{
  "query": {
    "kev": "1",
    "page": "47"
  },
  "count": 20,
  "total": 1734,
  "page": 47,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T00:48:40.801Z",
    "kev": "2026-10-08T00:49:40.486Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T00:48:40.801Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=47",
    "next": "https://spydr.io/threats.json?kev=1&page=48"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-5521",
      "url": "https://spydr.io/cve/CVE-2017-5521",
      "published": "2017-01-17T09:59:00.333Z",
      "modified": "2026-06-17T01:20:39.923Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.89245,
      "epss_percentile": 0.9978,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions. If the affected device has since entered end-of-life, it should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "netgear"
      ],
      "products": [
        "netgear r6200 firmware",
        "netgear r6300 firmware",
        "netgear vegn2610 firmware",
        "netgear ac1450 firmware",
        "netgear wnr1000v3 firmware",
        "netgear wndr3700v3 firmware",
        "netgear wndr4000 firmware",
        "netgear wndr4500 firmware",
        "netgear d6400 firmware",
        "netgear d6220 firmware",
        "netgear d6300 firmware",
        "netgear d6300b firmware",
        "netgear dgn2200bv4 firmware"
      ],
      "cwes": [],
      "description": "An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions."
    },
    {
      "id": "CVE-2011-4723",
      "url": "https://spydr.io/cve/CVE-2011-4723",
      "published": "2011-12-20T11:55:08.413Z",
      "modified": "2026-06-16T23:35:18.387Z",
      "score": 5.7,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "CISA ADP",
      "epss": 0.03064,
      "epss_percentile": 0.87223,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dlink"
      ],
      "products": [
        "dlink dir-300 firmware"
      ],
      "cwes": [
        "CWE-312"
      ],
      "description": "The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors."
    },
    {
      "id": "CVE-2011-1823",
      "url": "https://spydr.io/cve/CVE-2011-1823",
      "published": "2011-06-09T10:36:27.680Z",
      "modified": "2026-06-16T23:30:11.197Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.41367,
      "epss_percentile": 0.9864,
      "exploited": true,
      "kev": {
        "added": "2022-09-08",
        "due": "2022-09-29",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "google android"
      ],
      "cwes": [
        "CWE-190"
      ],
      "description": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak."
    },
    {
      "id": "CVE-2022-2294",
      "url": "https://spydr.io/cve/CVE-2022-2294",
      "published": "2022-07-28T02:15:07.797Z",
      "modified": "2026-08-04T05:16:28.260Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.70461,
      "epss_percentile": 0.99376,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2022-26352",
      "url": "https://spydr.io/cve/CVE-2022-26352",
      "published": "2022-07-17T22:15:08.787Z",
      "modified": "2026-06-17T04:35:02.220Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91248,
      "epss_percentile": 0.99809,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "dotcms"
      ],
      "products": [
        "dotcms"
      ],
      "cwes": [],
      "description": "An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution."
    },
    {
      "id": "CVE-2022-24706",
      "url": "https://spydr.io/cve/CVE-2022-24706",
      "published": "2022-04-26T10:15:35.083Z",
      "modified": "2026-06-17T04:32:20.160Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.9251,
      "epss_percentile": 0.99826,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache CouchDB"
      ],
      "cwes": [
        "CWE-1188"
      ],
      "description": "In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations."
    },
    {
      "id": "CVE-2022-22963",
      "url": "https://spydr.io/cve/CVE-2022-22963",
      "published": "2022-04-01T23:15:13.663Z",
      "modified": "2026-06-17T04:29:15.340Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99938,
      "epss_percentile": 0.99971,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "vmware",
        "oracle"
      ],
      "products": [
        "Spring Cloud Function"
      ],
      "cwes": [
        "CWE-94",
        "CWE-917"
      ],
      "description": "In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources."
    },
    {
      "id": "CVE-2022-24112",
      "url": "https://spydr.io/cve/CVE-2022-24112",
      "published": "2022-02-11T13:15:08.073Z",
      "modified": "2026-06-17T04:31:18.883Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96069,
      "epss_percentile": 0.99877,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache APISIX"
      ],
      "cwes": [
        "CWE-290"
      ],
      "description": "An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed."
    },
    {
      "id": "CVE-2021-39226",
      "url": "https://spydr.io/cve/CVE-2021-39226",
      "published": "2021-10-05T18:15:07.947Z",
      "modified": "2026-06-17T04:03:21.130Z",
      "score": 7.3,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "score_source": "NVD",
      "epss": 0.99933,
      "epss_percentile": 0.9997,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "grafana"
      ],
      "products": [
        "grafana"
      ],
      "cwes": [
        "CWE-287",
        "CWE-862"
      ],
      "description": "Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot \"public_mode\" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot \"public_mode\" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects."
    },
    {
      "id": "CVE-2021-38406",
      "url": "https://spydr.io/cve/CVE-2021-38406",
      "published": "2021-09-17T19:15:08.710Z",
      "modified": "2026-06-17T04:02:02.373Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.76428,
      "epss_percentile": 0.99529,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Delta Electronics"
      ],
      "products": [
        "Delta Electronics DOPSoft 2"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process."
