12-24",
"ransomware": true,
"required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available."
},
"priority": {
"tier": "P1",
"label": "Patch now",
"reason": "actively exploited in known ransomware campaigns; exploit probability 100%."
}
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27348/osv+and+ghsa+advisory+by+id?id=GHSA-jfh8-c2jp-5v3q' --header 'Authorization: Bearer YOUR_API_KEY'
{
"count": 50,
"released": "2026-07-16",
"total_kev": 1647,
"results": [
{
"cve": "CVE-2026-35273",
"vendor": "Oracle",
"product": " PeopleSoft Enterprise PeopleTools",
"name": "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
"date_added": "2026-06-12",
"due_date": "2026-06-15",
"ransomware": true,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.",
"epss": 0.9233,
"epss_percentile": 0.99812
},
{
"cve": "CVE-2026-50751",
"vendor": "Check Point",
"product": "Security Gateway",
"name": "Check Point Security Gateway Improper Authentication Vulnerability",
"date_added": "2026-06-08",
"due_date": "2026-06-11",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.",
"epss": 0.70099,
"epss_percentile": 0.99307
},
{
"cve": "CVE-2026-48027",
"vendor": "Nx",
"product": "Nx Console",
"name": "Nx Console Embedded Malicious Code Vulnerability",
"date_added": "2026-05-27",
"due_date": "2026-06-10",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.",
"epss": 0.0185,
"epss_percentile": 0.76784
},
{
"cve": "CVE-2026-45321",
"vendor": "TanStack",
"product": "TanStack",
"name": "TanStack Unspecified Vulnerability",
"date_added": "2026-05-27",
"due_date": "2026-06-10",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.",
"epss": 0.02342,
"epss_percentile": 0.81773
},
{
"cve": "CVE-2026-41940",
"vendor": "WebPros",
"product": "cPanel & WHM and WP2 (WordPress Squared)",
"name": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability",
"date_added": "2026-04-30",
"due_date": "2026-05-03",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
"epss": 0.981,
"epss_percentile": 0.99907
},
{
"cve": "CVE-2024-1708",
"vendor": "ConnectWise",
"product": "ScreenConnect",
"name": "ConnectWise ScreenConnect Path Traversal Vulnerability",
"date_added": "2026-04-28",
"due_date": "2026-05-12",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.",
"epss": 0.87624,
"epss_percentile": 0.99742
},
{
"cve": "CVE-2024-57728",
"vendor": "SimpleHelp ",
"product": "SimpleHelp",
"name": "SimpleHelp Path Traversal Vulnerability",
"date_added": "2026-04-24",
"due_date": "2026-05-08",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.",
"epss": 0.06982,
"epss_percentile": 0.93433
},
{
"cve": "CVE-2024-57726",
"vendor": "SimpleHelp ",
"product": "SimpleHelp",
"name": "SimpleHelp Missing Authorization Vulnerability",
"date_added": "2026-04-24",
"due_date": "2026-05-08",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.",
"epss": 0.08632,
"epss_percentile": 0.94514
},
{
"cve": "CVE-2026-33825",
"vendor": "Microsoft",
"product": "Defender",
"name": "Microsoft Defender Insufficient Granularity of Access Control Vulnerability",
"date_added": "2026-04-22",
"due_date": "2026-05-06",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.",
"epss": 0.06749,
"epss_percentile": 0.93237
},
{
"cve": "CVE-2023-27351",
"vendor": "PaperCut",
"product": "NG/MF",
"name": "PaperCut NG/MF Improper Authentication Vulnerability",
"date_added": "2026-04-20",
"due_date": "2026-05-04",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.",
"epss": 0.77388,
"epss_percentile": 0.99508
},
{
"cve": "CVE-2024-27199",
"vendor": "JetBrains",
"product": "TeamCity",
"name": "JetBrains TeamCity Relative Path Traversal Vulnerability",
"date_added": "2026-04-20",
"due_date": "2026-05-04",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27349/cisa+kev+catalog?ransomware=true&limit=50' --header 'Authorization: Bearer YOUR_API_KEY'
{
"id": "CVE-2021-44228",
"epss": 0.99999,
"epss_percentile": 1,
"score_date": "2026-07-21"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27350/epss+exploit-probability+score?id=CVE-2021-44228' --header 'Authorization: Bearer YOUR_API_KEY'
{
"requested": 3,
"resolved": 3,
"highest_priority": "P1",
"by_tier": {
"P1": 2,
"P2": 1
},
"results": [
{
"id": "CVE-2021-44228",
"description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
"published": "2021-12-10T10:15:09.143",
"last_modified": "2026-06-17T04:12:05.460",
"status": "Analyzed",
"cwe": [
"CWE-20",
"CWE-400",
"CWE-502",
"CWE-917"
],
"products": [
"siemens:6bk1602-0aa12-0tp0_firmware",
"siemens:6bk1602-0aa12-0tp0",
"siemens:6bk1602-0aa22-0tp0_firmware",
"siemens:6bk1602-0aa22-0tp0",
"siemens:6bk1602-0aa32-0tp0_firmware",
"siemens:6bk1602-0aa32-0tp0",
"siemens:6bk1602-0aa42-0tp0_firmware",
"siemens:6bk1602-0aa42-0tp0",
"siemens:6bk1602-0aa52-0tp0_firmware",
"siemens:6bk1602-0aa52-0tp0",
"apache:log4j",
"siemens:sppa-t3000_ses3000_firmware",
"siemens:sppa-t3000_ses3000",
"siemens:capital",
