किसी भी CVE या सॉफ़्टवेयर निर्भरता की जांच करें और CVSS (NVD), सक्रिय-शोषित स्थिति (CISA KEV) और शोषण संभावना (FIRST EPSS) को मिलाते हुए P1-P5 पैच-प्रायोरिटी परिणाम प्राप्त करें इसमें PyPI, npm, Go, Maven आदि के बीच OSV निर्भरता स्कैनिंग शामिल है केवल सूचना आधारित प्राथमिकता
{
"id": "CVE-2021-44228",
"description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
"published": "2021-12-10T10:15:09.143",
"last_modified": "2026-06-17T04:12:05.460",
"status": "Analyzed",
"cwe": [
"CWE-20",
"CWE-400",
"CWE-502",
"CWE-917"
],
"products": [
"siemens:6bk1602-0aa12-0tp0_firmware",
"siemens:6bk1602-0aa12-0tp0",
"siemens:6bk1602-0aa22-0tp0_firmware",
"siemens:6bk1602-0aa22-0tp0",
"siemens:6bk1602-0aa32-0tp0_firmware",
"siemens:6bk1602-0aa32-0tp0",
"siemens:6bk1602-0aa42-0tp0_firmware",
"siemens:6bk1602-0aa42-0tp0",
"siemens:6bk1602-0aa52-0tp0_firmware",
"siemens:6bk1602-0aa52-0tp0",
"apache:log4j",
"siemens:sppa-t3000_ses3000_firmware",
"siemens:sppa-t3000_ses3000",
"siemens:capital",
"siemens:comos",
"siemens:desigo_cc_advanced_reports",
"siemens:desigo_cc_info_center",
"siemens:e-car_operation_center",
"siemens:energy_engage",
"siemens:energyip"
],
"cpe_ranges": [
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0",
"vulnerable": false
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.0.1",
"versionEndExcluding": "2.3.1"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.4.0",
"versionEndExcluding": "2.12.2"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.13.0",
"versionEndExcluding": "2.15.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000_firmware",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"versionEndExcluding": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "comos",
"vulnerable": true,
"versionEndExcluding": "10.4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "3.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "e-car_operation_center",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "energy_engage",
"vulnerable": true,
"version": "3.1"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.5"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.6"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.7"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "9.0"
},
{
"vendor": "siemens",
"product": "energyip_prepay",
"vulnerable": true,
"versionEndExcluding": "3.8.0.12"
},
{
"vendor": "siemens",
"product": "gma-manager",
"vulnerable": true,
"versionEndExcluding": "8.6.2j-398"
},
{
"vendor": "siemens",
"product": "head-end_system_universal_device_integration_system",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "industrial_edge_management",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "industrial_edge_management_hub",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "logo\\!_soft_comfort",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "mendix",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "mindsphere",
"vulnerable": true,
"versionEndExcluding": "2021-12-16"
},
{
"vendor": "siemens",
"product": "navigator",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "nx",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "opcenter_intelligence",
"vulnerable": true,
"versionStartIncluding": "3.2"
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27344/cve+lookup+and+priority+verdict?id=CVE-2021-44228' --header 'Authorization: Bearer YOUR_API_KEY'
{
"total": 7,
"count": 3,
"weaponized": true,
"results": [
{
"id": "CVE-2017-5645",
"description": "In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.",
"published": "2017-04-17T21:59:00.373",
"last_modified": "2026-06-17T01:20:55.043",
"status": "Modified",
"cwe": [
"CWE-502"
],
"products": [
"apache:log4j",
"netapp:oncommand_api_services",
"netapp:oncommand_insight",
"netapp:oncommand_workflow_automation",
"netapp:service_level_manager",
"netapp:snapcenter",
"netapp:storage_automation_store",
"redhat:fuse",
"redhat:enterprise_linux",
"redhat:enterprise_linux_desktop",
"redhat:enterprise_linux_server",
"redhat:enterprise_linux_server_aus",
