Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2024-9379 · CISA Known Exploited Vulnerabilities

Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. | Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade…
Read full source summary
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements. | Required action: As Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution. | Federal remediation due: 2024-10-30
CVE-2024-23113 · CISA Known Exploited Vulnerabilities

Fortinet Multiple Products Format String Vulnerability

Vendor: Fortinet | Product: Multiple Products | Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-30
CVE-2024-43573 · CISA Known Exploited Vulnerabilities

Microsoft Windows MSHTML Platform Spoofing Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-29
CVE-2024-43572 · CISA Known Exploited Vulnerabilities

Microsoft Windows Management Console Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-29
CVE-2024-43047 · CISA Known Exploited Vulnerabilities

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Vendor: Qualcomm | Product: Multiple Chipsets | Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory. | Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. | Federal remediation due: 2024-10-29
CVE-2024-45519 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-24
CVE-2024-29824 · CISA Known Exploited Vulnerabilities

Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

Vendor: Ivanti | Product: Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-23
CVE-2019-0344 · CISA Known Exploited Vulnerabilities

SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

Vendor: SAP | Product: Commerce Cloud | SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-21
CVE-2020-15415 · CISA Known Exploited Vulnerabilities

DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

Vendor: DrayTek | Product: Multiple Vigor Routers | DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if…
Read full source summary
Vendor: DrayTek | Product: Multiple Vigor Routers | DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-21
CVE-2023-25280 · CISA Known Exploited Vulnerabilities

D-Link DIR-820 Router OS Command Injection Vulnerability

Vendor: D-Link | Product: DIR-820 Router | D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation…
Read full source summary
Vendor: D-Link | Product: DIR-820 Router | D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-21
CVE-2024-7593 · CISA Known Exploited Vulnerabilities

Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Vendor: Ivanti | Product: Virtual Traffic Manager | Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-15
CVE-2024-8963 · CISA Known Exploited Vulnerabilities

Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance. | Required action: As Ivanti CSA has…
Read full source summary
Vendor: Ivanti | Product: Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance. | Required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates. | Federal remediation due: 2024-10-10
CVE-2020-14644 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server Remote Code Execution Vulnerability

Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2022-21445 · CISA Known Exploited Vulnerabilities

Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Vendor: Oracle | Product: ADF Faces | Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2020-0618 · CISA Known Exploited Vulnerabilities

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Vendor: Microsoft | Product: SQL Server | Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Microsoft | Product: SQL Server | Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2024-27348 · CISA Known Exploited Vulnerabilities

Apache HugeGraph-Server Improper Access Control Vulnerability

Vendor: Apache | Product: HugeGraph-Server | Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-10-09
CVE-2014-0502 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Double Free Vulnerablity

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-08
CVE-2013-0648 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-08
CVE-2013-0643 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Incorrect Default Permissions Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-08
CVE-2014-0497 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Integer Underflow Vulnerablity

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2024-10-08
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index