Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 05:48 UTCOfficial source · JSON
CVE-2023-4863 · CISA Known Exploited Vulnerabilities

Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

Vendor: Google | Product: Chromium WebP | Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Google | Product: Chromium WebP | Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-04
CVE-2023-36761 · CISA Known Exploited Vulnerabilities

Microsoft Word Information Disclosure Vulnerability

Vendor: Microsoft | Product: Word | Microsoft Word contains an unspecified vulnerability that allows for information disclosure. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-03
CVE-2023-36802 · CISA Known Exploited Vulnerabilities

Microsoft Streaming Service Proxy Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Streaming Service Proxy | Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-03
CVE-2023-41064 · CISA Known Exploited Vulnerabilities

Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-02
CVE-2023-41061 · CISA Known Exploited Vulnerabilities

Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-02
CVE-2023-33246 · CISA Known Exploited Vulnerabilities

Apache RocketMQ Command Execution Vulnerability

Vendor: Apache | Product: RocketMQ | Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. | Required…
Read full source summary
Vendor: Apache | Product: RocketMQ | Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-27
CVE-2023-38831 · CISA Known Exploited Vulnerabilities

RARLAB WinRAR Code Execution Vulnerability

Vendor: RARLAB | Product: WinRAR | RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-14
CVE-2023-32315 · CISA Known Exploited Vulnerabilities

Ignite Realtime Openfire Path Traversal Vulnerability

Vendor: Ignite Realtime | Product: Openfire | Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-14
CVE-2023-38035 · CISA Known Exploited Vulnerabilities

Ivanti Sentry Authentication Bypass Vulnerability

Vendor: Ivanti | Product: Sentry | Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.…
Read full source summary
Vendor: Ivanti | Product: Sentry | Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-12
CVE-2023-27532 · CISA Known Exploited Vulnerabilities

Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

Vendor: Veeam | Product: Backup & Replication | Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. |…
Read full source summary
Vendor: Veeam | Product: Backup & Replication | Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-12
CVE-2023-26359 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-11
CVE-2023-24489 · CISA Known Exploited Vulnerabilities

Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Vendor: Citrix | Product: Content Collaboration | Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-09-06
CVE-2023-38180 · CISA Known Exploited Vulnerabilities

Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability

Vendor: Microsoft | Product: .NET Core and Visual Studio | Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-30
CVE-2017-18368 · CISA Known Exploited Vulnerabilities

Zyxel P660HN-T1A Routers Command Injection Vulnerability

Vendor: Zyxel | Product: P660HN-T1A Routers | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Zyxel | Product: P660HN-T1A Routers | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-28
CVE-2023-35081 · CISA Known Exploited Vulnerabilities

Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable). | Required action: Apply mitigations per vendor…
Read full source summary
Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable). | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-21
CVE-2023-37580 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-17
CVE-2023-38606 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Kernel Unspecified Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-16
CVE-2023-35078 · CISA Known Exploited Vulnerabilities

Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a…
Read full source summary
Vendor: Ivanti | Product: Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-15
CVE-2023-29298 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Improper Access Control Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-10
CVE-2023-38205 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Improper Access Control Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-08-10
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index