Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2015-5123 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-5122 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-3113 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Vendor: Adobe | Product: Flash Player | Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-2502 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-04
CVE-2015-0313 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-0311 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Remote Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2014-9163 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

Vendor: Adobe | Product: Flash Player | Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2022-23176 · CISA Known Exploited Vulnerabilities

WatchGuard Firebox and XTM Privilege Escalation Vulnerability

Vendor: WatchGuard | Product: Firebox and XTM | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-42287 · CISA Known Exploited Vulnerabilities

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Active Directory | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-42278 · CISA Known Exploited Vulnerabilities

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Active Directory | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-39793 · CISA Known Exploited Vulnerabilities

Google Pixel Out-of-Bounds Write Vulnerability

Vendor: Google | Product: Pixel | Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-27852 · CISA Known Exploited Vulnerabilities

Checkbox Survey Deserialization of Untrusted Data Vulnerability

Vendor: Checkbox | Product: Checkbox Survey | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. | Required action: Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable. | Federal remediation due: 2022-05-02
CVE-2021-22600 · CISA Known Exploited Vulnerabilities

Linux Kernel Privilege Escalation Vulnerability

Vendor: Linux | Product: Kernel | Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2020-2509 · CISA Known Exploited Vulnerabilities

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

Vendor: QNAP | Product: QNAP Network-Attached Storage (NAS) | QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2017-11317 · CISA Known Exploited Vulnerabilities

Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-3156 · CISA Known Exploited Vulnerabilities

Sudo Heap-Based Buffer Overflow Vulnerability

Vendor: Sudo | Product: Sudo | Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2021-31166 · CISA Known Exploited Vulnerabilities

Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

Vendor: Microsoft | Product: HTTP Protocol Stack | Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2017-0148 · CISA Known Exploited Vulnerabilities

Microsoft SMBv1 Server Remote Code Execution Vulnerability

Vendor: Microsoft | Product: SMBv1 server | The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2022-22965 · CISA Known Exploited Vulnerabilities

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Vendor: VMware | Product: Spring Framework | Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2022-22675 · CISA Known Exploited Vulnerabilities

Apple macOS Out-of-Bounds Write Vulnerability

Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index