    },
    {
      "id": "CVE-2021-31010",
      "url": "https://spydr.io/cve/CVE-2021-31010",
      "published": "2021-08-24T19:15:24.967Z",
      "modified": "2026-06-17T03:51:18.307Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.03673,
      "epss_percentile": 0.89356,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.."
    },
    {
      "id": "CVE-2020-36193",
      "url": "https://spydr.io/cve/CVE-2020-36193",
      "published": "2021-01-18T20:15:12.667Z",
      "modified": "2026-06-17T03:14:58.533Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.70595,
      "epss_percentile": 0.99379,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "php",
        "fedoraproject",
        "debian",
        "drupal"
      ],
      "products": [
        "php archive tar",
        "fedoraproject fedora",
        "debian linux",
        "drupal"
      ],
      "cwes": [
        "CWE-22",
        "CWE-59"
      ],
      "description": "Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948."
    },
    {
      "id": "CVE-2020-28949",
      "url": "https://spydr.io/cve/CVE-2020-28949",
      "published": "2020-11-19T19:15:11.937Z",
      "modified": "2026-06-17T03:10:53.810Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84554,
      "epss_percentile": 0.99698,
      "exploited": true,
      "kev": {
        "added": "2022-08-25",
        "due": "2022-09-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "php",
        "debian",
        "fedoraproject",
        "drupal"
      ],
      "products": [
        "php archive tar",
        "debian linux",
        "fedoraproject fedora",
        "drupal"
      ],
      "cwes": [],
      "description": "Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed."
    },
    {
      "id": "CVE-2022-0028",
      "url": "https://spydr.io/cve/CVE-2022-0028",
      "published": "2022-08-10T16:15:08.343Z",
      "modified": "2026-06-17T04:19:55.243Z",
      "score": 8.6,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
      "score_source": "NVD",
      "epss": 0.02542,
      "epss_percentile": 0.84505,
      "exploited": true,
      "kev": {
        "added": "2022-08-22",
        "due": "2022-09-12",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Palo Alto Networks"
      ],
      "products": [
        "Palo Alto Networks Cloud NGFW",
        "Palo Alto Networks PAN-OS",
        "Palo Alto Networks Prisma Access"
      ],
      "cwes": [
        "CWE-406"
      ],
      "description": "A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series (container) firewall against an attacker-specified target. To be misused by an external attacker, the firewall configuration must have a URL filtering profile with one or more blocked categories assigned to a source zone that has an external facing interface. This configuration is not typical for URL filtering and, if set, is likely unintended by the administrator. If exploited, this issue would not impact the confidentiality, integrity, or availability of our products. However, the resulting denial-of-service (DoS) attack may help obfuscate the identity of the attacker and implicate the firewall as the source of the attack. We have taken prompt action to address this issue in our PAN-OS software. All software updates for this issue are expected to be released no later than the week of August 15, 2022. This issue does not impact Panorama M-Series or Panorama virtual appliances. This issue has been resolved for all Cloud NGFW and Prisma Access customers and no additional action is required from them."
    },
    {
      "id": "CVE-2022-2856",
      "url": "https://spydr.io/cve/CVE-2022-2856",
      "published": "2022-09-26T16:15:11.207Z",
      "modified": "2026-06-17T04:42:42.850Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.0453,
      "epss_percentile": 0.91291,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google",
        "fedoraproject"
      ],
      "products": [
        "Google Chrome",
        "fedoraproject fedora"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page."
    },
    {
      "id": "CVE-2022-32894",
      "url": "https://spydr.io/cve/CVE-2022-32894",
      "published": "2022-08-24T20:15:09.193Z",
      "modified": "2026-06-17T04:48:09.577Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03286,
      "epss_percentile": 0.88114,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2022-32893",
      "url": "https://spydr.io/cve/CVE-2022-32893",
      "published": "2022-08-24T20:15:09.147Z",
      "modified": "2026-06-17T04:48:09.370Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.09931,
      "epss_percentile": 0.95478,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple Safari",
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2022-26923",
      "url": "https://spydr.io/cve/CVE-2022-26923",
      "published": "2022-05-10T21:15:10.133Z",
      "modified": "2026-06-17T04:36:07.943Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.835,
      "epss_percentile": 0.99679,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-295"
      ],
      "description": "Active Directory Domain Services Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-22536",
      "url": "https://spydr.io/cve/CVE-2022-22536",
      "published": "2022-02-09T23:15:18.620Z",
      "modified": "2026-06-17T04:28:33.183Z",
      "score": 10,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.97945,
      "epss_percentile": 0.99909,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP SE"
      ],
      "products": [
        "SAP SE SAP NetWeaver and ABAP Platform",
        "SAP SE SAP Web Dispatcher",
        "SAP SE SAP Content Server"
      ],
      "cwes": [
        "CWE-444"
      ],
      "description": "SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system."
    },
    {
      "id": "CVE-2022-21971",
      "url": "https://spydr.io/cve/CVE-2022-21971",
      "published": "2022-02-09T17:15:08.640Z",
      "modified": "2026-06-17T04:27:22.930Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.53934,
      "epss_percentile": 0.98978,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2"
      ],
      "cwes": [
        "CWE-824"
      ],
      "description": "Windows Runtime Remote Code Execution Vulnerability"
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
