{
  "query": {
    "exploited": "1",
    "page": "37"
  },
  "count": 20,
  "total": 1734,
  "page": 37,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T10:47:31.354Z",
    "kev": "2026-10-07T10:46:31.132Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T10:47:31.354Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=37",
    "next": "https://spydr.io/threats.json?exploited=1&page=38"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-42827",
      "url": "https://spydr.io/cve/CVE-2022-42827",
      "published": "2022-11-01T20:15:24.333Z",
      "modified": "2026-06-17T05:05:25.003Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01048,
      "epss_percentile": 0.63065,
      "exploited": true,
      "kev": {
        "added": "2022-10-25",
        "due": "2022-11-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2022-38181",
      "url": "https://spydr.io/cve/CVE-2022-38181",
      "published": "2022-10-25T19:15:11.487Z",
      "modified": "2026-06-17T04:56:14.803Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14093,
      "epss_percentile": 0.96472,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0."
    },
    {
      "id": "CVE-2016-20017",
      "url": "https://spydr.io/cve/CVE-2016-20017",
      "published": "2022-10-19T05:15:08.817Z",
      "modified": "2026-06-17T00:43:05.853Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.64238,
      "epss_percentile": 0.99212,
      "exploited": true,
      "kev": {
        "added": "2024-01-08",
        "due": "2024-01-29",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dsl-2750b firmware"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022."
    },
    {
      "id": "CVE-2022-21587",
      "url": "https://spydr.io/cve/CVE-2022-21587",
      "published": "2022-10-18T21:15:10.960Z",
      "modified": "2026-06-17T04:26:34.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.98342,
      "epss_percentile": 0.99917,
      "exploited": true,
      "kev": {
        "added": "2023-02-02",
        "due": "2023-02-23",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Web Applications Desktop Integrator"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2022-40684",
      "url": "https://spydr.io/cve/CVE-2022-40684",
      "published": "2022-10-18T14:15:09.747Z",
      "modified": "2026-08-06T05:16:37.827Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99984,
      "epss_percentile": 0.99983,
      "exploited": true,
      "kev": {
        "added": "2022-10-11",
        "due": "2022-11-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS, FortiProxy, FortiSwitchManager"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests."
    },
    {
      "id": "CVE-2022-41033",
      "url": "https://spydr.io/cve/CVE-2022-41033",
      "published": "2022-10-11T19:15:20.567Z",
      "modified": "2026-06-17T05:02:27.533Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.01696,
      "epss_percentile": 0.76391,
      "exploited": true,
      "kev": {
        "added": "2022-10-11",
        "due": "2022-11-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Windows COM+ Event System Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-38028",
      "url": "https://spydr.io/cve/CVE-2022-38028",
      "published": "2022-10-11T19:15:15.067Z",
      "modified": "2026-06-17T04:55:56.497Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.14949,
      "epss_percentile": 0.96625,
      "exploited": true,
      "kev": {
        "added": "2024-04-23",
        "due": "2024-05-14",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Windows Print Spooler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-41082",
      "url": "https://spydr.io/cve/CVE-2022-41082",
      "published": "2022-10-03T01:15:08.843Z",
      "modified": "2026-06-17T05:02:33.460Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.9997,
      "epss_percentile": 0.99978,
      "exploited": true,
      "kev": {
        "added": "2022-09-30",
        "due": "2022-10-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12",
        "Microsoft Exchange Server 2016 Cumulative Update 23"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Microsoft Exchange Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2022-41040",
      "url": "https://spydr.io/cve/CVE-2022-41040",
      "published": "2022-10-03T01:15:08.753Z",
      "modified": "2026-06-17T05:02:28.500Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99956,
      "epss_percentile": 0.99974,
      "exploited": true,
      "kev": {
        "added": "2022-09-30",
        "due": "2022-10-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12",
        "Microsoft Exchange Server 2016 Cumulative Update 23"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Microsoft Exchange Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-20775",
      "url": "https://spydr.io/cve/CVE-2022-20775",
      "published": "2022-09-30T19:15:11.467Z",
      "modified": "2026-06-17T04:25:04.257Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12475,
      "epss_percentile": 0.96115,
      "exploited": true,
      "kev": {
        "added": "2026-02-25",
        "due": "2026-02-27",
        "action": "Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Catalyst SD-WAN",
        "Cisco Catalyst SD-WAN Manager",
        "Cisco SD-WAN vContainer",
        "Cisco SD-WAN vEdge Cloud",
        "Cisco SD-WAN vEdge Router"
      ],
      "cwes": [
        "CWE-25",
        "CWE-22"
      ],
      "description": "A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF"
    },
    {
      "id": "CVE-2022-3075",
      "url": "https://spydr.io/cve/CVE-2022-3075",
      "published": "2022-09-26T16:15:13.463Z",
      "modified": "2026-06-17T04:58:46.630Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05806,
      "epss_percentile": 0.92926,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page."
