{
  "query": {
    "exploited": "1",
    "page": "40"
  },
  "count": 20,
  "total": 1734,
  "page": 40,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T14:47:40.746Z",
    "kev": "2026-10-07T14:46:40.605Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T14:47:40.746Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=40",
    "next": "https://spydr.io/threats.json?exploited=1&page=41"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-22960",
      "url": "https://spydr.io/cve/CVE-2022-22960",
      "published": "2022-04-13T18:15:13.510Z",
      "modified": "2026-06-17T04:29:14.960Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.35519,
      "epss_percentile": 0.98416,
      "exploited": true,
      "kev": {
        "added": "2022-04-15",
        "due": "2022-05-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware Workspace ONE Access, Identity Manager and vRealize Automation"
      ],
      "cwes": [
        "CWE-732"
      ],
      "description": "VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'."
    },
    {
      "id": "CVE-2022-22954",
      "url": "https://spydr.io/cve/CVE-2022-22954",
      "published": "2022-04-11T20:15:19.890Z",
      "modified": "2026-06-17T04:29:14.263Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99998,
      "epss_percentile": 0.9999,
      "exploited": true,
      "kev": {
        "added": "2022-04-14",
        "due": "2022-05-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware Workspace ONE Access and Identity Manager"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution."
    },
    {
      "id": "CVE-2022-0609",
      "url": "https://spydr.io/cve/CVE-2022-0609",
      "published": "2022-04-05T00:15:17.680Z",
      "modified": "2026-06-17T04:20:55.777Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22933,
      "epss_percentile": 0.97693,
      "exploited": true,
      "kev": {
        "added": "2022-02-15",
        "due": "2022-03-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-22965",
      "url": "https://spydr.io/cve/CVE-2022-22965",
      "published": "2022-04-01T23:15:13.870Z",
      "modified": "2026-06-17T04:29:15.610Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99638,
      "epss_percentile": 0.99949,
      "exploited": true,
      "kev": {
        "added": "2022-04-04",
        "due": "2022-04-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware",
        "cisco",
        "oracle",
        "siemens",
        "veritas"
      ],
      "products": [
        "Spring Framework"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it."
    },
    {
      "id": "CVE-2022-22963",
      "url": "https://spydr.io/cve/CVE-2022-22963",
      "published": "2022-04-01T23:15:13.663Z",
      "modified": "2026-06-17T04:29:15.340Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99938,
      "epss_percentile": 0.99971,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware",
        "oracle"
      ],
      "products": [
        "Spring Cloud Function"
      ],
      "cwes": [
        "CWE-94",
        "CWE-917"
      ],
      "description": "In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources."
    },
    {
      "id": "CVE-2022-26871",
      "url": "https://spydr.io/cve/CVE-2022-26871",
      "published": "2022-03-29T21:15:07.760Z",
      "modified": "2026-06-17T04:36:02.593Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19481,
      "epss_percentile": 0.97306,
      "exploited": true,
      "kev": {
        "added": "2022-03-31",
        "due": "2022-04-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Trend Micro"
      ],
      "products": [
        "Trend Micro Apex Central"
      ],
      "cwes": [
        "CWE-345"
      ],
      "description": "An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution."
    },
    {
      "id": "CVE-2022-22948",
      "url": "https://spydr.io/cve/CVE-2022-22948",
      "published": "2022-03-29T18:15:08.040Z",
      "modified": "2026-06-17T04:29:13.573Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.13282,
      "epss_percentile": 0.96292,
      "exploited": true,
      "kev": {
        "added": "2024-07-17",
        "due": "2024-08-07",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server and VMware Cloud Foundation",
        "vmware cloud_foundation",
        "vmware vcenter_server"
      ],
      "cwes": [
        "CWE-276"
      ],
      "description": "The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information."
    },
    {
      "id": "CVE-2022-26258",
      "url": "https://spydr.io/cve/CVE-2022-26258",
      "published": "2022-03-28T00:15:07.813Z",
      "modified": "2026-07-09T13:57:20.300Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91981,
      "epss_percentile": 0.99818,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-820l firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp."
    },
    {
      "id": "CVE-2022-0995",
      "url": "https://spydr.io/cve/CVE-2022-0995",
      "published": "2022-03-25T19:15:10.520Z",
      "modified": "2026-08-27T04:16:39.223Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08788,
      "epss_percentile": 0.95044,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "fedoraproject",
        "netapp"
      ],
      "products": [
        "kernel"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system."
