Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 00:56 UTCOfficial source · JSON
CVE-2021-41379 · CISA Known Exploited Vulnerabilities

Microsoft Windows Installer Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2020-1938 · CISA Known Exploited Vulnerabilities

Apache Tomcat Improper Privilege Management Vulnerability

Vendor: Apache | Product: Tomcat | Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2020-11899 · CISA Known Exploited Vulnerabilities

Treck TCP/IP stack Out-of-Bounds Read Vulnerability

Vendor: Treck TCP/IP stack | Product: IPv6 | The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2019-16928 · CISA Known Exploited Vulnerabilities

Exim Out-of-bounds Write Vulnerability

Vendor: Exim | Product: Exim Internet Mailer | Exim contains an out-of-bounds write vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2019-1652 · CISA Known Exploited Vulnerabilities

Cisco Small Business Routers Improper Input Validation Vulnerability

Vendor: Cisco | Product: Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation…
Read full source summary
Vendor: Cisco | Product: Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2019-1297 · CISA Known Exploited Vulnerabilities

Microsoft Excel Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Excel | A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-8581 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Exchange Server | A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-8298 · CISA Known Exploited Vulnerabilities

ChakraCore Scripting Engine Type Confusion Vulnerability

Vendor: ChakraCore | Product: ChakraCore scripting engine | The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0180 · CISA Known Exploited Vulnerabilities

Cisco IOS Software Denial-of-Service Vulnerability

Vendor: Cisco | Product: IOS Software | A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0179 · CISA Known Exploited Vulnerabilities

Cisco IOS Software Denial-of-Service Vulnerability

Vendor: Cisco | Product: IOS Software | A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0175 · CISA Known Exploited Vulnerabilities

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Vendor: Cisco | Product: IOS, XR, and XE Software | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Cisco | Product: IOS, XR, and XE Software | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0174 · CISA Known Exploited Vulnerabilities

Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

Vendor: Cisco | Product: IOS XE Software | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0173 · CISA Known Exploited Vulnerabilities

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

Vendor: Cisco | Product: IOS and IOS XE Software | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0172 · CISA Known Exploited Vulnerabilities

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

Vendor: Cisco | Product: IOS and IOS XE Software | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0167 · CISA Known Exploited Vulnerabilities

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Vendor: Cisco | Product: IOS, XR, and XE Software | There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Cisco | Product: IOS, XR, and XE Software | There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0161 · CISA Known Exploited Vulnerabilities

Cisco IOS Software Resource Management Errors Vulnerability

Vendor: Cisco | Product: IOS Software | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0159 · CISA Known Exploited Vulnerabilities

Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

Vendor: Cisco | Product: IOS Software and Cisco IOS XE Software | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Cisco | Product: IOS Software and Cisco IOS XE Software | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0158 · CISA Known Exploited Vulnerabilities

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

Vendor: Cisco | Product: IOS Software and Cisco IOS XE Software | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Cisco | Product: IOS Software and Cisco IOS XE Software | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0156 · CISA Known Exploited Vulnerabilities

Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

Vendor: Cisco | Product: IOS Software and Cisco IOS XE Software | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2018-0155 · CISA Known Exploited Vulnerabilities

Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

Vendor: Cisco | Product: Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition. | Required action:…
Read full source summary
Vendor: Cisco | Product: Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index