{
  "query": {
    "exploited": "1",
    "page": "49"
  },
  "count": 20,
  "total": 1734,
  "page": 49,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T22:48:36.014Z",
    "kev": "2026-10-07T23:49:38.149Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T23:48:38.351Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=49",
    "next": "https://spydr.io/threats.json?exploited=1&page=50"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-22899",
      "url": "https://spydr.io/cve/CVE-2021-22899",
      "published": "2021-05-27T12:15:07.963Z",
      "modified": "2026-06-17T03:37:58.977Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22915,
      "epss_percentile": 0.97695,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti"
      ],
      "products": [
        "Pulse Connect Secure"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature"
    },
    {
      "id": "CVE-2021-22894",
      "url": "https://spydr.io/cve/CVE-2021-22894",
      "published": "2021-05-27T12:15:07.923Z",
      "modified": "2026-06-17T03:37:58.127Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41284,
      "epss_percentile": 0.98637,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti"
      ],
      "products": [
        "Pulse Connect Secure"
      ],
      "cwes": [
        "CWE-94",
        "CWE-119"
      ],
      "description": "A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room."
    },
    {
      "id": "CVE-2021-21985",
      "url": "https://spydr.io/cve/CVE-2021-21985",
      "published": "2021-05-26T15:15:07.937Z",
      "modified": "2026-08-12T05:17:36.797Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99993,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vCenter Server and VMware Cloud Foundation"
      ],
      "cwes": [
        "CWE-918",
        "CWE-20",
        "CWE-470"
      ],
      "description": "The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server."
    },
    {
      "id": "CVE-2021-27562",
      "url": "https://spydr.io/cve/CVE-2021-27562",
      "published": "2021-05-25T19:15:07.737Z",
      "modified": "2026-06-17T03:45:08.407Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.03093,
      "epss_percentile": 0.87334,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "trustedfirmware"
      ],
      "products": [
        "trustedfirmware trusted firmware-m"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode."
    },
    {
      "id": "CVE-2021-29256",
      "url": "https://spydr.io/cve/CVE-2021-29256",
      "published": "2021-05-24T18:15:08.033Z",
      "modified": "2026-06-17T03:47:27.647Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02988,
      "epss_percentile": 0.86907,
      "exploited": true,
      "kev": {
        "added": "2023-07-07",
        "due": "2023-07-28",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": ". The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0."
    },
    {
      "id": "CVE-2021-28799",
      "url": "https://spydr.io/cve/CVE-2021-28799",
      "published": "2021-05-13T03:15:06.843Z",
      "modified": "2026-06-17T03:46:53.003Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.7825,
      "epss_percentile": 0.99571,
      "exploited": true,
      "kev": {
        "added": "2022-03-31",
        "due": "2022-04-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. HBS 3",
        "QNAP Systems Inc. HBS 2",
        "QNAP Systems Inc. HBS 1.3"
      ],
      "cwes": [
        "CWE-285"
      ],
      "description": "An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 ."
    },
    {
      "id": "CVE-2021-31207",
      "url": "https://spydr.io/cve/CVE-2021-31207",
      "published": "2021-05-11T19:15:10.397Z",
      "modified": "2026-06-17T03:51:27.123Z",
      "score": 6.6,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99782,
      "epss_percentile": 0.99955,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 9",
        "Microsoft Exchange Server 2016 Cumulative Update 20",
        "Microsoft Exchange Server 2016 Cumulative Update 19",
        "Microsoft Exchange Server 2019 Cumulative Update 8"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Microsoft Exchange Server Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2021-31166",
      "url": "https://spydr.io/cve/CVE-2021-31166",
      "published": "2021-05-11T19:15:09.300Z",
      "modified": "2026-06-17T03:51:21.910Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99867,
      "epss_percentile": 0.99962,
      "exploited": true,
      "kev": {
        "added": "2022-04-06",
        "due": "2022-04-27",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "HTTP Protocol Stack Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2021-28664",
      "url": "https://spydr.io/cve/CVE-2021-28664",
      "published": "2021-05-10T15:15:07.590Z",
      "modified": "2026-06-17T03:46:43.977Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05407,
      "epss_percentile": 0.92479,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost gpu kernel driver",
        "arm midgard gpu kernel driver",
        "arm valhall gpu kernel driver"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0."
