{
  "query": {
    "exploited": "1",
    "page": "38"
  },
  "count": 20,
  "total": 1734,
  "page": 38,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T10:47:31.354Z",
    "kev": "2026-10-07T11:46:33.386Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T11:47:33.740Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=38",
    "next": "https://spydr.io/threats.json?exploited=1&page=39"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-27593",
      "url": "https://spydr.io/cve/CVE-2022-27593",
      "published": "2022-09-08T11:15:19.503Z",
      "modified": "2026-06-17T04:37:19.550Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87908,
      "epss_percentile": 0.99761,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. Photo Station"
      ],
      "cwes": [
        "CWE-610"
      ],
      "description": "An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later"
    },
    {
      "id": "CVE-2022-37055",
      "url": "https://spydr.io/cve/CVE-2022-37055",
      "published": "2022-08-28T17:15:08.363Z",
      "modified": "2026-06-17T04:54:32.267Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55531,
      "epss_percentile": 0.99015,
      "exploited": true,
      "kev": {
        "added": "2025-12-08",
        "due": "2025-12-29",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink go-rt-ac750 firmware"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,"
    },
    {
      "id": "CVE-2022-36537",
      "url": "https://spydr.io/cve/CVE-2022-36537",
      "published": "2022-08-26T20:15:08.303Z",
      "modified": "2026-06-17T04:53:38.087Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.95397,
      "epss_percentile": 0.99868,
      "exploited": true,
      "kev": {
        "added": "2023-02-27",
        "due": "2023-03-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zkoss"
      ],
      "products": [
        "zkoss zk framework"
      ],
      "cwes": [],
      "description": "ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader."
    },
    {
      "id": "CVE-2022-36804",
      "url": "https://spydr.io/cve/CVE-2022-36804",
      "published": "2022-08-25T06:15:09.077Z",
      "modified": "2026-06-17T04:54:00.640Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99174,
      "epss_percentile": 0.99934,
      "exploited": true,
      "kev": {
        "added": "2022-09-30",
        "due": "2022-10-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Bitbucket Server",
        "Atlassian Bitbucket Data Center"
      ],
      "cwes": [
        "CWE-78",
        "CWE-88"
      ],
      "description": "Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew."
    },
    {
      "id": "CVE-2022-32894",
      "url": "https://spydr.io/cve/CVE-2022-32894",
      "published": "2022-08-24T20:15:09.193Z",
      "modified": "2026-06-17T04:48:09.577Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03286,
      "epss_percentile": 0.88095,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2022-32893",
      "url": "https://spydr.io/cve/CVE-2022-32893",
      "published": "2022-08-24T20:15:09.147Z",
      "modified": "2026-06-17T04:48:09.370Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09931,
      "epss_percentile": 0.9547,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2022-37042",
      "url": "https://spydr.io/cve/CVE-2022-37042",
      "published": "2022-08-12T15:15:16.053Z",
      "modified": "2026-08-04T05:16:29.020Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91893,
      "epss_percentile": 0.99817,
      "exploited": true,
      "kev": {
        "added": "2022-08-11",
        "due": "2022-09-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925."
    },
    {
      "id": "CVE-2022-0028",
      "url": "https://spydr.io/cve/CVE-2022-0028",
      "published": "2022-08-10T16:15:08.343Z",
      "modified": "2026-06-17T04:19:55.243Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.02542,
      "epss_percentile": 0.84478,
      "exploited": true,
      "kev": {
        "added": "2022-08-22",
        "due": "2022-09-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-406"
      ],
      "description": "A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them."
