{
  "query": {
    "exploited": "1",
    "page": "52"
  },
  "count": 20,
  "total": 1734,
  "page": 52,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T02:48:45.529Z",
    "kev": "2026-10-08T02:49:45.513Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T02:48:45.528Z"
  },
  "links": {
    "web": "https://spydr.io/threats?exploited=1&page=52",
    "next": "https://spydr.io/threats.json?exploited=1&page=53"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2021-27104",
      "url": "https://spydr.io/cve/CVE-2021-27104",
      "published": "2021-02-16T21:15:13.280Z",
      "modified": "2026-06-17T03:44:18.213Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.56686,
      "epss_percentile": 0.99042,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "accellion"
      ],
      "products": [
        "accellion fta"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later."
    },
    {
      "id": "CVE-2021-27103",
      "url": "https://spydr.io/cve/CVE-2021-27103",
      "published": "2021-02-16T21:15:13.217Z",
      "modified": "2026-06-17T03:44:18.027Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11406,
      "epss_percentile": 0.95899,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "accellion"
      ],
      "products": [
        "accellion fta"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later."
    },
    {
      "id": "CVE-2021-27102",
      "url": "https://spydr.io/cve/CVE-2021-27102",
      "published": "2021-02-16T21:15:13.140Z",
      "modified": "2026-06-17T03:44:17.850Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03654,
      "epss_percentile": 0.89302,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "accellion"
      ],
      "products": [
        "accellion fta"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later."
    },
    {
      "id": "CVE-2021-27101",
      "url": "https://spydr.io/cve/CVE-2021-27101",
      "published": "2021-02-16T21:15:13.077Z",
      "modified": "2026-06-17T03:44:17.670Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05998,
      "epss_percentile": 0.93136,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "accellion"
      ],
      "products": [
        "accellion fta"
      ],
      "cwes": [],
      "description": "Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later."
    },
    {
      "id": "CVE-2021-21315",
      "url": "https://spydr.io/cve/CVE-2021-21315",
      "published": "2021-02-16T17:15:13.050Z",
      "modified": "2026-06-17T03:35:16.700Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90675,
      "epss_percentile": 0.99802,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sebhildebrandt"
      ],
      "products": [
        "sebhildebrandt systeminformation"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "The System Information Library for Node.JS (npm package \"systeminformation\") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected."
    },
    {
      "id": "CVE-2021-25298",
      "url": "https://spydr.io/cve/CVE-2021-25298",
      "published": "2021-02-15T13:15:12.857Z",
      "modified": "2026-07-09T13:39:54.287Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.75148,
      "epss_percentile": 0.995,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server."
    },
    {
      "id": "CVE-2021-25297",
      "url": "https://spydr.io/cve/CVE-2021-25297",
      "published": "2021-02-15T13:15:12.793Z",
      "modified": "2026-07-09T13:39:51.737Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.56659,
      "epss_percentile": 0.99042,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server."
    },
    {
      "id": "CVE-2021-25296",
      "url": "https://spydr.io/cve/CVE-2021-25296",
      "published": "2021-02-15T13:15:12.683Z",
      "modified": "2026-07-09T13:39:49.130Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.72182,
      "epss_percentile": 0.99423,
      "exploited": true,
      "kev": {
        "added": "2022-01-18",
        "due": "2022-02-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "nagios"
      ],
      "products": [
        "nagios xi"
      ],
      "cwes": [],
      "description": "Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server."
    },
    {
      "id": "CVE-2021-21311",
      "url": "https://spydr.io/cve/CVE-2021-21311",
      "published": "2021-02-11T21:15:13.820Z",
      "modified": "2026-06-17T03:35:16.213Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.98464,
      "epss_percentile": 0.99919,
      "exploited": true,
      "kev": {
        "added": "2025-09-29",
        "due": "2025-10-20",
        "action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vrana"
      ],
      "products": [
        "vrana adminer"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version 4.7.9."
    },
    {
      "id": "CVE-2021-21017",
      "url": "https://spydr.io/cve/CVE-2021-21017",
      "published": "2021-02-11T20:15:13.997Z",
      "modified": "2026-06-17T03:34:40.193Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "adobe.com",
      "epss": 0.86326,
      "epss_percentile": 0.99731,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Adobe"
      ],
      "products": [
        "Adobe Acrobat Reader"
      ],
      "cwes": [
        "CWE-122",
        "CWE-787"
      ],
      "description": "Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file."
    },
    {
      "id": "CVE-2021-23874",
      "url": "https://spydr.io/cve/CVE-2021-23874",
      "published": "2021-02-10T11:15:12.943Z",
      "modified": "2026-06-17T03:38:57.850Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01026,
      "epss_percentile": 0.62486,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "McAfee,LLC"
      ],
      "products": [
        "McAfee,LLC McAfee Total Protection (MTP)"
      ],
      "cwes": [
        "CWE-269",
        "CWE-732"
      ],
      "description": "Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense."