"redhat:enterprise_linux_server_eus",
"redhat:enterprise_linux_server_tus",
"redhat:enterprise_linux_workstation",
"oracle:api_gateway",
"oracle:application_testing_suite",
"oracle:autovue_vuelink_integration",
"oracle:banking_platform",
"oracle:bi_publisher"
],
"cpe_ranges": [
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.0",
"versionEndExcluding": "2.8.2"
},
{
"vendor": "netapp",
"product": "oncommand_api_services",
"vulnerable": true
},
{
"vendor": "netapp",
"product": "oncommand_insight",
"vulnerable": true
},
{
"vendor": "netapp",
"product": "oncommand_workflow_automation",
"vulnerable": true
},
{
"vendor": "netapp",
"product": "service_level_manager",
"vulnerable": true
},
{
"vendor": "netapp",
"product": "snapcenter",
"vulnerable": true
},
{
"vendor": "netapp",
"product": "storage_automation_store",
"vulnerable": true
},
{
"vendor": "redhat",
"product": "fuse",
"vulnerable": true,
"version": "1.0"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "6.0"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "6.7"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "7.0"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "7.3"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "7.4"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "7.5"
},
{
"vendor": "redhat",
"product": "enterprise_linux",
"vulnerable": true,
"version": "7.6"
},
{
"vendor": "redhat",
"product": "enterprise_linux_desktop",
"vulnerable": true,
"version": "7.0"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server",
"vulnerable": true,
"version": "7.0"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_aus",
"vulnerable": true,
"version": "7.4"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_aus",
"vulnerable": true,
"version": "7.6"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_eus",
"vulnerable": true,
"version": "7.4"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_eus",
"vulnerable": true,
"version": "7.5"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_eus",
"vulnerable": true,
"version": "7.6"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_tus",
"vulnerable": true,
"version": "7.4"
},
{
"vendor": "redhat",
"product": "enterprise_linux_server_tus",
"vulnerable": true,
"version": "7.6"
},
{
"vendor": "redhat",
"product": "enterprise_linux_workstation",
"vulnerable": true,
"version": "7.0"
},
{
"vendor": "oracle",
"product": "api_gateway",
"vulnerable": true,
"version": "11.1.2.4.0"
},
{
"vendor": "oracle",
"product": "application_testing_suite",
"vulnerable": true,
"version": "13.3.0.1"
},
{
"vendor": "oracle",
"product": "autovue_vuelink_integration",
"vulnerable": true,
"version": "21.0.0"
},
{
"vendor": "oracle",
"product": "autovue_vuelink_integration",
"vulnerable": true,
"version": "21.0.1"
},
{
"vendor": "oracle",
"product": "banking_platform",
"vulnerable": true,
"version": "2.6.0"
},
{
"vendor": "oracle",
"product": "banking_platform",
"vulnerable": true,
"version": "2.6.1"
},
{
"vendor": "oracle",
"product": "banking_platform",
"vulnerable": true,
"version": "2.6.2"
},
{
"vendor": "oracle",
"product": "bi_publisher",
"vulnerable": true,
"version": "11.1.1.7.0"
},
{
"vendor": "oracle",
"product": "bi_publisher",
"vulnerable": true,
"version": "11.1.1.9.0"
},
{
"vendor": "oracle",
"product": "bi_publisher",
"vulnerable": true,
"version": "12.2.1.3.0"
},
{
"vendor": "oracle",
"product": "bi_publisher",
"vulnerable": true,
"version": "12.2.1.4.0"
},
{
"vendor": "oracle",
"product": "communications_converged_application_server_-_service_controller",
"vulnerable": true,
"version": "6.1"
},
{
"vendor": "oracle",
"product": "communications_instant_messaging_server",
"vulnerable": true,
"version": "10.0.1.3.0"
}]}],"_note":"Response truncated for documentation purposes"}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27345/search+cves?q=log4j&severity=CRITICAL&limit=20&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY'
{
"days": 7,
"total": 38,
"count": 1,
"weaponized": true,
"results": [
{
"id": "CVE-2026-44596",
