{
  "query": {
    "kev": "1",
    "page": "73"
  },
  "count": 20,
  "total": 1739,
  "page": 73,
  "limit": 20,
  "updated": {
    "cves": "2026-10-09T00:50:36.126Z",
    "kev": "2026-10-09T01:50:38.055Z",
    "epss": "2026-10-09T01:01:36.165Z",
    "breaches": "2026-10-09T00:49:35.859Z",
    "posts": "2026-10-09T01:50:38.405Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=73",
    "next": "https://spydr.io/threats.json?kev=1&page=74"
  },
  "coverage": {
    "cves_published_since": "2026-06-11",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-17562",
      "url": "https://spydr.io/cve/CVE-2017-17562",
      "published": "2017-12-12T19:29:00.207Z",
      "modified": "2026-06-17T01:11:15.933Z",
      "score": 8.1,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.96262,
      "epss_percentile": 0.99879,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "embedthis",
        "oracle"
      ],
      "products": [
        "embedthis goahead",
        "oracle integrated lights out manager"
      ],
      "cwes": [],
      "description": "Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using untrusted HTTP request parameters in the cgiHandler function in cgi.c. When combined with the glibc dynamic linker, this behaviour can be abused for remote code execution using special parameter names such as LD_PRELOAD. An attacker can POST their shared object payload in the body of the request, and reference it using /proc/self/fd/0."
    },
    {
      "id": "CVE-2017-12149",
      "url": "https://spydr.io/cve/CVE-2017-12149",
      "published": "2017-10-04T21:01:00.180Z",
      "modified": "2026-10-07T17:58:24.273Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.90713,
      "epss_percentile": 0.99803,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Red Hat, Inc."
      ],
      "products": [
        "Red Hat, Inc. jbossas"
      ],
      "cwes": [
        "CWE-502"
      ],
      "description": "In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data."
    },
    {
      "id": "CVE-2010-1871",
      "url": "https://spydr.io/cve/CVE-2010-1871",
      "published": "2010-08-05T13:23:09.477Z",
      "modified": "2026-06-16T23:19:29.840Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.83397,
      "epss_percentile": 0.99676,
      "exploited": true,
      "kev": {
        "added": "2021-12-10",
        "due": "2022-06-10",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "redhat",
        "netapp"
      ],
      "products": [
        "redhat jboss enterprise application platform",
        "netapp oncommand balance",
        "netapp oncommand insight",
        "netapp oncommand unified manager"
      ],
      "cwes": [
        "CWE-917"
      ],
      "description": "JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured."
    },
    {
      "id": "CVE-2021-44077",
      "url": "https://spydr.io/cve/CVE-2021-44077",
      "published": "2021-11-29T04:15:06.737Z",
      "modified": "2026-06-17T04:11:52.397Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.93298,
      "epss_percentile": 0.99836,
      "exploited": true,
      "kev": {
        "added": "2021-12-01",
        "due": "2021-12-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine servicedesk plus",
        "zohocorp manageengine servicedesk plus msp",
        "zohocorp manageengine supportcenter plus"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration."
    },
    {
      "id": "CVE-2021-40438",
      "url": "https://spydr.io/cve/CVE-2021-40438",
      "published": "2021-09-16T15:15:07.633Z",
      "modified": "2026-08-06T05:16:35.670Z",
      "score": 9,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99999,
      "epss_percentile": 0.99997,
      "exploited": true,
      "kev": {
        "added": "2021-12-01",
        "due": "2021-12-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apache Software Foundation"
      ],
      "products": [
        "Apache Software Foundation Apache HTTP Server"
      ],
      "cwes": [
        "CWE-918"
      ],
      "description": "A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier."
    },
    {
      "id": "CVE-2021-37415",
      "url": "https://spydr.io/cve/CVE-2021-37415",
      "published": "2021-09-01T06:15:06.530Z",
      "modified": "2026-06-17T04:00:29.513Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99825,
      "epss_percentile": 0.99959,
      "exploited": true,
      "kev": {
        "added": "2021-12-01",
        "due": "2021-12-15",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "zohocorp"
      ],
      "products": [
        "zohocorp manageengine servicedesk plus"
      ],
      "cwes": [
        "CWE-306"
      ],
      "description": "Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication."
