{
  "query": {
    "kev": "1",
    "page": "56"
  },
  "count": 20,
  "total": 1734,
  "page": 56,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T10:49:04.872Z",
    "kev": "2026-10-08T10:50:04.958Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T06:48:55.302Z",
    "posts": "2026-10-08T10:49:04.872Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=56",
    "next": "https://spydr.io/threats.json?kev=1&page=57"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2022-24521",
      "url": "https://spydr.io/cve/CVE-2022-24521",
      "published": "2022-04-15T19:15:11.107Z",
      "modified": "2026-06-17T04:32:02.300Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.07076,
      "epss_percentile": 0.94056,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2008 R2 Service Pack 1"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Windows Common Log File System Driver Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2018-20753",
      "url": "https://spydr.io/cve/CVE-2018-20753",
      "published": "2019-02-05T06:29:00.593Z",
      "modified": "2026-08-13T05:17:18.220Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.29551,
      "epss_percentile": 0.98148,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "kaseya"
      ],
      "products": [
        "kaseya virtual system administrator"
      ],
      "cwes": [],
      "description": "Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild."
    },
    {
      "id": "CVE-2018-7602",
      "url": "https://spydr.io/cve/CVE-2018-7602",
      "published": "2018-07-19T17:29:00.373Z",
      "modified": "2026-10-02T14:54:58.763Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99172,
      "epss_percentile": 0.99934,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Drupal"
      ],
      "products": [
        "Drupal core"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild."
    },
    {
      "id": "CVE-2015-2502",
      "url": "https://spydr.io/cve/CVE-2015-2502",
      "published": "2015-08-19T10:59:00.090Z",
      "modified": "2026-06-17T00:24:12.337Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.51001,
      "epss_percentile": 0.98905,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka \"Memory Corruption Vulnerability,\" as exploited in the wild in August 2015."
    },
    {
      "id": "CVE-2015-5123",
      "url": "https://spydr.io/cve/CVE-2015-5123",
      "published": "2015-07-14T10:59:01.337Z",
      "modified": "2026-06-17T00:28:31.153Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.1883,
      "epss_percentile": 0.97218,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "opensuse",
        "suse",
        "adobe"
      ],
      "products": [
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux server eus",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "adobe flash player",
        "adobe flash player desktop runtime"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015."
    },
    {
      "id": "CVE-2015-5122",
      "url": "https://spydr.io/cve/CVE-2015-5122",
      "published": "2015-07-14T10:59:00.213Z",
      "modified": "2026-06-17T00:28:30.877Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93978,
      "epss_percentile": 0.99846,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "redhat",
        "opensuse",
        "suse"
      ],
      "products": [
        "adobe flash player",
        "adobe flash player desktop runtime",
        "redhat enterprise linux desktop",
        "redhat enterprise linux server",
        "redhat enterprise linux server eus",
        "redhat enterprise linux workstation",
        "opensuse evergreen",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015."
    },
    {
      "id": "CVE-2015-3113",
      "url": "https://spydr.io/cve/CVE-2015-3113",
      "published": "2015-06-23T21:59:01.960Z",
      "modified": "2026-06-17T00:25:19.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99812,
      "epss_percentile": 0.99958,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "hp",
        "redhat"
      ],
      "products": [
        "adobe flash player",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "hp insight orchestration",
        "hp system management homepage",
        "hp systems insight manager",
        "hp version control agent",
        "hp version control repository manager",
        "hp virtual connect enterprise manager",
        "redhat enterprise linux desktop",
        "redhat enterprise linux eus",
        "redhat enterprise linux server",
        "redhat enterprise linux workstation"
      ],
      "cwes": [
        "CWE-787",
        "CWE-122"
      ],
      "description": "Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015."
    },
    {
      "id": "CVE-2015-0313",
      "url": "https://spydr.io/cve/CVE-2015-0313",
      "published": "2015-02-02T19:59:00.053Z",
      "modified": "2026-06-17T00:19:58.420Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.95266,
      "epss_percentile": 0.99866,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "opensuse",
        "suse",
        "microsoft"
      ],
      "products": [
        "adobe flash player",
        "opensuse evergreen",
        "opensuse",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "microsoft internet explorer",
        "microsoft edge"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322."
    },
    {
      "id": "CVE-2015-0311",
      "url": "https://spydr.io/cve/CVE-2015-0311",
      "published": "2015-01-23T21:59:04.897Z",
      "modified": "2026-06-17T00:19:58.077Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.85589,
      "epss_percentile": 0.9972,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe",
        "suse",
        "microsoft"
      ],
      "products": [
        "adobe flash player",
        "suse linux enterprise desktop",
        "suse linux enterprise workstation extension",
        "microsoft internet explorer",
        "microsoft edge"
      ],
      "cwes": [],
      "description": "Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015."
    },
    {
      "id": "CVE-2014-9163",
      "url": "https://spydr.io/cve/CVE-2014-9163",
      "published": "2014-12-10T21:59:35.163Z",
      "modified": "2026-06-17T00:17:51.397Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "CISA ADP",
      "epss": 0.20724,
      "epss_percentile": 0.9748,
      "exploited": true,
      "kev": {
        "added": "2022-04-13",
        "due": "2022-05-04",
        "action": "The impacted product is end-of-life and should be disconnected if still in use.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "adobe"
      ],
      "products": [
        "adobe flash player"
      ],
      "cwes": [
        "CWE-121"
      ],
      "description": "Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014."
