Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 23:23 UTCOfficial source · JSON
CVE-2012-1823 · CISA Known Exploited Vulnerabilities

PHP-CGI Query String Parameter Vulnerability

Vendor: PHP | Product: PHP | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-4345 · CISA Known Exploited Vulnerabilities

Exim Privilege Escalation Vulnerability

Vendor: Exim | Product: Exim | Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-4344 · CISA Known Exploited Vulnerabilities

Exim Heap-Based Buffer Overflow Vulnerability

Vendor: Exim | Product: Exim | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-3035 · CISA Known Exploited Vulnerabilities

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Vendor: Cisco | Product: IOS XR | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-2861 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Directory Traversal Vulnerability

Vendor: Adobe | Product: ColdFusion | A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-2055 · CISA Known Exploited Vulnerabilities

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Vendor: Cisco | Product: IOS XR | Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-1151 · CISA Known Exploited Vulnerabilities

phpMyAdmin Remote Code Execution Vulnerability

Vendor: phpMyAdmin | Product: phpMyAdmin | Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2009-0927 · CISA Known Exploited Vulnerabilities

Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2005-2773 · CISA Known Exploited Vulnerabilities

HP OpenView Network Node Manager Remote Code Execution Vulnerability

Vendor: Hewlett Packard (HP) | Product: OpenView Network Node Manager | HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2020-5135 · CISA Known Exploited Vulnerabilities

SonicWall SonicOS Buffer Overflow Vulnerability

Vendor: SonicWall | Product: SonicOS | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1322 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1315 · CISA Known Exploited Vulnerabilities

Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1253 · CISA Known Exploited Vulnerabilities

Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1132 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1129 · CISA Known Exploited Vulnerabilities

Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1069 · CISA Known Exploited Vulnerabilities

Microsoft Task Scheduler Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Task Scheduler | A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-1064 · CISA Known Exploited Vulnerabilities

Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-0841 · CISA Known Exploited Vulnerabilities

Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2019-0543 · CISA Known Exploited Vulnerabilities

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index