Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 13:18 UTCOfficial source · JSON
CVE-2022-27925 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-01
CVE-2022-37042 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-01
CVE-2022-30333 · CISA Known Exploited Vulnerabilities

RARLAB UnRAR Directory Traversal Vulnerability

Vendor: RARLAB | Product: UnRAR | RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-30
CVE-2022-27924 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2022-26138 · CISA Known Exploited Vulnerabilities

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Vendor: Atlassian | Product: Confluence | Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-19
CVE-2022-26925 · CISA Known Exploited Vulnerabilities

Microsoft Windows LSA Spoofing Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. | Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch]. | Federal remediation due: 2022-07-22
CVE-2022-29499 · CISA Known Exploited Vulnerabilities

Mitel MiVoice Connect Data Validation Vulnerability

Vendor: Mitel | Product: MiVoice Connect | The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-30533 · CISA Known Exploited Vulnerabilities

Google Chromium PopupBlocker Security Bypass Vulnerability

Vendor: Google | Product: Chromium PopupBlocker | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Google | Product: Chromium PopupBlocker | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-4034 · CISA Known Exploited Vulnerabilities

Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

Vendor: Red Hat | Product: Polkit | The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-30983 · CISA Known Exploited Vulnerabilities

Apple iOS and iPadOS Buffer Overflow Vulnerability

Vendor: Apple | Product: iOS and iPadOS | Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-3837 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-9907 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2019-8605 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Use-After-Free Vulnerability

Vendor: Apple | Product: Multiple Products | A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2018-4344 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2022-30190 · CISA Known Exploited Vulnerabilities

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-05
CVE-2021-38163 · CISA Known Exploited Vulnerabilities

SAP NetWeaver Unrestricted File Upload Vulnerability

Vendor: SAP | Product: NetWeaver | SAP NetWeaver contains a vulnerability that allows unrestricted file upload. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-30
CVE-2016-2386 · CISA Known Exploited Vulnerabilities

SAP NetWeaver SQL Injection Vulnerability

Vendor: SAP | Product: NetWeaver | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-30
CVE-2016-2388 · CISA Known Exploited Vulnerabilities

SAP NetWeaver Information Disclosure Vulnerability

Vendor: SAP | Product: NetWeaver | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-30
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index