Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: F5 | Product: BIG-IP Traffic Management Microkernel | The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2020-14864 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: Intelligence Enterprise Edition | Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13671 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Airflow | A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13927 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Airflow's Experimental API | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-22017 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: vCenter Server | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2021-36260 · CISA Known Exploited Vulnerabilities
Vendor: Hikvision | Product: Security cameras web server | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2020-6572 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chrome Media | Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1458 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2013-3900 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: WinVerifyTrust function | A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-2725 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: WebLogic Server | Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-9670 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13382 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS and FortiProxy | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13383 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS and FortiProxy | A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1579 · CISA Known Exploited Vulnerabilities
Vendor: Exim | Product: Mail Transfer Agent (MTA) | Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2015-7450 · CISA Known Exploited Vulnerabilities
Vendor: IBM | Product: WebSphere Application Server and Server Hypervisor Edition | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2017-1000486 · CISA Known Exploited Vulnerabilities
Vendor: FatPipe | Product: WARP, IPVPN, and MPVPN software | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.