{
  "query": {
    "exploited": "1",
    "page": "42"
  },
  "count": 20,
  "total": 1734,
  "page": 42,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T16:47:45.059Z",
    "kev": "2026-10-07T16:46:45.142Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T16:47:45.059Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=42",
    "next": "https://spydr.io/threats.json?exploited=1&page=43"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-40407",
      "url": "https://spydr.io/cve/CVE-2021-40407",
      "published": "2022-01-28T20:15:11.607Z",
      "modified": "2026-06-17T04:06:52.767Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.47635,
      "epss_percentile": 0.98817,
      "exploited": true,
      "kev": {
        "added": "2024-12-18",
        "due": "2025-01-08",
        "action": "The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "reolink"
      ],
      "products": [
        "reolink rlc-410w firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability."
    },
    {
      "id": "CVE-2021-22600",
      "url": "https://spydr.io/cve/CVE-2021-22600",
      "published": "2022-01-26T14:15:08.123Z",
      "modified": "2026-06-17T03:37:27.450Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06586,
      "epss_percentile": 0.93655,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux Kernel"
      ],
      "products": [
        "Linux Kernel Kernel"
      ],
      "cwes": [
        "CWE-415"
      ],
      "description": "A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755"
    },
    {
      "id": "CVE-2021-35587",
      "url": "https://spydr.io/cve/CVE-2021-35587",
      "published": "2022-01-19T12:15:09.727Z",
      "modified": "2026-06-17T03:57:46.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.96284,
      "epss_percentile": 0.99879,
      "exploited": true,
      "kev": {
        "added": "2022-11-28",
        "due": "2022-12-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Access Manager"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2022-23227",
      "url": "https://spydr.io/cve/CVE-2022-23227",
      "published": "2022-01-14T18:15:10.303Z",
      "modified": "2026-06-17T04:29:42.067Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48497,
      "epss_percentile": 0.98836,
      "exploited": true,
      "kev": {
        "added": "2024-12-18",
        "due": "2025-01-08",
        "action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nuuo"
      ],
      "products": [
        "nuuo nvrmini2 firmware"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root."
    },
    {
      "id": "CVE-2022-23134",
      "url": "https://spydr.io/cve/CVE-2022-23134",
      "published": "2022-01-13T16:15:08.227Z",
      "modified": "2026-06-17T04:29:34.653Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.9526,
      "epss_percentile": 0.99865,
      "exploited": true,
      "kev": {
        "added": "2022-02-22",
        "due": "2022-03-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zabbix"
      ],
      "products": [
        "Zabbix Frontend"
      ],
      "cwes": [
        "CWE-284",
        "CWE-287"
      ],
      "description": "After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend."
    },
    {
      "id": "CVE-2022-23131",
      "url": "https://spydr.io/cve/CVE-2022-23131",
      "published": "2022-01-13T16:15:08.053Z",
      "modified": "2026-06-17T04:29:34.147Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95683,
      "epss_percentile": 0.99871,
      "exploited": true,
      "kev": {
        "added": "2022-02-22",
        "due": "2022-03-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Zabbix"
      ],
      "products": [
        "Zabbix Frontend"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default)."
    },
    {
      "id": "CVE-2022-21919",
      "url": "https://spydr.io/cve/CVE-2022-21919",
      "published": "2022-01-11T21:15:13.463Z",
      "modified": "2026-06-17T04:27:16.930Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.02434,
      "epss_percentile": 0.8374,
      "exploited": true,
      "kev": {
        "added": "2022-04-25",
        "due": "2022-05-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows User Profile Service Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-21882",
      "url": "https://spydr.io/cve/CVE-2022-21882",
      "published": "2022-01-11T21:15:11.507Z",
      "modified": "2026-08-15T04:18:00.220Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.59205,
      "epss_percentile": 0.99095,
      "exploited": true,
      "kev": {
        "added": "2022-02-04",
        "due": "2022-02-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-22265",
      "url": "https://spydr.io/cve/CVE-2022-22265",
      "published": "2022-01-10T14:12:35.837Z",
      "modified": "2026-06-17T04:28:08.200Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00392,
      "epss_percentile": 0.31077,
      "exploited": true,
      "kev": {
        "added": "2023-09-18",
        "due": "2023-10-09",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-703"
      ],
      "description": "An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution."
    },
    {
      "id": "CVE-2021-35247",
      "url": "https://spydr.io/cve/CVE-2021-35247",
      "published": "2022-01-10T14:10:17.667Z",
      "modified": "2026-06-17T03:57:22.850Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.03453,
      "epss_percentile": 0.88664,
      "exploited": true,
      "kev": {
        "added": "2022-01-21",
        "due": "2022-02-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SolarWinds"
      ],
      "products": [
        "SolarWinds Serv-U"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U."
