Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2021-22991 · CISA Known Exploited Vulnerabilities

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

Vendor: F5 | Product: BIG-IP Traffic Management Microkernel | The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2020-14864 · CISA Known Exploited Vulnerabilities

Oracle Business Intelligence Enterprise Edition Path Transversal

Vendor: Oracle | Product: Intelligence Enterprise Edition | Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13671 · CISA Known Exploited Vulnerabilities

Drupal core Un-restricted Upload of File

Vendor: Drupal | Product: Drupal core | Improper sanitization in the extension file names is present in Drupal core. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-11978 · CISA Known Exploited Vulnerabilities

Apache Airflow Command Injection

Vendor: Apache | Product: Airflow | A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13927 · CISA Known Exploited Vulnerabilities

Apache Airflow's Experimental API Authentication Bypass

Vendor: Apache | Product: Airflow's Experimental API | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-22017 · CISA Known Exploited Vulnerabilities

VMware vCenter Server Improper Access Control

Vendor: VMware | Product: vCenter Server | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2021-36260 · CISA Known Exploited Vulnerabilities

Hikvision Improper Input Validation

Vendor: Hikvision | Product: Security cameras web server | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2020-6572 · CISA Known Exploited Vulnerabilities

Google Chrome Media Use-After-Free Vulnerability

Vendor: Google | Product: Chrome Media | Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1458 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2013-3900 · CISA Known Exploited Vulnerabilities

Microsoft WinVerifyTrust function Remote Code Execution

Vendor: Microsoft | Product: WinVerifyTrust function | A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-2725 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server, Injection

Vendor: Oracle | Product: WebLogic Server | Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13382 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS and FortiProxy Improper Authorization

Vendor: Fortinet | Product: FortiOS and FortiProxy | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13383 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS and FortiProxy Out-of-bounds Write

Vendor: Fortinet | Product: FortiOS and FortiProxy | A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1579 · CISA Known Exploited Vulnerabilities

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Vendor: Palo Alto Networks | Product: PAN-OS | Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-10149 · CISA Known Exploited Vulnerabilities

Exim Mail Transfer Agent (MTA) Improper Input Validation

Vendor: Exim | Product: Mail Transfer Agent (MTA) | Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2015-7450 · CISA Known Exploited Vulnerabilities

IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

Vendor: IBM | Product: WebSphere Application Server and Server Hypervisor Edition | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2017-1000486 · CISA Known Exploited Vulnerabilities

Primetek Primefaces Remote Code Execution Vulnerability

Vendor: Primetek | Product: Primefaces Application | Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-7609 · CISA Known Exploited Vulnerabilities

Kibana Arbitrary Code Execution

Vendor: Elastic | Product: Kibana | Kibana contain an arbitrary code execution flaw in the Timelion visualizer. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2021-27860 · CISA Known Exploited Vulnerabilities

FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

Vendor: FatPipe | Product: WARP, IPVPN, and MPVPN software | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index