Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2019-18935 · CISA Known Exploited Vulnerabilities

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Vendor: Progress | Product: Telerik UI for ASP.NET AJAX | Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-22893 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8243 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Code Execution Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-22900 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-22894 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8260 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Code Execution Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-22899 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Command Injection Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-11510 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure | Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-11539 · CISA Known Exploited Vulnerabilities

Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Vendor: Ivanti | Product: Pulse Connect Secure and Pulse Policy Secure | Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-1906 · CISA Known Exploited Vulnerabilities

Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

Vendor: Qualcomm | Product: Multiple Chipsets | Multiple Qualcomm chipsets contain a detection of error condition without action vulnerability when improper handling of address deregistration on failure can lead to new GPU address allocation failure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1905 · CISA Known Exploited Vulnerabilities

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Vendor: Qualcomm | Product: Multiple Chipsets | Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-10221 · CISA Known Exploited Vulnerabilities

rConfig OS Command Injection Vulnerability

Vendor: rConfig | Product: rConfig | rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-35395 · CISA Known Exploited Vulnerabilities

Realtek AP-Router SDK Buffer Overflow Vulnerability

Vendor: Realtek | Product: AP-Router SDK | Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2017-16651 · CISA Known Exploited Vulnerabilities

Roundcube Webmail File Disclosure Vulnerability

Vendor: Roundcube | Product: Roundcube Webmail | Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-11652 · CISA Known Exploited Vulnerabilities

SaltStack Salt Path Traversal Vulnerability

Vendor: SaltStack | Product: Salt | SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-11651 · CISA Known Exploited Vulnerabilities

SaltStack Salt Authentication Bypass Vulnerability

Vendor: SaltStack | Product: Salt | SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security…
Read full source summary
Vendor: SaltStack | Product: Salt | SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication, which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-16846 · CISA Known Exploited Vulnerabilities

SaltStack Salt Shell Injection Vulnerability

Vendor: SaltStack | Product: Salt | SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-2380 · CISA Known Exploited Vulnerabilities

SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

Vendor: SAP | Product: Customer Relationship Management (CRM) | SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2010-5326 · CISA Known Exploited Vulnerabilities

SAP NetWeaver Remote Code Execution Vulnerability

Vendor: SAP | Product: NetWeaver | SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-9563 · CISA Known Exploited Vulnerabilities

SAP NetWeaver XML External Entity (XXE) Vulnerability

Vendor: SAP | Product: NetWeaver | SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index