{
  "query": {
    "exploited": "1",
    "page": "50"
  },
  "count": 20,
  "total": 1734,
  "page": 50,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T00:48:40.801Z",
    "kev": "2026-10-08T00:49:40.486Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T00:48:40.801Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=50",
    "next": "https://spydr.io/threats.json?exploited=1&page=51"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-21206",
      "url": "https://spydr.io/cve/CVE-2021-21206",
      "published": "2021-04-26T17:15:08.213Z",
      "modified": "2026-06-17T03:35:02.093Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09307,
      "epss_percentile": 0.95256,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2021-22205",
      "url": "https://spydr.io/cve/CVE-2021-22205",
      "published": "2021-04-23T18:15:08.167Z",
      "modified": "2026-08-06T05:16:35.427Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99731,
      "epss_percentile": 0.99952,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "GitLab"
      ],
      "products": [
        "GitLab"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution."
    },
    {
      "id": "CVE-2021-22204",
      "url": "https://spydr.io/cve/CVE-2021-22204",
      "published": "2021-04-23T18:15:08.127Z",
      "modified": "2026-06-17T03:36:47.890Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99981,
      "epss_percentile": 0.99981,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ExifTool"
      ],
      "products": [
        "ExifTool"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image"
    },
    {
      "id": "CVE-2021-22893",
      "url": "https://spydr.io/cve/CVE-2021-22893",
      "published": "2021-04-23T17:15:08.127Z",
      "modified": "2026-08-12T05:17:37.347Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.47172,
      "epss_percentile": 0.98807,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ivanti"
      ],
      "products": [
        "Pulse Connect Secure"
      ],
      "cwes": [
        "CWE-287",
        "CWE-416"
      ],
      "description": "Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild."
    },
    {
      "id": "CVE-2021-20023",
      "url": "https://spydr.io/cve/CVE-2021-20023",
      "published": "2021-04-20T12:15:12.587Z",
      "modified": "2026-10-01T21:17:16.097Z",
      "score": 4.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.51689,
      "epss_percentile": 0.98921,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall Email Security"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host."
    },
    {
      "id": "CVE-2021-3493",
      "url": "https://spydr.io/cve/CVE-2021-3493",
      "published": "2021-04-17T05:15:14.630Z",
      "modified": "2026-06-17T04:05:12.177Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.49166,
      "epss_percentile": 0.98858,
      "exploited": true,
      "kev": {
        "added": "2022-10-20",
        "due": "2022-11-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Ubuntu"
      ],
      "products": [
        "Ubuntu linux kernel"
      ],
      "cwes": [
        "CWE-270",
        "CWE-863"
      ],
      "description": "The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges."
    },
    {
      "id": "CVE-2020-2509",
      "url": "https://spydr.io/cve/CVE-2020-2509",
      "published": "2021-04-17T04:15:11.327Z",
      "modified": "2026-06-17T03:12:15.447Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.33987,
      "epss_percentile": 0.98361,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. QTS",
        "QNAP Systems Inc. QuTS hero"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later"
    },
    {
      "id": "CVE-2021-28310",
      "url": "https://spydr.io/cve/CVE-2021-28310",
      "published": "2021-04-13T20:15:16.267Z",
      "modified": "2026-06-17T03:46:08.633Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.0833,
      "epss_percentile": 0.94815,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1803",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-20022",
      "url": "https://spydr.io/cve/CVE-2021-20022",
      "published": "2021-04-09T18:15:13.460Z",
      "modified": "2026-10-01T21:17:15.817Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.16639,
      "epss_percentile": 0.96948,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall Email Security"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host."
    },
    {
      "id": "CVE-2021-20021",
      "url": "https://spydr.io/cve/CVE-2021-20021",
      "published": "2021-04-09T18:15:13.380Z",
      "modified": "2026-08-12T05:17:33.710Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.8878,
      "epss_percentile": 0.99775,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall Email Security"
      ],
      "cwes": [
        "CWE-269"
      ],
      "description": "A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host."
