Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 10:12 UTCOfficial source · JSON
CVE-2022-21587 · CISA Known Exploited Vulnerabilities

Oracle E-Business Suite Unspecified Vulnerability

Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-23
CVE-2023-22952 · CISA Known Exploited Vulnerabilities

Multiple SugarCRM Products Remote Code Execution Vulnerability

Vendor: SugarCRM | Product: Multiple Products | Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially crafted request, custom PHP code can be injected through the EmailTemplates. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-23
CVE-2017-11357 · CISA Known Exploited Vulnerabilities

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-16
CVE-2022-47966 · CISA Known Exploited Vulnerabilities

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Vendor: Zoho | Product: ManageEngine | Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-13
CVE-2022-44877 · CISA Known Exploited Vulnerabilities

CWP Control Web Panel OS Command Injection Vulnerability

Vendor: CWP | Product: Control Web Panel | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-07
CVE-2022-41080 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-31
CVE-2018-5430 · CISA Known Exploited Vulnerabilities

TIBCO JasperReports Server Information Disclosure Vulnerability

Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2018-18809 · CISA Known Exploited Vulnerabilities

TIBCO JasperReports Library Directory Traversal Vulnerability

Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2022-42856 · CISA Known Exploited Vulnerabilities

Apple iOS Type Confusion Vulnerability

Vendor: Apple | Product: iOS | Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-04
CVE-2022-42475 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability

Vendor: Fortinet | Product: FortiOS | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-44698 · CISA Known Exploited Vulnerabilities

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Defender | Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-27518 · CISA Known Exploited Vulnerabilities

Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability

Vendor: Citrix | Product: Application Delivery Controller (ADC) and Gateway | Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26500 · CISA Known Exploited Vulnerabilities

Veeam Backup & Replication Remote Code Execution Vulnerability

Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26501 · CISA Known Exploited Vulnerabilities

Veeam Backup & Replication Remote Code Execution Vulnerability

Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-4262 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-26
CVE-2021-35587 · CISA Known Exploited Vulnerabilities

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle | Product: Fusion Middleware | Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-19
CVE-2022-4135 · CISA Known Exploited Vulnerabilities

Google Chromium GPU Heap Buffer Overflow Vulnerability

Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply…
Read full source summary
Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-19
CVE-2022-41049 · CISA Known Exploited Vulnerabilities

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41091 · CISA Known Exploited Vulnerabilities

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index