"description": "Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an unauthenticated remote attacker could perform unlimited password-guessing attempts against any user account, significantly increasing the risk of successful brute-force attacks. This issue is fixed in versions 5.12.7 and 5.13.0.",
"published": "2026-07-16T17:16:55.880",
"last_modified": "2026-07-17T18:44:26.383",
"status": "Analyzed",
"cwe": [
"CWE-307"
],
"products": [
"spaceapplications:yamcs"
],
"references": [
"https://github.com/yamcs/yamcs/commit/309218c651680f79df11a8d0f8628f7033f98a83",
"https://github.com/yamcs/yamcs/commit/64392df531fbcbc65f19ee5724c4c23d289f49fc",
"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7",
"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0",
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4"
],
"exploit_available": true,
"exploit_refs": [
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4",
"https://github.com/yamcs/yamcs/security/advisories/GHSA-w5r6-mcgq-7pq4"
],
"has_patch": true,
"has_mitigation": false,
"cvss": 6.5,
"severity": "MEDIUM",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"epss": 0.0177,
"epss_percentile": 0.75706,
"kev": false,
"exploitation": {
"weaponized": true,
"metasploit": false,
"nuclei": false,
"exploit_db": true,
"public_exploit": true,
"kev": false,
"exploitdb_ids": [
"52605"
]
},
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "A working public exploit exists (Metasploit/Nuclei/Exploit-DB); exploit probability 2%.",
"score": 39
}
}
]
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27346/recently+published+cves?days=7&severity=CRITICAL&limit=1&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY'
{
"ecosystem": "PyPI",
"package": "django",
"version": "3.0",
"vulnerable": true,
"vuln_count": 31,
"highest_priority": "P2",
"vulnerabilities": [
{
"id": "GHSA-frmv-pr5f-9mcr",
"cve": "CVE-2025-64459",
"aliases": [
"BIT-django-2025-64459",
"CVE-2025-64459",
"PYSEC-2025-108"
],
"summary": "Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.",
"published": "2025-11-05T15:31:07Z",
"modified": "2026-06-05T14:45:52.053173828Z",
"fixed_versions": [
"4.2.26",
"5.1.14",
"5.2.8"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2025-64459",
"https://github.com/django/django/commit/06dd38324ac3d60d83d9f3adabf0dcdf423d2a85",
"https://github.com/django/django/commit/59ae82e67053d281ff4562a24bbba21299f0a7d4",
"https://github.com/django/django/commit/6703f364d767e949c5b0e4016433ef75063b4f9b",
"https://github.com/django/django/commit/72d2c87431f2ae0431d65d0ec792047f078c8241",
"https://docs.djangoproject.com/en/dev/releases/security",
"https://github.com/django/django",
"https://github.com/omarkurt/django-connector-CVE-2025-64459-testbed"
],
"cvss": 9.1,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"epss": 0.19396,
"epss_percentile": 0.9706,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "Critical severity (CVSS 9.1); exploit probability 19%."
}
},
{
"id": "GHSA-hmr4-m2h5-33qx",
"cve": "CVE-2020-7471",
"aliases": [
"BIT-django-2020-7471",
"CVE-2020-7471",
"PYSEC-2020-35"
],
"summary": "SQL injection in Django",
"published": "2020-02-11T21:03:20Z",
"modified": "2025-02-21T06:12:43.981276Z",
"fixed_versions": [
"1.11.28",
"2.2.10",
"3.0.3"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2020-7471",
"https://github.com/django/django/commit/001b0634cd309e372edb6d7d95d083d02b8e37bd",
"https://github.com/django/django/commit/505826b469b16ab36693360da9e11fd13213421b",
"https://github.com/django/django/commit/c67a368c16e4680b324b4f385398d638db4d8147",
"https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136",
"https://www.openwall.com/lists/oss-security/2020/02/03/1",
"https://www.djangoproject.com/weblog/2020/feb/03/security-releases",
"https://www.debian.org/security/2020/dsa-4629"
],
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.65336,
"epss_percentile": 0.99173,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "High exploit probability (65%) though not yet on KEV."
