Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2015-0310 · CISA Known Exploited Vulnerabilities

Adobe Flash Player ASLR Bypass Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2015-0016 · CISA Known Exploited Vulnerabilities

Microsoft Windows TS WebProxy Directory Traversal Vulnerability

Vendor: Microsoft | Product: Windows | Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-0071 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer ASLR Bypass Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-2360 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-2425 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-1769 · CISA Known Exploited Vulnerabilities

Microsoft Windows Mount Manager Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-4495 · CISA Known Exploited Vulnerabilities

Mozilla Firefox Security Feature Bypass Vulnerability

Vendor: Mozilla | Product: Firefox | Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-8651 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Integer Overflow Vulnerability

Vendor: Adobe | Product: Flash Player | Integer overflow in Adobe Flash Player allows attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2015-6175 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2015-1671 · CISA Known Exploited Vulnerabilities

Microsoft Windows Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-4148 · CISA Known Exploited Vulnerabilities

Microsoft Windows Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-8439 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Dereferenced Pointer Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2014-4123 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-0546 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Sandbox Bypass Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-2817 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-4077 · CISA Known Exploited Vulnerabilities

Microsoft IME Japanese Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Input Method Editor (IME) Japanese | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege…
Read full source summary
Vendor: Microsoft | Product: Input Method Editor (IME) Japanese | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2014-3153 · CISA Known Exploited Vulnerabilities

Linux Kernel Privilege Escalation Vulnerability

Vendor: Linux | Product: Kernel | The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-7331 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft | Product: Internet Explorer | An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-3993 · CISA Known Exploited Vulnerabilities

IBM InfoSphere BigInsights Invalid Input Vulnerability

Vendor: IBM | Product: InfoSphere BigInsights | Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2013-3896 · CISA Known Exploited Vulnerabilities

Microsoft Silverlight Information Disclosure Vulnerability

Vendor: Microsoft | Product: Silverlight | Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index