Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2022-22674 · CISA Known Exploited Vulnerabilities

Apple macOS Out-of-Bounds Read Vulnerability

Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2021-45382 · CISA Known Exploited Vulnerabilities

D-Link Multiple Routers Remote Code Execution Vulnerability

Vendor: D-Link | Product: Multiple Routers | A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-25
CVE-2022-26871 · CISA Known Exploited Vulnerabilities

Trend Micro Apex Central Arbitrary File Upload Vulnerability

Vendor: Trend Micro | Product: Apex Central | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2022-1040 · CISA Known Exploited Vulnerabilities

Sophos Firewall Authentication Bypass Vulnerability

Vendor: Sophos | Product: Firewall | An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-34484 · CISA Known Exploited Vulnerabilities

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-28799 · CISA Known Exploited Vulnerabilities

QNAP NAS Improper Authorization Vulnerability

Vendor: QNAP | Product: Network Attached Storage (NAS) | QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-21551 · CISA Known Exploited Vulnerabilities

Dell dbutil Driver Insufficient Access Control Vulnerability

Vendor: Dell | Product: dbutil Driver | Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2018-10562 · CISA Known Exploited Vulnerabilities

Dasan GPON Routers Command Injection Vulnerability

Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2018-10561 · CISA Known Exploited Vulnerabilities

Dasan GPON Routers Authentication Bypass Vulnerability

Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2022-1096 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2022-0543 · CISA Known Exploited Vulnerabilities

Debian-specific Redis Server Lua Sandbox Escape Vulnerability

Vendor: Redis | Product: Debian-specific Redis Servers | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-38646 · CISA Known Exploited Vulnerabilities

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-34486 · CISA Known Exploited Vulnerabilities

Microsoft Windows Event Tracing Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-26085 · CISA Known Exploited Vulnerabilities

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Vendor: Atlassian | Product: Confluence Server | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-20028 · CISA Known Exploited Vulnerabilities

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

Vendor: SonicWall | Product: Secure Remote Access (SRA) | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-18
CVE-2019-7483 · CISA Known Exploited Vulnerabilities

SonicWall SMA100 Directory Traversal Vulnerability

Vendor: SonicWall | Product: SMA100 | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8440 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8406 · CISA Known Exploited Vulnerabilities

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8405 · CISA Known Exploited Vulnerabilities

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2017-0213 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index