}
},
{
"id": "GHSA-vfq6-hq5r-27r6",
"cve": "CVE-2019-19844",
"aliases": [
"CVE-2019-19844",
"PYSEC-2019-16"
],
"summary": "Django Potential account hijack via password reset form",
"published": "2020-01-16T22:35:12Z",
"modified": "2024-09-20T15:24:05.816291Z",
"fixed_versions": [
"1.11.27",
"2.2.9",
"3.0.1"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2019-19844",
"https://github.com/django/django/commit/302a4ff1e8b1c798aab97673909c7a3dfda42c26",
"https://github.com/django/django/commit/4d334bea06cac63dc1272abcec545b85136cca0e",
"https://github.com/django/django/commit/5b1fbcef7a8bec991ebe7b2a18b5d5a95d72cb70",
"https://github.com/django/django/commit/f4cff43bf921fcea6a29b726eb66767f67753fa2",
"https://www.djangoproject.com/weblog/2019/dec/18/security-releases",
"https://www.debian.org/security/2020/dsa-4598",
"https://usn.ubuntu.com/4224-1"
],
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.3481,
"epss_percentile": 0.98255,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "Critical severity (CVSS 9.8); exploit probability 35%."
}
},
{
"id": "GHSA-xpfp-f569-q3p2",
"cve": "CVE-2021-35042",
"aliases": [
"BIT-django-2021-35042",
"CVE-2021-35042",
"PYSEC-2021-109"
],
"summary": "SQL Injection in Django",
"published": "2021-09-22T17:34:49Z",
"modified": "2025-02-21T05:30:56.014475Z",
"fixed_versions": [
"3.1.13",
"3.2.5"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2021-35042",
"https://github.com/django/django/commit/0bd57a879a0d54920bb9038a732645fb917040e9",
"https://github.com/django/django/commit/a34a5f724c5d5adb2109374ba3989ebb7b11f81f",
"https://github.com/django/django/commit/dae83a24519d6f284c74414e0b81d64d9b5a0db4",
"https://docs.djangoproject.com/en/3.2/releases/security",
"https://github.com/advisories/GHSA-xpfp-f569-q3p2",
"https://github.com/django/django",
"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2021-109.yaml"
],
"cvss": 9.8,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"epss": 0.44369,
"epss_percentile": 0.98627,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "Critical severity (CVSS 9.8); exploit probability 44%."
}
},
{
"id": "PYSEC-2020-35",
"cve": "CVE-2020-7471",
"aliases": [
"BIT-django-2020-7471",
"CVE-2020-7471",
"GHSA-hmr4-m2h5-33qx"
],
"summary": null,
"published": "2020-02-03T12:15:00Z",
"modified": "2023-12-06T01:00:38.606116Z",
"fixed_versions": [
"1.11.28",
"2.2.10",
"3.0.3",
"eb31d845323618d688ad429479c6dda973056136"
],
"references": [
"https://www.openwall.com/lists/oss-security/2020/02/03/1",
"https://docs.djangoproject.com/en/3.0/releases/security/",
"https://groups.google.com/forum/#!topic/django-announce/X45S86X5bZI",
"https://www.djangoproject.com/weblog/2020/feb/03/security-releases/",
"http://www.openwall.com/lists/oss-security/2020/02/03/1",
"https://github.com/django/django/commit/eb31d845323618d688ad429479c6dda973056136",
"https://usn.ubuntu.com/4264-1/",
"https://seclists.org/bugtraq/2020/Feb/30"
],
"cvss": null,
"severity": null,
"cvss_version": null,
"vector": null,
"epss": 0.65336,
"epss_percentile": 0.99173,
"kev": false,
"priority": {
"tier": "P2",
"label": "Urgent",
"reason": "High exploit probability (65%) though not yet on KEV."
