Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2023-25717 · CISA Known Exploited Vulnerabilities

Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

Vendor: Ruckus Wireless | Product: Multiple Products | Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs. | Required action: Apply updates per…
Read full source summary
Vendor: Ruckus Wireless | Product: Multiple Products | Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs. | Required action: Apply updates per vendor instructions or disconnect product if it is end-of-life. | Federal remediation due: 2023-06-02
CVE-2021-3560 · CISA Known Exploited Vulnerabilities

Red Hat Polkit Incorrect Authorization Vulnerability

Vendor: Red Hat | Product: Polkit | Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-06-02
CVE-2014-0196 · CISA Known Exploited Vulnerabilities

Linux Kernel Race Condition Vulnerability

Vendor: Linux | Product: Kernel | Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2023-06-02
CVE-2010-3904 · CISA Known Exploited Vulnerabilities

Linux Kernel Improper Input Validation Vulnerability

Vendor: Linux | Product: Kernel | Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2023-06-02
CVE-2015-5317 · CISA Known Exploited Vulnerabilities

Jenkins User Interface (UI) Information Disclosure Vulnerability

Vendor: Jenkins | Product: Jenkins User Interface (UI) | Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-06-02
CVE-2016-3427 · CISA Known Exploited Vulnerabilities

Oracle Java SE and JRockit Unspecified Vulnerability

Vendor: Oracle | Product: Java SE and JRockit | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in…
Read full source summary
Vendor: Oracle | Product: Java SE and JRockit | Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-06-02
CVE-2016-8735 · CISA Known Exploited Vulnerabilities

Apache Tomcat Remote Code Execution Vulnerability

Vendor: Apache | Product: Tomcat | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. | Required action: Apply updates per…
Read full source summary
Vendor: Apache | Product: Tomcat | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-06-02
CVE-2023-29336 · CISA Known Exploited Vulnerabilities

Microsoft Win32K Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-30
CVE-2023-1389 · CISA Known Exploited Vulnerabilities

TP-Link Archer AX-21 Command Injection Vulnerability

Vendor: TP-Link | Product: Archer AX21 | TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-22
CVE-2021-45046 · CISA Known Exploited Vulnerabilities

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Vendor: Apache | Product: Log4j2 | Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-22
CVE-2023-21839 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server Unspecified Vulnerability

Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-22
CVE-2023-28432 · CISA Known Exploited Vulnerabilities

MinIO Information Disclosure Vulnerability

Vendor: MinIO | Product: MinIO | MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-12
CVE-2023-27350 · CISA Known Exploited Vulnerabilities

PaperCut MF/NG Improper Access Control Vulnerability

Vendor: PaperCut | Product: MF/NG | PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-12
CVE-2023-2136 · CISA Known Exploited Vulnerabilities

Google Chrome Skia Integer Overflow Vulnerability

Vendor: Google | Product: Chromium Skia | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium Skia | Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-12
CVE-2017-6742 · CISA Known Exploited Vulnerabilities

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco | Product: IOS and IOS XE Software | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-10
CVE-2019-8526 · CISA Known Exploited Vulnerabilities

Apple macOS Use-After-Free Vulnerability

Vendor: Apple | Product: macOS | Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-08
CVE-2023-2033 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-08
CVE-2023-20963 · CISA Known Exploited Vulnerabilities

Android Framework Privilege Escalation Vulnerability

Vendor: Android | Product: Framework | Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-04
CVE-2023-29492 · CISA Known Exploited Vulnerabilities

Novi Survey Insecure Deserialization Vulnerability

Vendor: Novi Survey | Product: Novi Survey | Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-04
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index