Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action:…
Read full source summary
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30666 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation…
Read full source summary
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30713 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: macOS | Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30657 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: macOS | Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30665 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates…
Read full source summary
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30663 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates…
Read full source summary
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30761 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation…
Read full source summary
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-30869 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-9859 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-20090 · CISA Known Exploited Vulnerabilities
Vendor: Arcadyan | Product: Buffalo Firmware | Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27562 · CISA Known Exploited Vulnerabilities
Vendor: Arm | Product: Trusted Firmware | Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Arm | Product: Trusted Firmware | Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-28664 · CISA Known Exploited Vulnerabilities
Vendor: Arm | Product: Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-28663 · CISA Known Exploited Vulnerabilities
Vendor: Arm | Product: Mali Graphics Processing Unit (GPU) | Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-3398 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Confluence Server and Data Center | Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-26084 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Confluence Server and Data Center | Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-11580 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Crowd and Crowd Data Center | Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-3396 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Confluence Server and Data Server | Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-42258 · CISA Known Exploited Vulnerabilities
Vendor: BQE | Product: BillQuick Web Suite | BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-3452 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A…
Read full source summary
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3580 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive…
Read full source summary
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.