{
  "query": {
    "exploited": "1",
    "page": "36"
  },
  "count": 20,
  "total": 1734,
  "page": 36,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T10:47:31.354Z",
    "kev": "2026-10-07T10:46:31.132Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T10:47:31.354Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=36",
    "next": "https://spydr.io/threats.json?exploited=1&page=37"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-26486",
      "url": "https://spydr.io/cve/CVE-2022-26486",
      "published": "2022-12-22T20:15:22.797Z",
      "modified": "2026-08-19T15:29:21.807Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02351,
      "epss_percentile": 0.83149,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-03-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Firefox for Android",
        "Mozilla Thunderbird",
        "Mozilla Focus"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0."
    },
    {
      "id": "CVE-2022-26485",
      "url": "https://spydr.io/cve/CVE-2022-26485",
      "published": "2022-12-22T20:15:22.563Z",
      "modified": "2026-08-19T15:29:21.807Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14261,
      "epss_percentile": 0.96508,
      "exploited": true,
      "kev": {
        "added": "2022-03-07",
        "due": "2022-03-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Mozilla"
      ],
      "products": [
        "Mozilla Firefox",
        "Mozilla Firefox ESR",
        "Mozilla Firefox for Android",
        "Mozilla Thunderbird",
        "Mozilla Focus"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0."
    },
    {
      "id": "CVE-2022-42856",
      "url": "https://spydr.io/cve/CVE-2022-42856",
      "published": "2022-12-15T19:15:25.123Z",
      "modified": "2026-06-17T05:05:29.160Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08523,
      "epss_percentile": 0.94906,
      "exploited": true,
      "kev": {
        "added": "2022-12-14",
        "due": "2023-01-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.."
    },
    {
      "id": "CVE-2022-44698",
      "url": "https://spydr.io/cve/CVE-2022-44698",
      "published": "2022-12-13T19:15:14.403Z",
      "modified": "2026-06-17T05:08:47.430Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.76267,
      "epss_percentile": 0.99525,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016"
      ],
      "cwes": [],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2022-27518",
      "url": "https://spydr.io/cve/CVE-2022-27518",
      "published": "2022-12-13T17:15:14.350Z",
      "modified": "2026-06-17T04:37:09.663Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06683,
      "epss_percentile": 0.9372,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix Gateway, Citrix ADC"
      ],
      "cwes": [
        "CWE-664"
      ],
      "description": "Unauthenticated remote arbitrary code execution"
    },
    {
      "id": "CVE-2022-46169",
      "url": "https://spydr.io/cve/CVE-2022-46169",
      "published": "2022-12-05T21:15:10.527Z",
      "modified": "2026-06-17T05:11:21.140Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99826,
      "epss_percentile": 0.9996,
      "exploited": true,
      "kev": {
        "added": "2023-02-16",
        "due": "2023-03-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cacti"
      ],
      "products": [
        "cacti"
      ],
      "cwes": [
        "CWE-74",
        "CWE-78",
        "CWE-863"
      ],
      "description": "Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti. The following call to `gethostbyaddr` will resolve this IP address to the hostname of the server, which will pass the `poller` hostname check because of the default entry. After the authorization of the `remote_agent.php` file is bypassed, an attacker can trigger different actions. One of these actions is called `polldata`. The called function `poll_for_data` retrieves a few request parameters and loads the corresponding `poller_item` entries from the database. If the `action` of a `poller_item` equals `POLLER_ACTION_SCRIPT_PHP`, the function `proc_open` is used to execute a PHP script. The attacker-controlled parameter `$poller_id` is retrieved via the function `get_nfilter_request_var`, which allows arbitrary strings. This variable is later inserted into the string passed to `proc_open`, which leads to a command injection vulnerability. By e.g. providing the `poller_id=;id` the `id` command is executed. In order to reach the vulnerable call, the attacker must provide a `host_id` and `local_data_id`, where the `action` of the corresponding `poller_item` is set to `POLLER_ACTION_SCRIPT_PHP`. Both of these ids (`host_id` and `local_data_id`) can easily be bruteforced. The only requirement is that a `poller_item` with an `POLLER_ACTION_SCRIPT_PHP` action exists. This is very likely on a productive instance because this action is added by some predefined templates like `Device - Uptime` or `Device - Polling Time`. This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a `poller_item` with the `action` type `POLLER_ACTION_SCRIPT_PHP` (`2`) is configured. The authorization bypass should be prevented by not allowing an attacker to make `get_client_addr` (file `lib/functions.php`) return an arbitrary IP address. This could be done by not honoring the `HTTP_...` `$_SERVER` variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with `1.2.23` being the first release containing the patch."
    },
    {
      "id": "CVE-2022-4262",
      "url": "https://spydr.io/cve/CVE-2022-4262",
      "published": "2022-12-02T21:15:12.247Z",
      "modified": "2026-06-17T05:20:25.837Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.2351,
      "epss_percentile": 0.97744,
      "exploited": true,
      "kev": {
        "added": "2022-12-05",
        "due": "2022-12-26",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2022-40799",
      "url": "https://spydr.io/cve/CVE-2022-40799",
      "published": "2022-11-29T05:15:11.310Z",
      "modified": "2026-06-17T05:02:02.970Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.3365,
      "epss_percentile": 0.98348,
      "exploited": true,
      "kev": {
        "added": "2025-08-05",
        "due": "2025-08-26",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dnr-322l firmware"
      ],
      "cwes": [
        "CWE-494"
      ],
      "description": "Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device."
