{"catalogVersion":"2026.08.26","dateReleased":"2026-08-26T17:00:09.8976Z","summary":{"catalog":1682,"included":244,"review":125,"excluded":1313},"reviewQueue":[{"cve":"CVE-2026-8452","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","cwes":["CWE-119"]},{"cve":"CVE-2026-20349","vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)","cwes":["CWE-244"]},{"cve":"CVE-2026-15410","vendor":"SonicWall","product":"SMA1000 Appliances","cwes":["CWE-94"]},{"cve":"CVE-2008-4128","vendor":"Cisco","product":"IOS","cwes":["CWE-352"]},{"cve":"CVE-2026-20262","vendor":"Cisco","product":"Catalyst SD-WAN Manager","cwes":["CWE-22"]},{"cve":"CVE-2026-20245","vendor":"Cisco","product":"Catalyst SD-WAN Manager","cwes":["CWE-116"]},{"cve":"CVE-2026-6973","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","cwes":["CWE-20"]},{"cve":"CVE-2024-1708","vendor":"ConnectWise","product":"ScreenConnect","cwes":["CWE-22"]},{"cve":"CVE-2024-57728","vendor":"SimpleHelp","product":"SimpleHelp","cwes":["CWE-22"]},{"cve":"CVE-2026-20122","vendor":"Cisco","product":"Catalyst SD-WAN Manger","cwes":["CWE-648"]},{"cve":"CVE-2026-20133","vendor":"Cisco","product":"Catalyst SD-WAN Manager","cwes":["CWE-200"]},{"cve":"CVE-2026-20128","vendor":"Cisco","product":"Catalyst SD-WAN Manager","cwes":["CWE-257"]},{"cve":"CVE-2026-1340","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","cwes":["CWE-94"]},{"cve":"CVE-2025-26399","vendor":"SolarWinds","product":"Web Help Desk","cwes":["CWE-502"]},{"cve":"CVE-2026-1281","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","cwes":["CWE-94"]},{"cve":"CVE-2025-20393","vendor":"Cisco","product":"Multiple Products","cwes":["CWE-20"]},{"cve":"CVE-2025-58034","vendor":"Fortinet","product":"FortiWeb","cwes":["CWE-78"]},{"cve":"CVE-2025-20352","vendor":"Cisco","product":"IOS and IOS XE","cwes":["CWE-121"]},{"cve":"CVE-2025-20333","vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense","cwes":["CWE-120"]},{"cve":"CVE-2025-7775","vendor":"Citrix","product":"NetScaler","cwes":["CWE-119"]},{"cve":"CVE-2024-8069","vendor":"Citrix","product":"Session Recording","cwes":["CWE-502"]},{"cve":"CVE-2025-8876","vendor":"N-able","product":"N-Central","cwes":[]},{"cve":"CVE-2025-8875","vendor":"N-able","product":"N-Central","cwes":[]},{"cve":"CVE-2025-20337","vendor":"Cisco","product":"Identity Services Engine","cwes":["CWE-74"]},{"cve":"CVE-2025-20281","vendor":"Cisco","product":"Identity Services Engine","cwes":["CWE-74"]},{"cve":"CVE-2025-5777","vendor":"Citrix","product":"NetScaler ADC and Gateway","cwes":["CWE-125"]},{"cve":"CVE-2025-6543","vendor":"Citrix","product":"NetScaler ADC and Gateway","cwes":["CWE-119"]},{"cve":"CVE-2025-4428","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","cwes":["CWE-94"]},{"cve":"CVE-2023-44221","vendor":"SonicWall","product":"SMA100 Appliances","cwes":["CWE-78"]},{"cve":"CVE-2021-20035","vendor":"SonicWall","product":"SMA100 Appliances","cwes":["CWE-78"]},{"cve":"CVE-2023-20118","vendor":"Cisco","product":"Small Business RV Series Routers","cwes":["CWE-77"]},{"cve":"CVE-2024-12686","vendor":"BeyondTrust","product":"Privileged Remote Access (PRA) and Remote Support (RS)","cwes":["CWE-78"]},{"cve":"CVE-2025-0282","vendor":"Ivanti","product":"Connect Secure, Policy Secure, and ZTA Gateways","cwes":["CWE-121"]},{"cve":"CVE-2014-2120","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","cwes":["CWE-79"]},{"cve":"CVE-2024-20481","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","cwes":["CWE-772"]},{"cve":"CVE-2024-9380","vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","cwes":["CWE-77"]},{"cve":"CVE-2024-9379","vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","cwes":["CWE-89"]},{"cve":"CVE-2024-8190","vendor":"Ivanti","product":"Cloud Services Appliance","cwes":["CWE-78"]},{"cve":"CVE-2024-40766","vendor":"SonicWall","product":"SonicOS","cwes":["CWE-284"]},{"cve":"CVE-2024-28986","vendor":"SolarWinds","product":"Web Help Desk","cwes":["CWE-502"]},{"cve":"CVE-2024-28995","vendor":"SolarWinds","product":"Serv-U","cwes":["CWE-22"]},{"cve":"CVE-2024-20399","vendor":"Cisco","product":"NX-OS","cwes":["CWE-78"]},{"cve":"CVE-2024-20353","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","cwes":["CWE-835"]},{"cve":"CVE-2020-3259","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","cwes":["CWE-200"]},{"cve":"CVE-2023-6549","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","cwes":["CWE-119"]},{"cve":"CVE-2023-6548","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","cwes":["CWE-94"]},{"cve":"CVE-2024-21887","vendor":"Ivanti","product":"Connect Secure and Policy Secure","cwes":["CWE-77"]},{"cve":"CVE-2023-4966","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","cwes":["CWE-119"]},{"cve":"CVE-2023-20109","vendor":"Cisco","product":"IOS and IOS XE","cwes":["CWE-787"]},{"cve":"CVE-2023-3519","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","cwes":["CWE-94"]},{"cve":"CVE-2004-1464","vendor":"Cisco","product":"IOS","cwes":[]},{"cve":"CVE-2016-6415","vendor":"Cisco","product":"IOS, IOS XR, and IOS XE","cwes":["CWE-200"]},{"cve":"CVE-2017-6742","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2022-41328","vendor":"Fortinet","product":"FortiOS","cwes":["CWE-22"]},{"cve":"CVE-2020-3433","vendor":"Cisco","product":"AnyConnect Secure","cwes":["CWE-427"]},{"cve":"CVE-2020-3153","vendor":"Cisco","product":"AnyConnect Secure","cwes":["CWE-427"]},{"cve":"CVE-2018-13374","vendor":"Fortinet","product":"FortiOS and FortiADC","cwes":["CWE-732"]},{"cve":"CVE-2019-15271","vendor":"Cisco","product":"RV Series Routers","cwes":["CWE-502"]},{"cve":"CVE-2016-6366","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","cwes":["CWE-119"]},{"cve":"CVE-2016-6367","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","cwes":["CWE-77"]},{"cve":"CVE-2022-20821","vendor":"Cisco","product":"IOS XR","cwes":["CWE-923"]},{"cve":"CVE-2021-20028","vendor":"SonicWall","product":"Secure Remote Access (SRA)","cwes":["CWE-89"]},{"cve":"CVE-2019-7483","vendor":"SonicWall","product":"SMA100","cwes":["CWE-22"]},{"cve":"CVE-2019-12991","vendor":"Citrix","product":"SD-WAN and NetScaler","cwes":["CWE-78"]},{"cve":"CVE-2019-12989","vendor":"Citrix","product":"SD-WAN and NetScaler","cwes":["CWE-89"]},{"cve":"CVE-2018-11138","vendor":"Quest","product":"KACE System Management Appliance","cwes":["CWE-78"]},{"cve":"CVE-2015-0666","vendor":"Cisco","product":"Prime Data Center Network Manager (DCNM)","cwes":["CWE-22"]},{"cve":"CVE-2010-3035","vendor":"Cisco","product":"IOS XR","cwes":["CWE-20"]},{"cve":"CVE-2009-2055","vendor":"Cisco","product":"IOS XR","cwes":["CWE-20"]},{"cve":"CVE-2020-5135","vendor":"SonicWall","product":"SonicOS","cwes":["CWE-120"]},{"cve":"CVE-2020-8218","vendor":"Pulse Secure","product":"Pulse Connect Secure","cwes":["CWE-94"]},{"cve":"CVE-2019-1652","vendor":"Cisco","product":"Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers","cwes":["CWE-20"]},{"cve":"CVE-2018-0180","vendor":"Cisco","product":"IOS Software","cwes":["CWE-399"]},{"cve":"CVE-2018-0179","vendor":"Cisco","product":"IOS Software","cwes":["CWE-399"]},{"cve":"CVE-2018-0174","vendor":"Cisco","product":"IOS XE Software","cwes":["CWE-20"]},{"cve":"CVE-2018-0173","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-20"]},{"cve":"CVE-2018-0172","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-20"]},{"cve":"CVE-2018-0167","vendor":"Cisco","product":"IOS, XR, and XE Software","cwes":["CWE-119"]},{"cve":"CVE-2018-0161","vendor":"Cisco","product":"IOS Software","cwes":["CWE-399"]},{"cve":"CVE-2018-0159","vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","cwes":["CWE-20"]},{"cve":"CVE-2018-0156","vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","cwes":["CWE-399"]},{"cve":"CVE-2018-0155","vendor":"Cisco","product":"Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches","cwes":["CWE-388"]},{"cve":"CVE-2018-0154","vendor":"Cisco","product":"IOS Software","cwes":["CWE-399"]},{"cve":"CVE-2017-6744","vendor":"Cisco","product":"IOS software","cwes":["CWE-119"]},{"cve":"CVE-2017-6743","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2017-6740","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2017-6739","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2017-6738","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2017-6737","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2017-6736","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-119"]},{"cve":"CVE-2017-6663","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":[]},{"cve":"CVE-2017-6627","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-399"]},{"cve":"CVE-2017-12319","vendor":"Cisco","product":"IOS XE Software","cwes":["CWE-20"]},{"cve":"CVE-2017-12238","vendor":"Cisco","product":"Catalyst 6800 Series Switches","cwes":["CWE-399"]},{"cve":"CVE-2017-12237","vendor":"Cisco","product":"IOS and IOS XE Software","cwes":["CWE-399"]},{"cve":"CVE-2017-12235","vendor":"Cisco","product":"IOS software","cwes":["CWE-20"]},{"cve":"CVE-2017-12234","vendor":"Cisco","product":"IOS software","cwes":["CWE-20"]},{"cve":"CVE-2017-12233","vendor":"Cisco","product":"IOS software","cwes":["CWE-20"]},{"cve":"CVE-2017-12232","vendor":"Cisco","product":"IOS software","cwes":["CWE-399"]},{"cve":"CVE-2017-12231","vendor":"Cisco","product":"IOS software","cwes":["CWE-399"]},{"cve":"CVE-2021-20038","vendor":"SonicWall","product":"SMA 100 Appliances","cwes":["CWE-121"]},{"cve":"CVE-2021-35247","vendor":"SolarWinds","product":"Serv-U","cwes":["CWE-20"]},{"cve":"CVE-2018-13383","vendor":"Fortinet","product":"FortiOS and FortiProxy","cwes":["CWE-787"]},{"cve":"CVE-2021-44168","vendor":"Fortinet","product":"FortiOS","cwes":["CWE-494"]},{"cve":"CVE-2020-3452","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","cwes":["CWE-20"]},{"cve":"CVE-2020-3580","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","cwes":["CWE-79"]},{"cve":"CVE-2021-1497","vendor":"Cisco","product":"HyperFlex HX","cwes":["CWE-78"]},{"cve":"CVE-2021-1498","vendor":"Cisco","product":"HyperFlex HX","cwes":["CWE-78"]},{"cve":"CVE-2018-0171","vendor":"Cisco","product":"IOS and IOS XE","cwes":["CWE-20"]},{"cve":"CVE-2020-3118","vendor":"Cisco","product":"IOS XR","cwes":["CWE-134"]},{"cve":"CVE-2020-3161","vendor":"Cisco","product":"Cisco IP Phones","cwes":["CWE-20"]},{"cve":"CVE-2019-1653","vendor":"Cisco","product":"Small Business RV320 and RV325 Routers","cwes":["CWE-284"]},{"cve":"CVE-2018-0296","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","cwes":["CWE-20"]},{"cve":"CVE-2020-8195","vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","cwes":["CWE-20"]},{"cve":"CVE-2020-8196","vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","cwes":["CWE-284"]},{"cve":"CVE-2019-11634","vendor":"Citrix","product":"Workspace Application and Receiver for Windows","cwes":[]},{"cve":"CVE-2021-35464","vendor":"ForgeRock","product":"Access Management (AM)","cwes":["CWE-502"]},{"cve":"CVE-2020-15505","vendor":"Ivanti","product":"MobileIron Multiple Products","cwes":["CWE-706"]},{"cve":"CVE-2020-8243","vendor":"Ivanti","product":"Pulse Connect Secure","cwes":["CWE-94"]},{"cve":"CVE-2021-22900","vendor":"Ivanti","product":"Pulse Connect Secure","cwes":["CWE-94"]},{"cve":"CVE-2021-22894","vendor":"Ivanti","product":"Pulse Connect Secure","cwes":["CWE-94"]},{"cve":"CVE-2020-8260","vendor":"Ivanti","product":"Pulse Connect Secure","cwes":["CWE-434"]},{"cve":"CVE-2021-22899","vendor":"Ivanti","product":"Pulse Connect Secure","cwes":["CWE-77"]},{"cve":"CVE-2019-11539","vendor":"Ivanti","product":"Pulse Connect Secure and Pulse Policy Secure","cwes":["CWE-78"]},{"cve":"CVE-2021-35211","vendor":"SolarWinds","product":"Serv-U","cwes":["CWE-787"]}],"decisions":[{"cve":"CVE-2021-23758","vendor":"Ajax.NET Professional","product":"Ajax.NET Professional","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-3246","vendor":"Red Hat","product":"Libuser","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-5287","vendor":"Red Hat","product":"Automatic Bug Reporting Tool","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0995","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-8452","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but impact is denial of service only"},{"cve":"CVE-2019-1068","vendor":"Microsoft","product":"SQL Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-60004","vendor":"Gitea","product":"Gitea","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21962","vendor":"Oracle","product":"HTTP Server and Oracle Weblogic Server Proxy Plug-in","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-73570","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-72530","vendor":"TrueConf","product":"Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-72529","vendor":"TrueConf","product":"Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-64849","vendor":"MLflow","product":"MLflow","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-33824","vendor":"Microsoft","product":"Internet Key Exchange (IKE) Service Extensions","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-59310","vendor":"Broadcom","product":"VMware vCenter","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-55040","vendor":"Microsoft","product":"SharePoint","outcome":"included","reason":"classified via cwe: federation-trust"},{"cve":"CVE-2026-65400","vendor":"Apple","product":"macOS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-62593","vendor":"Ray-Project","product":"Ray","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20349","vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2026-68820","vendor":"Microsoft","product":"Windows Ancillary Function Driver for WinSock","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-72898","vendor":"Metabase","product":"Metabase","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-8037","vendor":"Progress","product":"LoadMaster","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-63077","vendor":"JetBrains","product":"TeamCity","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-18556","vendor":"N-able","product":"N-central","outcome":"included","reason":"vendor: N-able; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-34486","vendor":"Apache","product":"Tomcat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-9198","vendor":"IBM","product":"Langflow","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-18577","vendor":"N-able","product":"N-central","outcome":"included","reason":"vendor: N-able; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-20316","vendor":"Cisco","product":"Secure Firewall Management Center (FMC)","outcome":"included","reason":"vendor: Cisco/Duo; classified via cwe: credential-exposure"},{"cve":"CVE-2025-68686","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-16812","vendor":"Arista","product":"VeloCloud Orchestrator","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-16232","vendor":"Check Point","product":"SmartConsole","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-50522","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-60137","vendor":"WordPress","product":"Core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-63030","vendor":"WordPress","product":"Core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-0770","vendor":"Langflow","product":"Langflow","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27137","vendor":"DD-WRT","product":"DD-WRT","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-58644","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-25089","vendor":"Fortinet","product":"FortiSandbox","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-39808","vendor":"Fortinet","product":"FortiSandbox","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-46817","vendor":"Oracle","product":"E-Business Suite","outcome":"included","reason":"classified via cwe: privilege-escalation, pre-auth-bypass"},{"cve":"CVE-2023-4346","vendor":"KNX Association","product":"KNX Protocol Connection Authorization Option 1","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-56155","vendor":"Microsoft","product":"Active Directory Federation Services","outcome":"included","reason":"vendor: Microsoft identity; classified via keyword: federation-trust, privilege-escalation"},{"cve":"CVE-2026-56164","vendor":"Microsoft","product":"SharePoint Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-15409","vendor":"SonicWall","product":"SMA1000 Appliances","outcome":"included","reason":"vendor: SonicWall; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-15410","vendor":"SonicWall","product":"SMA1000 Appliances","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2008-4128","vendor":"Cisco","product":"IOS","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2026-56291","vendor":"Balbooa","product":"Forms","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-48939","vendor":"iCagenda","product":"iCagenda","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-48908","vendor":"JoomShaper","product":"SP Page Builder","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-55255","vendor":"Langflow","product":"Langflow","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-56290","vendor":"Joomlack","product":"Page Builder","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-48282","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-45659","vendor":"Microsoft","product":"SharePoint Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-48558","vendor":"SimpleHelp","product":"SimpleHelp","outcome":"included","reason":"vendor: SimpleHelp; classified via cwe: federation-trust"},{"cve":"CVE-2026-12569","vendor":"PTC","product":"Windchill and FlexPLM","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20230","vendor":"Cisco","product":"Unified Communications Manager","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-67038","vendor":"Lantronix","product":"EDS5000","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-34910","vendor":"Ubiquiti","product":"UniFi OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-34909","vendor":"Ubiquiti","product":"UniFi OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-34908","vendor":"Ubiquiti","product":"UniFi OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20253","vendor":"Splunk","product":"Enterprise","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-48907","vendor":"Widget Factory","product":"Joomla Content Editor","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-54420","vendor":"LiteSpeed","product":"cPanel Plugin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20262","vendor":"Cisco","product":"Catalyst SD-WAN Manager","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2026-35273","vendor":"Oracle","product":"PeopleSoft Enterprise PeopleTools","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-10520","vendor":"Ivanti","product":"Sentry","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-11645","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-7473","vendor":"Arista","product":"Extensible Operating System","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20245","vendor":"Cisco","product":"Catalyst SD-WAN Manager","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2026-42271","vendor":"BerriAI","product":"LiteLLM","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-50751","vendor":"Check Point","product":"Security Gateway","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-28318","vendor":"SolarWinds","product":"Serv-U","outcome":"included","reason":"vendor: N-able; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-45247","vendor":"Mirasvit","product":"Mirasvit Full Page Cache Warmer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0492","vendor":"Linux","product":"Kernel","outcome":"included","reason":"classified via cwe: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2025-48595","vendor":"Android","product":"Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-21182","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-0257","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"included","reason":"classified via cwe: session-handling"},{"cve":"CVE-2026-48027","vendor":"Nx","product":"Nx Console","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-45321","vendor":"TanStack","product":"TanStack","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-8398","vendor":"Daemon","product":"Daemon Tools Lite","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-48172","vendor":"LiteSpeed","product":"cPanel Plugin","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2026-9082","vendor":"Drupal","product":"Core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-34291","vendor":"Langflow","product":"Langflow","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-34926","vendor":"Trend Micro","product":"Apex