    },
    {
      "id": "CVE-2020-11261",
      "url": "https://spydr.io/cve/CVE-2020-11261",
      "published": "2021-06-09T05:15:07.643Z",
      "modified": "2026-06-17T02:49:49.450Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01604,
      "epss_percentile": 0.75112,
      "exploited": true,
      "kev": {
        "added": "2021-12-01",
        "due": "2022-06-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Qualcomm, Inc."
      ],
      "products": [
        "Qualcomm, Inc. Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables"
      ],
      "cwes": [
        "CWE-787",
        "CWE-20"
      ],
      "description": "Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables"
    },
    {
      "id": "CVE-2018-14847",
      "url": "https://spydr.io/cve/CVE-2018-14847",
      "published": "2018-08-02T07:29:00.280Z",
      "modified": "2026-06-17T01:41:44.820Z",
      "score": 9.1,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "score_source": "NVD",
      "epss": 0.95981,
      "epss_percentile": 0.99875,
      "exploited": true,
      "kev": {
        "added": "2021-12-01",
        "due": "2022-06-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "mikrotik"
      ],
      "products": [
        "mikrotik routeros"
      ],
      "cwes": [
        "CWE-22"
      ],
      "description": "MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface."
    },
    {
      "id": "CVE-2021-42321",
      "url": "https://spydr.io/cve/CVE-2021-42321",
      "published": "2021-11-10T01:19:50.047Z",
      "modified": "2026-08-19T19:23:07.277Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.91737,
      "epss_percentile": 0.99816,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Exchange Server 2016 Cumulative Update 21",
        "Microsoft Exchange Server 2016 Cumulative Update 22",
        "Microsoft Exchange Server 2019 Cumulative Update 10",
        "Microsoft Exchange Server 2019 Cumulative Update 11"
      ],
      "cwes": [],
      "description": "Microsoft Exchange Server Remote Code Execution Vulnerability"
    },
    {
      "id": "CVE-2021-42292",
      "url": "https://spydr.io/cve/CVE-2021-42292",
      "published": "2021-11-10T01:19:47.007Z",
      "modified": "2026-08-19T19:23:04.123Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.43005,
      "epss_percentile": 0.9869,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft 365 Apps for Enterprise",
        "Microsoft Excel 2013 Service Pack 1",
        "Microsoft Excel 2016",
        "Microsoft Office 2013 Service Pack 1",
        "Microsoft Office 2016",
        "Microsoft Office 2019",
        "Microsoft Office 2019 for Mac",
        "Microsoft Office LTSC 2021",
        "Microsoft Office LTSC for Mac 2021"
      ],
      "cwes": [],
      "description": "Microsoft Excel Security Feature Bypass Vulnerability"
    },
    {
      "id": "CVE-2021-40449",
      "url": "https://spydr.io/cve/CVE-2021-40449",
      "published": "2021-10-13T01:15:09.703Z",
      "modified": "2026-06-17T04:06:56.427Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "microsoft.com",
      "epss": 0.74129,
      "epss_percentile": 0.99478,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows 10 Version 1809",
        "Microsoft Windows Server 2019",
        "Microsoft Windows Server 2019 (Server Core installation)",
        "Microsoft Windows 10 Version 1909",
        "Microsoft Windows 10 Version 21H1",
        "Microsoft Windows Server 2022",
        "Microsoft Windows 10 Version 2004",
        "Microsoft Windows Server version 2004",
        "Microsoft Windows 10 Version 20H2",
        "Microsoft Windows Server version 20H2",
        "Microsoft Windows 11 version 21H2",
        "Microsoft Windows 10 Version 1507",
        "Microsoft Windows 10 Version 1607",
        "Microsoft Windows Server 2016",
        "Microsoft Windows Server 2016 (Server Core installation)",
        "Microsoft Windows 7",
        "Microsoft Windows 7 Service Pack 1",
        "Microsoft Windows 8.1",
        "Microsoft Windows Server 2008 Service Pack 2",
        "Microsoft Windows Server 2008 Service Pack 2 (Server Core installation)"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Win32k Elevation of Privilege Vulnerability"
    },
    {
      "id": "CVE-2021-22204",
