Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 20:35 UTCOfficial source · JSON
CVE-2018-8405 · CISA Known Exploited Vulnerabilities

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2017-0213 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2017-0059 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2017-0037 · CISA Known Exploited Vulnerabilities

Microsoft Edge and Internet Explorer Type Confusion Vulnerability

Vendor: Microsoft | Product: Edge and Internet Explorer | Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2016-7201 · CISA Known Exploited Vulnerabilities

Microsoft Edge Memory Corruption Vulnerability

Vendor: Microsoft | Product: Edge | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2016-7200 · CISA Known Exploited Vulnerabilities

Microsoft Edge Memory Corruption Vulnerability

Vendor: Microsoft | Product: Edge | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2016-0189 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Internet Explorer | The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2016-0151 · CISA Known Exploited Vulnerabilities

Microsoft Windows CSRSS Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Client-Server Run-time Subsystem (CSRSS) | The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2016-0040 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | The kernel in Microsoft Windows allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2015-2426 · CISA Known Exploited Vulnerabilities

Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2015-2419 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Internet Explorer | JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2015-1770 · CISA Known Exploited Vulnerabilities

Microsoft Office Uninitialized Memory Use Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2013-3660 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2013-2729 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2013-2551 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Use-After-Free Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2013-2465 · CISA Known Exploited Vulnerabilities

Oracle Java SE Unspecified Vulnerability

Vendor: Oracle | Product: Java SE | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2013-1690 · CISA Known Exploited Vulnerabilities

Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2012-5076 · CISA Known Exploited Vulnerabilities

Oracle Java SE Sandbox Bypass Vulnerability

Vendor: Oracle | Product: Java SE | The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2012-2539 · CISA Known Exploited Vulnerabilities

Microsoft Word Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Word | Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2012-2034 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Memory Corruption Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-18
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index