"siemens:comos",
"siemens:desigo_cc_advanced_reports",
"siemens:desigo_cc_info_center",
"siemens:e-car_operation_center",
"siemens:energy_engage",
"siemens:energyip"
],
"cpe_ranges": [
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0",
"vulnerable": false
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.0.1",
"versionEndExcluding": "2.3.1"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.4.0",
"versionEndExcluding": "2.12.2"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.13.0",
"versionEndExcluding": "2.15.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000_firmware",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"versionEndExcluding": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "comos",
"vulnerable": true,
"versionEndExcluding": "10.4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "3.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "e-car_operation_center",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "energy_engage",
"vulnerable": true,
"version": "3.1"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.5"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true
}
]
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27354/rank+a+list+of+cves+fix-first?ids=CVE-2021-44228,CVE-2019-19844,CVE-2014-0160&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY'
{
"days": 7,
"cutoff": "2026-07-15",
"count": 9,
"results": [
{
"cve": "CVE-2026-60137",
"vendor": "WordPress",
"product": "Core",
"name": "WordPress Core SQL Injection Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-08-04",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
"epss": 0.20395,
"epss_percentile": 0.97219
},
{
"cve": "CVE-2026-63030",
"vendor": "WordPress",
"product": "Core",
"name": "WordPress Core Interpretation Conflict Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-07-24",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
"epss": 0.38599,
"epss_percentile": 0.98425
},
{
"cve": "CVE-2026-0770",
"vendor": "Langflow",
"product": "Langflow",
"name": "Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-07-24",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. ",
"epss": 0.54503,
"epss_percentile": 0.98911
},
{
"cve": "CVE-2021-27137",
"vendor": "DD-WRT",
"product": "DD-WRT",
"name": "DD-WRT Stack-Based Buffer Overflow Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-07-24",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
"epss": 0.10809,
"epss_percentile": 0.95377
},
{
"cve": "CVE-2026-58644",
"vendor": "Microsoft",
"product": "SharePoint",
"name": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
"epss": 0.01465,
"epss_percentile": 0.709
},
{
"cve": "CVE-2026-25089",
"vendor": "Fortinet",
"product": "FortiSandbox",
"name": "Fortinet FortiSandbox OS Command Injection Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.",
"epss": 0.36135,
"epss_percentile": 0.98317
},
{
"cve": "CVE-2026-39808",
"vendor": "Fortinet",
"product": "FortiSandbox",
"name": "Fortinet FortiSandbox OS Command Injection Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
"epss": 0.84158,
"epss_percentile": 0.99669
},
{
"cve": "CVE-2026-46817",
"vendor": "Oracle",
"product": "E-Business Suite",
"name": "Oracle E-Business Suite Improper Privilege Management Vulnerability",
"date_added": "2026-07-15",
"due_date": "2026-07-18",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.",
"epss": 0.01045,
"epss_percentile": 0.6053
},
{
"cve": "CVE-2023-4346",
"vendor": "KNX Association",
"product": "KNX Protocol Connection Authorization Option 1",
"name": "KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability",
"date_added": "2026-07-15",
"due_date": "2026-07-29",
"ransomware": false
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27355/newly+exploited+cves+kev+feed?days=7&limit=100' --header 'Authorization: Bearer YOUR_API_KEY'
注册后,每个开发者都会被分配一个个人 API 访问密钥,这是一个唯一的字母和数字组合,用于访问我们的 API 端点。要使用 漏洞情报与CVE优先级排序 API 进行身份验证,只需在 Authorization 标头中包含您的 bearer token。
| 标头 | 描述 |
|---|---|
授权
|
必需
应为 Bearer access_key. 订阅后,请查看上方的"您的 API 访问密钥"。
|
无长期承诺。随时升级、降级或取消。 免费试用包括最多 50 个请求。
(年度计费可节省 2 个月 🎉)
领先企业的信赖之选
查找任何CVE或软件依赖项,并获取P1-P5补丁优先级判定,结合CVSS(NVD)、主动利用状态(CISA KEV)和利用概率(FIRST EPSS)。包括对PyPI、npm、Go、Maven等的OSV依赖扫描。仅用于信息优先级排序
每个端点返回有关CVE的详细信息,包括描述、发布日期、CVSS分数、利用概率和优先级判决。例如,CVE查询端点提供特定CVE的全面视图,而软件包漏洞端点列出了已知的软件包漏洞
关键字段包括"id"(CVE 标识符)、"description"(漏洞详情)、"published"(发布日期)、"status"(分析状态)、"cwe"(常见弱点枚举)和"priority"(P1-P5 判决)这些字段有助于评估漏洞的严重性和相关性
参数因端点而异 对于CVE搜索端点,您可以使用“q”(关键字)、“severity”(严重性级别)或“cpe”(通用平台枚举) 包漏洞端点允许指定“package”(软件包)和“version”(版本)以缩小结果
响应数据采用 JSON 格式结构,顶级字段指示结果的总数以及包含单个 CVE 条目的“结果”数组。每个条目包括详细属性,如“描述”、“发布日期”和“修复版本”
该API从多个可信来源聚合数据,包括国家漏洞数据库(NVD)、CISA的已知利用漏洞(KEV)目录和FIRST的漏洞预测评分系统(EPSS)这确保了全面和可靠的漏洞信息
典型的用例包括漏洞管理 风险评估 和补丁工作优先级的确定 安全团队可以使用API识别软件依赖中的关键漏洞并作出明智的修复决策
用户可以分析返回的数据,根据严重性和可利用性优先考虑漏洞。例如,通过关注EPSS分数高的P1-P2漏洞,组织可以有效分配资源以减轻风险
数据准确性通过来自权威来源的定期更新和自动一致性检查来保持 API整合多个数据集交叉引用信息以确保用户获得最准确和最新的漏洞数据