{
  "query": {
    "kev": "1",
    "page": "48"
  },
  "count": 20,
  "total": 1734,
  "page": 48,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T00:48:40.801Z",
    "kev": "2026-10-08T01:49:42.842Z",
    "epss": "2026-10-08T01:00:40.923Z",
    "breaches": "2026-10-08T00:48:40.536Z",
    "posts": "2026-10-08T01:48:43.051Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=48",
    "next": "https://spydr.io/threats.json?kev=1&page=49"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-15944",
      "url": "https://spydr.io/cve/CVE-2017-15944",
      "published": "2017-12-11T17:29:00.490Z",
      "modified": "2026-06-17T01:08:31.113Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98303,
      "epss_percentile": 0.99916,
      "exploited": true,
      "kev": {
        "added": "2022-08-18",
        "due": "2022-09-08",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "paloaltonetworks"
      ],
      "products": [
        "paloaltonetworks pan-os"
      ],
      "cwes": [
        "CWE-20",
        "CWE-119"
      ],
      "description": "Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface."
    },
    {
      "id": "CVE-2022-37042",
      "url": "https://spydr.io/cve/CVE-2022-37042",
      "published": "2022-08-12T15:15:16.053Z",
      "modified": "2026-08-04T05:16:29.020Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.91893,
      "epss_percentile": 0.99817,
      "exploited": true,
      "kev": {
        "added": "2022-08-11",
        "due": "2022-09-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925."
    },
    {
      "id": "CVE-2022-27925",
      "url": "https://spydr.io/cve/CVE-2022-27925",
      "published": "2022-04-21T00:15:08.407Z",
      "modified": "2026-10-01T19:17:14.417Z",
      "score": 7.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98676,
      "epss_percentile": 0.99923,
      "exploited": true,
      "kev": {
        "added": "2022-08-11",
        "due": "2022-09-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal."
    },
    {
      "id": "CVE-2022-34713",
      "url": "https://spydr.io/cve/CVE-2022-34713",
      "published": "2022-08-09T20:15:11.487Z",
      "modified": "2026-06-17T04:50:46.483Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.67757,
      "epss_percentile": 0.99303,
      "exploited": true,
      "kev": {
        "added": "2022-08-09",
        "due": "2022-08-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)"
      ],
      "cwes": [],
      "description": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2022-30333",
      "url": "https://spydr.io/cve/CVE-2022-30333",
      "published": "2022-05-09T08:15:06.937Z",
      "modified": "2026-10-02T14:54:55.840Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.99233,
      "epss_percentile": 0.99936,
      "exploited": true,
      "kev": {
        "added": "2022-08-09",
        "due": "2022-08-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "rarlab",
        "debian"
      ],
      "products": [
        "rarlab unrar",
        "debian linux"
      ],
      "cwes": [
        "CWE-22",
        "CWE-59"
      ],
      "description": "RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected."
    },
    {
      "id": "CVE-2022-27924",
      "url": "https://spydr.io/cve/CVE-2022-27924",
      "published": "2022-04-21T00:15:08.360Z",
      "modified": "2026-10-02T14:55:01.717Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.93908,
      "epss_percentile": 0.99844,
      "exploited": true,
      "kev": {
        "added": "2022-08-04",
        "due": "2022-08-25",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "synacor"
      ],
      "products": [
        "synacor zimbra collaboration suite"
      ],
      "cwes": [
        "CWE-74"
      ],
      "description": "Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries."
    },
    {
      "id": "CVE-2022-26138",
      "url": "https://spydr.io/cve/CVE-2022-26138",
      "published": "2022-07-20T18:15:08.617Z",
      "modified": "2026-06-17T04:34:46.187Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.98241,
      "epss_percentile": 0.99915,
      "exploited": true,
      "kev": {
        "added": "2022-07-29",
        "due": "2022-08-19",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Atlassian"
      ],
      "products": [
        "Atlassian Questions For Confluence"
      ],
      "cwes": [
        "CWE-798"
      ],
      "description": "The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app."
    },
    {
      "id": "CVE-2022-22047",
      "url": "https://spydr.io/cve/CVE-2022-22047",
      "published": "2022-07-12T23:15:10.343Z",
      "modified": "2026-06-17T04:27:33.870Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.18765,
      "epss_percentile": 0.97211,
      "exploited": true,
      "kev": {
        "added": "2022-07-12",
        "due": "2022-08-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)"
      ],
      "cwes": [
        "CWE-426"
      ],
      "description": "Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2022-26925",
      "url": "https://spydr.io/cve/CVE-2022-26925",
      "published": "2022-05-10T21:15:10.187Z",
      "modified": "2026-06-17T04:36:08.233Z",
      "score": 5.9,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.10476,
      "epss_percentile": 0.95645,
      "exploited": true,
      "kev": {
        "added": "2022-07-01",
        "due": "2022-07-22",
        "action": "Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Windows LSA Spoofing Vulnerability"
    },
    {
      "id": "CVE-2022-29499",
      "url": "https://spydr.io/cve/CVE-2022-29499",
      "published": "2022-04-26T02:15:37.107Z",
      "modified": "2026-08-06T05:16:37.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.55242,
      "epss_percentile": 0.99009,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mitel"
      ],
      "products": [
        "mitel mivoice connect"
      ],
      "cwes": [
        "CWE-20"
      ],
      "description": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA."