    },
    {
      "id": "CVE-2022-34713",
      "url": "https://spydr.io/cve/CVE-2022-34713",
      "published": "2022-08-09T20:15:11.487Z",
      "modified": "2026-06-17T04:50:46.483Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.67757,
      "epss_percentile": 0.99302,
      "exploited": true,
      "kev": {
        "added": "2022-08-09",
        "due": "2022-08-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2022-2294",
      "url": "https://spydr.io/cve/CVE-2022-2294",
      "published": "2022-07-28T02:15:07.797Z",
      "modified": "2026-08-04T05:16:28.260Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70461,
      "epss_percentile": 0.99375,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-1364",
      "url": "https://spydr.io/cve/CVE-2022-1364",
      "published": "2022-07-26T22:15:09.147Z",
      "modified": "2026-06-17T04:22:17.713Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1372,
      "epss_percentile": 0.96407,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-1096",
      "url": "https://spydr.io/cve/CVE-2022-1096",
      "published": "2022-07-23T00:15:08.333Z",
      "modified": "2026-06-17T04:21:49.070Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.24205,
      "epss_percentile": 0.97799,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-26138",
      "url": "https://spydr.io/cve/CVE-2022-26138",
      "published": "2022-07-20T18:15:08.617Z",
      "modified": "2026-06-17T04:34:46.187Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98241,
      "epss_percentile": 0.99914,
      "exploited": true,
      "kev": {
        "added": "2022-07-29",
        "due": "2022-08-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Questions For Confluence"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app."
    },
    {
      "id": "CVE-2022-35405",
      "url": "https://spydr.io/cve/CVE-2022-35405",
      "published": "2022-07-19T15:15:08.680Z",
      "modified": "2026-06-17T04:51:46.637Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99924,
      "epss_percentile": 0.99969,
      "exploited": true,
      "kev": {
        "added": "2022-09-22",
        "due": "2022-10-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine access manager plus",
        "zohocorp manageengine pam360",
        "zohocorp manageengine password manager pro"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)"
    },
    {
      "id": "CVE-2022-33891",
      "url": "https://spydr.io/cve/CVE-2022-33891",
      "published": "2022-07-18T07:15:07.600Z",
      "modified": "2026-06-17T04:49:25.943Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93244,
      "epss_percentile": 0.99835,
      "exploited": true,
      "kev": {
        "added": "2023-03-07",
        "due": "2023-03-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Spark"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter can allow someone to perform impersonation by providing an arbitrary user name. A malicious user might then be able to reach a permission check function that will ultimately build a Unix shell command based on their input, and execute it. This will result in arbitrary shell command execution as the user Spark is currently running as. This affects Apache Spark versions 3.0.3 and earlier, versions 3.1.1 to 3.1.2, and versions 3.2.0 to 3.2.1."
    },
    {
      "id": "CVE-2022-26352",
      "url": "https://spydr.io/cve/CVE-2022-26352",
      "published": "2022-07-17T22:15:08.787Z",
      "modified": "2026-06-17T04:35:02.220Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91248,
      "epss_percentile": 0.99809,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dotcms"
      ],
      "products": [
        "dotcms"
      ],
      "cwes": [],
      "description": "An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution."
    },
    {
      "id": "CVE-2022-22047",
      "url": "https://spydr.io/cve/CVE-2022-22047",
      "published": "2022-07-12T23:15:10.343Z",
      "modified": "2026-06-17T04:27:33.870Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.18765,
      "epss_percentile": 0.97206,
      "exploited": true,
      "kev": {
        "added": "2022-07-12",
        "due": "2022-08-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)"
      ],
      "cwes": [
        "CWE-426"
      ],
      "description": "Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-22071",
      "url": "https://spydr.io/cve/CVE-2022-22071",
      "published": "2022-06-14T10:15:19.003Z",
      "modified": "2026-06-17T04:27:37.993Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00411,
      "epss_percentile": 0.33155,
      "exploited": true,
      "kev": {
        "added": "2023-12-05",
        "due": "2023-12-26",
        "action": "Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music"
    },
    {
      "id": "CVE-2022-26134",
      "url": "https://spydr.io/cve/CVE-2022-26134",
      "published": "2022-06-03T22:15:07.717Z",
      "modified": "2026-06-17T04:34:44.940Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99994,
      "exploited": true,
      "kev": {
        "added": "2022-06-02",
        "due": "2022-06-06",
        "action": "Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Confluence Data Center",
        "Atlassian Confluence Server"
      ],
      "cwes": [
        "CWE-917"
      ],
      "description": "In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1."
    },
    {
      "id": "CVE-2022-30190",
      "url": "https://spydr.io/cve/CVE-2022-30190",
      "published": "2022-06-01T20:15:07.983Z",
      "modified": "2026-08-06T05:16:37.550Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99163,
      "epss_percentile": 0.99933,
      "exploited": true,
      "kev": {
        "added": "2022-06-14",
        "due": "2022-07-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)"
      ],
      "cwes": [],
      "description": "A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