      "url": "https://spydr.io/cve/CVE-2021-22204",
      "published": "2021-04-23T18:15:08.127Z",
      "modified": "2026-06-17T03:36:47.890Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.99981,
      "epss_percentile": 0.99981,
      "exploited": true,
      "kev": {
        "added": "2021-11-17",
        "due": "2021-12-01",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "ExifTool"
      ],
      "products": [
        "ExifTool"
      ],
      "cwes": [
        "CWE-94"
      ],
      "description": "Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image"
    },
    {
      "id": "CVE-2021-38003",
      "url": "https://spydr.io/cve/CVE-2021-38003",
      "published": "2021-11-23T22:15:07.937Z",
      "modified": "2026-06-17T04:01:23.563Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.38573,
      "epss_percentile": 0.98546,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-755"
      ],
      "description": "Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2021-38000",
      "url": "https://spydr.io/cve/CVE-2021-38000",
      "published": "2021-11-23T22:15:07.807Z",
      "modified": "2026-06-17T04:01:23.103Z",
      "score": 6.1,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.04948,
      "epss_percentile": 0.9194,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome",
        "google android"
      ],
      "cwes": [
        "CWE-601",
        "CWE-20"
      ],
      "description": "Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page."
    },
    {
      "id": "CVE-2021-42258",
      "url": "https://spydr.io/cve/CVE-2021-42258",
      "published": "2021-10-22T22:15:07.907Z",
      "modified": "2026-06-17T04:09:31.510Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.74426,
      "epss_percentile": 0.99484,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "bqe"
      ],
      "products": [
        "bqe billquick web suite"
      ],
      "cwes": [
        "CWE-89"
      ],
      "description": "BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell."
    },
    {
      "id": "CVE-2021-30807",
      "url": "https://spydr.io/cve/CVE-2021-30807",
      "published": "2021-10-19T14:15:08.313Z",
      "modified": "2026-06-17T03:50:55.710Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.28839,
      "epss_percentile": 0.9811,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."
    },
    {
      "id": "CVE-2021-27561",
      "url": "https://spydr.io/cve/CVE-2021-27561",
      "published": "2021-10-15T18:15:07.490Z",
      "modified": "2026-06-17T03:45:08.230Z",
      "score": 9.8,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.82865,
      "epss_percentile": 0.99666,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "yealink"
      ],
      "products": [
        "yealink device management"
      ],
      "cwes": [
        "CWE-78"
      ],
      "description": "Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication."
    },
    {
      "id": "CVE-2021-37976",
      "url": "https://spydr.io/cve/CVE-2021-37976",
      "published": "2021-10-08T22:15:08.417Z",
      "modified": "2026-06-17T04:01:20.387Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.19901,
      "epss_percentile": 0.97367,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-862"
      ],
      "description": "Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page."
    },
    {
      "id": "CVE-2021-37975",
      "url": "https://spydr.io/cve/CVE-2021-37975",
      "published": "2021-10-08T22:15:08.373Z",
      "modified": "2026-06-17T04:01:20.160Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.34887,
      "epss_percentile": 0.98399,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
    },
    {
      "id": "CVE-2021-37973",
      "url": "https://spydr.io/cve/CVE-2021-37973",
      "published": "2021-10-08T22:15:08.287Z",
      "modified": "2026-06-17T04:01:19.780Z",
      "score": 9.6,
      "severity": "critical",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11735,
      "epss_percentile": 0.95976,
      "exploited": true,
      "kev": {
        "added": "2021-11-03",
        "due": "2021-11-17",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Google"
      ],
      "products": [
        "Google Chrome"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
