{
  "query": {
    "kev": "1",
    "page": "44"
  },
  "count": 20,
  "total": 1734,
  "page": 44,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T22:48:36.014Z",
    "kev": "2026-10-07T22:49:35.832Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T22:48:36.006Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=44",
    "next": "https://spydr.io/threats.json?kev=1&page=45"
  },
  "coverage": {
    "cves_published_since": "2026-06-09",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2015-2291",
      "url": "https://spydr.io/cve/CVE-2015-2291",
      "published": "2017-08-09T18:29:00.933Z",
      "modified": "2026-10-01T19:17:11.830Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09011,
      "epss_percentile": 0.95153,
      "exploited": true,
      "kev": {
        "added": "2023-02-10",
        "due": "2023-03-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "intel"
      ],
      "products": [
        "intel ethernet diagnostics driver iqvw32.sys",
        "intel ethernet diagnostics driver iqvw64.sys"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call."
    },
    {
      "id": "CVE-2023-22952",
      "url": "https://spydr.io/cve/CVE-2023-22952",
      "published": "2023-01-11T09:15:08.787Z",
      "modified": "2026-06-17T05:36:30.243Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.80139,
      "epss_percentile": 0.99611,
      "exploited": true,
      "kev": {
        "added": "2023-02-02",
        "due": "2023-02-23",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sugarcrm"
      ],
      "products": [
        "sugarcrm"
      ],
      "cwes": [
        "CWE-20",
        "CWE-94"
      ],
      "description": "In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation."
    },
    {
      "id": "CVE-2022-21587",
      "url": "https://spydr.io/cve/CVE-2022-21587",
      "published": "2022-10-18T21:15:10.960Z",
      "modified": "2026-06-17T04:26:34.010Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.98342,
      "epss_percentile": 0.99917,
      "exploited": true,
      "kev": {
        "added": "2023-02-02",
        "due": "2023-02-23",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Web Applications Desktop Integrator"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2017-11357",
      "url": "https://spydr.io/cve/CVE-2017-11357",
      "published": "2017-08-23T17:29:00.227Z",
      "modified": "2026-08-14T05:16:54.257Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.77679,
      "epss_percentile": 0.99557,
      "exploited": true,
      "kev": {
        "added": "2023-01-26",
        "due": "2023-02-16",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "progress"
      ],
      "products": [
        "progress telerik ui for asp.net ajax"
      ],
      "cwes": [
        "CWE-434"
      ],
      "description": "Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code."
    },
    {
      "id": "CVE-2022-47966",
      "url": "https://spydr.io/cve/CVE-2022-47966",
      "published": "2023-01-18T18:15:10.570Z",
      "modified": "2026-07-31T04:16:41.843Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99753,
      "epss_percentile": 0.99954,
      "exploited": true,
      "kev": {
        "added": "2023-01-23",
        "due": "2023-02-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine access manager plus",
        "zohocorp manageengine ad360",
        "zohocorp manageengine adaudit plus",
        "zohocorp manageengine admanager plus",
        "zohocorp manageengine adselfservice plus",
        "zohocorp manageengine analytics plus",
        "zohocorp manageengine assetexplorer",
        "zohocorp manageengine key manager plus",
        "zohocorp manageengine pam360",
        "zohocorp manageengine password manager pro",
        "zohocorp manageengine servicedesk plus",
        "zohocorp manageengine servicedesk plus msp",
        "zohocorp manageengine supportcenter plus",
        "zohocorp manageengine application control plus",
        "zohocorp manageengine browser security plus",
        "zohocorp manageengine device control plus",
        "zohocorp manageengine endpoint dlp plus",
        "zohocorp manageengine os deployer",
        "zohocorp manageengine patch manager plus",
        "zohocorp manageengine remote access plus"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active)."
