Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Exim | Product: Exim | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-3035 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: IOS XR | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-2861 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: ColdFusion | A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-2055 · CISA Known Exploited Vulnerabilities
Vendor: phpMyAdmin | Product: phpMyAdmin | Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-0927 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SonicOS | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1405 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1322 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1315 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1253 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1132 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1129 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1069 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Task Scheduler | A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1064 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-0841 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-0543 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2018-8120 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2017-0101 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.