    },
    {
      "id": "CVE-2021-28663",
      "url": "https://spydr.io/cve/CVE-2021-28663",
      "published": "2021-05-10T15:15:07.557Z",
      "modified": "2026-06-17T03:46:43.793Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.12084,
      "epss_percentile": 0.96047,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "arm"
      ],
      "products": [
        "arm bifrost_gpu_kernel_driver",
        "arm valhall_gpu_kernel_driver",
        "arm midgard_gpu_kernel_driver"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0."
    },
    {
      "id": "CVE-2021-31755",
      "url": "https://spydr.io/cve/CVE-2021-31755",
      "published": "2021-05-07T23:15:07.047Z",
      "modified": "2026-06-17T03:52:12.150Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.86511,
      "epss_percentile": 0.99735,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "tenda"
      ],
      "products": [
        "tenda ac11 firmware"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request."
    },
    {
      "id": "CVE-2021-1906",
      "url": "https://spydr.io/cve/CVE-2021-1906",
      "published": "2021-05-07T09:15:08.280Z",
      "modified": "2026-06-17T03:32:48.490Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.0052,
      "epss_percentile": 0.42305,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables"
      ],
      "cwes": [],
      "description": "Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables"
    },
    {
      "id": "CVE-2021-1905",
      "url": "https://spydr.io/cve/CVE-2021-1905",
      "published": "2021-05-07T09:15:08.243Z",
      "modified": "2026-06-17T03:32:47.910Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01543,
      "epss_percentile": 0.74187,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables"
    },
    {
      "id": "CVE-2021-32030",
      "url": "https://spydr.io/cve/CVE-2021-32030",
      "published": "2021-05-06T15:15:07.973Z",
      "modified": "2026-06-17T03:52:42.307Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99393,
      "epss_percentile": 0.99941,
      "exploited": true,
      "kev": {
        "added": "2025-06-02",
        "due": "2025-06-23",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "asus"
      ],
      "products": [
        "asus lyra mini firmware",
        "asus gt-ac2900 firmware"
      ],
      "cwes": [
        "CWE-287"
      ],
      "description": "The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\\0' matches the device's default value of '\\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN."
    },
    {
      "id": "CVE-2021-1498",
      "url": "https://spydr.io/cve/CVE-2021-1498",
      "published": "2021-05-06T13:15:10.537Z",
      "modified": "2026-06-17T03:31:54.907Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99991,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco HyperFlex HX Data Platform"
      ],
      "cwes": [
        "CWE-78",
        "CWE-77"
      ],
      "description": "Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2021-1497",
      "url": "https://spydr.io/cve/CVE-2021-1497",
      "published": "2021-05-06T13:15:10.500Z",
      "modified": "2026-06-17T03:31:54.773Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9993,
      "epss_percentile": 0.9997,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco HyperFlex HX Data Platform"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory."
    },
    {
      "id": "CVE-2021-21551",
      "url": "https://spydr.io/cve/CVE-2021-21551",
      "published": "2021-05-04T16:15:07.867Z",
      "modified": "2026-06-17T03:35:45.760Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.79249,
      "epss_percentile": 0.99592,
      "exploited": true,
      "kev": {
        "added": "2022-03-31",
        "due": "2022-04-21",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Dell"
      ],
      "products": [
        "Dell dbutil"
      ],
      "cwes": [
        "CWE-782"
      ],
      "description": "Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required."
    },
    {
      "id": "CVE-2021-20090",
      "url": "https://spydr.io/cve/CVE-2021-20090",
      "published": "2021-04-29T15:15:10.630Z",
      "modified": "2026-06-17T03:33:15.487Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99982,
      "epss_percentile": 0.99982,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "buffalo"
      ],
      "products": [
        "Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication."
    },
    {
      "id": "CVE-2021-21224",
      "url": "https://spydr.io/cve/CVE-2021-21224",
      "published": "2021-04-26T17:15:08.703Z",
      "modified": "2026-06-17T03:35:04.383Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84173,
      "epss_percentile": 0.99691,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."
    },
    {
      "id": "CVE-2021-21220",
      "url": "https://spydr.io/cve/CVE-2021-21220",
      "published": "2021-04-26T17:15:08.593Z",
      "modified": "2026-06-17T03:35:03.853Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70435,
      "epss_percentile": 0.99376,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
