AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-36537

HIGH · CVSS 7.5 EPSS 95.34% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-08-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Known

Added to KEV: 2023-02-27

Required action: Apply updates per vendor instructions.

CVE
CVE-2022-36537
Severity
HIGH
CVSS
7.5
EPSS
95.34%

Original NVD Description

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.