    },
    {
      "id": "CVE-2021-39793",
      "url": "https://spydr.io/cve/CVE-2021-39793",
      "published": "2022-03-16T15:15:12.430Z",
      "modified": "2026-06-17T04:04:10.107Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.00685,
      "epss_percentile": 0.51099,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A"
    },
    {
      "id": "CVE-2022-23176",
      "url": "https://spydr.io/cve/CVE-2022-23176",
      "published": "2022-02-24T15:15:28.447Z",
      "modified": "2026-06-17T04:29:37.677Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.10805,
      "epss_percentile": 0.95742,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "watchguard"
      ],
      "products": [
        "watchguard fireware"
      ],
      "cwes": [],
      "description": "WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3."
    },
    {
      "id": "CVE-2021-22600",
      "url": "https://spydr.io/cve/CVE-2021-22600",
      "published": "2022-01-26T14:15:08.123Z",
      "modified": "2026-06-17T03:37:27.450Z",
      "score": 7,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.06586,
      "epss_percentile": 0.93665,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Linux Kernel"
      ],
      "products": [
        "Linux Kernel Kernel"
      ],
      "cwes": [
        "CWE-415"
      ],
      "description": "A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755"
    },
    {
      "id": "CVE-2021-42287",
      "url": "https://spydr.io/cve/CVE-2021-42287",
      "published": "2021-11-10T01:19:46.137Z",
      "modified": "2026-08-19T19:23:00.553Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.7717,
      "epss_percentile": 0.99544,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [],
      "description": "Active Directory Domain Services Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-42278",
      "url": "https://spydr.io/cve/CVE-2021-42278",
      "published": "2021-11-10T01:19:44.300Z",
      "modified": "2026-08-19T19:22:57.137Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.73297,
      "epss_percentile": 0.99452,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows Server 2008 R2 Service Pack 1",
        "Microsoft Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)",
        "Microsoft Windows Server 2012",
        "Microsoft Windows Server 2012 (Server Core installation)",
        "Microsoft Windows Server 2012 R2",
        "Microsoft Windows Server 2012 R2 (Server Core installation)",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows Server 2022",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [],
      "description": "Active Directory Domain Services Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-27852",
      "url": "https://spydr.io/cve/CVE-2021-27852",
      "published": "2021-05-27T21:15:20.567Z",
      "modified": "2026-06-17T03:45:31.033Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.30258,
      "epss_percentile": 0.98184,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Checkbox"
      ],
      "products": [
        "Checkbox Survey"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7."
    },
    {
      "id": "CVE-2020-2509",
      "url": "https://spydr.io/cve/CVE-2020-2509",
      "published": "2021-04-17T04:15:11.327Z",
      "modified": "2026-06-17T03:12:15.447Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.33987,
      "epss_percentile": 0.98361,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "QNAP Systems Inc."
      ],
      "products": [
        "QNAP Systems Inc. QTS",
        "QNAP Systems Inc. QuTS hero"
      ],
      "cwes": [
        "CWE-77",
        "CWE-78"
      ],
      "description": "A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later"
    },
    {
      "id": "CVE-2017-11317",
      "url": "https://spydr.io/cve/CVE-2017-11317",
      "published": "2017-08-23T17:29:00.177Z",
      "modified": "2026-06-17T01:01:36.190Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.84175,
      "epss_percentile": 0.99692,
      "exploited": true,
      "kev": {
        "added": "2022-04-11",
        "due": "2022-05-02",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "telerik"
      ],
      "products": [
        "telerik ui for asp.net ajax"
      ],
      "cwes": [
        "CWE-326"
      ],
      "description": "Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code."
    },
    {
      "id": "CVE-2021-31166",
      "url": "https://spydr.io/cve/CVE-2021-31166",
      "published": "2021-05-11T19:15:09.300Z",
      "modified": "2026-06-17T03:51:21.910Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.99867,
      "epss_percentile": 0.99962,
      "exploited": true,
      "kev": {
        "added": "2022-04-06",
        "due": "2022-04-27",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "HTTP Protocol Stack Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2021-3156",
      "url": "https://spydr.io/cve/CVE-2021-3156",
      "published": "2021-01-26T21:15:12.987Z",
      "modified": "2026-06-17T04:04:45.830Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99962,
      "epss_percentile": 0.99976,
      "exploited": true,
      "kev": {
        "added": "2022-04-06",
        "due": "2022-04-27",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "sudo project",
        "fedoraproject",
        "debian",
        "netapp",
        "mcafee",
        "synology",
        "beyondtrust",
        "oracle"
      ],
      "products": [
        "sudo project sudo",
        "fedoraproject fedora",
        "debian linux",
        "netapp active iq unified manager",
        "netapp cloud backup",
        "netapp hci management node",
        "netapp oncommand unified manager core package",
        "netapp ontap select deploy administration utility",
        "netapp ontap tools",
        "netapp solidfire",
        "mcafee web gateway",
        "synology diskstation manager unified controller",
        "synology diskstation manager",
        "synology skynas firmware",
        "synology vs960hd firmware",
        "beyondtrust privilege management for mac",
        "beyondtrust privilege management for unix/linux",
        "oracle micros compact workstation 3 firmware",
        "oracle micros es400 firmware",
        "oracle micros kitchen display system firmware"
      ],
      "cwes": [
        "CWE-193"
      ],
      "description": "Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