}
},
{
"id": "GHSA-3gh2-xw74-jmcw",
"cve": "CVE-2020-9402",
"aliases": [
"BIT-django-2020-9402",
"CVE-2020-9402",
"PYSEC-2020-36"
],
"summary": "SQL injection in Django",
"published": "2020-06-05T14:52:07Z",
"modified": "2026-07-09T16:56:16.012032693Z",
"fixed_versions": [
"1.11.29",
"2.2.11",
"3.0.4"
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2020-9402",
"https://github.com/django/django/commit/6695d29b1c1ce979725816295a26ecc64ae0e927",
"https://www.djangoproject.com/weblog/2020/mar/04/security-releases",
"https://www.debian.org/security/2020/dsa-4705",
"https://usn.ubuntu.com/4296-1"
]
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27347/package+and+dependency+vulnerabilities?ecosystem=PyPI&name=django&version=3.0' --header 'Authorization: Bearer YOUR_API_KEY'
{
"id": "GHSA-jfh8-c2jp-5v3q",
"cve": "CVE-2021-44228",
"aliases": [
"CVE-2021-44228"
],
"summary": "Remote code injection in Log4j",
"published": "2021-12-10T00:40:56Z",
"modified": "2025-10-22T19:37:02.616807Z",
"fixed_versions": [],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
"https://github.com/apache/logging-log4j2/pull/608",
"https://github.com/github/advisory-database/pull/5501",
"https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdf",
"https://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html",
"https://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html",
"https://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.html",
"https://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.html"
],
"cvss": 10,
"severity": "CRITICAL",
"cvss_version": "3.1",
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H",
"epss": 0.99999,
"epss_percentile": 1,
"kev": true,
"kev_details": {
"date_added": "2021-12-10",
"due_date": "2021-12-24",
"ransomware": true,
"required_action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available."
},
"priority": {
"tier": "P1",
"label": "Patch now",
"reason": "actively exploited in known ransomware campaigns; exploit probability 100%."
}
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27348/osv+and+ghsa+advisory+by+id?id=GHSA-jfh8-c2jp-5v3q' --header 'Authorization: Bearer YOUR_API_KEY'
{
"count": 50,
"released": "2026-07-16",
"total_kev": 1647,
"results": [
{
"cve": "CVE-2026-35273",
"vendor": "Oracle",
"product": " PeopleSoft Enterprise PeopleTools",
"name": "Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
"date_added": "2026-06-12",
"due_date": "2026-06-15",
"ransomware": true,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.",
"epss": 0.9233,
"epss_percentile": 0.99812
},
{
"cve": "CVE-2026-50751",
"vendor": "Check Point",
"product": "Security Gateway",
"name": "Check Point Security Gateway Improper Authentication Vulnerability",
"date_added": "2026-06-08",
"due_date": "2026-06-11",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.",
"epss": 0.70099,
"epss_percentile": 0.99307
},
{
"cve": "CVE-2026-48027",
"vendor": "Nx",
"product": "Nx Console",
"name": "Nx Console Embedded Malicious Code Vulnerability",
"date_added": "2026-05-27",
"due_date": "2026-06-10",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.",
"epss": 0.0185,
"epss_percentile": 0.76784
},
{
"cve": "CVE-2026-45321",
"vendor": "TanStack",
"product": "TanStack",
"name": "TanStack Unspecified Vulnerability",
"date_added": "2026-05-27",
"due_date": "2026-06-10",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.",
"epss": 0.02342,
"epss_percentile": 0.81773
},
{
"cve": "CVE-2026-41940",
"vendor": "WebPros",
"product": "cPanel & WHM and WP2 (WordPress Squared)",
"name": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability",
"date_added": "2026-04-30",
"due_date": "2026-05-03",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
