{
  "query": {
    "exploited": "1",
    "page": "39"
  },
  "count": 20,
  "total": 1734,
  "page": 39,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T12:47:36.253Z",
    "kev": "2026-10-07T13:46:38.070Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T13:47:38.262Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=39",
    "next": "https://spydr.io/threats.json?exploited=1&page=40"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-22675",
      "url": "https://spydr.io/cve/CVE-2022-22675",
      "published": "2022-05-26T18:15:09.153Z",
      "modified": "2026-06-17T04:28:47.750Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12492,
      "epss_percentile": 0.9612,
      "exploited": true,
      "kev": {
        "added": "2022-04-04",
        "due": "2022-04-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2022-22674",
      "url": "https://spydr.io/cve/CVE-2022-22674",
      "published": "2022-05-26T18:15:09.107Z",
      "modified": "2026-06-17T04:28:47.590Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.01133,
      "epss_percentile": 0.65374,
      "exploited": true,
      "kev": {
        "added": "2022-04-04",
        "due": "2022-04-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS"
      ],
      "cwes": [
        "CWE-125"
      ],
      "description": "An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory."
    },
    {
      "id": "CVE-2022-20821",
      "url": "https://spydr.io/cve/CVE-2022-20821",
      "published": "2022-05-26T14:15:08.123Z",
      "modified": "2026-06-17T04:25:11.087Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.11471,
      "epss_percentile": 0.95909,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS XR Software"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system."
    },
    {
      "id": "CVE-2022-29303",
      "url": "https://spydr.io/cve/CVE-2022-29303",
      "published": "2022-05-12T16:15:07.600Z",
      "modified": "2026-06-17T04:39:59.293Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97997,
      "epss_percentile": 0.99909,
      "exploited": true,
      "kev": {
        "added": "2023-07-13",
        "due": "2023-08-03",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "contec"
      ],
      "products": [
        "contec sv-cpt-mc310 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php."
    },
    {
      "id": "CVE-2022-30525",
      "url": "https://spydr.io/cve/CVE-2022-30525",
      "published": "2022-05-12T14:15:07.053Z",
      "modified": "2026-06-17T04:43:46.390Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99944,
      "epss_percentile": 0.99973,
      "exploited": true,
      "kev": {
        "added": "2022-05-16",
        "due": "2022-06-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zyxel"
      ],
      "products": [
        "Zyxel USG FLEX 100(W) firmware",
        "Zyxel USG FLEX 200 firmware",
        "Zyxel USG FLEX 500 firmware",
        "Zyxel USG FLEX 700 firmware",
        "Zyxel ATP series firmware",
        "Zyxel VPN series firmware",
        "Zyxel USG FLEX 50(W) firmware",
        "Zyxel USG 20(W)-VPN firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device."
    },
    {
      "id": "CVE-2022-26925",
      "url": "https://spydr.io/cve/CVE-2022-26925",
      "published": "2022-05-10T21:15:10.187Z",
      "modified": "2026-06-17T04:36:08.233Z",
      "score": 5.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.10476,
      "epss_percentile": 0.95636,
      "exploited": true,
      "kev": {
        "added": "2022-07-01",
        "due": "2022-07-22",
        "action": "Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Windows LSA Spoofing Vulnerability"
    },
    {
      "id": "CVE-2022-26923",
      "url": "https://spydr.io/cve/CVE-2022-26923",
      "published": "2022-05-10T21:15:10.133Z",
      "modified": "2026-06-17T04:36:07.943Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.835,
      "epss_percentile": 0.99679,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-295"
      ],
      "description": "Active Directory Domain Services Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-30333",
      "url": "https://spydr.io/cve/CVE-2022-30333",
      "published": "2022-05-09T08:15:06.937Z",
      "modified": "2026-10-02T14:54:55.840Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.99233,
      "epss_percentile": 0.99936,
      "exploited": true,
      "kev": {
        "added": "2022-08-09",
        "due": "2022-08-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rarlab",
        "debian"
      ],
      "products": [
        "rarlab unrar",
        "debian linux"
      ],
      "cwes": [
        "CWE-22",
        "CWE-59"
      ],
      "description": "RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected."
    },
    {
      "id": "CVE-2022-1388",
      "url": "https://spydr.io/cve/CVE-2022-1388",
      "published": "2022-05-05T17:15:10.570Z",
      "modified": "2026-06-17T04:22:20.683Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "f5.com",
      "epss": 0.99954,
      "epss_percentile": 0.99974,
      "exploited": true,
      "kev": {
        "added": "2022-05-10",
        "due": "2022-05-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "F5"
      ],
      "products": [
        "F5 BIG-IP"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated"
    },
    {
      "id": "CVE-2022-24706",
      "url": "https://spydr.io/cve/CVE-2022-24706",
      "published": "2022-04-26T10:15:35.083Z",
      "modified": "2026-06-17T04:32:20.160Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9251,
      "epss_percentile": 0.99825,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache CouchDB"
      ],
      "cwes": [
        "CWE-1188"
      ],
      "description": "In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations."
