{
  "query": {
    "exploited": "1",
    "page": "41"
  },
  "count": 20,
  "total": 1734,
  "page": 41,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T14:47:40.746Z",
    "kev": "2026-10-07T15:46:42.531Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T15:47:42.703Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=41",
    "next": "https://spydr.io/threats.json?exploited=1&page=42"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-22706",
      "url": "https://spydr.io/cve/CVE-2022-22706",
      "published": "2022-03-03T15:15:08.610Z",
      "modified": "2026-06-17T04:28:50.043Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01062,
      "epss_percentile": 0.6348,
      "exploited": true,
      "kev": {
        "added": "2023-03-30",
        "due": "2023-04-20",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0."
    },
    {
      "id": "CVE-2022-23176",
      "url": "https://spydr.io/cve/CVE-2022-23176",
      "published": "2022-02-24T15:15:28.447Z",
      "modified": "2026-06-17T04:29:37.677Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10805,
      "epss_percentile": 0.95735,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "watchguard"
      ],
      "products": [
        "watchguard fireware"
      ],
      "cwes": [],
      "description": "WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3."
    },
    {
      "id": "CVE-2022-0543",
      "url": "https://spydr.io/cve/CVE-2022-0543",
      "published": "2022-02-18T20:15:17.583Z",
      "modified": "2026-06-17T04:20:48.593Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99351,
      "epss_percentile": 0.99939,
      "exploited": true,
      "kev": {
        "added": "2022-03-28",
        "due": "2022-04-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Debian"
      ],
      "products": [
        "Debian redis"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution."
    },
    {
      "id": "CVE-2021-45382",
      "url": "https://spydr.io/cve/CVE-2021-45382",
      "published": "2022-02-17T21:15:07.737Z",
      "modified": "2026-06-17T04:13:19.093Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97836,
      "epss_percentile": 0.99907,
      "exploited": true,
      "kev": {
        "added": "2022-04-04",
        "due": "2022-04-25",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-820l firmware",
        "dlink dir-820lw firmware",
        "dlink dir-826l firmware",
        "dlink dir-830l firmware",
        "dlink dir-836l firmware",
        "dlink dir-810l firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life (\"EOL\") /End of Service Life (\"EOS\") Life-Cycle and as such this issue will not be patched."
    },
    {
      "id": "CVE-2021-3560",
      "url": "https://spydr.io/cve/CVE-2021-3560",
      "published": "2022-02-16T19:15:08.450Z",
      "modified": "2026-06-17T04:05:20.767Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23708,
      "epss_percentile": 0.97763,
      "exploited": true,
      "kev": {
        "added": "2023-05-12",
        "due": "2023-06-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "polkit project",
        "debian",
        "canonical",
        "redhat"
      ],
      "products": [
        "polkit"
      ],
      "cwes": [
        "CWE-863",
        "CWE-754"
      ],
      "description": "It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability."
    },
    {
      "id": "CVE-2022-24086",
      "url": "https://spydr.io/cve/CVE-2022-24086",
      "published": "2022-02-16T17:15:13.307Z",
      "modified": "2026-06-17T04:31:16.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.99199,
      "epss_percentile": 0.99934,
      "exploited": true,
      "kev": {
        "added": "2022-02-15",
        "due": "2022-03-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Magento Commerce"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution."
    },
    {
      "id": "CVE-2021-4102",
      "url": "https://spydr.io/cve/CVE-2021-4102",
      "published": "2022-02-11T23:15:08.273Z",
      "modified": "2026-06-17T04:19:02.250Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07836,
      "epss_percentile": 0.94524,
      "exploited": true,
      "kev": {
        "added": "2021-12-15",
        "due": "2021-12-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-0185",
      "url": "https://spydr.io/cve/CVE-2022-0185",
      "published": "2022-02-11T18:15:10.890Z",
      "modified": "2026-06-17T04:20:06.923Z",
      "score": 8.4,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.25151,
      "epss_percentile": 0.97882,
      "exploited": true,
      "kev": {
        "added": "2024-08-21",
        "due": "2024-09-11",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux"
      ],
      "products": [
        "kernel",
        "linux_kernel"
      ],
      "cwes": [
        "CWE-190",
        "CWE-191"
      ],
      "description": "A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system."
