Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2023-43208 · CISA Known Exploited Vulnerabilities

NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

Vendor: NextGen Healthcare | Product: Mirth Connect | NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-06-10
CVE-2024-4761 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-06-06
CVE-2021-40655 · CISA Known Exploited Vulnerabilities

D-Link DIR-605 Router Information Disclosure Vulnerability

Vendor: D-Link | Product: DIR-605 Router | D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired…
Read full source summary
Vendor: D-Link | Product: DIR-605 Router | D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. | Federal remediation due: 2024-06-06
CVE-2014-100005 · CISA Known Exploited Vulnerabilities

D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

Vendor: D-Link | Product: DIR-600 Router | D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be…
Read full source summary
Vendor: D-Link | Product: DIR-600 Router | D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. | Federal remediation due: 2024-06-06
CVE-2024-30040 · CISA Known Exploited Vulnerabilities

Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-06-04
CVE-2024-30051 · CISA Known Exploited Vulnerabilities

Microsoft DWM Core Library Privilege Escalation Vulnerability

Vendor: Microsoft | Product: DWM Core Library | Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-06-04
CVE-2024-4671 · CISA Known Exploited Vulnerabilities

Google Chromium Visuals Use-After-Free Vulnerability

Vendor: Google | Product: Chromium | Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions or discontinue use of the…
Read full source summary
Vendor: Google | Product: Chromium | Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-06-03
CVE-2023-7028 · CISA Known Exploited Vulnerabilities

GitLab Community and Enterprise Editions Improper Access Control Vulnerability

Vendor: GitLab | Product: GitLab CE/EE | GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: GitLab | Product: GitLab CE/EE | GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-05-22
CVE-2024-29988 · CISA Known Exploited Vulnerabilities

Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: SmartScreen Prompt | Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are…
Read full source summary
Vendor: Microsoft | Product: SmartScreen Prompt | Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-05-21
CVE-2024-4040 · CISA Known Exploited Vulnerabilities

CrushFTP VFS Sandbox Escape Vulnerability

Vendor: CrushFTP | Product: CrushFTP | CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS). | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-05-01
CVE-2024-20359 · CISA Known Exploited Vulnerabilities

Cisco ASA and FTD Privilege Escalation Vulnerability

Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-05-01
CVE-2024-20353 · CISA Known Exploited Vulnerabilities

Cisco ASA and FTD Denial of Service Vulnerability

Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-05-01
CVE-2022-38028 · CISA Known Exploited Vulnerabilities

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-05-14
CVE-2024-3400 · CISA Known Exploited Vulnerabilities

Palo Alto Networks PAN-OS Command Injection Vulnerability

Vendor: Palo Alto Networks | Product: PAN-OS | Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. | Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention…
Read full source summary
Vendor: Palo Alto Networks | Product: PAN-OS | Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall. | Required action: Apply mitigations per vendor instructions as they become available. Otherwise, users with vulnerable versions of affected devices should enable Threat Prevention IDs available from the vendor. See the vendor bulletin for more details and a patch release schedule. | Federal remediation due: 2024-04-19
CVE-2024-3273 · CISA Known Exploited Vulnerabilities

D-Link Multiple NAS Devices Command Injection Vulnerability

Vendor: D-Link | Product: Multiple NAS Devices | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be…
Read full source summary
Vendor: D-Link | Product: Multiple NAS Devices | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. | Federal remediation due: 2024-05-02
CVE-2024-3272 · CISA Known Exploited Vulnerabilities

D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

Vendor: D-Link | Product: Multiple NAS Devices | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life…
Read full source summary
Vendor: D-Link | Product: Multiple NAS Devices | D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. | Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. | Federal remediation due: 2024-05-02
CVE-2024-29748 · CISA Known Exploited Vulnerabilities

Android Pixel Privilege Escalation Vulnerability

Vendor: Android | Product: Pixel | Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-04-25
CVE-2024-29745 · CISA Known Exploited Vulnerabilities

Android Pixel Information Disclosure Vulnerability

Vendor: Android | Product: Pixel | Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-04-25
CVE-2023-24955 · CISA Known Exploited Vulnerabilities

Microsoft SharePoint Server Code Injection Vulnerability

Vendor: Microsoft | Product: SharePoint Server | Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2024-04-16
CVE-2019-7256 · CISA Known Exploited Vulnerabilities

Nice Linear eMerge E3-Series OS Command Injection Vulnerability

Vendor: Nice | Product: Linear eMerge E3-Series | Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution. | Required action: Contact the vendor for guidance on remediating firmware, per their advisory. | Federal remediation due: 2024-04-15
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index