Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 06:04 UTCOfficial source · JSON
CVE-2021-21975 · CISA Known Exploited Vulnerabilities

VMware Server Side Request Forgery in vRealize Operations Manager API

Vendor: VMware | Product: vRealize Operations Manager API | Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-21315 · CISA Known Exploited Vulnerabilities

System Information Library for Node.JS Command Injection

Vendor: Npm package | Product: System Information Library for Node.JS | In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-22991 · CISA Known Exploited Vulnerabilities

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

Vendor: F5 | Product: BIG-IP Traffic Management Microkernel | The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2020-14864 · CISA Known Exploited Vulnerabilities

Oracle Business Intelligence Enterprise Edition Path Transversal

Vendor: Oracle | Product: Intelligence Enterprise Edition | Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13671 · CISA Known Exploited Vulnerabilities

Drupal core Un-restricted Upload of File

Vendor: Drupal | Product: Drupal core | Improper sanitization in the extension file names is present in Drupal core. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-11978 · CISA Known Exploited Vulnerabilities

Apache Airflow Command Injection

Vendor: Apache | Product: Airflow | A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-13927 · CISA Known Exploited Vulnerabilities

Apache Airflow's Experimental API Authentication Bypass

Vendor: Apache | Product: Airflow's Experimental API | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-22017 · CISA Known Exploited Vulnerabilities

VMware vCenter Server Improper Access Control

Vendor: VMware | Product: vCenter Server | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2021-36260 · CISA Known Exploited Vulnerabilities

Hikvision Improper Input Validation

Vendor: Hikvision | Product: Security cameras web server | A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-01-24
CVE-2020-6572 · CISA Known Exploited Vulnerabilities

Google Chrome Media Use-After-Free Vulnerability

Vendor: Google | Product: Chrome Media | Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1458 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2013-3900 · CISA Known Exploited Vulnerabilities

Microsoft WinVerifyTrust function Remote Code Execution

Vendor: Microsoft | Product: WinVerifyTrust function | A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-2725 · CISA Known Exploited Vulnerabilities

Oracle WebLogic Server, Injection

Vendor: Oracle | Product: WebLogic Server | Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13382 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS and FortiProxy Improper Authorization

Vendor: Fortinet | Product: FortiOS and FortiProxy | An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2018-13383 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS and FortiProxy Out-of-bounds Write

Vendor: Fortinet | Product: FortiOS and FortiProxy | A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-1579 · CISA Known Exploited Vulnerabilities

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Vendor: Palo Alto Networks | Product: PAN-OS | Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2019-10149 · CISA Known Exploited Vulnerabilities

Exim Mail Transfer Agent (MTA) Improper Input Validation

Vendor: Exim | Product: Mail Transfer Agent (MTA) | Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2015-7450 · CISA Known Exploited Vulnerabilities

IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.

Vendor: IBM | Product: WebSphere Application Server and Server Hypervisor Edition | Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
CVE-2017-1000486 · CISA Known Exploited Vulnerabilities

Primetek Primefaces Remote Code Execution Vulnerability

Vendor: Primetek | Product: Primefaces Application | Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-10
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index