    },
    {
      "id": "CVE-2022-4135",
      "url": "https://spydr.io/cve/CVE-2022-4135",
      "published": "2022-11-25T01:15:09.957Z",
      "modified": "2026-06-17T05:20:03.057Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.31864,
      "epss_percentile": 0.98262,
      "exploited": true,
      "kev": {
        "added": "2022-11-28",
        "due": "2022-12-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2022-41223",
      "url": "https://spydr.io/cve/CVE-2022-41223",
      "published": "2022-11-22T01:15:32.897Z",
      "modified": "2026-06-17T05:02:49.103Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10657,
      "epss_percentile": 0.95687,
      "exploited": true,
      "kev": {
        "added": "2023-02-21",
        "due": "2023-03-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel mivoice connect"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type."
    },
    {
      "id": "CVE-2022-40765",
      "url": "https://spydr.io/cve/CVE-2022-40765",
      "published": "2022-11-22T01:15:31.847Z",
      "modified": "2026-06-17T05:02:00.547Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10566,
      "epss_percentile": 0.95665,
      "exploited": true,
      "kev": {
        "added": "2023-02-21",
        "due": "2023-03-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel mivoice connect"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters."
    },
    {
      "id": "CVE-2022-23748",
      "url": "https://spydr.io/cve/CVE-2022-23748",
      "published": "2022-11-17T23:15:14.383Z",
      "modified": "2026-06-17T04:30:45.160Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09092,
      "epss_percentile": 0.95172,
      "exploited": true,
      "kev": {
        "added": "2025-02-06",
        "due": "2025-02-27",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "audinate"
      ],
      "products": [
        "Audinate Dante Application Library for Windows"
      ],
      "cwes": [
        "CWE-114",
        "CWE-426"
      ],
      "description": "mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files."
    },
    {
      "id": "CVE-2022-41128",
      "url": "https://spydr.io/cve/CVE-2022-41128",
      "published": "2022-11-09T22:15:25.453Z",
      "modified": "2026-08-10T16:18:24.890Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.24623,
      "epss_percentile": 0.97831,
      "exploited": true,
      "kev": {
        "added": "2022-11-08",
        "due": "2022-12-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows Scripting Languages Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2022-41125",
      "url": "https://spydr.io/cve/CVE-2022-41125",
      "published": "2022-11-09T22:15:25.307Z",
      "modified": "2026-08-10T16:18:24.687Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.03046,
      "epss_percentile": 0.8712,
      "exploited": true,
      "kev": {
        "added": "2022-11-08",
        "due": "2022-12-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows CNG Key Isolation Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-41091",
      "url": "https://spydr.io/cve/CVE-2022-41091",
      "published": "2022-11-09T22:15:22.093Z",
      "modified": "2026-08-10T16:18:20.797Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.01806,
      "epss_percentile": 0.77864,
      "exploited": true,
      "kev": {
        "added": "2022-11-08",
        "due": "2022-12-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2022-41080",
      "url": "https://spydr.io/cve/CVE-2022-41080",
      "published": "2022-11-09T22:15:21.550Z",
      "modified": "2026-08-10T16:18:19.843Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.77326,
      "epss_percentile": 0.99547,
      "exploited": true,
      "kev": {
        "added": "2023-01-10",
        "due": "2023-01-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12"
      ],
      "cwes": [],
      "description": "Microsoft Exchange Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-41073",
      "url": "https://spydr.io/cve/CVE-2022-41073",
      "published": "2022-11-09T22:15:21.207Z",
      "modified": "2026-08-10T16:18:19.340Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02278,
      "epss_percentile": 0.82567,
      "exploited": true,
      "kev": {
        "added": "2022-11-08",
        "due": "2022-12-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows Print Spooler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-41049",
      "url": "https://spydr.io/cve/CVE-2022-41049",
      "published": "2022-11-09T22:15:19.567Z",
      "modified": "2026-08-10T16:18:15.733Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.02491,
      "epss_percentile": 0.84137,
      "exploited": true,
      "kev": {
        "added": "2022-11-14",
        "due": "2022-12-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2022-31199",
      "url": "https://spydr.io/cve/CVE-2022-31199",
      "published": "2022-11-08T01:15:09.767Z",
      "modified": "2026-06-17T04:45:01.133Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.36009,
      "epss_percentile": 0.98436,
      "exploited": true,
      "kev": {
        "added": "2023-07-11",
        "due": "2023-08-01",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netwrix"
      ],
      "products": [
        "netwrix auditor"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors."
    },
    {
      "id": "CVE-2022-3723",
      "url": "https://spydr.io/cve/CVE-2022-3723",
      "published": "2022-11-01T23:15:19.710Z",
      "modified": "2026-06-17T05:00:10.620Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07921,
      "epss_percentile": 0.94573,
      "exploited": true,
      "kev": {
        "added": "2022-10-28",
        "due": "2022-11-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
