Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2022-30333 · CISA Known Exploited Vulnerabilities

RARLAB UnRAR Directory Traversal Vulnerability

Vendor: RARLAB | Product: UnRAR | RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-30
CVE-2022-27924 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-25
CVE-2022-26138 · CISA Known Exploited Vulnerabilities

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Vendor: Atlassian | Product: Confluence | Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-19
CVE-2022-26925 · CISA Known Exploited Vulnerabilities

Microsoft Windows LSA Spoofing Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. | Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch]. | Federal remediation due: 2022-07-22
CVE-2022-29499 · CISA Known Exploited Vulnerabilities

Mitel MiVoice Connect Data Validation Vulnerability

Vendor: Mitel | Product: MiVoice Connect | The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-30533 · CISA Known Exploited Vulnerabilities

Google Chromium PopupBlocker Security Bypass Vulnerability

Vendor: Google | Product: Chromium PopupBlocker | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Google | Product: Chromium PopupBlocker | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-4034 · CISA Known Exploited Vulnerabilities

Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

Vendor: Red Hat | Product: Polkit | The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2021-30983 · CISA Known Exploited Vulnerabilities

Apple iOS and iPadOS Buffer Overflow Vulnerability

Vendor: Apple | Product: iOS and iPadOS | Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-3837 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2020-9907 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2019-8605 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Use-After-Free Vulnerability

Vendor: Apple | Product: Multiple Products | A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2018-4344 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-18
CVE-2022-30190 · CISA Known Exploited Vulnerabilities

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-05
CVE-2021-38163 · CISA Known Exploited Vulnerabilities

SAP NetWeaver Unrestricted File Upload Vulnerability

Vendor: SAP | Product: NetWeaver | SAP NetWeaver contains a vulnerability that allows unrestricted file upload. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-30
CVE-2016-2386 · CISA Known Exploited Vulnerabilities

SAP NetWeaver SQL Injection Vulnerability

Vendor: SAP | Product: NetWeaver | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-30
CVE-2016-2388 · CISA Known Exploited Vulnerabilities

SAP NetWeaver Information Disclosure Vulnerability

Vendor: SAP | Product: NetWeaver | The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-30
CVE-2019-7195 · CISA Known Exploited Vulnerabilities

QNAP Photo Station Path Traversal Vulnerability

Vendor: QNAP | Product: Photo Station | QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2019-7194 · CISA Known Exploited Vulnerabilities

QNAP Photo Station Path Traversal Vulnerability

Vendor: QNAP | Product: Photo Station | QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index