One","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2008-4250","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-1537","vendor":"Microsoft","product":"DirectX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-3459","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-0249","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-0806","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-41091","vendor":"Microsoft","product":"Defender","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-45498","vendor":"Microsoft","product":"Defender","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-42897","vendor":"Microsoft","product":"Microsoft","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20182","vendor":"Cisco","product":"Catalyst SD-WAN","outcome":"included","reason":"vendor: Cisco/Duo; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-42208","vendor":"BerriAI","product":"LiteLLM","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-6973","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2026-0300","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-31431","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-41940","vendor":"WebPros","product":"cPanel & WHM and WP2 (WordPress Squared)","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-1708","vendor":"ConnectWise","product":"ScreenConnect","outcome":"review","reason":"relevant (vendor: ConnectWise) but classifies to no failure mode"},{"cve":"CVE-2026-32202","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-29635","vendor":"D-Link","product":"DIR-823X","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-7399","vendor":"Samsung","product":"MagicINFO 9 Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-57728","vendor":"SimpleHelp","product":"SimpleHelp","outcome":"review","reason":"relevant (vendor: SimpleHelp) but classifies to no failure mode"},{"cve":"CVE-2024-57726","vendor":"SimpleHelp","product":"SimpleHelp","outcome":"included","reason":"vendor: SimpleHelp; classified via cwe: privilege-escalation"},{"cve":"CVE-2026-39987","vendor":"Marimo","product":"Marimo","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-33825","vendor":"Microsoft","product":"Defender","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20122","vendor":"Cisco","product":"Catalyst SD-WAN Manger","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2026-20133","vendor":"Cisco","product":"Catalyst SD-WAN Manager","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2025-2749","vendor":"Kentico","product":"Kentico Xperience","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-27351","vendor":"PaperCut","product":"NG/MF","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-48700","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20128","vendor":"Cisco","product":"Catalyst SD-WAN Manager","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2025-32975","vendor":"Quest","product":"KACE Systems Management Appliance (SMA)","outcome":"included","reason":"vendor: One Identity; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-27199","vendor":"JetBrains","product":"TeamCity","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-34197","vendor":"Apache","product":"ActiveMQ","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-0238","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-32201","vendor":"Microsoft","product":"SharePoint Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1854","vendor":"Microsoft","product":"Visual Basic for Applications (VBA)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-60710","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-21529","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36424","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9715","vendor":"Adobe","product":"Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21643","vendor":"Fortinet","product":"FortiClient EMS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-34621","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-1340","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2026-35616","vendor":"Fortinet","product":"FortiClient EMS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-3502","vendor":"TrueConf","product":"Client","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-5281","vendor":"Google","product":"Dawn","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-3055","vendor":"Citrix","product":"NetScaler","outcome":"included","reason":"vendor: Citrix; classified via keyword: federation-trust"},{"cve":"CVE-2025-53521","vendor":"F5","product":"BIG-IP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-33634","vendor":"Aquasecurity","product":"Trivy","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-33017","vendor":"Langflow","product":"Langflow","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-32432","vendor":"Craft CMS","product":"Craft CMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-54068","vendor":"Laravel","product":"Livewire","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-43510","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-43520","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-31277","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20131","vendor":"Cisco","product":"Secure Firewall Management Center (FMC)","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-66376","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20963","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-47813","vendor":"Wing FTP Server","product":"Wing FTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-3910","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-3909","vendor":"Google","product":"Skia","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-68613","vendor":"n8n","product":"n8n","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22054","vendor":"Omnissa","product":"Workspace One UEM","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-26399","vendor":"SolarWinds","product":"Web Help Desk","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2026-1603","vendor":"Ivanti","product":"Endpoint Manager (EPM)","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2017-7921","vendor":"Hikvision","product":"Multiple Products","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-22681","vendor":"Rockwell","product":"Multiple Products","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2023-43000","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30952","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41974","vendor":"Apple","product":"iOS and iPadOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-22719","vendor":"Broadcom","product":"VMware Aria Operations","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21385","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-20775","vendor":"Cisco","product":"SD-WAN","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: privilege-escalation"},{"cve":"CVE-2026-20127","vendor":"Cisco","product":"Catalyst SD-WAN Controller and Manager","outcome":"included","reason":"vendor: Cisco/Duo; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-25108","vendor":"Soliton Systems K.K","product":"FileZen","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-49113","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-68461","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22175","vendor":"GitLab","product":"GitLab","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-22769","vendor":"Dell","product":"RecoverPoint for Virtual Machines (RP4VMs)","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2020-7796","vendor":"Synacor","product":"Zimbra Collaboration Suite","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-7694","vendor":"TeamT5","product":"ThreatSonar Anti-Ransomware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2008-0015","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-2441","vendor":"Google","product":"Chromium","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-1731","vendor":"BeyondTrust","product":"Remote Support (RS) and Privileged Remote Access (PRA)","outcome":"included","reason":"vendor: BeyondTrust; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-20700","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-43468","vendor":"Microsoft","product":"Configuration Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-15556","vendor":"Notepad++","product":"Notepad++","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-40536","vendor":"SolarWinds","product":"Web Help Desk","outcome":"included","reason":"vendor: N-able; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-21513","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21525","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21510","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21533","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2026-21519","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21514","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-11953","vendor":"React Native Community","product":"CLI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-24423","vendor":"SmarterTools","product":"SmarterMail","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-39935","vendor":"GitLab","product":"Community and Enterprise Editions","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-64328","vendor":"Sangoma","product":"FreePBX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-19006","vendor":"Sangoma","product":"FreePBX","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-40551","vendor":"SolarWinds","product":"Web Help Desk","outcome":"included","reason":"vendor: N-able; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2026-1281","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2026-24858","vendor":"Fortinet","product":"Multiple Products","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2018-14634","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-52691","vendor":"SmarterTools","product":"SmarterMail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-23760","vendor":"SmarterTools","product":"SmarterMail","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2026-24061","vendor":"GNU","product":"InetUtils","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-21509","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-37079","vendor":"Broadcom","product":"VMware vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-68645","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-34026","vendor":"Versa","product":"Concerto","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-31125","vendor":"Vite","product":"Vitejs","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-54313","vendor":"Prettier","product":"eslint-config-prettier","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2026-20045","vendor":"Cisco","product":"Unified Communications Manager","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: privilege-escalation"},{"cve":"CVE-2026-20805","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-8110","vendor":"Gogs","product":"Gogs","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-0556","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-37164","vendor":"Hewlett Packard Enterprise (HPE)","product":"OneView","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-14847","vendor":"MongoDB","product":"MongoDB and MongoDB Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-52163","vendor":"Digiever","product":"DS-2105 Pro","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2025-14733","vendor":"WatchGuard","product":"Firebox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-59374","vendor":"ASUS","product":"Live Update","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-40602","vendor":"SonicWall","product":"SMA1000 appliance","outcome":"included","reason":"vendor: SonicWall; classified via cwe: privilege-escalation"},{"cve":"CVE-2025-20393","vendor":"Cisco","product":"Multiple Products","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2025-59718","vendor":"Fortinet","product":"Multiple Products","outcome":"included","reason":"vendor: Fortinet; classified via cwe: federation-trust"},{"cve":"CVE-2025-14611","vendor":"Gladinet","product":"CentreStack and Triofox","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2025-43529","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-4063","vendor":"Sierra Wireless","product":"AirLink ALEOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-14174","vendor":"Google","product":"Chromium","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-58360","vendor":"OSGeo","product":"GeoServer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-6218","vendor":"RARLAB","product":"WinRAR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-62221","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-37055","vendor":"D-Link","product":"Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-66644","vendor":"Array Networks","product":"ArrayOS AG","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-55182","vendor":"Meta","product":"React Server Components","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26828","vendor":"OpenPLC","product":"ScadaBR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-48633","vendor":"Android","product":"Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-48572","vendor":"Android","product":"Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26829","vendor":"OpenPLC","product":"ScadaBR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-61757","vendor":"Oracle","product":"Fusion Middleware","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-13223","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-58034","vendor":"Fortinet","product":"FortiWeb","outcome":"review","reason":"relevant (vendor: Fortinet) but classifies to no failure mode"},{"cve":"CVE-2025-64446","vendor":"Fortinet","product":"FortiWeb","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-12480","vendor":"Gladinet","product":"Triofox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-62215","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-9242","vendor":"WatchGuard","product":"Firebox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21042","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-48703","vendor":"CWP","product":"Control Web Panel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-11371","vendor":"Gladinet","product":"CentreStack and Triofox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-41244","vendor":"Broadcom","product":"VMware Aria Operations and VMware Tools","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24893","vendor":"XWiki","product":"Platform","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-6204","vendor":"Dassault Systèmes","product":"DELMIA Apriso","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-6205","vendor":"Dassault Systèmes","product":"DELMIA Apriso","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2025-54236","vendor":"Adobe","product":"Commerce and Magento","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-59287","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-61932","vendor":"Motex","product":"LANSCOPE Endpoint Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-48503","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-2746","vendor":"Kentico","product":"Xperience CMS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-2747","vendor":"Kentico","product":"Xperience CMS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-33073","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-61884","vendor":"Oracle","product":"E-Business Suite","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-54253","vendor":"Adobe","product":"Experience Manager (AEM) Forms","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-47827","vendor":"IGEL","product":"IGEL OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24990","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-59230","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7836","vendor":"SKYSEA","product":"Client View","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-43798","vendor":"Grafana Labs","product":"Grafana","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-27915","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22555","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-3962","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-43226","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3918","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-3402","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-3765","vendor":"Mozilla","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-61882","vendor":"Oracle","product":"E-Business Suite","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-6278","vendor":"GNU","product":"GNU Bash","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-1000353","vendor":"Jenkins","product":"Jenkins","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-7755","vendor":"Juniper","product":"ScreenOS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-21043","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-4008","vendor":"Smartbedded","product":"Meteobridge","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-32463","vendor":"Sudo","product":"Sudo","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-59689","vendor":"Libraesva","product":"Email Security Gateway","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-10035","vendor":"Fortra","product":"GoAnywhere MFT","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-20352","vendor":"Cisco","product":"IOS and IOS XE","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2021-21311","vendor":"Adminer","product":"Adminer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-20362","vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense","outcome":"included","reason":"vendor: Cisco/Duo; classified via cwe: privilege-escalation"},{"cve":"CVE-2025-20333","vendor":"Cisco","product":"Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2025-10585","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-5086","vendor":"Dassault Systèmes","product":"DELMIA Apriso","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-38352","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-48543","vendor":"Android","product":"Runtime","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-53690","vendor":"Sitecore","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-50224","vendor":"TP-Link","product":"TL-WR841N","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-9377","vendor":"TP-Link","product":"Multiple Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-24363","vendor":"TP-Link","product":"TL-WA855RE","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-55177","vendor":"Meta Platforms","product":"WhatsApp","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2025-57819","vendor":"Sangoma","product":"FreePBX","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-7775","vendor":"Citrix","product":"NetScaler","outcome":"review","reason":"relevant (vendor: Citrix) but impact is denial of service only"},{"cve":"CVE-2025-48384","vendor":"Git","product":"Git","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-8068","vendor":"Citrix","product":"Session Recording","outcome":"included","reason":"vendor: Citrix; classified via cwe: privilege-escalation"},{"cve":"CVE-2024-8069","vendor":"Citrix","product":"Session Recording","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2025-43300","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-54948","vendor":"Trend Micro","product":"Apex One","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-8876","vendor":"N-able","product":"N-Central","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2025-8875","vendor":"N-able","product":"N-Central","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2025-8088","vendor":"RARLAB","product":"WinRAR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2007-0671","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3893","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-25078","vendor":"D-Link","product":"DCS-2530L and DCS-2670L Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-25079","vendor":"D-Link","product":"DCS-2530L and DCS-2670L Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-40799","vendor":"D-Link","product":"DNR-322L","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-2533","vendor":"PaperCut","product":"NG/MF","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-20337","vendor":"Cisco","product":"Identity Services Engine","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2025-20281","vendor":"Cisco","product":"Identity Services Engine","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2025-2775","vendor":"SysAid","product":"SysAid On-Prem","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-2776","vendor":"SysAid","product":"SysAid On-Prem","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-6558","vendor":"Google","product":"Chromium","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-54309","vendor":"CrushFTP","product":"CrushFTP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-49704","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-49706","vendor":"Microsoft","product":"SharePoint","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-53770","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-25257","vendor":"Fortinet","product":"FortiWeb","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-47812","vendor":"Wing