Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2010-0188 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Reader and Acrobat | Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2009-3129 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Excel | Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2009-1123 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2008-3431 · CISA Known Exploited Vulnerabilities
Vendor: Oracle | Product: VirtualBox | An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2008-2992 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2004-0210 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2002-0367 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2022-24682 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaborate Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-11
CVE-2017-8570 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2017-0222 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2014-6352 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2022-23131 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Commerce and Magento Open Source | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-01
CVE-2022-0609 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium Animation | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Google | Product: Chromium Animation | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-01
CVE-2019-0752 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2018-8174 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2018-20250 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-08-15
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.