"epss": 0.981,
"epss_percentile": 0.99907
},
{
"cve": "CVE-2024-1708",
"vendor": "ConnectWise",
"product": "ScreenConnect",
"name": "ConnectWise ScreenConnect Path Traversal Vulnerability",
"date_added": "2026-04-28",
"due_date": "2026-05-12",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.",
"epss": 0.87624,
"epss_percentile": 0.99742
},
{
"cve": "CVE-2024-57728",
"vendor": "SimpleHelp ",
"product": "SimpleHelp",
"name": "SimpleHelp Path Traversal Vulnerability",
"date_added": "2026-04-24",
"due_date": "2026-05-08",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.",
"epss": 0.06982,
"epss_percentile": 0.93433
},
{
"cve": "CVE-2024-57726",
"vendor": "SimpleHelp ",
"product": "SimpleHelp",
"name": "SimpleHelp Missing Authorization Vulnerability",
"date_added": "2026-04-24",
"due_date": "2026-05-08",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.",
"epss": 0.08632,
"epss_percentile": 0.94514
},
{
"cve": "CVE-2026-33825",
"vendor": "Microsoft",
"product": "Defender",
"name": "Microsoft Defender Insufficient Granularity of Access Control Vulnerability",
"date_added": "2026-04-22",
"due_date": "2026-05-06",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.",
"epss": 0.06749,
"epss_percentile": 0.93237
},
{
"cve": "CVE-2023-27351",
"vendor": "PaperCut",
"product": "NG/MF",
"name": "PaperCut NG/MF Improper Authentication Vulnerability",
"date_added": "2026-04-20",
"due_date": "2026-05-04",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"short_description": "PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.",
"epss": 0.77388,
"epss_percentile": 0.99508
},
{
"cve": "CVE-2024-27199",
"vendor": "JetBrains",
"product": "TeamCity",
"name": "JetBrains TeamCity Relative Path Traversal Vulnerability",
"date_added": "2026-04-20",
"due_date": "2026-05-04",
"ransomware": true,
"required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27349/cisa+kev+catalog?ransomware=true&limit=50' --header 'Authorization: Bearer YOUR_API_KEY'
{
"id": "CVE-2021-44228",
"epss": 0.99999,
"epss_percentile": 1,
"score_date": "2026-07-21"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27350/epss+exploit-probability+score?id=CVE-2021-44228' --header 'Authorization: Bearer YOUR_API_KEY'
{
"requested": 3,
"resolved": 3,
"highest_priority": "P1",
"by_tier": {
"P1": 2,
"P2": 1
},
"results": [
{
"id": "CVE-2021-44228",
"description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.",
"published": "2021-12-10T10:15:09.143",
"last_modified": "2026-06-17T04:12:05.460",
"status": "Analyzed",
"cwe": [
"CWE-20",
"CWE-400",
"CWE-502",
"CWE-917"
],
"products": [
"siemens:6bk1602-0aa12-0tp0_firmware",
"siemens:6bk1602-0aa12-0tp0",
"siemens:6bk1602-0aa22-0tp0_firmware",
"siemens:6bk1602-0aa22-0tp0",
"siemens:6bk1602-0aa32-0tp0_firmware",
"siemens:6bk1602-0aa32-0tp0",
"siemens:6bk1602-0aa42-0tp0_firmware",
"siemens:6bk1602-0aa42-0tp0",
"siemens:6bk1602-0aa52-0tp0_firmware",
"siemens:6bk1602-0aa52-0tp0",
"apache:log4j",
"siemens:sppa-t3000_ses3000_firmware",
"siemens:sppa-t3000_ses3000",
"siemens:capital",
"siemens:comos",
"siemens:desigo_cc_advanced_reports",
"siemens:desigo_cc_info_center",
"siemens:e-car_operation_center",
"siemens:energy_engage",
"siemens:energyip"
],
"cpe_ranges": [
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa12-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa22-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa32-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa42-0tp0",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0_firmware",
"vulnerable": true,
"versionEndExcluding": "2.7.0"
},
{
"vendor": "siemens",
"product": "6bk1602-0aa52-0tp0",
"vulnerable": false