FTP Server","product":"Wing FTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-5777","vendor":"Citrix","product":"NetScaler ADC and Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2019-9621","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-5418","vendor":"Rails","product":"Ruby on Rails","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-10033","vendor":"PHP","product":"PHPMailer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-3931","vendor":"Looking Glass","product":"Multi-Router Looking Glass (MRLG)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-6554","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-48928","vendor":"TeleMessage","product":"TM SGNL","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-48927","vendor":"TeleMessage","product":"TM SGNL","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-6543","vendor":"Citrix","product":"NetScaler ADC and Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but impact is denial of service only"},{"cve":"CVE-2019-6693","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via cwe: credential-exposure"},{"cve":"CVE-2024-0769","vendor":"D-Link","product":"DIR-859 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-54085","vendor":"AMI","product":"MegaRAC SPx","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-0386","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33538","vendor":"TP-Link","product":"Multiple Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-43200","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-33053","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24016","vendor":"Wazuh","product":"Wazuh Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-42009","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-32433","vendor":"Erlang","product":"Erlang/OTP","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-5419","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21479","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2025-21480","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2025-27038","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-32030","vendor":"ASUS","product":"Routers","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-3935","vendor":"ConnectWise","product":"ScreenConnect","outcome":"included","reason":"vendor: ConnectWise; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-35939","vendor":"Craft CMS","product":"Craft CMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-56145","vendor":"Craft CMS","product":"Craft CMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-39780","vendor":"ASUS","product":"RT-AX55 Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-4632","vendor":"Samsung","product":"MagicINFO 9 Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-38950","vendor":"ZKTeco","product":"BioTime","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-27443","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-27920","vendor":"Srimax","product":"Output Messenger","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-11182","vendor":"MDaemon","product":"Email Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-4428","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2025-4427","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-42999","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-12987","vendor":"DrayTek","product":"Vigor Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-32756","vendor":"Fortinet","product":"Multiple Products","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-32709","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-30397","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-32706","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-32701","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-30400","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-47729","vendor":"TeleMessage","product":"TM SGNL","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-11120","vendor":"GeoVision","product":"Multiple Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-6047","vendor":"GeoVision","product":"Multiple Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-27363","vendor":"FreeType","product":"FreeType","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-3248","vendor":"Langflow","product":"Langflow","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-34028","vendor":"Commvault","product":"Command Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-58136","vendor":"Yiiframework","product":"Yii","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38475","vendor":"Apache","product":"HTTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-44221","vendor":"SonicWall","product":"SMA100 Appliances","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2025-31324","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-1976","vendor":"Broadcom","product":"Brocade Fabric OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-42599","vendor":"Qualitia","product":"Active! Mail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-3928","vendor":"Commvault","product":"Web Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24054","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-31201","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-31200","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20035","vendor":"SonicWall","product":"SMA100 Appliances","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2024-53150","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-53197","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-29824","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-30406","vendor":"Gladinet","product":"CentreStack","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-31161","vendor":"CrushFTP","product":"CrushFTP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-22457","vendor":"Ivanti","product":"Connect Secure, Policy Secure, and ZTA Gateways","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-24813","vendor":"Apache","product":"Tomcat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-20439","vendor":"Cisco","product":"Smart Licensing Utility","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-2783","vendor":"Google","product":"Chromium Mojo","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-9875","vendor":"Sitecore","product":"CMS and Experience Platform (XP)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-9874","vendor":"Sitecore","product":"CMS and Experience Platform (XP)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-30154","vendor":"reviewdog","product":"action-setup GitHub Action","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-12637","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-48248","vendor":"NAKIVO","product":"Backup and Replication","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-1316","vendor":"Edimax","product":"IC-7100 IP Camera","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-30066","vendor":"tj-actions","product":"changed-files GitHub Action","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24472","vendor":"Fortinet","product":"FortiOS and FortiProxy","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2025-21590","vendor":"Juniper","product":"Junos OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24201","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24993","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24991","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24985","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24984","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24983","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-26633","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-13161","vendor":"Ivanti","product":"Endpoint Manager (EPM)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2024-13160","vendor":"Ivanti","product":"Endpoint Manager (EPM)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2024-13159","vendor":"Ivanti","product":"Endpoint Manager (EPM)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2024-57968","vendor":"Advantive","product":"VeraCore","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-25181","vendor":"Advantive","product":"VeraCore","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-22226","vendor":"VMware","product":"ESXi, Workstation, and Fusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-22225","vendor":"VMware","product":"ESXi","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-22224","vendor":"VMware","product":"ESXi and Workstation","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-50302","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4885","vendor":"Progress","product":"WhatsUp Gold","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8639","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-43769","vendor":"Hitachi Vantara","product":"Pentaho Business Analytics (BA) Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-43939","vendor":"Hitachi Vantara","product":"Pentaho Business Analytics (BA) Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20118","vendor":"Cisco","product":"Small Business RV Series Routers","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2023-34192","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-49035","vendor":"Microsoft","product":"Partner Center","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2024-20953","vendor":"Oracle","product":"Agile Product Lifecycle Management (PLM)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-3066","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24989","vendor":"Microsoft","product":"Power Pages","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-0111","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-23209","vendor":"Craft CMS","product":"Craft CMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-0108","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-53704","vendor":"SonicWall","product":"SonicOS","outcome":"included","reason":"vendor: SonicWall; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-57727","vendor":"SimpleHelp","product":"SimpleHelp","outcome":"included","reason":"vendor: SimpleHelp; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2025-24200","vendor":"Apple","product":"iOS and iPadOS","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2024-41710","vendor":"Mitel","product":"SIP Phones","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-40891","vendor":"Zyxel","product":"DSL CPE Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-40890","vendor":"Zyxel","product":"DSL CPE Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21418","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21391","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-0994","vendor":"Trimble","product":"Cityworks","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-15069","vendor":"Sophos","product":"XG Firewall","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-29574","vendor":"Sophos","product":"CyberoamOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-21413","vendor":"Microsoft","product":"Office Outlook","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-23748","vendor":"Audinate","product":"Dante Discovery","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-0411","vendor":"7-Zip","product":"7-Zip","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-53104","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19410","vendor":"Paessler","product":"PRTG Network Monitor","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-9276","vendor":"Paessler","product":"PRTG Network Monitor","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-29059","vendor":"Microsoft","product":".NET Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-45195","vendor":"Apache","product":"OFBiz","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-24085","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-23006","vendor":"SonicWall","product":"SMA1000 Appliances","outcome":"included","reason":"vendor: SonicWall; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-11023","vendor":"JQuery","product":"JQuery","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-50603","vendor":"Aviatrix","product":"Controllers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21335","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21334","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2025-21333","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-55591","vendor":"Fortinet","product":"FortiOS and FortiProxy","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-48365","vendor":"Qlik","product":"Sense","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-12686","vendor":"BeyondTrust","product":"Privileged Remote Access (PRA) and Remote Support (RS)","outcome":"review","reason":"relevant (vendor: BeyondTrust) but classifies to no failure mode"},{"cve":"CVE-2025-0282","vendor":"Ivanti","product":"Connect Secure, Policy Secure, and ZTA Gateways","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2020-2883","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-55550","vendor":"Mitel","product":"MiCollab","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-41713","vendor":"Mitel","product":"MiCollab","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-3393","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44207","vendor":"Acclaim Systems","product":"USAHERDS","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2024-12356","vendor":"BeyondTrust","product":"Privileged Remote Access (PRA) and Remote Support (RS)","outcome":"included","reason":"vendor: BeyondTrust; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2021-40407","vendor":"Reolink","product":"RLC-410W IP Camera","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-11001","vendor":"Reolink","product":"Multiple IP Cameras","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-23227","vendor":"NUUO","product":"NVRmini2 Devices","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2018-14933","vendor":"NUUO","product":"NVRmini Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-55956","vendor":"Cleo","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-35250","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-20767","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-50623","vendor":"Cleo","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-49138","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-51378","vendor":"CyberPersons","product":"CyberPanel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-11667","vendor":"Zyxel","product":"Multiple Firewalls","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-11680","vendor":"ProjectSend","product":"ProjectSend","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-45727","vendor":"North Grid","product":"Proself","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28461","vendor":"Array Networks","product":"AG/vxAG ArrayOS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-21287","vendor":"Oracle","product":"Agile Product Lifecycle Management (PLM)","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2024-44309","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-44308","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38813","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38812","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-9474","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-0012","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-1212","vendor":"Progress","product":"Kemp LoadMaster","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-9465","vendor":"Palo Alto Networks","product":"Expedition","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-9463","vendor":"Palo Alto Networks","product":"Expedition","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26086","vendor":"Atlassian","product":"Jira Server and Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-2120","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2021-41277","vendor":"Metabase","product":"Metabase","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-43451","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-49039","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2019-16278","vendor":"Nostromo","product":"nhttpd","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-51567","vendor":"CyberPersons","product":"CyberPanel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-43093","vendor":"Android","product":"Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-5910","vendor":"Palo Alto Networks","product":"Expedition","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-8956","vendor":"PTZOptics","product":"PT30X-SDI/NDI Cameras","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-8957","vendor":"PTZOptics","product":"PT30X-SDI/NDI Cameras","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-37383","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-20481","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2024-47575","vendor":"Fortinet","product":"FortiManager","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-38094","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-9537","vendor":"ScienceLogic","product":"SL1","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-40711","vendor":"Veeam","product":"Backup & Replication","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-28987","vendor":"SolarWinds","product":"Web Help Desk","outcome":"included","reason":"vendor: N-able; classified via cwe: credential-exposure"},{"cve":"CVE-2024-9680","vendor":"Mozilla","product":"Firefox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-30088","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-9380","vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2024-9379","vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2024-23113","vendor":"Fortinet","product":"Multiple Products","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2024-43573","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-43572","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-43047","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-45519","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-29824","vendor":"Ivanti","product":"Endpoint Manager (EPM)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2019-0344","vendor":"SAP","product":"Commerce Cloud","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-15415","vendor":"DrayTek","product":"Multiple Vigor Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-25280","vendor":"D-Link","product":"DIR-820 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-7593","vendor":"Ivanti","product":"Virtual Traffic Manager","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-8963","vendor":"Ivanti","product":"Cloud Services Appliance (CSA)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-14644","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-21445","vendor":"Oracle","product":"ADF Faces","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0618","vendor":"Microsoft","product":"SQL Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-27348","vendor":"Apache","product":"HugeGraph-Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0502","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0648","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0643","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0497","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-6670","vendor":"Progress","product":"WhatsUp Gold","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-43461","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-8190","vendor":"Ivanti","product":"Cloud Services Appliance","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2024-38217","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38014","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2024-38226","vendor":"Microsoft","product":"Publisher","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-40766","vendor":"SonicWall","product":"SonicOS","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2017-1000253","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3714","vendor":"ImageMagick","product":"ImageMagick","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-7262","vendor":"Kingsoft","product":"WPS Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20124","vendor":"DrayTek","product":"VigorConnect","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20123","vendor":"DrayTek","product":"VigorConnect","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-7965","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38856","vendor":"Apache","product":"OFBiz","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2024-7971","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-39717","vendor":"Versa","product":"Director","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31196","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0185","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-33045","vendor":"Dahua","product":"IP