    },
    {
      "id": "CVE-2021-4034",
      "url": "https://spydr.io/cve/CVE-2021-4034",
      "published": "2022-01-28T20:15:12.193Z",
      "modified": "2026-08-15T04:17:57.927Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.94345,
      "epss_percentile": 0.99851,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "polkit project",
        "redhat",
        "canonical",
        "suse",
        "oracle",
        "siemens",
        "starwindsoftware"
      ],
      "products": [
        "polkit"
      ],
      "cwes": [
        "CWE-787",
        "CWE-125"
      ],
      "description": "A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine."
    },
    {
      "id": "CVE-2021-30983",
      "url": "https://spydr.io/cve/CVE-2021-30983",
      "published": "2021-08-24T19:15:23.507Z",
      "modified": "2026-06-17T03:51:15.600Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02923,
      "epss_percentile": 0.86634,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2021-30533",
      "url": "https://spydr.io/cve/CVE-2021-30533",
      "published": "2021-06-07T20:15:08.730Z",
      "modified": "2026-06-17T03:50:24.617Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.16742,
      "epss_percentile": 0.96964,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-863"
      ],
      "description": "Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe."
    },
    {
      "id": "CVE-2020-9907",
      "url": "https://spydr.io/cve/CVE-2020-9907",
      "published": "2020-10-16T17:15:16.590Z",
      "modified": "2026-06-17T03:28:47.057Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.03199,
      "epss_percentile": 0.87741,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple tvOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2020-3837",
      "url": "https://spydr.io/cve/CVE-2020-3837",
      "published": "2020-02-27T21:15:16.630Z",
      "modified": "2026-06-17T03:19:07.070Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14839,
      "epss_percentile": 0.96614,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges."
    },
    {
      "id": "CVE-2019-8605",
      "url": "https://spydr.io/cve/CVE-2019-8605",
      "published": "2019-12-18T18:15:28.833Z",
      "modified": "2026-06-17T02:42:14.560Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.17609,
      "epss_percentile": 0.97078,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS",
        "Apple macOS",
        "Apple tvOS",
        "Apple watchOS"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges."
    },
    {
      "id": "CVE-2018-4344",
      "url": "https://spydr.io/cve/CVE-2018-4344",
      "published": "2019-04-03T18:29:09.173Z",
      "modified": "2026-06-17T01:58:49.423Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.02374,
      "epss_percentile": 0.83326,
      "exploited": true,
      "kev": {
        "added": "2022-06-27",
        "due": "2022-07-18",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "iOS, macOS, tvOS, watchOS"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5."
    },
    {
      "id": "CVE-2022-30190",
      "url": "https://spydr.io/cve/CVE-2022-30190",
      "published": "2022-06-01T20:15:07.983Z",
      "modified": "2026-08-06T05:16:37.550Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99163,
      "epss_percentile": 0.99933,
      "exploited": true,
      "kev": {
        "added": "2022-06-14",
        "due": "2022-07-05",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)"
      ],
      "cwes": [],
      "description": "A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability."
    },
    {
      "id": "CVE-2021-38163",
      "url": "https://spydr.io/cve/CVE-2021-38163",
      "published": "2021-09-14T12:15:10.890Z",
      "modified": "2026-06-17T04:01:38.330Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.36898,
      "epss_percentile": 0.98475,
      "exploited": true,
      "kev": {
        "added": "2022-06-09",
        "due": "2022-06-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "SAP SE"
      ],
      "products": [
        "SAP SE SAP NetWeaver (Visual Composer 7.0 RT)"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable."
    },
    {
      "id": "CVE-2016-2388",
      "url": "https://spydr.io/cve/CVE-2016-2388",
      "published": "2016-02-16T15:59:02.103Z",
      "modified": "2026-06-17T00:43:57.187Z",
      "score": 5.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.52206,
      "epss_percentile": 0.98933,
      "exploited": true,
      "kev": {
        "added": "2022-06-09",
        "due": "2022-06-30",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sap"
      ],
      "products": [
        "sap netweaver application server java"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
