Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Perl | Product: Exiftool | Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-40449 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Unspecified vulnerability allows for an authenticated user to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-42321 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange | An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-42292 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-27104 · CISA Known Exploited Vulnerabilities
Vendor: Accellion | Product: FTA | Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27102 · CISA Known Exploited Vulnerabilities
Vendor: Accellion | Product: FTA | Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27101 · CISA Known Exploited Vulnerabilities
Vendor: Accellion | Product: FTA | Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27103 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-28550 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2018-4939 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-15961 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-03
CVE-2020-5735 · CISA Known Exploited Vulnerabilities
Vendor: Amcrest | Product: Cameras and Network Video Recorder (NVR) | Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-2215 · CISA Known Exploited Vulnerabilities
Vendor: Android | Product: Android Kernel | Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0041 · CISA Known Exploited Vulnerabilities
Vendor: Android | Product: Android Kernel | Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Android | Product: Android Kernel | Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0069 · CISA Known Exploited Vulnerabilities
Vendor: MediaTek | Product: Multiple Chipsets | Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." | Required action: Apply…
Read full source summary
Vendor: MediaTek | Product: Multiple Chipsets | Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-9805 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Struts | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-42013 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-41773 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. |…
Read full source summary
Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.