Camera Firmware","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-33044","vendor":"Dahua","product":"IP Camera Firmware","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-23897","vendor":"Jenkins","product":"Jenkins Command Line Interface (CLI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-28986","vendor":"SolarWinds","product":"Web Help Desk","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2024-38107","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38106","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38193","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38213","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38178","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38189","vendor":"Microsoft","product":"Project","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-32113","vendor":"Apache","product":"OFBiz","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-36971","vendor":"Android","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-0824","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-37085","vendor":"VMware","product":"ESXi","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-45249","vendor":"Acronis","product":"Cyber Infrastructure (ACI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-5217","vendor":"ServiceNow","product":"Utah, Vancouver, and Washington DC Now Platform","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4879","vendor":"ServiceNow","product":"Utah, Vancouver, and Washington DC Now Platform","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-39891","vendor":"Twilio","product":"Authy","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-4792","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22948","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-28995","vendor":"SolarWinds","product":"Serv-U","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2024-34102","vendor":"Adobe","product":"Commerce and Magento Open Source","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-36401","vendor":"OSGeo","product":"GeoServer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-23692","vendor":"Rejetto","product":"HTTP File Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38080","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-38112","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-20399","vendor":"Cisco","product":"NX-OS","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2020-13965","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-2586","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24816","vendor":"OSGeo","product":"JAI-EXT","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4358","vendor":"Progress","product":"Telerik Report Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-26169","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2024-32896","vendor":"Android","product":"Pixel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4577","vendor":"PHP Group","product":"PHP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4610","vendor":"Arm","product":"Mali GPU Kernel Driver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-3506","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-1086","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-24919","vendor":"Check Point","product":"Quantum Security Gateways","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4978","vendor":"Justice AV Solutions","product":"Viewer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-5274","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-17519","vendor":"Apache","product":"Flink","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4947","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-43208","vendor":"NextGen Healthcare","product":"Mirth Connect","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4761","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-40655","vendor":"D-Link","product":"DIR-605 Router","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2014-100005","vendor":"D-Link","product":"DIR-600 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-30040","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-30051","vendor":"Microsoft","product":"DWM Core Library","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4671","vendor":"Google","product":"Chromium","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-7028","vendor":"GitLab","product":"GitLab CE/EE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-29988","vendor":"Microsoft","product":"SmartScreen Prompt","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-4040","vendor":"CrushFTP","product":"CrushFTP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-20359","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: privilege-escalation"},{"cve":"CVE-2024-20353","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2022-38028","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-3400","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-3273","vendor":"D-Link","product":"Multiple NAS Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-3272","vendor":"D-Link","product":"Multiple NAS Devices","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2024-29748","vendor":"Android","product":"Pixel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-29745","vendor":"Android","product":"Pixel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-24955","vendor":"Microsoft","product":"SharePoint Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7256","vendor":"Nice","product":"Linear eMerge E3-Series","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44529","vendor":"Ivanti","product":"Endpoint Manager Cloud Service Appliance (EPM CSA)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2023-48788","vendor":"Fortinet","product":"FortiClient EMS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2024-27198","vendor":"JetBrains","product":"TeamCity","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-23225","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-23296","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-21237","vendor":"Android","product":"Pixel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36380","vendor":"Sunhillo","product":"SureLine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-21338","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-29360","vendor":"Microsoft","product":"Streaming Service","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-1709","vendor":"ConnectWise","product":"ScreenConnect","outcome":"included","reason":"vendor: ConnectWise; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2020-3259","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2024-21410","vendor":"Microsoft","product":"Exchange Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-21412","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-21351","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-43770","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-21762","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2023-4762","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-48618","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-21893","vendor":"Ivanti","product":"Connect Secure, Policy Secure, and Neurons","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass, federation-trust"},{"cve":"CVE-2023-22527","vendor":"Atlassian","product":"Confluence Data Center and Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2024-23222","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-34048","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-35082","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM) and MobileIron Core","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-0519","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-6549","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but impact is denial of service only"},{"cve":"CVE-2023-6548","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2018-15133","vendor":"Laravel","product":"Laravel Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-29357","vendor":"Microsoft","product":"SharePoint Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-46805","vendor":"Ivanti","product":"Connect Secure and Policy Secure","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2024-21887","vendor":"Ivanti","product":"Connect Secure and Policy Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2023-23752","vendor":"Joomla!","product":"Joomla!","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-20017","vendor":"D-Link","product":"DSL-2750B Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41990","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-27524","vendor":"Apache","product":"Superset","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-29300","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-38203","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-7101","vendor":"Spreadsheet::ParseExcel","product":"Spreadsheet::ParseExcel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-7024","vendor":"Google","product":"Chromium WebRTC","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-49897","vendor":"FXC","product":"AE1021, AE1021PE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-47565","vendor":"QNAP","product":"VioStor NVR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-6448","vendor":"Unitronics","product":"Vision PLC and HMI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41266","vendor":"Qlik","product":"Sense","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41265","vendor":"Qlik","product":"Sense","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33107","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33106","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33063","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22071","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-42917","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-42916","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-6345","vendor":"Google","product":"Chromium Skia","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-49103","vendor":"ownCloud","product":"ownCloud graphapi","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-4911","vendor":"GNU","product":"GNU C Library","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36584","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-1671","vendor":"Sophos","product":"Web Appliance","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-2551","vendor":"Oracle","product":"Fusion Middleware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36033","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36025","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36036","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-47246","vendor":"SysAid","product":"SysAid Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36844","vendor":"Juniper","product":"Junos OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36845","vendor":"Juniper","product":"Junos OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36846","vendor":"Juniper","product":"Junos OS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-36847","vendor":"Juniper","product":"Junos OS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-36851","vendor":"Juniper","product":"Junos OS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-29552","vendor":"IETF","product":"Service Location Protocol (SLP)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-22518","vendor":"Atlassian","product":"Confluence Data Center and Server","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2023-46604","vendor":"Apache","product":"ActiveMQ","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-46748","vendor":"F5","product":"BIG-IP Configuration Utility","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-46747","vendor":"F5","product":"BIG-IP Configuration Utility","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-5631","vendor":"Roundcube","product":"Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20273","vendor":"Cisco","product":"Cisco IOS XE Web UI","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: privilege-escalation"},{"cve":"CVE-2023-4966","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2023-20198","vendor":"Cisco","product":"IOS XE Web UI","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2023-21608","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20109","vendor":"Cisco","product":"IOS and IOS XE","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2023-41763","vendor":"Microsoft","product":"Skype for Business","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36563","vendor":"Microsoft","product":"WordPad","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-44487","vendor":"IETF","product":"HTTP/2","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-22515","vendor":"Atlassian","product":"Confluence Data Center and Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-40044","vendor":"Progress","product":"WS_FTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-42824","vendor":"Apple","product":"iOS and iPadOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-42793","vendor":"JetBrains","product":"TeamCity","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-28229","vendor":"Microsoft","product":"Windows CNG Key Isolation Service","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-4211","vendor":"Arm","product":"Mali GPU Kernel Driver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-5217","vendor":"Google","product":"Chromium libvpx","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-14667","vendor":"Red Hat","product":"JBoss RichFaces Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41991","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41992","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41993","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41179","vendor":"Trend Micro","product":"Apex One and Worry-Free Business Security","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28434","vendor":"MinIO","product":"MinIO","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2022-22265","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-8361","vendor":"Realtek","product":"SDK","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6884","vendor":"Zyxel","product":"EMG2926 Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-3129","vendor":"Laravel","product":"Ignition","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-26369","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-35674","vendor":"Android","product":"Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20269","vendor":"Cisco","product":"Adaptive Security Appliance and Firepower Threat Defense","outcome":"included","reason":"vendor: Cisco/Duo; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-4863","vendor":"Google","product":"Chromium WebP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36761","vendor":"Microsoft","product":"Word","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36802","vendor":"Microsoft","product":"Streaming Service Proxy","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41064","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-41061","vendor":"Apple","product":"iOS, iPadOS, and watchOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33246","vendor":"Apache","product":"RocketMQ","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-38831","vendor":"RARLAB","product":"WinRAR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32315","vendor":"Ignite Realtime","product":"Openfire","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-38035","vendor":"Ivanti","product":"Sentry","outcome":"included","reason":"vendor: Ivanti; classified via cwe: privilege-escalation"},{"cve":"CVE-2023-27532","vendor":"Veeam","product":"Backup & Replication","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-26359","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-24489","vendor":"Citrix","product":"Content Collaboration","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2023-38180","vendor":"Microsoft","product":".NET Core and Visual Studio","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-18368","vendor":"Zyxel","product":"P660HN-T1A Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-35081","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2023-37580","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-38606","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-35078","vendor":"Ivanti","product":"Endpoint Manager Mobile (EPMM)","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-29298","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-38205","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-3519","vendor":"Citrix","product":"NetScaler ADC and NetScaler Gateway","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2023-36884","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-29303","vendor":"SolarView","product":"Compact","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-37450","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32046","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32049","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-35311","vendor":"Microsoft","product":"Outlook","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-36874","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-31199","vendor":"Netwrix","product":"Auditor","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-29256","vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-17621","vendor":"D-Link","product":"DIR-859 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-20500","vendor":"D-Link","product":"DWL-2600AP Access Point","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25487","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25489","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25394","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25395","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25371","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25372","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32434","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32435","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32439","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20867","vendor":"VMware","product":"Tools","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-27992","vendor":"Zyxel","product":"Multiple Network-Attached Storage (NAS) Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20887","vendor":"VMware","product":"Aria Operations for Networks","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-35730","vendor":"Roundcube","product":"Roundcube Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-12641","vendor":"Roundcube","product":"Roundcube Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44026","vendor":"Roundcube","product":"Roundcube Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-9079","vendor":"Mozilla","product":"Firefox, Firefox ESR, and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0165","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-27997","vendor":"Fortinet","product":"FortiOS and FortiProxy SSL-VPN","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2023-3079","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33009","vendor":"Zyxel","product":"Multiple Firewalls","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-33010","vendor":"Zyxel","product":"Multiple Firewalls","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-34362","vendor":"Progress","product":"MOVEit Transfer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28771","vendor":"Zyxel","product":"Multiple Firewalls","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-2868","vendor":"Barracuda Networks","product":"Email Security Gateway (ESG) Appliance","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32409","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28204","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-32373","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2004-1464","vendor":"Cisco","product":"IOS","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2016-6415","vendor":"Cisco","product":"IOS, IOS XR, and IOS XE","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2023-21492","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-25717","vendor":"Ruckus Wireless","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-3560","vendor":"Red Hat","product":"Polkit","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2014-0196","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-3904","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-5317","vendor":"Jenkins","product":"Jenkins User Interface (UI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3427","vendor":"Oracle","product":"Java SE and JRockit","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-8735","vendor":"Apache","product":"Tomcat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-29336","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-1389","vendor":"TP-Link","product":"Archer