Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Apple | Product: iOS and macOS | Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-11
CVE-2021-20038 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SMA 100 Appliances | SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-11
CVE-2020-5722 · CISA Known Exploited Vulnerabilities
Vendor: Grandstream | Product: UCM6200 | Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2020-0787 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2017-5689 · CISA Known Exploited Vulnerabilities
Vendor: Intel | Product: Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability | Intel products contain a vulnerability which can allow attackers to perform privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2014-1776 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2014-6271 · CISA Known Exploited Vulnerabilities
Vendor: GNU | Product: Bourne-Again Shell (Bash) | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2014-7169 · CISA Known Exploited Vulnerabilities
Vendor: GNU | Product: Bourne-Again Shell (Bash) | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2006-1547 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Struts 1 | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-21
CVE-2012-0391 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-21
CVE-2021-35247 · CISA Known Exploited Vulnerabilities
Vendor: October CMS | Product: October CMS | In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-25296 · CISA Known Exploited Vulnerabilities
Vendor: Nagios | Product: Nagios XI | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-25297 · CISA Known Exploited Vulnerabilities
Vendor: Nagios | Product: Nagios XI | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-25298 · CISA Known Exploited Vulnerabilities
Vendor: Nagios | Product: Nagios XI | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-40870 · CISA Known Exploited Vulnerabilities
Vendor: Aviatrix | Product: Aviatrix Controller | Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-33766 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-21975 · CISA Known Exploited Vulnerabilities
Vendor: VMware | Product: vRealize Operations Manager API | Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-21315 · CISA Known Exploited Vulnerabilities
Vendor: Npm package | Product: System Information Library for Node.JS | In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.