    },
    {
      "id": "CVE-2021-21148",
      "url": "https://spydr.io/cve/CVE-2021-21148",
      "published": "2021-02-09T16:15:12.390Z",
      "modified": "2026-06-17T03:34:54.850Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.19968,
      "epss_percentile": 0.97378,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2021-22502",
      "url": "https://spydr.io/cve/CVE-2021-22502",
      "published": "2021-02-08T22:15:12.527Z",
      "modified": "2026-06-17T03:37:20.340Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9674,
      "epss_percentile": 0.99886,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microfocus"
      ],
      "products": [
        "Operation Bridge Reporter."
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server."
    },
    {
      "id": "CVE-2021-20016",
      "url": "https://spydr.io/cve/CVE-2021-20016",
      "published": "2021-02-04T06:15:13.817Z",
      "modified": "2026-08-12T05:17:33.173Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.40038,
      "epss_percentile": 0.98598,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SonicWall"
      ],
      "products": [
        "SonicWall SMA100"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x."
    },
    {
      "id": "CVE-2020-2506",
      "url": "https://spydr.io/cve/CVE-2020-2506",
      "published": "2021-02-03T16:15:13.807Z",
      "modified": "2026-06-17T03:12:15.060Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01982,
      "epss_percentile": 0.79915,
      "exploited": true,
      "kev": {
        "added": "2022-03-25",
        "due": "2022-04-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. Helpdesk"
      ],
      "cwes": [
        "CWE-284"
      ],
      "description": "The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3."
    },
    {
      "id": "CVE-2020-25506",
      "url": "https://spydr.io/cve/CVE-2020-25506",
      "published": "2021-02-02T13:15:12.570Z",
      "modified": "2026-06-17T03:06:52.573Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99968,
      "epss_percentile": 0.99978,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dns-320 firmware"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution."
    },
    {
      "id": "CVE-2020-29557",
      "url": "https://spydr.io/cve/CVE-2020-29557",
      "published": "2021-01-29T20:15:12.933Z",
      "modified": "2026-06-17T03:11:25.717Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.5432,
      "epss_percentile": 0.98987,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2022-05-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-825 r1 firmware"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution."
    },
    {
      "id": "CVE-2021-3156",
      "url": "https://spydr.io/cve/CVE-2021-3156",
      "published": "2021-01-26T21:15:12.987Z",
      "modified": "2026-06-17T04:04:45.830Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99962,
      "epss_percentile": 0.99976,
      "exploited": true,
      "kev": {
        "added": "2022-04-06",
        "due": "2022-04-27",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sudo project",
        "fedoraproject",
        "debian",
        "netapp",
        "mcafee",
        "synology",
        "beyondtrust",
        "oracle"
      ],
      "products": [
        "sudo project sudo",
        "fedoraproject fedora",
        "debian linux",
        "netapp active iq unified manager",
        "netapp cloud backup",
        "netapp hci management node",
        "netapp oncommand unified manager core package",
        "netapp ontap select deploy administration utility",
        "netapp ontap tools",
        "netapp solidfire",
        "mcafee web gateway",
        "synology diskstation manager unified controller",
        "synology diskstation manager",
        "synology skynas firmware",
        "synology vs960hd firmware",
        "beyondtrust privilege management for mac",
        "beyondtrust privilege management for unix/linux",
        "oracle micros compact workstation 3 firmware",
        "oracle micros es400 firmware",
        "oracle micros kitchen display system firmware"
      ],
      "cwes": [
        "CWE-193"
      ],
      "description": "Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character."
    },
    {
      "id": "CVE-2020-36193",
      "url": "https://spydr.io/cve/CVE-2020-36193",
      "published": "2021-01-18T20:15:12.667Z",
      "modified": "2026-06-17T03:14:58.533Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.70595,
      "epss_percentile": 0.99379,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "php",
        "fedoraproject",
        "debian",
        "drupal"
      ],
      "products": [
        "php archive tar",
        "fedoraproject fedora",
        "debian linux",
        "drupal"
      ],
      "cwes": [
        "CWE-22",
        "CWE-59"
      ],
      "description": "Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948."
    },
    {
      "id": "CVE-2020-6572",
      "url": "https://spydr.io/cve/CVE-2020-6572",
      "published": "2021-01-14T21:15:13.693Z",
      "modified": "2026-06-17T03:23:37.420Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10586,
      "epss_percentile": 0.95677,
      "exploited": true,
      "kev": {
        "added": "2022-01-10",
        "due": "2022-07-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
