Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 12:50 UTCOfficial source · JSON
CVE-2019-4716 · CISA Known Exploited Vulnerabilities

IBM Planning Analytics Remote Code Execution Vulnerability

Vendor: IBM | Product: Planning Analytics | IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-3715 · CISA Known Exploited Vulnerabilities

ImageMagick Arbitrary File Deletion Vulnerability

Vendor: ImageMagick | Product: ImageMagick | ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-3718 · CISA Known Exploited Vulnerabilities

ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

Vendor: ImageMagick | Product: ImageMagick | ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-15505 · CISA Known Exploited Vulnerabilities

Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

Vendor: Ivanti | Product: MobileIron Multiple Products | Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30116 · CISA Known Exploited Vulnerabilities

Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

Vendor: Kaseya | Product: Virtual System/Server Administrator (VSA) | Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-7961 · CISA Known Exploited Vulnerabilities

Liferay Portal Deserialization of Untrusted Data Vulnerability

Vendor: Liferay | Product: Liferay Portal | Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-23874 · CISA Known Exploited Vulnerabilities

McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

Vendor: McAfee | Product: McAfee Total Protection (MTP) | McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-22506 · CISA Known Exploited Vulnerabilities

Micro Focus Access Manager Information Leakage Vulnerability

Vendor: Micro Focus | Product: Micro Focus Access Manager | Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-22502 · CISA Known Exploited Vulnerabilities

Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

Vendor: Micro Focus | Product: Operation Bridge Reporter (OBR) | Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2014-1812 · CISA Known Exploited Vulnerabilities

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-38647 · CISA Known Exploited Vulnerabilities

Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2016-0167 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0878 · CISA Known Exploited Vulnerabilities

Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Edge and Internet Explorer | Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-31955 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Information Disclosure Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1647 · CISA Known Exploited Vulnerabilities

Microsoft Defender Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Defender | Microsoft Defender contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2016-0185 · CISA Known Exploited Vulnerabilities

Microsoft Windows Media Center Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a specially crafted Media Center link (.mcl) file that references malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0683 · CISA Known Exploited Vulnerabilities

Microsoft Windows Installer Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-17087 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-33742 · CISA Known Exploited Vulnerabilities

Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index