    },
    {
      "id": "CVE-2022-44877",
      "url": "https://spydr.io/cve/CVE-2022-44877",
      "published": "2023-01-05T23:15:09.150Z",
      "modified": "2026-06-17T05:09:01.120Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99995,
      "epss_percentile": 0.99988,
      "exploited": true,
      "kev": {
        "added": "2023-01-17",
        "due": "2023-02-07",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "control-webpanel"
      ],
      "products": [
        "control-webpanel webpanel"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter."
    },
    {
      "id": "CVE-2023-21674",
      "url": "https://spydr.io/cve/CVE-2023-21674",
      "published": "2023-01-10T22:15:16.307Z",
      "modified": "2026-06-17T05:33:36.547Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.40987,
      "epss_percentile": 0.98627,
      "exploited": true,
      "kev": {
        "added": "2023-01-10",
        "due": "2023-01-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-41080",
      "url": "https://spydr.io/cve/CVE-2022-41080",
      "published": "2022-11-09T22:15:21.550Z",
      "modified": "2026-08-10T16:18:19.843Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.77326,
      "epss_percentile": 0.99548,
      "exploited": true,
      "kev": {
        "added": "2023-01-10",
        "due": "2023-01-31",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2013 Cumulative Update 23",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2016 Cumulative Update 23",
        "Microsoft Exchange Server 2019 Cumulative Update 11",
        "Microsoft Exchange Server 2019 Cumulative Update 12"
      ],
      "cwes": [],
      "description": "Microsoft Exchange Server Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2018-18809",
      "url": "https://spydr.io/cve/CVE-2018-18809",
      "published": "2019-03-07T22:29:00.323Z",
      "modified": "2026-06-17T01:47:56.560Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.79064,
      "epss_percentile": 0.99591,
      "exploited": true,
      "kev": {
        "added": "2022-12-29",
        "due": "2023-01-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TIBCO Software Inc."
      ],
      "products": [
        "TIBCO Software Inc. TIBCO JasperReports Library",
        "TIBCO Software Inc. TIBCO JasperReports Library Community Edition",
        "TIBCO Software Inc. TIBCO JasperReports Library for ActiveMatrix BPM",
        "TIBCO Software Inc. TIBCO JasperReports Server",
        "TIBCO Software Inc. TIBCO JasperReports Server Community Edition",
        "TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM",
        "TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy",
        "TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a directory-traversal vulnerability that may theoretically allow web server users to access contents of the host system. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions up to and including 6.3.4; 6.4.1; 6.4.2; 6.4.21; 7.1.0; 7.2.0, TIBCO JasperReports Library Community Edition: versions up to and including 6.7.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions up to and including 6.4.21, TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.3; 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 7.1.0, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0."
    },
    {
      "id": "CVE-2018-5430",
      "url": "https://spydr.io/cve/CVE-2018-5430",
      "published": "2018-04-17T18:29:00.293Z",
      "modified": "2026-06-17T02:00:17.883Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.48986,
      "epss_percentile": 0.98854,
      "exploited": true,
      "kev": {
        "added": "2022-12-29",
        "due": "2023-01-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "TIBCO Software Inc."
      ],
      "products": [
        "TIBCO Software Inc. TIBCO JasperReports Server",
        "TIBCO Software Inc. TIBCO JasperReports Server Community Edition",
        "TIBCO Software Inc. TIBCO JasperReports Server for ActiveMatrix BPM",
        "TIBCO Software Inc. TIBCO Jaspersoft for AWS with Multi-Tenancy",
        "TIBCO Software Inc. TIBCO Jaspersoft Reporting and Analytics for AWS"
      ],
      "cwes": [
        "CWE-22",
        "CWE-200"
      ],
      "description": "The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2."
    },
    {
      "id": "CVE-2022-42856",
      "url": "https://spydr.io/cve/CVE-2022-42856",
      "published": "2022-12-15T19:15:25.123Z",
      "modified": "2026-06-17T05:05:29.160Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.08523,
      "epss_percentile": 0.94916,
      "exploited": true,
      "kev": {
        "added": "2022-12-14",
        "due": "2023-01-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.."
