Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2010-0232 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Exception Handler Vulnerability

Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2010-0188 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2009-3129 · CISA Known Exploited Vulnerabilities

Microsoft Excel Featheader Record Memory Corruption Vulnerability

Vendor: Microsoft | Product: Excel | Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2009-1123 · CISA Known Exploited Vulnerabilities

Microsoft Windows Improper Input Validation Vulnerability

Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2008-3431 · CISA Known Exploited Vulnerabilities

Oracle VirtualBox Insufficient Input Validation Vulnerability

Vendor: Oracle | Product: VirtualBox | An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2008-2992 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Input Validation Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2004-0210 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2002-0367 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2022-24682 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

Vendor: Synacor | Product: Zimbra Collaborate Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-11
CVE-2017-8570 · CISA Known Exploited Vulnerabilities

Microsoft Office Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Office | A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2017-0222 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Internet Explorer | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2014-6352 · CISA Known Exploited Vulnerabilities

Microsoft Windows Code Injection Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2022-23131 · CISA Known Exploited Vulnerabilities

Zabbix Frontend Authentication Bypass Vulnerability

Vendor: Zabbix | Product: Frontend | Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-08
CVE-2022-23134 · CISA Known Exploited Vulnerabilities

Zabbix Frontend Improper Access Control Vulnerability

Vendor: Zabbix | Product: Frontend | Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-08
CVE-2022-24086 · CISA Known Exploited Vulnerabilities

Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

Vendor: Adobe | Product: Commerce and Magento Open Source | Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-01
CVE-2022-0609 · CISA Known Exploited Vulnerabilities

Google Chromium Animation Use-After-Free Vulnerability

Vendor: Google | Product: Chromium Animation | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Google | Product: Chromium Animation | Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-01
CVE-2019-0752 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Type Confusion Vulnerability

Vendor: Microsoft | Product: Internet Explorer | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2018-8174 · CISA Known Exploited Vulnerabilities

Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution" | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2018-20250 · CISA Known Exploited Vulnerabilities

WinRAR Absolute Path Traversal Vulnerability

Vendor: RARLAB | Product: WinRAR | WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-15
CVE-2018-15982 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-08-15
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index