Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Microsoft | Product: Word | Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2013-3906 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Graphics Component | Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2022-22620 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-25
CVE-2021-36934 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-24
CVE-2020-0796 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SMBv3 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2018-1000861 · CISA Known Exploited Vulnerabilities
Vendor: Jenkins | Product: Jenkins Stapler Web Framework | A code execution vulnerability exists in the Stapler web framework used by Jenkins | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-9791 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Struts 1 | The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-8464 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-10271 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: WebLogic Server | Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-0263 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-0262 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | A remote code execution vulnerability exists in Microsoft Office. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-0145 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SMBv1 | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2017-0144 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SMBv1 | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2016-3088 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: ActiveMQ | The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2015-2051 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DIR-645 Router | D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-08-10
CVE-2015-1635 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: HTTP.sys | Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2015-1130 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: OS X | The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2014-4404 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: OS X | Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2022-21882 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-18
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.