Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 19:54 UTCOfficial source · JSON
CVE-2022-22965 · CISA Known Exploited Vulnerabilities

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Vendor: VMware | Product: Spring Framework | Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2022-22675 · CISA Known Exploited Vulnerabilities

Apple macOS Out-of-Bounds Write Vulnerability

Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2022-22674 · CISA Known Exploited Vulnerabilities

Apple macOS Out-of-Bounds Read Vulnerability

Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2021-45382 · CISA Known Exploited Vulnerabilities

D-Link Multiple Routers Remote Code Execution Vulnerability

Vendor: D-Link | Product: Multiple Routers | A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-25
CVE-2022-26871 · CISA Known Exploited Vulnerabilities

Trend Micro Apex Central Arbitrary File Upload Vulnerability

Vendor: Trend Micro | Product: Apex Central | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2022-1040 · CISA Known Exploited Vulnerabilities

Sophos Firewall Authentication Bypass Vulnerability

Vendor: Sophos | Product: Firewall | An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-34484 · CISA Known Exploited Vulnerabilities

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-28799 · CISA Known Exploited Vulnerabilities

QNAP NAS Improper Authorization Vulnerability

Vendor: QNAP | Product: Network Attached Storage (NAS) | QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-21551 · CISA Known Exploited Vulnerabilities

Dell dbutil Driver Insufficient Access Control Vulnerability

Vendor: Dell | Product: dbutil Driver | Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2018-10562 · CISA Known Exploited Vulnerabilities

Dasan GPON Routers Command Injection Vulnerability

Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2018-10561 · CISA Known Exploited Vulnerabilities

Dasan GPON Routers Authentication Bypass Vulnerability

Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2022-1096 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2022-0543 · CISA Known Exploited Vulnerabilities

Debian-specific Redis Server Lua Sandbox Escape Vulnerability

Vendor: Redis | Product: Debian-specific Redis Servers | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-38646 · CISA Known Exploited Vulnerabilities

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-34486 · CISA Known Exploited Vulnerabilities

Microsoft Windows Event Tracing Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-26085 · CISA Known Exploited Vulnerabilities

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Vendor: Atlassian | Product: Confluence Server | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-20028 · CISA Known Exploited Vulnerabilities

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

Vendor: SonicWall | Product: Secure Remote Access (SRA) | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-18
CVE-2019-7483 · CISA Known Exploited Vulnerabilities

SonicWall SMA100 Directory Traversal Vulnerability

Vendor: SonicWall | Product: SMA100 | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8440 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8406 · CISA Known Exploited Vulnerabilities

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index