{
  "query": {
    "exploited": "1",
    "page": "43"
  },
  "count": 20,
  "total": 1734,
  "page": 43,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T16:47:45.059Z",
    "kev": "2026-10-07T17:46:46.967Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T16:47:45.059Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=43",
    "next": "https://spydr.io/threats.json?exploited=1&page=44"
  },
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-44228",
      "url": "https://spydr.io/cve/CVE-2021-44228",
      "published": "2021-12-10T10:15:09.143Z",
      "modified": "2026-08-11T19:33:44.513Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 1,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2021-12-24",
        "action": "For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache Log4j2"
      ],
      "cwes": [
        "CWE-20",
        "CWE-400",
        "CWE-502",
        "CWE-917"
      ],
      "description": "Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects."
    },
    {
      "id": "CVE-2021-44529",
      "url": "https://spydr.io/cve/CVE-2021-44529",
      "published": "2021-12-08T22:15:10.163Z",
      "modified": "2026-08-04T05:16:27.567Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99105,
      "epss_percentile": 0.99933,
      "exploited": true,
      "kev": {
        "added": "2024-03-25",
        "due": "2024-04-15",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti"
      ],
      "products": [
        "Ivanti EPM",
        "ivanti endpoint_manager_cloud_services_appliance"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody)."
    },
    {
      "id": "CVE-2021-27860",
      "url": "https://spydr.io/cve/CVE-2021-27860",
      "published": "2021-12-08T17:15:10.800Z",
      "modified": "2026-06-17T03:45:32.300Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.39824,
      "epss_percentile": 0.98588,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-01-24",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "FatPipe"
      ],
      "products": [
        "FatPipe WARP",
        "FatPipe IPVPN",
        "FatPipe MPVPN"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006."
    },
    {
      "id": "CVE-2021-20038",
      "url": "https://spydr.io/cve/CVE-2021-20038",
      "published": "2021-12-08T10:15:07.750Z",
      "modified": "2026-06-17T03:33:11.327Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99912,
      "epss_percentile": 0.99967,
      "exploited": true,
      "kev": {
        "added": "2022-01-28",
        "due": "2022-02-11",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA100"
      ],
      "cwes": [
        "CWE-121",
        "CWE-787"
      ],
      "description": "A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions."
    },
    {
      "id": "CVE-2021-43798",
      "url": "https://spydr.io/cve/CVE-2021-43798",
      "published": "2021-12-07T19:15:07.633Z",
      "modified": "2026-06-17T04:11:27.540Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "github.com",
      "epss": 0.88503,
      "epss_percentile": 0.99771,
      "exploited": true,
      "kev": {
        "added": "2025-10-09",
        "due": "2025-10-30",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "grafana"
      ],
      "products": [
        "grafana"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline."
    },
    {
      "id": "CVE-2021-23758",
      "url": "https://spydr.io/cve/CVE-2021-23758",
      "published": "2021-12-03T20:15:07.557Z",
      "modified": "2026-08-27T04:16:38.863Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82578,
      "epss_percentile": 0.99659,
      "exploited": true,
      "kev": {
        "added": "2026-08-26",
        "due": "2026-09-09",
        "action": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ajaxpro.2 project",
        "michaelschwarz"
      ],
      "products": [
        "AjaxPro.2"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution."
    },
    {
      "id": "CVE-2021-44077",
      "url": "https://spydr.io/cve/CVE-2021-44077",
      "published": "2021-11-29T04:15:06.737Z",
      "modified": "2026-06-17T04:11:52.397Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93298,
      "epss_percentile": 0.99836,
      "exploited": true,
      "kev": {
        "added": "2021-12-01",
        "due": "2021-12-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine servicedesk plus",
        "zohocorp manageengine servicedesk plus msp",
        "zohocorp manageengine supportcenter plus"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration."
    },
    {
      "id": "CVE-2021-38003",
      "url": "https://spydr.io/cve/CVE-2021-38003",
      "published": "2021-11-23T22:15:07.937Z",
      "modified": "2026-06-17T04:01:23.563Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.38573,
      "epss_percentile": 0.98542,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-755"
      ],
      "description": "Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2021-38000",
      "url": "https://spydr.io/cve/CVE-2021-38000",
      "published": "2021-11-23T22:15:07.807Z",
      "modified": "2026-06-17T04:01:23.103Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.04948,
      "epss_percentile": 0.91919,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome",
        "google android"
      ],
      "cwes": [
        "CWE-601",
        "CWE-20"
      ],
      "description": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page."