AX21","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-45046","vendor":"Apache","product":"Log4j2","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-21839","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28432","vendor":"MinIO","product":"MinIO","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-27350","vendor":"PaperCut","product":"MF/NG","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-2136","vendor":"Google","product":"Chromium Skia","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6742","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2019-8526","vendor":"Apple","product":"macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-2033","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-20963","vendor":"Android","product":"Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-29492","vendor":"Novi Survey","product":"Novi Survey","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28252","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28205","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-28206","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27876","vendor":"Veritas","product":"Backup Exec Agent","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-27877","vendor":"Veritas","product":"Backup Exec Agent","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-27878","vendor":"Veritas","product":"Backup Exec Agent","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2019-1388","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2023-26083","vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-27926","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3163","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-7494","vendor":"Samba","product":"Samba","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-42948","vendor":"Fortra","product":"Cobalt Strike","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-39197","vendor":"Fortra","product":"Cobalt Strike","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30900","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-38181","vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-0266","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-3038","vendor":"Google","product":"Chromium Network Service","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22706","vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-26360","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-23397","vendor":"Microsoft","product":"Office","outcome":"included","reason":"classified via cwe: session-handling"},{"cve":"CVE-2023-24880","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2022-41328","vendor":"Fortinet","product":"FortiOS","outcome":"review","reason":"relevant (vendor: Fortinet) but classifies to no failure mode"},{"cve":"CVE-2021-39144","vendor":"XStream","product":"XStream","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-5741","vendor":"Plex","product":"Media Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-28810","vendor":"Zoho","product":"ManageEngine","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2022-33891","vendor":"Apache","product":"Spark","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-35914","vendor":"Teclib","product":"GLPI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-36537","vendor":"ZK Framework","product":"AuUploader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-47986","vendor":"IBM","product":"Aspera Faspex","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41223","vendor":"Mitel","product":"MiVoice Connect","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-40765","vendor":"Mitel","product":"MiVoice Connect","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-46169","vendor":"Cacti","product":"Cacti","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-21715","vendor":"Microsoft","product":"Office","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2023-23376","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-23529","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-21823","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2291","vendor":"Intel","product":"Ethernet Diagnostics Driver for Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24990","vendor":"TerraMaster","product":"TerraMaster OS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-0669","vendor":"Fortra","product":"GoAnywhere MFT","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-21587","vendor":"Oracle","product":"E-Business Suite","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2023-22952","vendor":"SugarCRM","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-11357","vendor":"Telerik","product":"User Interface (UI) for ASP.NET AJAX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-47966","vendor":"Zoho","product":"ManageEngine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-44877","vendor":"CWP","product":"Control Web Panel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41080","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2023-21674","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-5430","vendor":"TIBCO","product":"JasperReports","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-18809","vendor":"TIBCO","product":"JasperReports","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-42856","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-42475","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2022-44698","vendor":"Microsoft","product":"Defender","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-27518","vendor":"Citrix","product":"Application Delivery Controller (ADC) and Gateway","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass, federation-trust"},{"cve":"CVE-2022-26500","vendor":"Veeam","product":"Backup & Replication","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26501","vendor":"Veeam","product":"Backup & Replication","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-4262","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-35587","vendor":"Oracle","product":"Fusion Middleware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-4135","vendor":"Google","product":"Chromium GPU","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41049","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41091","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2022-41073","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41125","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41128","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25337","vendor":"Samsung","product":"Mobile Devices","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-25369","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25370","vendor":"Samsung","product":"Mobile Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-3723","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-42827","vendor":"Apple","product":"iOS and iPadOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-3433","vendor":"Cisco","product":"AnyConnect Secure","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2020-3153","vendor":"Cisco","product":"AnyConnect Secure","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2018-19323","vendor":"GIGABYTE","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19322","vendor":"GIGABYTE","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19321","vendor":"GIGABYTE","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19320","vendor":"GIGABYTE","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41352","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-3493","vendor":"Linux","product":"Kernel","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2022-40684","vendor":"Fortinet","product":"Multiple Products","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-41033","vendor":"Microsoft","product":"Windows COM+ Event System Service","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41082","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-41040","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-36804","vendor":"Atlassian","product":"Bitbucket Server and Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-3236","vendor":"Sophos","product":"Firewall","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-35405","vendor":"Zoho","product":"ManageEngine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-40139","vendor":"Trend Micro","product":"Apex One and Apex One as a Service","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-6282","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2597","vendor":"Code Aurora","product":"ACDB Audio Driver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2596","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2094","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-2568","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-37969","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-32917","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-3075","vendor":"Google","product":"Chromium Mojo","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-27593","vendor":"QNAP","product":"Photo Station","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26258","vendor":"D-Link","product":"DIR-820L","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9934","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-7445","vendor":"MikroTik","product":"RouterOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-6530","vendor":"D-Link","product":"Multiple Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-2628","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-13374","vendor":"Fortinet","product":"FortiOS and FortiADC","outcome":"review","reason":"relevant (vendor: Fortinet) but classifies to no failure mode"},{"cve":"CVE-2017-5521","vendor":"NETGEAR","product":"Multiple Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-4723","vendor":"D-Link","product":"DIR-300 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-1823","vendor":"Android","product":"Android OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26352","vendor":"dotCMS","product":"dotCMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24706","vendor":"Apache","product":"CouchDB","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24112","vendor":"Apache","product":"APISIX","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-22963","vendor":"VMware Tanzu","product":"Spring Cloud","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-2294","vendor":"WebRTC","product":"WebRTC","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-39226","vendor":"Grafana Labs","product":"Grafana","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-38406","vendor":"Delta Electronics","product":"DOPSoft 2","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31010","vendor":"Apple","product":"iOS, macOS, watchOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-36193","vendor":"PEAR","product":"Archive_Tar","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-28949","vendor":"PEAR","product":"Archive_Tar","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0028","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22536","vendor":"SAP","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-32894","vendor":"Apple","product":"iOS and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-32893","vendor":"Apple","product":"iOS and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-2856","vendor":"Google","product":"Chromium Intents","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26923","vendor":"Microsoft","product":"Active Directory","outcome":"included","reason":"vendor: Microsoft identity; classified via keyword: privilege-escalation"},{"cve":"CVE-2022-21971","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-15944","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-27925","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-37042","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-34713","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-30333","vendor":"RARLAB","product":"UnRAR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-27924","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26138","vendor":"Atlassian","product":"Confluence","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2022-22047","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26925","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-29499","vendor":"Mitel","product":"MiVoice Connect","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30533","vendor":"Google","product":"Chromium PopupBlocker","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-4034","vendor":"Red Hat","product":"Polkit","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30983","vendor":"Apple","product":"iOS and iPadOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-3837","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9907","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-8605","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-4344","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-30190","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38163","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-2386","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-2388","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7195","vendor":"QNAP","product":"Photo Station","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7194","vendor":"QNAP","product":"Photo Station","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7193","vendor":"QNAP","product":"QTS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7192","vendor":"QNAP","product":"Photo Station","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2019-5825","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-15271","vendor":"Cisco","product":"RV Series Routers","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2018-6065","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-4990","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-17480","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-17463","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6862","vendor":"NETGEAR","product":"Multiple Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-5070","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-5030","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-5198","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-1646","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-1331","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-5054","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-4969","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1889","vendor":"Microsoft","product":"XML Core Services","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0767","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0754","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0151","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-2462","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-0609","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-2883","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-2572","vendor":"Microsoft","product":"PowerPoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-1297","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-4324","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-3953","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-1862","vendor":"Adobe","product":"Acrobat and Reader, Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-0563","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-0557","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2008-0655","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2007-5659","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2006-2492","vendor":"Microsoft","product":"Word","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26134","vendor":"Atlassian","product":"Confluence Server/Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-3010","vendor":"Oracle","product":"Solaris","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3393","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7256","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-1010","vendor":"Adobe","product":"Flash Player and AIR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0984","vendor":"Adobe","product":"Flash Player and AIR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0034","vendor":"Microsoft","product":"Silverlight","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-0310","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-0016","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-0071","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2360","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2425","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1769","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-4495","vendor":"Mozilla","product":"Firefox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-8651","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-6175","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1671","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-4148","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-8439","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-4123","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0546","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-2817","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-4077","vendor":"Microsoft","product":"Input Method Editor (IME) Japanese","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-3153","vendor":"Linux","product":"Kernel","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2013-7331","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3993","vendor":"IBM","product":"InfoSphere BigInsights","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3896","vendor":"Microsoft","product":"Silverlight","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2423","vendor":"Oracle","product":"Java Runtime Environment (JRE)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0431","vendor":"Oracle","product":"Java Runtime Environment (JRE)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0422","vendor":"Oracle","product":"Java Runtime Environment (JRE)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0074","vendor":"Microsoft","product":"Silverlight","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1710","vendor":"Oracle","product":"Fusion Middleware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-1428","vendor":"Red Hat","product":"JBoss","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-0840","vendor":"Oracle","product":"Java Runtime Environment (JRE)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-0738","vendor":"Red Hat","product":"JBoss","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8611","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19953","vendor":"QNAP","product":"Network Attached Storage (NAS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19949","vendor":"QNAP","product":"Network Attached Storage (NAS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-19943","vendor":"QNAP","product":"Network Attached Storage (NAS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0147","vendor":"Microsoft","product":"SMBv1 server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0022","vendor":"Microsoft","product":"XML Core Services","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0005","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0149","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0210","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-8291","vendor":"Artifex","product":"Ghostscript","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-8543","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-18362","vendor":"Kaseya","product":"Virtual System/Server Administrator (VSA)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0162","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3351","vendor":"Microsoft","product":"Internet Explorer and Edge","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4655","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4656","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4657","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-6366","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2016-6367","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2016-3298","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-20821","vendor":"Cisco","product":"IOS XR","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2021-1048","vendor":"Android","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-0920","vendor":"Android","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30883","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1027","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0638","vendor":"Microsoft","product":"Update