    },
    {
      "id": "CVE-2022-42475",
      "url": "https://spydr.io/cve/CVE-2022-42475",
      "published": "2023-01-02T09:15:09.490Z",
      "modified": "2026-06-17T05:04:59.630Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99474,
      "epss_percentile": 0.99943,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Fortinet"
      ],
      "products": [
        "Fortinet FortiProxy",
        "Fortinet FortiOS"
      ],
      "cwes": [
        "CWE-197",
        "CWE-787"
      ],
      "description": "A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests."
    },
    {
      "id": "CVE-2022-44698",
      "url": "https://spydr.io/cve/CVE-2022-44698",
      "published": "2022-12-13T19:15:14.403Z",
      "modified": "2026-06-17T05:08:47.430Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.76267,
      "epss_percentile": 0.99526,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016"
      ],
      "cwes": [],
      "description": "Windows SmartScreen Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2022-27518",
      "url": "https://spydr.io/cve/CVE-2022-27518",
      "published": "2022-12-13T17:15:14.350Z",
      "modified": "2026-06-17T04:37:09.663Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06683,
      "epss_percentile": 0.93729,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Citrix"
      ],
      "products": [
        "Citrix Gateway, Citrix ADC"
      ],
      "cwes": [
        "CWE-664"
      ],
      "description": "Unauthenticated remote arbitrary code execution"
    },
    {
      "id": "CVE-2022-26501",
      "url": "https://spydr.io/cve/CVE-2022-26501",
      "published": "2022-03-17T21:15:08.233Z",
      "modified": "2026-06-17T04:35:18.700Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04104,
      "epss_percentile": 0.90486,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veeam"
      ],
      "products": [
        "veeam backup & replication"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2)."
    },
    {
      "id": "CVE-2022-26500",
      "url": "https://spydr.io/cve/CVE-2022-26500",
      "published": "2022-03-17T21:15:08.193Z",
      "modified": "2026-06-17T04:35:18.530Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.05828,
      "epss_percentile": 0.92967,
      "exploited": true,
      "kev": {
        "added": "2022-12-13",
        "due": "2023-01-03",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "veeam"
      ],
      "products": [
        "veeam backup & replication"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code."
    },
    {
      "id": "CVE-2022-4262",
      "url": "https://spydr.io/cve/CVE-2022-4262",
      "published": "2022-12-02T21:15:12.247Z",
      "modified": "2026-06-17T05:20:25.837Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.2351,
      "epss_percentile": 0.97748,
      "exploited": true,
      "kev": {
        "added": "2022-12-05",
        "due": "2022-12-26",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-843"
      ],
      "description": "Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2022-4135",
      "url": "https://spydr.io/cve/CVE-2022-4135",
      "published": "2022-11-25T01:15:09.957Z",
      "modified": "2026-06-17T05:20:03.057Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.31864,
      "epss_percentile": 0.98264,
      "exploited": true,
      "kev": {
        "added": "2022-11-28",
        "due": "2022-12-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)"
    },
    {
      "id": "CVE-2021-35587",
      "url": "https://spydr.io/cve/CVE-2021-35587",
      "published": "2022-01-19T12:15:09.727Z",
      "modified": "2026-06-17T03:57:46.353Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "oracle.com",
      "epss": 0.96284,
      "epss_percentile": 0.99879,
      "exploited": true,
      "kev": {
        "added": "2022-11-28",
        "due": "2022-12-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Oracle Corporation"
      ],
      "products": [
        "Oracle Corporation Access Manager"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "id": "CVE-2022-41049",
      "url": "https://spydr.io/cve/CVE-2022-41049",
      "published": "2022-11-09T22:15:19.567Z",
      "modified": "2026-08-10T16:18:15.733Z",
      "score": 5.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L",
      "score_source": "microsoft.com",
      "epss": 0.02491,
      "epss_percentile": 0.84165,
      "exploited": true,
      "kev": {
        "added": "2022-11-14",
        "due": "2022-12-09",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 22H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 11 version 22H2",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022"
      ],
      "cwes": [],
      "description": "Windows Mark of the Web Security Feature Bypass Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