    },
    {
      "id": "CVE-2022-1040",
      "url": "https://spydr.io/cve/CVE-2022-1040",
      "published": "2022-03-25T12:15:07.750Z",
      "modified": "2026-06-17T04:21:42.953Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99796,
      "epss_percentile": 0.99956,
      "exploited": true,
      "kev": {
        "added": "2022-03-31",
        "due": "2022-04-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Sophos"
      ],
      "products": [
        "Sophos Firewall"
      ],
      "cwes": [],
      "description": "An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older."
    },
    {
      "id": "CVE-2022-22620",
      "url": "https://spydr.io/cve/CVE-2022-22620",
      "published": "2022-03-18T18:15:13.787Z",
      "modified": "2026-06-17T04:28:41.780Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.16342,
      "epss_percentile": 0.96883,
      "exploited": true,
      "kev": {
        "added": "2022-02-11",
        "due": "2022-02-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari (v and )",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2022-22587",
      "url": "https://spydr.io/cve/CVE-2022-22587",
      "published": "2022-03-18T18:15:12.480Z",
      "modified": "2026-06-17T04:28:38.310Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11638,
      "epss_percentile": 0.95945,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-02-11",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2022-26501",
      "url": "https://spydr.io/cve/CVE-2022-26501",
      "published": "2022-03-17T21:15:08.233Z",
      "modified": "2026-06-17T04:35:18.700Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04104,
      "epss_percentile": 0.90473,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veeam"
      ],
      "products": [
        "veeam backup & replication"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2)."
    },
    {
      "id": "CVE-2022-26500",
      "url": "https://spydr.io/cve/CVE-2022-26500",
      "published": "2022-03-17T21:15:08.193Z",
      "modified": "2026-06-17T04:35:18.530Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05828,
      "epss_percentile": 0.92955,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veeam"
      ],
      "products": [
        "veeam backup & replication"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code."
    },
    {
      "id": "CVE-2021-39793",
      "url": "https://spydr.io/cve/CVE-2021-39793",
      "published": "2022-03-16T15:15:12.430Z",
      "modified": "2026-06-17T04:04:10.107Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00685,
      "epss_percentile": 0.51025,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A"
    },
    {
      "id": "CVE-2022-26143",
      "url": "https://spydr.io/cve/CVE-2022-26143",
      "published": "2022-03-10T17:47:32.813Z",
      "modified": "2026-06-17T04:34:46.337Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87325,
      "epss_percentile": 0.99752,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel micollab",
        "mitel mivoice business express"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack."
    },
    {
      "id": "CVE-2022-0847",
      "url": "https://spydr.io/cve/CVE-2022-0847",
      "published": "2022-03-10T17:44:57.283Z",
      "modified": "2026-06-17T04:21:21.750Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.92795,
      "epss_percentile": 0.99828,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "fedoraproject",
        "redhat",
        "ovirt",
        "netapp",
        "siemens",
        "sonicwall"
      ],
      "products": [
        "kernel"
      ],
      "cwes": [
        "CWE-665"
      ],
      "description": "A flaw was found in the way the \"flags\" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system."
    },
    {
      "id": "CVE-2022-26318",
      "url": "https://spydr.io/cve/CVE-2022-26318",
      "published": "2022-03-04T18:15:08.367Z",
      "modified": "2026-06-17T04:34:58.110Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.78157,
      "epss_percentile": 0.99569,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "watchguard"
      ],
      "products": [
        "watchguard fireware"
      ],
      "cwes": [],
      "description": "On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2."
    },
    {
      "id": "CVE-2022-22947",
      "url": "https://spydr.io/cve/CVE-2022-22947",
      "published": "2022-03-03T22:15:08.673Z",
      "modified": "2026-06-17T04:29:13.420Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98253,
      "epss_percentile": 0.99915,
      "exploited": true,
      "kev": {
        "added": "2022-05-16",
        "due": "2022-06-06",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware",
        "oracle"
      ],
      "products": [
        "Spring Cloud Gateway"
      ],
      "cwes": [
        "CWE-94",
        "CWE-917"
      ],
      "description": "In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host."
    },
    {
      "id": "CVE-2022-0492",
      "url": "https://spydr.io/cve/CVE-2022-0492",
      "published": "2022-03-03T19:15:08.633Z",
      "modified": "2026-06-17T04:20:42.910Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05528,
      "epss_percentile": 0.92589,
      "exploited": true,
      "kev": {
        "added": "2026-06-02",
        "due": "2026-06-05",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netapp",
        "linux",
        "debian",
        "redhat",
        "canonical",
        "fedoraproject"
      ],
      "products": [
        "kernel"
      ],
      "cwes": [
        "CWE-287",
        "CWE-862"
      ],
      "description": "A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