    },
    {
      "id": "CVE-2022-24112",
      "url": "https://spydr.io/cve/CVE-2022-24112",
      "published": "2022-02-11T13:15:08.073Z",
      "modified": "2026-06-17T04:31:18.883Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96069,
      "epss_percentile": 0.99877,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache APISIX"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed."
    },
    {
      "id": "CVE-2022-20708",
      "url": "https://spydr.io/cve/CVE-2022-20708",
      "published": "2022-02-10T18:15:09.467Z",
      "modified": "2026-06-17T04:24:54.707Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14863,
      "epss_percentile": 0.96612,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-78"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20703",
      "url": "https://spydr.io/cve/CVE-2022-20703",
      "published": "2022-02-10T18:15:09.197Z",
      "modified": "2026-06-17T04:24:53.813Z",
      "score": 8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09203,
      "epss_percentile": 0.95207,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-295"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20701",
      "url": "https://spydr.io/cve/CVE-2022-20701",
      "published": "2022-02-10T18:15:09.087Z",
      "modified": "2026-06-17T04:24:53.510Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09747,
      "epss_percentile": 0.95403,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20700",
      "url": "https://spydr.io/cve/CVE-2022-20700",
      "published": "2022-02-10T18:15:09.033Z",
      "modified": "2026-06-17T04:24:53.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05655,
      "epss_percentile": 0.92755,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-20699",
      "url": "https://spydr.io/cve/CVE-2022-20699",
      "published": "2022-02-10T18:15:08.980Z",
      "modified": "2026-06-17T04:24:53.200Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72458,
      "epss_percentile": 0.99428,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco Small Business RV Series Router Firmware"
      ],
      "cwes": [
        "CWE-121",
        "CWE-1284"
      ],
      "description": "Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2022-22536",
      "url": "https://spydr.io/cve/CVE-2022-22536",
      "published": "2022-02-09T23:15:18.620Z",
      "modified": "2026-06-17T04:28:33.183Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97945,
      "epss_percentile": 0.99909,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP SE"
      ],
      "products": [
        "SAP SE SAP NetWeaver and ABAP Platform",
        "SAP SE SAP Web Dispatcher",
        "SAP SE SAP Content Server"
      ],
      "cwes": [
        "CWE-444"
      ],
      "description": "SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system."
    },
    {
      "id": "CVE-2022-22718",
      "url": "https://spydr.io/cve/CVE-2022-22718",
      "published": "2022-02-09T17:15:10.280Z",
      "modified": "2026-06-17T04:28:51.470Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.18464,
      "epss_percentile": 0.97171,
      "exploited": true,
      "kev": {
        "added": "2022-04-19",
        "due": "2022-05-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [],
      "description": "Windows Print Spooler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-21999",
      "url": "https://spydr.io/cve/CVE-2022-21999",
      "published": "2022-02-09T17:15:09.563Z",
      "modified": "2026-06-17T04:27:26.760Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.41007,
      "epss_percentile": 0.98625,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-22",
        "CWE-59"
      ],
      "description": "Windows Print Spooler Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-21971",
      "url": "https://spydr.io/cve/CVE-2022-21971",
      "published": "2022-02-09T17:15:08.640Z",
      "modified": "2026-06-17T04:27:22.930Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.53934,
      "epss_percentile": 0.98976,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2"
      ],
      "cwes": [
        "CWE-824"
      ],
      "description": "Windows Runtime Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2022-24682",
      "url": "https://spydr.io/cve/CVE-2022-24682",
      "published": "2022-02-09T04:15:07.400Z",
      "modified": "2026-08-07T05:16:55.740Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.30931,
      "epss_percentile": 0.98217,
      "exploited": true,
      "kev": {
        "added": "2022-02-25",
        "due": "2022-03-11",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-116"
      ],
      "description": "An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document."
    },
    {
      "id": "CVE-2021-4034",
      "url": "https://spydr.io/cve/CVE-2021-4034",
      "published": "2022-01-28T20:15:12.193Z",
      "modified": "2026-08-15T04:17:57.927Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94345,
      "epss_percentile": 0.99851,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "polkit project",
        "redhat",
        "canonical",
        "suse",
        "oracle",
        "siemens",
        "starwindsoftware"
      ],
      "products": [
        "polkit"
      ],
      "cwes": [
        "CWE-787",
        "CWE-125"
      ],
      "description": "A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