    },
    {
      "id": "CVE-2021-44026",
      "url": "https://spydr.io/cve/CVE-2021-44026",
      "published": "2021-11-19T04:15:07.197Z",
      "modified": "2026-06-17T04:11:48.777Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.69882,
      "epss_percentile": 0.99358,
      "exploited": true,
      "kev": {
        "added": "2023-06-22",
        "due": "2023-07-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "roundcube",
        "fedoraproject",
        "debian"
      ],
      "products": [
        "roundcube webmail",
        "fedoraproject fedora",
        "debian linux"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params."
    },
    {
      "id": "CVE-2021-41277",
      "url": "https://spydr.io/cve/CVE-2021-41277",
      "published": "2021-11-17T20:15:10.587Z",
      "modified": "2026-06-17T04:08:13.543Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.97178,
      "epss_percentile": 0.99895,
      "exploited": true,
      "kev": {
        "added": "2024-11-12",
        "due": "2024-12-03",
        "action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "metabase"
      ],
      "products": [
        "metabase"
      ],
      "cwes": [
        "CWE-200",
        "CWE-22"
      ],
      "description": "Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application."
    },
    {
      "id": "CVE-2021-42321",
      "url": "https://spydr.io/cve/CVE-2021-42321",
      "published": "2021-11-10T01:19:50.047Z",
      "modified": "2026-08-19T19:23:07.277Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.91737,
      "epss_percentile": 0.99815,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2016 Cumulative Update 21",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2019 Cumulative Update 10",
        "Microsoft Exchange Server 2019 Cumulative Update 11"
      ],
      "cwes": [],
      "description": "Microsoft Exchange Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2021-42292",
      "url": "https://spydr.io/cve/CVE-2021-42292",
      "published": "2021-11-10T01:19:47.007Z",
      "modified": "2026-08-19T19:23:04.123Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.43005,
      "epss_percentile": 0.98687,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Excel 2013 Service Pack 1",
        "Microsoft Excel 2016",
        "Microsoft Office 2013 Service Pack 1",
        "Microsoft Office 2016",
        "Microsoft Office 2019",
        "Microsoft Office 2019 for Mac",
        "Microsoft Office LTSC 2021",
        "Microsoft Office LTSC for Mac 2021"
      ],
      "cwes": [],
      "description": "Microsoft Excel Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2021-42287",
      "url": "https://spydr.io/cve/CVE-2021-42287",
      "published": "2021-11-10T01:19:46.137Z",
      "modified": "2026-08-19T19:23:00.553Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.7717,
      "epss_percentile": 0.99543,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [],
      "description": "Active Directory Domain Services Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-42278",
      "url": "https://spydr.io/cve/CVE-2021-42278",
      "published": "2021-11-10T01:19:44.300Z",
      "modified": "2026-08-19T19:22:57.137Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.73297,
      "epss_percentile": 0.99451,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [],
      "description": "Active Directory Domain Services Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-41379",
      "url": "https://spydr.io/cve/CVE-2021-41379",
      "published": "2021-11-10T01:19:32.127Z",
      "modified": "2026-08-19T19:22:46.060Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "microsoft.com",
      "epss": 0.19452,
      "epss_percentile": 0.97304,
      "exploited": true,
      "kev": {
        "added": "2022-03-03",
        "due": "2022-03-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "Windows Installer Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-42237",
      "url": "https://spydr.io/cve/CVE-2021-42237",
      "published": "2021-11-05T10:15:08.240Z",
      "modified": "2026-07-09T13:57:14.483Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97566,
      "epss_percentile": 0.99902,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sitecore"
      ],
      "products": [
        "sitecore experience platform"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability."
    },
    {
      "id": "CVE-2021-42258",
      "url": "https://spydr.io/cve/CVE-2021-42258",
      "published": "2021-10-22T22:15:07.907Z",
      "modified": "2026-06-17T04:09:31.510Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74426,
      "epss_percentile": 0.99482,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "bqe"
      ],
      "products": [
        "bqe billquick web suite"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell."
    },
    {
      "id": "CVE-2021-30807",
      "url": "https://spydr.io/cve/CVE-2021-30807",
      "published": "2021-10-19T14:15:08.313Z",
      "modified": "2026-06-17T03:50:55.710Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28839,
      "epss_percentile": 0.98106,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2021-27561",
      "url": "https://spydr.io/cve/CVE-2021-27561",
      "published": "2021-10-15T18:15:07.490Z",
      "modified": "2026-06-17T03:45:08.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82865,
      "epss_percentile": 0.99665,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "yealink"
      ],
      "products": [
        "yealink device management"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
