Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-5122 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-3113 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-2502 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-04
CVE-2015-0313 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2015-0311 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2014-9163 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-04
CVE-2022-23176 · CISA Known Exploited Vulnerabilities
Vendor: WatchGuard | Product: Firebox and XTM | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-42287 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Active Directory | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-42278 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Active Directory | Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-39793 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Pixel | Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-27852 · CISA Known Exploited Vulnerabilities
Vendor: Checkbox | Product: Checkbox Survey | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. | Required action: Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable. | Federal remediation due: 2022-05-02
CVE-2021-22600 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2020-2509 · CISA Known Exploited Vulnerabilities
Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-02
CVE-2021-3156 · CISA Known Exploited Vulnerabilities
Vendor: Sudo | Product: Sudo | Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2021-31166 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: HTTP Protocol Stack | Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2017-0148 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SMBv1 server | The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-27
CVE-2022-22965 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: Spring Framework | Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2022-22675 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.