Notification Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7286","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7287","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0676","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-5786","vendor":"Google","product":"Chrome Blink","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0703","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0880","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-13720","vendor":"Google","product":"Chrome WebAudio","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-11707","vendor":"Mozilla","product":"Firefox and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-11708","vendor":"Mozilla","product":"Firefox and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-8720","vendor":"WebKitGTK","product":"WebKitGTK","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-18426","vendor":"Meta Platforms","product":"WhatsApp","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1385","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1130","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-5002","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8589","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-30525","vendor":"Zyxel","product":"Multiple Firewalls","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22947","vendor":"VMware","product":"Spring Cloud Gateway","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-1388","vendor":"F5","product":"BIG-IP","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-1789","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-8506","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-4113","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0322","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0160","vendor":"OpenSSL","product":"OpenSSL","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-29464","vendor":"WSO2","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26904","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-21919","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0847","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-41357","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-40450","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1003029","vendor":"Jenkins","product":"Script Security Plugin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-6882","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-3568","vendor":"Meta Platforms","product":"WhatsApp","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22718","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22960","vendor":"VMware","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-1364","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-3929","vendor":"Crestron","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-16057","vendor":"D-Link","product":"DNS-320 Storage Device","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-7841","vendor":"Schneider Electric","product":"U.motion Builder","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4523","vendor":"Trihedral","product":"VTScada (formerly VTS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0780","vendor":"InduSoft","product":"Web Studio","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-5330","vendor":"Ubiquiti","product":"AirOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2007-3010","vendor":"Alcatel","product":"OmniPCX Enterprise","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22954","vendor":"VMware","product":"Workspace ONE Access and Identity Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24521","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-7602","vendor":"Drupal","product":"Core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-20753","vendor":"Kaseya","product":"Virtual System/Server Administrator (VSA)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-5123","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-5122","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-3113","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2502","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-0313","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-0311","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-9163","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-23176","vendor":"WatchGuard","product":"Firebox and XTM","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-42287","vendor":"Microsoft","product":"Active Directory","outcome":"included","reason":"vendor: Microsoft identity; classified via cwe: privilege-escalation"},{"cve":"CVE-2021-42278","vendor":"Microsoft","product":"Active Directory","outcome":"included","reason":"vendor: Microsoft identity; classified via keyword: privilege-escalation"},{"cve":"CVE-2021-39793","vendor":"Google","product":"Pixel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27852","vendor":"Checkbox","product":"Checkbox Survey","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22600","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-2509","vendor":"QNAP","product":"QNAP Network-Attached Storage (NAS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-11317","vendor":"Telerik","product":"User Interface (UI) for ASP.NET AJAX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-3156","vendor":"Sudo","product":"Sudo","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31166","vendor":"Microsoft","product":"HTTP Protocol Stack","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0148","vendor":"Microsoft","product":"SMBv1 server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22965","vendor":"VMware","product":"Spring Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22675","vendor":"Apple","product":"macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22674","vendor":"Apple","product":"macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-45382","vendor":"D-Link","product":"Multiple Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26871","vendor":"Trend Micro","product":"Apex Central","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-1040","vendor":"Sophos","product":"Firewall","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-34484","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-28799","vendor":"QNAP","product":"Network Attached Storage (NAS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21551","vendor":"Dell","product":"dbutil Driver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-10562","vendor":"Dasan","product":"Gigabit Passive Optical Network (GPON) Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-10561","vendor":"Dasan","product":"Gigabit Passive Optical Network (GPON) Routers","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-1096","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0543","vendor":"Redis","product":"Debian-specific Redis Servers","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-38646","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-34486","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26085","vendor":"Atlassian","product":"Confluence Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20028","vendor":"SonicWall","product":"Secure Remote Access (SRA)","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2019-7483","vendor":"SonicWall","product":"SMA100","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2018-8440","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8406","vendor":"Microsoft","product":"DirectX Graphics Kernel (DXGKRNL)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8405","vendor":"Microsoft","product":"DirectX Graphics Kernel (DXGKRNL)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0213","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0059","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0037","vendor":"Microsoft","product":"Edge and Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7201","vendor":"Microsoft","product":"Edge","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7200","vendor":"Microsoft","product":"Edge","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0189","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0151","vendor":"Microsoft","product":"Client-Server Run-time Subsystem (CSRSS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0040","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2426","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2419","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1770","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3660","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2729","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2551","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2465","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-1690","vendor":"Mozilla","product":"Firefox and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-5076","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-2539","vendor":"Microsoft","product":"Word","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-2034","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0518","vendor":"Oracle","product":"Fusion Middleware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-2005","vendor":"Microsoft","product":"Ancillary Function Driver (afd.sys)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-4398","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26318","vendor":"WatchGuard","product":"Firebox and XTM Appliances","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26143","vendor":"Mitel","product":"MiCollab, MiVoice Business Express","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-21999","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-42237","vendor":"Sitecore","product":"XP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22941","vendor":"Citrix","product":"ShareFile","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-9377","vendor":"D-Link","product":"DIR-610 Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9054","vendor":"Zyxel","product":"Multiple Network-Attached Storage (NAS) Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-7247","vendor":"OpenBSD","product":"OpenSMTPD","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-5410","vendor":"VMware Tanzu","product":"Spring Cloud Configuration (Config) Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-25223","vendor":"Sophos","product":"SG UTM","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-2506","vendor":"QNAP Systems","product":"Helpdesk","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-2021","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"included","reason":"classified via cwe: federation-trust"},{"cve":"CVE-2020-1956","vendor":"Apache","product":"Kylin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1631","vendor":"Juniper","product":"Junos OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-6340","vendor":"Drupal","product":"Core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-2616","vendor":"Oracle","product":"BI Publisher (Formerly XML Publisher)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-16920","vendor":"D-Link","product":"Multiple Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-15107","vendor":"Webmin","product":"Webmin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-12991","vendor":"Citrix","product":"SD-WAN and NetScaler","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2019-12989","vendor":"Citrix","product":"SD-WAN and NetScaler","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2019-11043","vendor":"PHP","product":"FastCGI Process Manager (FPM)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-10068","vendor":"Kentico","product":"Xperience","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1003030","vendor":"Jenkins","product":"Matrix Project Plugin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0903","vendor":"Microsoft","product":"Graphics Device Interface (GDI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8414","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8373","vendor":"Microsoft","product":"Internet Explorer Scripting Engine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-6961","vendor":"VMware","product":"SD-WAN Edge","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-14839","vendor":"LG","product":"N1A1 NAS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-1273","vendor":"VMware Tanzu","product":"Spring Data Commons","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-11138","vendor":"Quest","product":"KACE System Management Appliance","outcome":"review","reason":"relevant (vendor: One Identity) but classifies to no failure mode"},{"cve":"CVE-2018-0147","vendor":"Cisco","product":"Secure Access Control System (ACS)","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2018-0125","vendor":"Cisco","product":"VPN Routers","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2017-6334","vendor":"NETGEAR","product":"DGN2200 Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6316","vendor":"Citrix","product":"NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2017-3881","vendor":"Cisco","product":"IOS and IOS XE","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2017-12617","vendor":"Apache","product":"Tomcat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-12615","vendor":"Apache","product":"Tomcat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0146","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7892","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4171","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-1555","vendor":"NETGEAR","product":"Wireless Access Point (WAP) Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-11021","vendor":"D-Link","product":"DCS-930L Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-10174","vendor":"NETGEAR","product":"WNR2000v5 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0752","vendor":"Rails","product":"Ruby on Rails","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-4068","vendor":"Arcserve","product":"Unified Data Protection (UDP)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-3035","vendor":"TP-Link","product":"Multiple Archer Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1427","vendor":"Elastic","product":"Elasticsearch","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1187","vendor":"D-Link and TRENDnet","product":"Multiple Devices","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2015-0666","vendor":"Cisco","product":"Prime Data Center Network Manager (DCNM)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2014-6332","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-6324","vendor":"Microsoft","product":"Kerberos Key Distribution Center (KDC)","outcome":"included","reason":"vendor: Microsoft identity; classified via keyword: privilege-escalation"},{"cve":"CVE-2014-6287","vendor":"Rejetto","product":"HTTP File Server (HFS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-3120","vendor":"Elastic","product":"Elasticsearch","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0130","vendor":"Rails","product":"Ruby on Rails","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-5223","vendor":"D-Link","product":"DSL-2760U","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-4810","vendor":"Hewlett Packard (HP)","product":"ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-2251","vendor":"Apache","product":"Struts","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1823","vendor":"PHP","product":"PHP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-4345","vendor":"Exim","product":"Exim","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-4344","vendor":"Exim","product":"Exim","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-3035","vendor":"Cisco","product":"IOS XR","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2010-2861","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-2055","vendor":"Cisco","product":"IOS XR","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2009-1151","vendor":"phpMyAdmin","product":"phpMyAdmin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-0927","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2005-2773","vendor":"Hewlett Packard (HP)","product":"OpenView Network Node Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-5135","vendor":"SonicWall","product":"SonicOS","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2019-1405","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1322","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1315","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1253","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1132","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1129","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1069","vendor":"Microsoft","product":"Task Scheduler","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1064","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0841","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0543","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2018-8120","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0101","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3309","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2546","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26486","vendor":"Mozilla","product":"Firefox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-26485","vendor":"Mozilla","product":"Firefox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21973","vendor":"VMware","product":"vCenter Server and Cloud Foundation","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8218","vendor":"Pulse Secure","product":"Pulse Connect Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2019-11581","vendor":"Atlassian","product":"Jira Server and Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6077","vendor":"NETGEAR","product":"Wireless Router DGN2200","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-6277","vendor":"NETGEAR","product":"Multiple Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0631","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0629","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0625","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-3960","vendor":"Adobe","product":"BlazeDS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-20708","vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2022-20703","vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","outcome":"included","reason":"vendor: Cisco/Duo; classified via cwe: federation-trust"},{"cve":"CVE-2022-20701","vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2022-20700","vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2022-20699","vendor":"Cisco","product":"Small Business RV160, RV260, RV340, and RV345 Series Routers","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2021-41379","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1938","vendor":"Apache","product":"Tomcat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-11899","vendor":"Treck TCP/IP stack","product":"IPv6","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-16928","vendor":"Exim","product":"Exim Internet Mailer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1652","vendor":"Cisco","product":"Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2019-1297","vendor":"Microsoft","product":"Excel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8581","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8298","vendor":"ChakraCore","product":"ChakraCore scripting engine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-0180","vendor":"Cisco","product":"IOS Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0179","vendor":"Cisco","product":"IOS Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0175","vendor":"Cisco","product":"IOS, XR, and XE Software","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: privilege-escalation"},{"cve":"CVE-2018-0174","vendor":"Cisco","product":"IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0173","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0172","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0167","vendor":"Cisco","product":"IOS, XR, and XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2018-0161","vendor":"Cisco","product":"IOS Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0159","vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0158","vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2018-0156","vendor":"Cisco","product":"IOS Software and Cisco IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0155","vendor":"Cisco","product":"Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0154","vendor":"Cisco","product":"IOS Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2018-0151","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass, privilege-escalation"},{"cve":"CVE-2017-8540","vendor":"Microsoft","product":"Malware Protection Engine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6744","vendor":"Cisco","product":"IOS