Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2017-11357 · CISA Known Exploited Vulnerabilities

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-16
CVE-2022-47966 · CISA Known Exploited Vulnerabilities

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Vendor: Zoho | Product: ManageEngine | Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-13
CVE-2022-44877 · CISA Known Exploited Vulnerabilities

CWP Control Web Panel OS Command Injection Vulnerability

Vendor: CWP | Product: Control Web Panel | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-07
CVE-2022-41080 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-31
CVE-2018-5430 · CISA Known Exploited Vulnerabilities

TIBCO JasperReports Server Information Disclosure Vulnerability

Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2018-18809 · CISA Known Exploited Vulnerabilities

TIBCO JasperReports Library Directory Traversal Vulnerability

Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2022-42856 · CISA Known Exploited Vulnerabilities

Apple iOS Type Confusion Vulnerability

Vendor: Apple | Product: iOS | Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-04
CVE-2022-42475 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Vendor: Fortinet | Product: FortiOS | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-44698 · CISA Known Exploited Vulnerabilities

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Defender | Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-27518 · CISA Known Exploited Vulnerabilities

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Vendor: Citrix | Product: Application Delivery Controller (ADC) and Gateway | Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26500 · CISA Known Exploited Vulnerabilities

Veeam Backup & Replication Remote Code Execution Vulnerability

Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26501 · CISA Known Exploited Vulnerabilities

Veeam Backup & Replication Remote Code Execution Vulnerability

Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-4262 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-26
CVE-2021-35587 · CISA Known Exploited Vulnerabilities

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle | Product: Fusion Middleware | Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-19
CVE-2022-4135 · CISA Known Exploited Vulnerabilities

Google Chromium GPU Heap Buffer Overflow Vulnerability

Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply…
Read full source summary
Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-19
CVE-2022-41049 · CISA Known Exploited Vulnerabilities

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41091 · CISA Known Exploited Vulnerabilities

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41073 · CISA Known Exploited Vulnerabilities

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41125 · CISA Known Exploited Vulnerabilities

Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index