Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Apache | Product: HTTP Server | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Apache | Product: HTTP Server | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-4437 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Shiro | Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-17558 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Solr | The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-17530 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Struts | Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-5638 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Struts | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-11776 · CISA Known Exploited Vulnerabilities
Vendor: Apache | Product: Struts | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same…
Read full source summary
Vendor: Apache | Product: Struts | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30858 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-6223 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS and macOS | Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30860 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-27930 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30807 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-27950 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-27932 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-9818 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-9819 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30762 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1782 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1870 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1871 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1879 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action:…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.