Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2022-41328 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS Path Traversal Vulnerability

Vendor: Fortinet | Product: FortiOS | Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-04
CVE-2021-39144 · CISA Known Exploited Vulnerabilities

XStream Remote Code Execution Vulnerability

Vendor: XStream | Product: XStream | XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: XStream | Product: XStream | XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-31
CVE-2020-5741 · CISA Known Exploited Vulnerabilities

Plex Media Server Remote Code Execution Vulnerability

Vendor: Plex | Product: Media Server | Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-31
CVE-2022-28810 · CISA Known Exploited Vulnerabilities

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Vendor: Zoho | Product: ManageEngine | Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-28
CVE-2022-33891 · CISA Known Exploited Vulnerabilities

Apache Spark Command Injection Vulnerability

Vendor: Apache | Product: Spark | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-28
CVE-2022-35914 · CISA Known Exploited Vulnerabilities

Teclib GLPI Remote Code Execution Vulnerability

Vendor: Teclib | Product: GLPI | Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-28
CVE-2022-36537 · CISA Known Exploited Vulnerabilities

ZK Framework AuUploader Unspecified Vulnerability

Vendor: ZK Framework | Product: AuUploader | ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. | Required action: Apply updates per…
Read full source summary
Vendor: ZK Framework | Product: AuUploader | ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-20
CVE-2022-47986 · CISA Known Exploited Vulnerabilities

IBM Aspera Faspex Code Execution Vulnerability

Vendor: IBM | Product: Aspera Faspex | IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-14
CVE-2022-41223 · CISA Known Exploited Vulnerabilities

Mitel MiVoice Connect Code Injection Vulnerability

Vendor: Mitel | Product: MiVoice Connect | The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-14
CVE-2022-40765 · CISA Known Exploited Vulnerabilities

Mitel MiVoice Connect Command Injection Vulnerability

Vendor: Mitel | Product: MiVoice Connect | The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-14
CVE-2022-46169 · CISA Known Exploited Vulnerabilities

Cacti Command Injection Vulnerability

Vendor: Cacti | Product: Cacti | Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-09
CVE-2023-21715 · CISA Known Exploited Vulnerabilities

Microsoft Office Publisher Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-07
CVE-2023-23529 · CISA Known Exploited Vulnerabilities

Apple Multiple Products WebKit Type Confusion Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Apple | Product: Multiple Products | Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-07
CVE-2023-21823 · CISA Known Exploited Vulnerabilities

Microsoft Windows Graphic Component Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-07
CVE-2015-2291 · CISA Known Exploited Vulnerabilities

Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

Vendor: Intel | Product: Ethernet Diagnostics Driver for Windows | Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-03
CVE-2022-24990 · CISA Known Exploited Vulnerabilities

TerraMaster OS Remote Command Execution Vulnerability

Vendor: TerraMaster | Product: TerraMaster OS | TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-03
CVE-2023-0669 · CISA Known Exploited Vulnerabilities

Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Vendor: Fortra | Product: GoAnywhere MFT | Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-03-03
CVE-2022-21587 · CISA Known Exploited Vulnerabilities

Oracle E-Business Suite Unspecified Vulnerability

Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-23
CVE-2023-22952 · CISA Known Exploited Vulnerabilities

Multiple SugarCRM Products Remote Code Execution Vulnerability

Vendor: SugarCRM | Product: Multiple Products | Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-23
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index