Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2016-0162 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft | Product: Internet Explorer | An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-3351 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

Vendor: Microsoft | Product: Internet Explorer and Edge | An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-4655 · CISA Known Exploited Vulnerabilities

Apple iOS Information Disclosure Vulnerability

Vendor: Apple | Product: iOS | The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-4656 · CISA Known Exploited Vulnerabilities

Apple iOS Memory Corruption Vulnerability

Vendor: Apple | Product: iOS | A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-4657 · CISA Known Exploited Vulnerabilities

Apple iOS Webkit Memory Corruption Vulnerability

Vendor: Apple | Product: iOS | Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-6366 · CISA Known Exploited Vulnerabilities

Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

Vendor: Cisco | Product: Adaptive Security Appliance (ASA) | A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-6367 · CISA Known Exploited Vulnerabilities

Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

Vendor: Cisco | Product: Adaptive Security Appliance (ASA) | A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2016-3298 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

Vendor: Microsoft | Product: Internet Explorer | An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2022-20821 · CISA Known Exploited Vulnerabilities

Cisco IOS XR Open Port Vulnerability

Vendor: Cisco | Product: IOS XR | Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2021-1048 · CISA Known Exploited Vulnerabilities

Android Kernel Use-After-Free Vulnerability

Vendor: Android | Product: Kernel | Android kernel contains a use-after-free vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2021-0920 · CISA Known Exploited Vulnerabilities

Android Kernel Race Condition Vulnerability

Vendor: Android | Product: Kernel | Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2021-30883 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2020-1027 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2020-0638 · CISA Known Exploited Vulnerabilities

Microsoft Update Notification Manager Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Update Notification Manager | Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-7286 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-7287 · CISA Known Exploited Vulnerabilities

Apple iOS Memory Corruption Vulnerability

Vendor: Apple | Product: iOS | Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-0676 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft | Product: Internet Explorer | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-5786 · CISA Known Exploited Vulnerabilities

Google Chrome Blink Use-After-Free Vulnerability

Vendor: Google | Product: Chrome Blink | Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-0703 · CISA Known Exploited Vulnerabilities

Microsoft Windows SMB Information Disclosure Vulnerability

Vendor: Microsoft | Product: Windows | An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-0880 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index