software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6743","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6740","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6739","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6738","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6737","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6736","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2017-6663","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-6627","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12319","vendor":"Cisco","product":"IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12240","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2017-12238","vendor":"Cisco","product":"Catalyst 6800 Series Switches","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12237","vendor":"Cisco","product":"IOS and IOS XE Software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12235","vendor":"Cisco","product":"IOS software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12234","vendor":"Cisco","product":"IOS software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12233","vendor":"Cisco","product":"IOS software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12232","vendor":"Cisco","product":"IOS software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-12231","vendor":"Cisco","product":"IOS software","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2017-11826","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-11292","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0261","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0001","vendor":"Microsoft","product":"Graphics Device Interface (GDI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-8562","vendor":"Siemens","product":"SIMATIC CP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7855","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7262","vendor":"Microsoft","product":"Excel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7193","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-5195","vendor":"Linux","product":"Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4117","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-1019","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0099","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-7645","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-5119","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-4902","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-3043","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2590","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2545","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2424","vendor":"Microsoft","product":"PowerPoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2387","vendor":"Microsoft","product":"ATM Font Driver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1701","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1642","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-4114","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-0496","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-5065","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3897","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3346","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-1675","vendor":"Mozilla","product":"Firefox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-1347","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0641","vendor":"Adobe","product":"Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0640","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-0632","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-4681","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1856","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1723","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-1535","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0507","vendor":"Oracle","product":"Java SE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-3544","vendor":"Oracle","product":"Java SE JDK and JRE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-1889","vendor":"Microsoft","product":"Forefront Threat Management Gateway (TMG)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2011-0611","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-3333","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-0232","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-0188","vendor":"Adobe","product":"Reader and Acrobat","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-3129","vendor":"Microsoft","product":"Excel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2009-1123","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2008-3431","vendor":"Oracle","product":"VirtualBox","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2008-2992","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2004-0210","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2002-0367","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24682","vendor":"Synacor","product":"Zimbra Collaborate Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-8570","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0222","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-6352","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-23131","vendor":"Zabbix","product":"Frontend","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2022-23134","vendor":"Zabbix","product":"Frontend","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-24086","vendor":"Adobe","product":"Commerce and Magento Open Source","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-0609","vendor":"Google","product":"Chromium Animation","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0752","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8174","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-20250","vendor":"RARLAB","product":"WinRAR","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-15982","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-9841","vendor":"PHPUnit","product":"PHPUnit","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-1761","vendor":"Microsoft","product":"Word","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3906","vendor":"Microsoft","product":"Graphics Component","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22620","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36934","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0796","vendor":"Microsoft","product":"SMBv3","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-1000861","vendor":"Jenkins","product":"Jenkins Stapler Web Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-9791","vendor":"Apache","product":"Struts 1","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-8464","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-10271","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0263","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0262","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0145","vendor":"Microsoft","product":"SMBv1","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0144","vendor":"Microsoft","product":"SMBv1","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3088","vendor":"Apache","product":"ActiveMQ","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-2051","vendor":"D-Link","product":"DIR-645 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1635","vendor":"Microsoft","product":"HTTP.sys","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1130","vendor":"Apple","product":"OS X","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-4404","vendor":"Apple","product":"OS X","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-21882","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2022-22587","vendor":"Apple","product":"iOS and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20038","vendor":"SonicWall","product":"SMA 100 Appliances","outcome":"review","reason":"relevant (vendor: SonicWall) but classifies to no failure mode"},{"cve":"CVE-2020-5722","vendor":"Grandstream","product":"UCM6200","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0787","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2017-5689","vendor":"Intel","product":"Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-1776","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-6271","vendor":"GNU","product":"Bourne-Again Shell (Bash)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-7169","vendor":"GNU","product":"Bourne-Again Shell (Bash)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2006-1547","vendor":"Apache","product":"Struts 1","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0391","vendor":"Apache","product":"Struts 2","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8453","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-35247","vendor":"SolarWinds","product":"Serv-U","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2021-32648","vendor":"October CMS","product":"October CMS","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-25296","vendor":"Nagios","product":"Nagios XI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25297","vendor":"Nagios","product":"Nagios XI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-25298","vendor":"Nagios","product":"Nagios XI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-40870","vendor":"Aviatrix","product":"Aviatrix Controller","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-33766","vendor":"Microsoft","product":"Exchange Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-21975","vendor":"VMware","product":"vRealize Operations Manager API","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21315","vendor":"Npm package","product":"System Information Library for Node.JS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22991","vendor":"F5","product":"BIG-IP Traffic Management Microkernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-14864","vendor":"Oracle","product":"Intelligence Enterprise Edition","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-13671","vendor":"Drupal","product":"Drupal core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-11978","vendor":"Apache","product":"Airflow","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-13927","vendor":"Apache","product":"Airflow's Experimental API","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-22017","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36260","vendor":"Hikvision","product":"Security cameras web server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-6572","vendor":"Google","product":"Chrome Media","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1458","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2013-3900","vendor":"Microsoft","product":"WinVerifyTrust function","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-2725","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-9670","vendor":"Synacor","product":"Zimbra Collaboration Suite (ZCS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-13382","vendor":"Fortinet","product":"FortiOS and FortiProxy","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2018-13383","vendor":"Fortinet","product":"FortiOS and FortiProxy","outcome":"review","reason":"relevant (vendor: Fortinet) but classifies to no failure mode"},{"cve":"CVE-2019-1579","vendor":"Palo Alto Networks","product":"PAN-OS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-10149","vendor":"Exim","product":"Mail Transfer Agent (MTA)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-7450","vendor":"IBM","product":"WebSphere Application Server and Server Hypervisor Edition","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-1000486","vendor":"Primetek","product":"Primefaces Application","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7609","vendor":"Elastic","product":"Kibana","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27860","vendor":"FatPipe","product":"WARP, IPVPN, and MPVPN software","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-43890","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-4102","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44515","vendor":"Zoho","product":"Desktop Central","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-13272","vendor":"Linux","product":"Kernel","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-35394","vendor":"Realtek","product":"Jungle Software Development Kit (SDK)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-7238","vendor":"Sonatype","product":"Nexus Repository Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0193","vendor":"Apache","product":"Solr","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44168","vendor":"Fortinet","product":"FortiOS","outcome":"review","reason":"relevant (vendor: Fortinet) but classifies to no failure mode"},{"cve":"CVE-2017-17562","vendor":"Embedthis","product":"GoAhead","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-12149","vendor":"Red Hat","product":"JBoss Application Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-1871","vendor":"Red Hat","product":"JBoss Seam 2","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-17463","vendor":"Fuel CMS","product":"Fuel CMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8816","vendor":"Pi-hole","product":"AdminLTE","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-10758","vendor":"MongoDB","product":"mongo-express","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44228","vendor":"Apache","product":"Log4j2","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-11261","vendor":"Qualcomm","product":"Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-14847","vendor":"MikroTik","product":"RouterOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-37415","vendor":"Zoho","product":"ManageEngine ServiceDesk Plus (SDP)","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-40438","vendor":"Apache","product":"Apache","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-44077","vendor":"Zoho","product":"ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-22204","vendor":"Perl","product":"Exiftool","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-40449","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-42321","vendor":"Microsoft","product":"Exchange","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-42292","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27104","vendor":"Accellion","product":"FTA","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27102","vendor":"Accellion","product":"FTA","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27101","vendor":"Accellion","product":"FTA","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27103","vendor":"Accellion","product":"FTA","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21017","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-28550","vendor":"Adobe","product":"Acrobat and Reader","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-4939","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-15961","vendor":"Adobe","product":"ColdFusion","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-4878","vendor":"Adobe","product":"Flash Player","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-5735","vendor":"Amcrest","product":"Cameras and Network Video Recorder (NVR)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-2215","vendor":"Android","product":"Android Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0041","vendor":"Android","product":"Android Kernel","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0069","vendor":"MediaTek","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-9805","vendor":"Apache","product":"Struts","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-42013","vendor":"Apache","product":"HTTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-41773","vendor":"Apache","product":"HTTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0211","vendor":"Apache","product":"HTTP Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-4437","vendor":"Apache","product":"Shiro","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-17558","vendor":"Apache","product":"Solr","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-17530","vendor":"Apache","product":"Struts","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-5638","vendor":"Apache","product":"Struts","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-11776","vendor":"Apache","product":"Struts","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30858","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-6223","vendor":"Apple","product":"iOS and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30860","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-27930","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30807","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-27950","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-27932","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9818","vendor":"Apple","product":"iOS, iPadOS, and watchOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9819","vendor":"Apple","product":"iOS, iPadOS, and watchOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30762","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1782","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1870","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1871","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1879","vendor":"Apple","product":"iOS, iPadOS, and watchOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30661","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30666","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30713","vendor":"Apple","product":"macOS","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-30657","vendor":"Apple","product":"macOS","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-30665","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30663","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30761","vendor":"Apple","product":"iOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30869","vendor":"Apple","product":"iOS, iPadOS, and macOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-9859","vendor":"Apple","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20090","vendor":"Arcadyan","product":"Buffalo Firmware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27562","vendor":"Arm","product":"Trusted Firmware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-28664","vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-28663","vendor":"Arm","product":"Mali Graphics Processing Unit (GPU)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-3398","vendor":"Atlassian","product":"Confluence Server and Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26084","vendor":"Atlassian","product":"Confluence Server and Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-11580","vendor":"Atlassian","product":"Crowd and Crowd Data Center","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-3396","vendor":"Atlassian","product":"Confluence Server and Data Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-42258","vendor":"BQE","product":"BillQuick Web Suite","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-3452","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2020-3580","vendor":"Cisco","product":"Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2021-1497","vendor":"Cisco","product":"HyperFlex HX","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2021-1498","vendor":"Cisco","product":"HyperFlex HX","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2018-0171","vendor":"Cisco","product":"IOS and IOS XE","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but impact is denial of service only"},{"cve":"CVE-2020-3118","vendor":"Cisco","product":"IOS XR","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2020-3566","vendor":"Cisco","product":"IOS XR","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-3569","vendor":"Cisco","product":"IOS XR","outcome":"included","reason":"vendor: Cisco/Duo; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-3161","vendor":"Cisco","product":"Cisco IP Phones","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2019-1653","vendor":"Cisco","product":"Small Business RV320 and RV325 Routers","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2018-0296","vendor":"Cisco","product":"Adaptive Security Appliance (ASA)","outcome":"review","reason":"relevant (vendor: Cisco/Duo) but classifies to no failure mode"},{"cve":"CVE-2019-13608","vendor":"Citrix","product":"StoreFront Server","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-8193","vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-8195","vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2020-8196","vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2019-19781","vendor":"Citrix","product":"Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance","outcome":"included","reason":"vendor: Citrix; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2019-11634","vendor":"Citrix","product":"Workspace Application and Receiver for Windows","outcome":"review","reason":"relevant (vendor: Citrix) but classifies to no failure