{
  "query": {
    "exploited": "1",
    "page": "35"
  },
  "count": 20,
  "total": 1734,
  "page": 35,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T08:47:26.795Z",
    "kev": "2026-10-07T09:46:28.973Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T09:47:28.904Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=35",
    "next": "https://spydr.io/threats.json?exploited=1&page=36"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-41328",
      "url": "https://spydr.io/cve/CVE-2022-41328",
      "published": "2023-03-07T17:15:12.093Z",
      "modified": "2026-06-17T05:03:02.417Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.10682,
      "epss_percentile": 0.95697,
      "exploited": true,
      "kev": {
        "added": "2023-03-14",
        "due": "2023-04-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlying Linux system via crafted CLI commands."
    },
    {
      "id": "CVE-2019-8720",
      "url": "https://spydr.io/cve/CVE-2019-8720",
      "published": "2023-03-06T23:15:10.287Z",
      "modified": "2026-06-17T02:42:26.303Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01556,
      "epss_percentile": 0.74362,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "webkitgtk",
        "wpewebkit",
        "redhat"
      ],
      "products": [
        "webkitgtk"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues."
    },
    {
      "id": "CVE-2023-23529",
      "url": "https://spydr.io/cve/CVE-2023-23529",
      "published": "2023-02-27T20:15:14.710Z",
      "modified": "2026-06-17T05:37:21.160Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09502,
      "epss_percentile": 0.95318,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple Safari",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2022-47986",
      "url": "https://spydr.io/cve/CVE-2022-47986",
      "published": "2023-02-17T16:15:10.873Z",
      "modified": "2026-06-17T05:14:33.047Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99965,
      "epss_percentile": 0.99977,
      "exploited": true,
      "kev": {
        "added": "2023-02-21",
        "due": "2023-03-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "IBM"
      ],
      "products": [
        "IBM Aspera Faspex"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512."
    },
    {
      "id": "CVE-2023-23752",
      "url": "https://spydr.io/cve/CVE-2023-23752",
      "published": "2023-02-16T17:15:10.603Z",
      "modified": "2026-06-17T05:37:50.963Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99827,
      "epss_percentile": 0.9996,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Joomla! Project",
        "joomla"
      ],
      "products": [
        "Joomla! Project Joomla! CMS",
        "joomla\\!"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints."
    },
    {
      "id": "CVE-2023-21823",
      "url": "https://spydr.io/cve/CVE-2023-21823",
      "published": "2023-02-14T21:15:12.297Z",
      "modified": "2026-08-19T17:18:20.093Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.05563,
      "epss_percentile": 0.92635,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Office for Android",
        "Microsoft Office for iOS",
        "Microsoft Office for Universal",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "Windows Graphics Component Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-23376",
      "url": "https://spydr.io/cve/CVE-2023-23376",
      "published": "2023-02-14T20:15:16.907Z",
      "modified": "2026-08-19T17:18:20.433Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.10853,
      "epss_percentile": 0.95746,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2023-21715",
      "url": "https://spydr.io/cve/CVE-2023-21715",
      "published": "2023-02-14T20:15:14.280Z",
      "modified": "2026-08-19T17:18:12.137Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12011,
      "epss_percentile": 0.96027,
      "exploited": true,
      "kev": {
        "added": "2023-02-14",
        "due": "2023-03-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Microsoft Publisher Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2023-21529",
      "url": "https://spydr.io/cve/CVE-2023-21529",
      "published": "2023-02-14T20:15:11.743Z",
      "modified": "2026-08-19T17:18:05.870Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.59294,
      "epss_percentile": 0.99097,
      "exploited": true,
      "kev": {
        "added": "2026-04-13",
        "due": "2026-04-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Microsoft Exchange Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2023-25717",
      "url": "https://spydr.io/cve/CVE-2023-25717",
      "published": "2023-02-13T20:15:10.973Z",
      "modified": "2026-06-17T05:41:48.213Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98069,
      "epss_percentile": 0.99911,
      "exploited": true,
      "kev": {
        "added": "2023-05-12",
        "due": "2023-06-02",
        "action": "Apply updates per vendor instructions or disconnect product if it is end-of-life.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ruckuswireless",
        "commscope"
      ],
      "products": [
        "ruckuswireless ruckus wireless admin",
        "ruckuswireless smartzone ap",
        "commscope ruckus smartzone firmware"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring."
    },
    {
      "id": "CVE-2022-24990",
      "url": "https://spydr.io/cve/CVE-2022-24990",
      "published": "2023-02-07T18:15:09.100Z",
      "modified": "2026-06-17T04:32:54.773Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.83166,
      "epss_percentile": 0.99671,
      "exploited": true,
      "kev": {
        "added": "2023-02-10",
        "due": "2023-03-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "terra-master"
      ],
      "products": [
        "terra-master terramaster operating system"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending \"User-Agent: TNAS\" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response."