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.0.1",
"versionEndExcluding": "2.3.1"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.4.0",
"versionEndExcluding": "2.12.2"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"versionStartIncluding": "2.13.0",
"versionEndExcluding": "2.15.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "apache",
"product": "log4j",
"vulnerable": true,
"version": "2.0"
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000_firmware",
"vulnerable": true
},
{
"vendor": "siemens",
"product": "sppa-t3000_ses3000",
"vulnerable": false
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"versionEndExcluding": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "capital",
"vulnerable": true,
"version": "2019.1"
},
{
"vendor": "siemens",
"product": "comos",
"vulnerable": true,
"versionEndExcluding": "10.4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "3.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "4.2"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_advanced_reports",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.0"
},
{
"vendor": "siemens",
"product": "desigo_cc_info_center",
"vulnerable": true,
"version": "5.1"
},
{
"vendor": "siemens",
"product": "e-car_operation_center",
"vulnerable": true,
"versionEndExcluding": "2021-12-13"
},
{
"vendor": "siemens",
"product": "energy_engage",
"vulnerable": true,
"version": "3.1"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true,
"version": "8.5"
},
{
"vendor": "siemens",
"product": "energyip",
"vulnerable": true
}
]
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27354/rank+a+list+of+cves+fix-first?ids=CVE-2021-44228,CVE-2019-19844,CVE-2014-0160&weaponized=true' --header 'Authorization: Bearer YOUR_API_KEY'
{
"days": 7,
"cutoff": "2026-07-15",
"count": 9,
"results": [
{
"cve": "CVE-2026-60137",
"vendor": "WordPress",
"product": "Core",
"name": "WordPress Core SQL Injection Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-08-04",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
"epss": 0.20395,
"epss_percentile": 0.97219
},
{
"cve": "CVE-2026-63030",
"vendor": "WordPress",
"product": "Core",
"name": "WordPress Core Interpretation Conflict Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-07-24",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
"epss": 0.38599,
"epss_percentile": 0.98425
},
{
"cve": "CVE-2026-0770",
"vendor": "Langflow",
"product": "Langflow",
"name": "Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-07-24",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. ",
"epss": 0.54503,
"epss_percentile": 0.98911
},
{
"cve": "CVE-2021-27137",
"vendor": "DD-WRT",
"product": "DD-WRT",
"name": "DD-WRT Stack-Based Buffer Overflow Vulnerability",
"date_added": "2026-07-21",
"due_date": "2026-07-24",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
"epss": 0.10809,
"epss_percentile": 0.95377
},
{
"cve": "CVE-2026-58644",
"vendor": "Microsoft",
"product": "SharePoint",
"name": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
"epss": 0.01465,
"epss_percentile": 0.709
},
{
"cve": "CVE-2026-25089",
"vendor": "Fortinet",
"product": "FortiSandbox",
"name": "Fortinet FortiSandbox OS Command Injection Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.",
"epss": 0.36135,
"epss_percentile": 0.98317
},
{
"cve": "CVE-2026-39808",
"vendor": "Fortinet",
"product": "FortiSandbox",
"name": "Fortinet FortiSandbox OS Command Injection Vulnerability",
"date_added": "2026-07-16",
"due_date": "2026-07-19",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
"epss": 0.84158,
"epss_percentile": 0.99669
},
{
"cve": "CVE-2026-46817",
"vendor": "Oracle",
"product": "E-Business Suite",