    },
    {
      "id": "CVE-2021-44168",
      "url": "https://spydr.io/cve/CVE-2021-44168",
      "published": "2022-01-04T13:15:07.957Z",
      "modified": "2026-06-17T04:11:59.317Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00865,
      "epss_percentile": 0.57301,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-494"
      ],
      "description": "A download of code without integrity check vulnerability in the \"execute restore src-vis\" command of FortiOS before 7.0.3 may allow a local authenticated attacker to download arbitrary files on the device via specially crafted update packages."
    },
    {
      "id": "CVE-2021-44207",
      "url": "https://spydr.io/cve/CVE-2021-44207",
      "published": "2021-12-21T18:15:08.143Z",
      "modified": "2026-06-17T04:12:03.230Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.17578,
      "epss_percentile": 0.97068,
      "exploited": true,
      "kev": {
        "added": "2024-12-23",
        "due": "2025-01-13",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "acclaimsystems"
      ],
      "products": [
        "acclaimsystems usaherds"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials."
    },
    {
      "id": "CVE-2021-22054",
      "url": "https://spydr.io/cve/CVE-2021-22054",
      "published": "2021-12-17T17:15:12.590Z",
      "modified": "2026-10-01T19:17:13.960Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99677,
      "epss_percentile": 0.9995,
      "exploited": true,
      "kev": {
        "added": "2026-03-09",
        "due": "2026-03-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware Workspace ONE UEM console"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information."
    },
    {
      "id": "CVE-2021-1048",
      "url": "https://spydr.io/cve/CVE-2021-1048",
      "published": "2021-12-15T19:15:14.917Z",
      "modified": "2026-06-17T03:30:51.917Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01,
      "epss_percentile": 0.61593,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel"
    },
    {
      "id": "CVE-2021-0920",
      "url": "https://spydr.io/cve/CVE-2021-0920",
      "published": "2021-12-15T19:15:11.017Z",
      "modified": "2026-06-17T03:30:39.430Z",
      "score": 6.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0082,
      "epss_percentile": 0.55853,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "google",
        "debian"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-362",
        "CWE-416"
      ],
      "description": "In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel"
    },
    {
      "id": "CVE-2021-43890",
      "url": "https://spydr.io/cve/CVE-2021-43890",
      "published": "2021-12-15T15:15:11.207Z",
      "modified": "2026-08-06T05:16:36.653Z",
      "score": 7.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10295,
      "epss_percentile": 0.95578,
      "exploited": true,
      "kev": {
        "added": "2021-12-15",
        "due": "2021-12-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft App Installer"
      ],
      "cwes": [],
      "description": "We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please see the Security Updates table for the link to the updated app. Alternatively you can download and install the Installer using the links provided in the FAQ section. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. December 27 2023 Update: In recent months, Microsoft Threat Intelligence has seen an increase in activity from threat actors leveraging social engineering and phishing techniques to target Windows OS users and utilizing the ms-appinstaller URI scheme. To address this increase in activity, we have updated the App Installer to disable the ms-appinstaller protocol by default and recommend other potential mitigations."
    },
    {
      "id": "CVE-2021-43226",
      "url": "https://spydr.io/cve/CVE-2021-43226",
      "published": "2021-12-15T15:15:09.737Z",
      "modified": "2026-08-22T04:16:54.773Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03098,
      "epss_percentile": 0.87333,
      "exploited": true,
      "kev": {
        "added": "2025-10-06",
        "due": "2025-10-27",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2"
      ],
      "cwes": [],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-45046",
      "url": "https://spydr.io/cve/CVE-2021-45046",
      "published": "2021-12-14T19:15:07.733Z",
      "modified": "2026-06-17T04:13:05.570Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99977,
      "epss_percentile": 0.9998,
      "exploited": true,
      "kev": {
        "added": "2023-05-01",
        "due": "2023-05-22",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Log4j"
      ],
      "cwes": [
        "CWE-917"
      ],
      "description": "It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default."
    },
    {
      "id": "CVE-2021-39935",
      "url": "https://spydr.io/cve/CVE-2021-39935",
      "published": "2021-12-13T16:15:09.367Z",
      "modified": "2026-06-17T04:04:27.387Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.3614,
      "epss_percentile": 0.98439,
      "exploited": true,
      "kev": {
        "added": "2026-02-03",
        "due": "2026-02-24",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GitLab"
      ],
      "products": [
        "GitLab"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API"
    },
    {
      "id": "CVE-2021-44515",
      "url": "https://spydr.io/cve/CVE-2021-44515",
      "published": "2021-12-12T05:15:07.997Z",
      "modified": "2026-06-17T04:12:29.943Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99871,
      "epss_percentile": 0.99963,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine desktop central"
      ],
      "cwes": [],
      "description": "Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