    },
    {
      "id": "CVE-2022-29499",
      "url": "https://spydr.io/cve/CVE-2022-29499",
      "published": "2022-04-26T02:15:37.107Z",
      "modified": "2026-08-06T05:16:37.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55242,
      "epss_percentile": 0.99007,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel mivoice connect"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA."
    },
    {
      "id": "CVE-2022-27926",
      "url": "https://spydr.io/cve/CVE-2022-27926",
      "published": "2022-04-21T00:15:08.450Z",
      "modified": "2026-06-17T04:37:45.020Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.17634,
      "epss_percentile": 0.97075,
      "exploited": true,
      "kev": {
        "added": "2023-04-03",
        "due": "2023-04-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request parameters."
    },
    {
      "id": "CVE-2022-27925",
      "url": "https://spydr.io/cve/CVE-2022-27925",
      "published": "2022-04-21T00:15:08.407Z",
      "modified": "2026-10-01T19:17:14.417Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98676,
      "epss_percentile": 0.99923,
      "exploited": true,
      "kev": {
        "added": "2022-08-11",
        "due": "2022-09-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal."
    },
    {
      "id": "CVE-2022-27924",
      "url": "https://spydr.io/cve/CVE-2022-27924",
      "published": "2022-04-21T00:15:08.360Z",
      "modified": "2026-10-02T14:55:01.717Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.93908,
      "epss_percentile": 0.99844,
      "exploited": true,
      "kev": {
        "added": "2022-08-04",
        "due": "2022-08-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries."
    },
    {
      "id": "CVE-2022-21445",
      "url": "https://spydr.io/cve/CVE-2022-21445",
      "published": "2022-04-19T21:15:15.907Z",
      "modified": "2026-06-17T04:26:16.837Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.62478,
      "epss_percentile": 0.99169,
      "exploited": true,
      "kev": {
        "added": "2024-09-18",
        "due": "2024-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation",
        "oracle"
      ],
      "products": [
        "Oracle Corporation Application Development Framework (ADF)",
        "oracle jdeveloper"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2022-29464",
      "url": "https://spydr.io/cve/CVE-2022-29464",
      "published": "2022-04-18T22:15:09.027Z",
      "modified": "2026-06-17T04:40:13.993Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99992,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "wso2"
      ],
      "products": [
        "wso2 api manager",
        "wso2 enterprise integrator",
        "wso2 identity server",
        "wso2 identity server analytics",
        "wso2 identity server as key manager",
        "wso2 open banking am",
        "wso2 open banking iam",
        "wso2 open banking km"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0."
    },
    {
      "id": "CVE-2022-28810",
      "url": "https://spydr.io/cve/CVE-2022-28810",
      "published": "2022-04-18T13:15:08.233Z",
      "modified": "2026-06-17T04:39:06.870Z",
      "score": 6.8,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70966,
      "epss_percentile": 0.9939,
      "exploited": true,
      "kev": {
        "added": "2023-03-07",
        "due": "2023-03-28",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine adselfservice plus"
      ],
      "cwes": [
        "CWE-78",
        "CWE-798"
      ],
      "description": "Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field."
    },
    {
      "id": "CVE-2022-26904",
      "url": "https://spydr.io/cve/CVE-2022-26904",
      "published": "2022-04-15T19:15:15.027Z",
      "modified": "2026-06-17T04:36:05.480Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.16948,
      "epss_percentile": 0.96988,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-362"
      ],
      "description": "Windows User Profile Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-24521",
      "url": "https://spydr.io/cve/CVE-2022-24521",
      "published": "2022-04-15T19:15:11.107Z",
      "modified": "2026-06-17T04:32:02.300Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.07076,
      "epss_percentile": 0.94047,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-24816",
      "url": "https://spydr.io/cve/CVE-2022-24816",
      "published": "2022-04-13T21:15:07.683Z",
      "modified": "2026-06-17T04:32:35.060Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99911,
      "epss_percentile": 0.99967,
      "exploited": true,
      "kev": {
        "added": "2024-06-26",
        "due": "2024-07-17",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "geosolutions-it",
        "geosolutionsgroup"
      ],
      "products": [
        "geosolutions-it jai-ext",
        "geosolutionsgroup jai-ext"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
