Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2020-1147 · CISA Known Exploited Vulnerabilities

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Vendor: Microsoft | Product: .NET Framework, SharePoint, Visual Studio | Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. | Required action:…
Read full source summary
Vendor: Microsoft | Product: .NET Framework, SharePoint, Visual Studio | Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-1214 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-3235 · CISA Known Exploited Vulnerabilities

Microsoft Office OLE DLL Side Loading Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-0863 · CISA Known Exploited Vulnerabilities

Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-38648 · CISA Known Exploited Vulnerabilities

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-6819 · CISA Known Exploited Vulnerabilities

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-6820 · CISA Known Exploited Vulnerabilities

Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-17026 · CISA Known Exploited Vulnerabilities

Mozilla Firefox And Thunderbird Type Confusion Vulnerability

Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-15949 · CISA Known Exploited Vulnerabilities

Nagios XI Remote Code Execution Vulnerability

Vendor: Nagios | Product: Nagios XI | Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-19356 · CISA Known Exploited Vulnerabilities

Netis WF2419 Devices Remote Code Execution Vulnerability

Vendor: Netis | Product: WF2419 Devices | Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-2555 · CISA Known Exploited Vulnerabilities

Oracle Multiple Products Remote Code Execution Vulnerability

Vendor: Oracle | Product: Multiple Products | Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router…
Read full source summary
Vendor: Oracle | Product: Multiple Products | Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system. Impacted Oracle products: Oracle Coherence in Fusion Middleware, Oracle Utilities Framework, Oracle Retail Assortment Planning, Oracle Commerce, Oracle Communications Diameter Signaling Router (DSR). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2012-3152 · CISA Known Exploited Vulnerabilities

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle | Product: Fusion Middleware | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-14871 · CISA Known Exploited Vulnerabilities

Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability

Vendor: Oracle | Product: Solaris and Zettabyte File System (ZFS) | Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2015-4852 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability

Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-14750 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server Remote Code Execution Vulnerability

Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-14882 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server Remote Code Execution Vulnerability

Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-14883 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server Unspecified Vulnerability

Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8644 · CISA Known Exploited Vulnerabilities

PlaySMS Server-Side Template Injection Vulnerability

Vendor: PlaySMS | Product: PlaySMS | PlaySMS contains a server-side template injection vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index