    },
    {
      "id": "CVE-2021-1879",
      "url": "https://spydr.io/cve/CVE-2021-1879",
      "published": "2021-04-02T19:15:20.770Z",
      "modified": "2026-06-17T03:32:42.883Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.07082,
      "epss_percentile": 0.94061,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple iOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2021-1871",
      "url": "https://spydr.io/cve/CVE-2021-1871",
      "published": "2021-04-02T19:15:20.663Z",
      "modified": "2026-06-17T03:32:41.847Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.07002,
      "epss_percentile": 0.94,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [],
      "description": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2021-1870",
      "url": "https://spydr.io/cve/CVE-2021-1870",
      "published": "2021-04-02T19:15:20.567Z",
      "modified": "2026-06-17T03:32:41.677Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0771,
      "epss_percentile": 0.94463,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [],
      "description": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2021-1789",
      "url": "https://spydr.io/cve/CVE-2021-1789",
      "published": "2021-04-02T18:15:21.747Z",
      "modified": "2026-06-17T03:32:33.900Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.13975,
      "epss_percentile": 0.96461,
      "exploited": true,
      "kev": {
        "added": "2022-05-04",
        "due": "2022-05-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution."
    },
    {
      "id": "CVE-2021-1782",
      "url": "https://spydr.io/cve/CVE-2021-1782",
      "published": "2021-04-02T18:15:21.373Z",
      "modified": "2026-06-17T03:32:33.030Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02222,
      "epss_percentile": 0.82157,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-667"
      ],
      "description": "A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2021-22991",
      "url": "https://spydr.io/cve/CVE-2021-22991",
      "published": "2021-03-31T18:15:14.787Z",
      "modified": "2026-06-17T03:38:10.083Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.61064,
      "epss_percentile": 0.99139,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "f5"
      ],
      "products": [
        "BIG-IP"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual server may be incorrectly handled by the Traffic Management Microkernel (TMM) URI normalization, which may trigger a buffer overflow, resulting in a DoS attack. In certain situations, it may theoretically allow bypass of URL based access control or remote code execution (RCE). Note: Software versions which have reached End of Software Development (EoSD) are not evaluated."
    },
    {
      "id": "CVE-2021-21975",
      "url": "https://spydr.io/cve/CVE-2021-21975",
      "published": "2021-03-31T18:15:14.597Z",
      "modified": "2026-10-02T14:54:50.597Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.78001,
      "epss_percentile": 0.99566,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware"
      ],
      "products": [
        "VMware vRealize Operations"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials."
    },
    {
      "id": "CVE-2021-22986",
      "url": "https://spydr.io/cve/CVE-2021-22986",
      "published": "2021-03-31T15:15:15.153Z",
      "modified": "2026-06-17T03:38:09.413Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99898,
      "epss_percentile": 0.99965,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "f5"
      ],
      "products": [
        "BIG-IP; BIG-IQ"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated."
    },
    {
      "id": "CVE-2021-25372",
      "url": "https://spydr.io/cve/CVE-2021-25372",
      "published": "2021-03-26T19:15:12.303Z",
      "modified": "2026-06-17T03:41:57.807Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00804,
      "epss_percentile": 0.55385,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-787",
        "CWE-703"
      ],
      "description": "An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access."
    },
    {
      "id": "CVE-2021-25371",
      "url": "https://spydr.io/cve/CVE-2021-25371",
      "published": "2021-03-26T19:15:12.227Z",
      "modified": "2026-06-17T03:41:57.673Z",
      "score": 6.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00802,
      "epss_percentile": 0.55278,
      "exploited": true,
      "kev": {
        "added": "2023-06-29",
        "due": "2023-07-20",
        "action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Samsung Mobile"
      ],
      "products": [
        "Samsung Mobile Devices"
      ],
      "cwes": [
        "CWE-912"
      ],
      "description": "A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
