Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 22:37 UTCOfficial source · JSON
CVE-2017-0146 · CISA Known Exploited Vulnerabilities

Microsoft Windows SMB Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-7892 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-4171 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Remote Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-1555 · CISA Known Exploited Vulnerabilities

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Vendor: NETGEAR | Product: Wireless Access Point (WAP) Devices | Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-11021 · CISA Known Exploited Vulnerabilities

D-Link DCS-930L Devices OS Command Injection Vulnerability

Vendor: D-Link | Product: DCS-930L Devices | setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-10174 · CISA Known Exploited Vulnerabilities

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

Vendor: NETGEAR | Product: WNR2000v5 Router | The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-0752 · CISA Known Exploited Vulnerabilities

Ruby on Rails Directory Traversal Vulnerability

Vendor: Rails | Product: Ruby on Rails | Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-4068 · CISA Known Exploited Vulnerabilities

Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Vendor: Arcserve | Product: Unified Data Protection (UDP) | Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-3035 · CISA Known Exploited Vulnerabilities

TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Vendor: TP-Link | Product: Multiple Archer Devices | Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-1427 · CISA Known Exploited Vulnerabilities

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

Vendor: Elastic | Product: Elasticsearch | The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-1187 · CISA Known Exploited Vulnerabilities

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

Vendor: D-Link and TRENDnet | Product: Multiple Devices | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2015-0666 · CISA Known Exploited Vulnerabilities

Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

Vendor: Cisco | Product: Prime Data Center Network Manager (DCNM) | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6324 · CISA Known Exploited Vulnerabilities

Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Kerberos Key Distribution Center (KDC) | The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6287 · CISA Known Exploited Vulnerabilities

Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

Vendor: Rejetto | Product: HTTP File Server (HFS) | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-3120 · CISA Known Exploited Vulnerabilities

Elasticsearch Remote Code Execution Vulnerability

Vendor: Elastic | Product: Elasticsearch | Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-0130 · CISA Known Exploited Vulnerabilities

Ruby on Rails Directory Traversal Vulnerability

Vendor: Rails | Product: Ruby on Rails | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-5223 · CISA Known Exploited Vulnerabilities

D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

Vendor: D-Link | Product: DSL-2760U | A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-4810 · CISA Known Exploited Vulnerabilities

HP Multiple Products Remote Code Execution Vulnerability

Vendor: Hewlett Packard (HP) | Product: ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Hewlett Packard (HP) | Product: ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-2251 · CISA Known Exploited Vulnerabilities

Apache Struts Improper Input Validation Vulnerability

Vendor: Apache | Product: Struts | Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index