    },
    {
      "id": "CVE-2022-3038",
      "url": "https://spydr.io/cve/CVE-2022-3038",
      "published": "2022-09-26T16:15:11.793Z",
      "modified": "2026-06-17T04:58:41.230Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24925,
      "epss_percentile": 0.9786,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "fedoraproject"
      ],
      "products": [
        "Google Chrome",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-2856",
      "url": "https://spydr.io/cve/CVE-2022-2856",
      "published": "2022-09-26T16:15:11.207Z",
      "modified": "2026-06-17T04:42:42.850Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.0453,
      "epss_percentile": 0.91279,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "fedoraproject"
      ],
      "products": [
        "Google Chrome",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page."
    },
    {
      "id": "CVE-2022-41352",
      "url": "https://spydr.io/cve/CVE-2022-41352",
      "published": "2022-09-26T02:15:10.733Z",
      "modified": "2026-09-10T04:17:37.410Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95478,
      "epss_percentile": 0.9987,
      "exploited": true,
      "kev": {
        "added": "2022-10-20",
        "due": "2022-11-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio."
    },
    {
      "id": "CVE-2022-3236",
      "url": "https://spydr.io/cve/CVE-2022-3236",
      "published": "2022-09-23T13:15:10.327Z",
      "modified": "2026-06-17T04:59:07.653Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98905,
      "epss_percentile": 0.99927,
      "exploited": true,
      "kev": {
        "added": "2022-09-23",
        "due": "2022-10-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sophos"
      ],
      "products": [
        "Sophos Firewall"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older."
    },
    {
      "id": "CVE-2022-39197",
      "url": "https://spydr.io/cve/CVE-2022-39197",
      "published": "2022-09-22T01:15:11.963Z",
      "modified": "2026-06-17T04:57:53.710Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.46446,
      "epss_percentile": 0.98788,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "helpsystems"
      ],
      "products": [
        "helpsystems cobalt strike"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed)."
    },
    {
      "id": "CVE-2022-32917",
      "url": "https://spydr.io/cve/CVE-2022-32917",
      "published": "2022-09-20T21:15:11.200Z",
      "modified": "2026-06-17T04:48:12.837Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05603,
      "epss_percentile": 0.9269,
      "exploited": true,
      "kev": {
        "added": "2022-09-14",
        "due": "2022-10-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2022-40139",
      "url": "https://spydr.io/cve/CVE-2022-40139",
      "published": "2022-09-19T18:15:09.960Z",
      "modified": "2026-06-17T05:01:01.087Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03291,
      "epss_percentile": 0.88119,
      "exploited": true,
      "kev": {
        "added": "2022-09-15",
        "due": "2022-10-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro"
      ],
      "products": [
        "Trend Micro Apex One"
      ],
      "cwes": [],
      "description": "Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability."
    },
    {
      "id": "CVE-2022-35914",
      "url": "https://spydr.io/cve/CVE-2022-35914",
      "published": "2022-09-19T16:15:11.253Z",
      "modified": "2026-06-17T04:52:30.600Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9988,
      "epss_percentile": 0.99965,
      "exploited": true,
      "kev": {
        "added": "2023-03-07",
        "due": "2023-03-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "glpi-project"
      ],
      "products": [
        "glpi-project glpi"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection."
    },
    {
      "id": "CVE-2022-37969",
      "url": "https://spydr.io/cve/CVE-2022-37969",
      "published": "2022-09-13T19:15:12.323Z",
      "modified": "2026-09-10T04:17:35.097Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.28275,
      "epss_percentile": 0.98073,
      "exploited": true,
      "kev": {
        "added": "2022-09-14",
        "due": "2022-10-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