mode"},{"cve":"CVE-2020-29557","vendor":"D-Link","product":"DIR-825 R1 Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-25506","vendor":"D-Link","product":"DNS-320 Device","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-15811","vendor":"DotNetNuke (DNN)","product":"DotNetNuke (DNN)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-18325","vendor":"DotNetNuke (DNN)","product":"DotNetNuke (DNN)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-9822","vendor":"DotNetNuke (DNN)","product":"DotNetNuke (DNN)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-15752","vendor":"Docker","product":"Desktop Community Edition","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8515","vendor":"DrayTek","product":"Multiple Vigor Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-7600","vendor":"Drupal","product":"Drupal Core","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22205","vendor":"GitLab","product":"Community and Enterprise Editions","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-6789","vendor":"Exim","product":"Exim","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8657","vendor":"EyesOfNetwork","product":"EyesOfNetwork","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2020-8655","vendor":"EyesOfNetwork","product":"EyesOfNetwork","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2020-5902","vendor":"F5","product":"BIG-IP","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22986","vendor":"F5","product":"BIG-IP and BIG-IQ Centralized Management","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-35464","vendor":"ForgeRock","product":"Access Management (AM)","outcome":"review","reason":"relevant (vendor: ForgeRock) but classifies to no failure mode"},{"cve":"CVE-2019-5591","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2020-12812","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2018-13379","vendor":"Fortinet","product":"FortiOS","outcome":"included","reason":"vendor: Fortinet; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-16010","vendor":"Google","product":"Chrome for Android UI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-15999","vendor":"Google","product":"Chrome FreeType","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21166","vendor":"Google","product":"Chromium","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-16017","vendor":"Google","product":"Chrome","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-37976","vendor":"Google","product":"Chromium","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2020-16009","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30632","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-16013","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30633","vendor":"Google","product":"Chromium Indexed DB API","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21148","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-37973","vendor":"Google","product":"Chromium Portals","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30551","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-37975","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-6418","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30554","vendor":"Google","product":"Chromium WebGL","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21206","vendor":"Google","product":"Chromium Blink","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38000","vendor":"Google","product":"Chromium Intents","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38003","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21224","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21193","vendor":"Google","product":"Chromium Blink","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21220","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-30563","vendor":"Google","product":"Chromium V8","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-4430","vendor":"IBM","product":"Data Risk Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-4427","vendor":"IBM","product":"Data Risk Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-4428","vendor":"IBM","product":"Data Risk Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-4716","vendor":"IBM","product":"Planning Analytics","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3715","vendor":"ImageMagick","product":"ImageMagick","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3718","vendor":"ImageMagick","product":"ImageMagick","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-15505","vendor":"Ivanti","product":"MobileIron Multiple Products","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2021-30116","vendor":"Kaseya","product":"Virtual System/Server Administrator (VSA)","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2020-7961","vendor":"Liferay","product":"Liferay Portal","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-23874","vendor":"McAfee","product":"McAfee Total Protection (MTP)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22506","vendor":"Micro Focus","product":"Micro Focus Access Manager","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22502","vendor":"Micro Focus","product":"Operation Bridge Reporter (OBR)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2014-1812","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38647","vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","outcome":"included","reason":"classified via cwe: federation-trust"},{"cve":"CVE-2016-0167","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0878","vendor":"Microsoft","product":"Edge and Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31955","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1647","vendor":"Microsoft","product":"Defender","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-33739","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-0185","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0683","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-17087","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-33742","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31199","vendor":"Microsoft","product":"Enhanced Cryptographic Provider","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-33771","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31956","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31201","vendor":"Microsoft","product":"Enhanced Cryptographic Provider","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-31979","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0938","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-17144","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0986","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1020","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38645","vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-34523","vendor":"Microsoft","product":"Exchange Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2017-7269","vendor":"Microsoft","product":"Internet Information Services (IIS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36948","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38649","vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0688","vendor":"Microsoft","product":"Exchange Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2017-0143","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-7255","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0708","vendor":"Microsoft","product":"Remote Desktop Services","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-34473","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1464","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: federation-trust"},{"cve":"CVE-2021-1732","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-34527","vendor":"Microsoft","product":"Windows","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-31207","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0803","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1040","vendor":"Microsoft","product":"Hyper-V RemoteFX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-28310","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1350","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26411","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0859","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-40444","vendor":"Microsoft","product":"MSHTML","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-8759","vendor":"Microsoft","product":".NET Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-8653","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0797","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36942","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1215","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-0798","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-0802","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-0158","vendor":"Microsoft","product":"MSCOMCTL.OCX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-1641","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27085","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0541","vendor":"Microsoft","product":"MSHTML","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-11882","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0674","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27059","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1367","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-0199","vendor":"Microsoft","product":"Office and WordPad","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1380","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1429","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-11774","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0968","vendor":"Microsoft","product":"Internet Explorer","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1472","vendor":"Microsoft","product":"Netlogon","outcome":"included","reason":"vendor: Microsoft identity; classified via keyword: privilege-escalation"},{"cve":"CVE-2021-26855","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26858","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27065","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1054","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1675","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-34448","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0601","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0604","vendor":"Microsoft","product":"SharePoint","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-0646","vendor":"Microsoft","product":".NET Framework","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0808","vendor":"Microsoft","product":"Win32k","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-26857","vendor":"Microsoft","product":"Exchange Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-1147","vendor":"Microsoft","product":".NET Framework, SharePoint, Visual Studio","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-1214","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-3235","vendor":"Microsoft","product":"Office","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-0863","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36955","vendor":"Microsoft","product":"Windows","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-38648","vendor":"Microsoft","product":"Open Management Infrastructure (OMI)","outcome":"included","reason":"classified via cwe: federation-trust"},{"cve":"CVE-2020-6819","vendor":"Mozilla","product":"Firefox and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-6820","vendor":"Mozilla","product":"Firefox and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-17026","vendor":"Mozilla","product":"Firefox and Thunderbird","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-15949","vendor":"Nagios","product":"Nagios XI","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-26919","vendor":"NETGEAR","product":"JGS516PE Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-19356","vendor":"Netis","product":"WF2419 Devices","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-2555","vendor":"Oracle","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2012-3152","vendor":"Oracle","product":"Fusion Middleware","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-14871","vendor":"Oracle","product":"Solaris and Zettabyte File System (ZFS)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2015-4852","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-14750","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-14882","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-14883","vendor":"Oracle","product":"WebLogic Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8644","vendor":"PlaySMS","product":"PlaySMS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-18935","vendor":"Progress","product":"Telerik UI for ASP.NET AJAX","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-22893","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"included","reason":"vendor: Ivanti; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2020-8243","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2021-22900","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2021-22894","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2020-8260","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2021-22899","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2019-11510","vendor":"Ivanti","product":"Pulse Connect Secure","outcome":"included","reason":"vendor: Ivanti; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2019-11539","vendor":"Ivanti","product":"Pulse Connect Secure and Pulse Policy Secure","outcome":"review","reason":"relevant (vendor: Ivanti) but classifies to no failure mode"},{"cve":"CVE-2021-1906","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-1905","vendor":"Qualcomm","product":"Multiple Chipsets","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-10221","vendor":"rConfig","product":"rConfig","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-35395","vendor":"Realtek","product":"AP-Router SDK","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-16651","vendor":"Roundcube","product":"Roundcube Webmail","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-11652","vendor":"SaltStack","product":"Salt","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-11651","vendor":"SaltStack","product":"Salt","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-16846","vendor":"SaltStack","product":"Salt","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-2380","vendor":"SAP","product":"Customer Relationship Management (CRM)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2010-5326","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2016-9563","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-6287","vendor":"SAP","product":"NetWeaver","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2020-6207","vendor":"SAP","product":"Solution Manager","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2016-3976","vendor":"SAP","product":"NetWeaver","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-16256","vendor":"SIMalliance","product":"Toolbox Browser","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-10148","vendor":"SolarWinds","product":"Orion","outcome":"included","reason":"vendor: N-able; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-35211","vendor":"SolarWinds","product":"Serv-U","outcome":"review","reason":"relevant (vendor: N-able) but classifies to no failure mode"},{"cve":"CVE-2016-3643","vendor":"SolarWinds","product":"Virtualization Manager","outcome":"included","reason":"vendor: N-able; classified via keyword: privilege-escalation"},{"cve":"CVE-2020-10199","vendor":"Sonatype","product":"Nexus Repository","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-20021","vendor":"SonicWall","product":"SonicWall Email Security","outcome":"included","reason":"vendor: SonicWall; classified via cwe: pre-auth-bypass"},{"cve":"CVE-2019-7481","vendor":"SonicWall","product":"SMA100","outcome":"included","reason":"vendor: SonicWall; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2021-20022","vendor":"SonicWall","product":"SonicWall Email Security","outcome":"included","reason":"vendor: SonicWall; classified via keyword: privilege-escalation"},{"cve":"CVE-2021-20023","vendor":"SonicWall","product":"SonicWall Email Security","outcome":"included","reason":"vendor: SonicWall; classified via keyword: privilege-escalation"},{"cve":"CVE-2021-20016","vendor":"SonicWall","product":"SSLVPN SMA100","outcome":"included","reason":"vendor: SonicWall; classified via keyword: pre-auth-bypass"},{"cve":"CVE-2020-12271","vendor":"Sophos","product":"SFOS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-10181","vendor":"Sumavision","product":"Enhanced Multimedia Router (EMR)","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-6327","vendor":"Symantec","product":"Symantec Messaging Gateway","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-18988","vendor":"TeamViewer","product":"Desktop","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2017-9248","vendor":"Progress","product":"ASP.NET AJAX and Sitefinity","outcome":"included","reason":"classified via cwe: credential-exposure"},{"cve":"CVE-2021-31755","vendor":"Tenda","product":"AC11 Router","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-10987","vendor":"Tenda","product":"AC1900 Router AC15 Model","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-14558","vendor":"Tenda","product":"AC7, AC9, and AC10 Routers","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2018-20062","vendor":"ThinkPHP","product":"noneCms","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-9082","vendor":"ThinkPHP","product":"ThinkPHP","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2019-18187","vendor":"Trend Micro","product":"OfficeScan","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8467","vendor":"Trend Micro","product":"Apex One and OfficeScan","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8468","vendor":"Trend Micro","product":"Apex One, OfficeScan and Worry-Free Business Security Agents","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-24557","vendor":"Trend Micro","product":"Apex One, OfficeScan, and Worry-Free Business Security","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-8599","vendor":"Trend Micro","product":"Apex One and OfficeScan","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36742","vendor":"Trend Micro","product":"Apex One, Apex One as a Service, and Worry-Free Business Security","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-36741","vendor":"Trend Micro","product":"Apex One, Apex One as a Service, and Worry-Free Business Security","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-20085","vendor":"TVT","product":"NVMS-1000","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-5849","vendor":"Unraid","product":"Unraid","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2020-5847","vendor":"Unraid","product":"Unraid","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-16759","vendor":"vBulletin","product":"vBulletin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-17496","vendor":"vBulletin","product":"vBulletin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-5544","vendor":"VMware","product":"VMware ESXi and Horizon DaaS","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-3992","vendor":"VMware","product":"ESXi","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-3950","vendor":"VMware","product":"Multiple Products","outcome":"included","reason":"classified via cwe: privilege-escalation"},{"cve":"CVE-2021-22005","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-3952","vendor":"VMware","product":"vCenter Server","outcome":"included","reason":"classified via cwe: pre-auth-bypass"},{"cve":"CVE-2021-21972","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-21985","vendor":"VMware","product":"vCenter Server","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-4006","vendor":"VMware","product":"Multiple Products","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-25213","vendor":"WordPress","product":"File Manager Plugin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-11738","vendor":"WordPress","product":"Snap Creek Duplicator Plugin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-9978","vendor":"WordPress","product":"Social Warfare Plugin","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-27561","vendor":"Yealink","product":"Device Management","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2021-40539","vendor":"Zoho","product":"ManageEngine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-10189","vendor":"Zoho","product":"ManageEngine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2019-8394","vendor":"Zoho","product":"ManageEngine","outcome":"excluded","reason":"no allowlisted vendor and no identity-mapped CWE"},{"cve":"CVE-2020-29583","vendor":"Zyxel","product":"Multiple Products","outcome":"included","reason":"classified via cwe: credential-exposure"}]}