    },
    {
      "id": "CVE-2023-0669",
      "url": "https://spydr.io/cve/CVE-2023-0669",
      "published": "2023-02-06T20:15:14.300Z",
      "modified": "2026-08-06T05:16:38.057Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99996,
      "exploited": true,
      "kev": {
        "added": "2023-02-10",
        "due": "2023-03-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortra"
      ],
      "products": [
        "Fortra Goanywhere MFT"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2."
    },
    {
      "id": "CVE-2023-0266",
      "url": "https://spydr.io/cve/CVE-2023-0266",
      "published": "2023-01-30T14:15:10.500Z",
      "modified": "2026-06-17T05:25:09.763Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03702,
      "epss_percentile": 0.89425,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux"
      ],
      "products": [
        "Linux Kernel"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free vulnerability exists in the ALSA PCM package in the Linux Kernel. SNDRV_CTL_IOCTL_ELEM_{READ|WRITE}32 is missing locks that can be used in a use-after-free that can result in a priviledge escalation to gain ring0 access from the system user. We recommend upgrading past commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e"
    },
    {
      "id": "CVE-2023-21608",
      "url": "https://spydr.io/cve/CVE-2023-21608",
      "published": "2023-01-18T19:15:11.877Z",
      "modified": "2026-06-17T05:33:17.210Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.61475,
      "epss_percentile": 0.99146,
      "exploited": true,
      "kev": {
        "added": "2023-10-10",
        "due": "2023-10-31",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Acrobat Reader"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
    },
    {
      "id": "CVE-2022-47966",
      "url": "https://spydr.io/cve/CVE-2022-47966",
      "published": "2023-01-18T18:15:10.570Z",
      "modified": "2026-07-31T04:16:41.843Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99753,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2023-01-23",
        "due": "2023-02-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine access manager plus",
        "zohocorp manageengine ad360",
        "zohocorp manageengine adaudit plus",
        "zohocorp manageengine admanager plus",
        "zohocorp manageengine adselfservice plus",
        "zohocorp manageengine analytics plus",
        "zohocorp manageengine assetexplorer",
        "zohocorp manageengine key manager plus",
        "zohocorp manageengine pam360",
        "zohocorp manageengine password manager pro",
        "zohocorp manageengine servicedesk plus",
        "zohocorp manageengine servicedesk plus msp",
        "zohocorp manageengine supportcenter plus",
        "zohocorp manageengine application control plus",
        "zohocorp manageengine browser security plus",
        "zohocorp manageengine device control plus",
        "zohocorp manageengine endpoint dlp plus",
        "zohocorp manageengine os deployer",
        "zohocorp manageengine patch manager plus",
        "zohocorp manageengine remote access plus"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active)."
    },
    {
      "id": "CVE-2023-21839",
      "url": "https://spydr.io/cve/CVE-2023-21839",
      "published": "2023-01-18T00:15:13.450Z",
      "modified": "2026-06-17T05:34:09.560Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "oracle.com",
      "epss": 0.999,
      "epss_percentile": 0.99965,
      "exploited": true,
      "kev": {
        "added": "2023-05-01",
        "due": "2023-05-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation WebLogic Server"
      ],
      "cwes": [
        "CWE-502",
        "CWE-306"
      ],
      "description": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)."
    },
    {
      "id": "CVE-2023-22952",
      "url": "https://spydr.io/cve/CVE-2023-22952",
      "published": "2023-01-11T09:15:08.787Z",
      "modified": "2026-06-17T05:36:30.243Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.80139,
      "epss_percentile": 0.9961,
      "exploited": true,
      "kev": {
        "added": "2023-02-02",
        "due": "2023-02-23",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sugarcrm"
      ],
      "products": [
        "sugarcrm"
      ],
      "cwes": [
        "CWE-20",
        "CWE-94"
      ],
      "description": "In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation."
    },
    {
      "id": "CVE-2023-21674",
      "url": "https://spydr.io/cve/CVE-2023-21674",
      "published": "2023-01-10T22:15:16.307Z",
      "modified": "2026-06-17T05:33:36.547Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.40987,
      "epss_percentile": 0.98625,
      "exploited": true,
      "kev": {
        "added": "2023-01-10",
        "due": "2023-01-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-44877",
      "url": "https://spydr.io/cve/CVE-2022-44877",
      "published": "2023-01-05T23:15:09.150Z",
      "modified": "2026-06-17T05:09:01.120Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99995,
      "epss_percentile": 0.99988,
      "exploited": true,
      "kev": {
        "added": "2023-01-17",
        "due": "2023-02-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "control-webpanel"
      ],
      "products": [
        "control-webpanel webpanel"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter."
    },
    {
      "id": "CVE-2022-42475",
      "url": "https://spydr.io/cve/CVE-2022-42475",
      "published": "2023-01-02T09:15:09.490Z",
      "modified": "2026-06-17T05:04:59.630Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99474,
      "epss_percentile": 0.99943,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiProxy",
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-197",
        "CWE-787"
      ],
      "description": "A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