"name": "Oracle E-Business Suite Improper Privilege Management Vulnerability",
"date_added": "2026-07-15",
"due_date": "2026-07-18",
"ransomware": false,
"required_action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
"short_description": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.",
"epss": 0.01045,
"epss_percentile": 0.6053
},
{
"cve": "CVE-2023-4346",
"vendor": "KNX Association",
"product": "KNX Protocol Connection Authorization Option 1",
"name": "KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability",
"date_added": "2026-07-15",
"due_date": "2026-07-29",
"ransomware": false
}
],
"_note": "Response truncated for documentation purposes"
}
curl --location --request GET 'https://zylalabs.com/api/13270/vulnerability+intelligence+and+cve+prioritization+api/27355/newly+exploited+cves+kev+feed?days=7&limit=100' --header 'Authorization: Bearer YOUR_API_KEY'
साइन अप करने के बाद, प्रत्येक डेवलपर को एक पर्सनल API एक्सेस की असाइन की जाती है, जो अक्षरों और अंकों का एक यूनिक संयोजन होता है, जिसका उपयोग हमारे API एंडपॉइंट तक पहुंचने के लिए किया जाता है। प्रमाणीकरण के लिए जोखिम बुद्धिमत्ता और सीवीई प्राथमिकता API के साथ बस अपने बेयरर टोकन को Authorization हेडर में शामिल करें।
| हेडर | विवरण |
|---|---|
Authorization
|
आवश्यक
होना चाहिए Bearer access_key. जब आप सब्सक्राइब हों तो ऊपर "Your API Access Key" देखें।
|
कोई लंबी अवधि की प्रतिबद्धता नहीं। कभी भी अपग्रेड, डाउनग्रेड या कैंसल करें। फ्री ट्रायल में 50 रिक्वेस्ट तक शामिल हैं।
(वार्षिक बिलिंग के साथ 2 महीने बचाएँ 🎉)
अग्रणी कंपनियों का भरोसा
प्रत्येक एंडपॉइंट CVE के बारे में विस्तृत जानकारी लौटाता है जिसमें विवरण, प्रकाशित तिथियाँ, CVSS स्कोर, एक्सप्लॉइट संभावनाएँ और प्राथमिकता निर्णय शामिल हैं उदाहरण के लिए CVE लुकअप एंडपॉइंट एक विशेष CVE का व्यापक दृश्य प्रदान करता है जबकि पैकेज कमजोरी एंडपॉइंट सॉफ़्टवेयर पैकेज के लिए ज्ञात कमजोरियों को सूचीबद्ध करता है
मुख्य क्षेत्रों में "id" (CVE पहचानकर्ता), "description" (कमजोरी विवरण), "published" (प्रकाशन तिथि), "status" (विश्लेषण स्थिति), "cwe" (कॉमन वीकनेस एन्यूरेशन), और "priority" (P1-P5 निर्णय) शामिल हैं ये क्षेत्र कमजोरियों की गंभीरता और प्रासंगिकता का आकलन करने में मदद करते हैं
उपायं अंक निर्धारण बिंदु के अनुसार भिन्न होते हैं। CVE खोज अंत बिंदु के लिए, आप "q" (कीवर्ड), "severity" (गंभीरता स्तर), या "cpe" (कॉमन प्लेटफ़ॉर्म अनुक्रमण) का उपयोग कर सकते हैं। पैकेज कमजोरियों के अंत बिंदु में परिणामों को संकीर्ण करने के लिए "पैकेज" और "संस्करण" निर्दिष्ट करने की अनुमति होती है
प्रतिक्रिया डेटा JSON फॉर्मेट में संरचित है जिसमें शीर्ष स्तरीय फ़ील्ड कुल परिणामों की गणना और व्यक्तिगत CVE प्रविष्टियों को समाहित करने वाला "परिणाम" का एक एरे है प्रत्येक प्रविष्टि में "विवरण" "प्रकाशित" और "स्थिर_संस्करण" जैसे विस्तृत विशेषताएँ शामिल हैं
एपीआई कई विश्वसनीय स्रोतों से डेटा एकत्र करता है जिसमें नेशनल वल्नेरबिलिटी डेटाबेस (एनवीडी) CISA का ज्ञात शोषित कमजोरियों (केईवी) सूची और FIRST का शोषण भविष्यवाणी स्कोरिंग सिस्टम (ईपीएसएस) शामिल हैं यह व्यापक और विश्वसनीय कमजोरियों की जानकारी सुनिश्चित करता है
विशिष्ट उपयोग के मामले में कमजोरियों का प्रबंधन जोखिम मूल्यांकन और पैचिंग प्रयासों की प्राथमिकता शामिल हैं सुरक्षा टीमें अपने सॉफ़्टवेयर निर्भरताओं में महत्वपूर्ण कमजोरियों की पहचान करने और सुधार पर समझदारी से निर्णय लेने के लिए एपीआई का उपयोग कर सकती हैं
उपयोगकर्ता लौटाई गई डेटा का विश्लेषण करके गंभीरता और शोषणीयता के आधार पर कमजोरियों को प्राथमिकता दे सकते हैं उदाहरण के लिए उच्च EPSS स्कोर वाले P1-P2 कमजोरियों पर ध्यान केंद्रित करके संगठन संसाधनों को प्रभावी ढंग से आवंटित कर सकते हैं ताकि जोखिम को कम किया जा सके
डेटा की सटीकता को प्राधिकृत स्रोतों से नियमित अपडेट और संगति के लिए स्वचालित जांचों के माध्यम से बनाए रखा जाता है एपीआई कई डेटासेट को एकीकृत करता है जानकारी को पार-रेफरेंस करके यह सुनिश्चित करता है कि उपयोगकर्ताओं को सबसे सटीक और अद्यतन संवेदनशीलता डेटा प्राप्त हो