Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2013-2423 · CISA Known Exploited Vulnerabilities

Oracle JRE Unspecified Vulnerability

Vendor: Oracle | Product: Java Runtime Environment (JRE) | Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-0431 · CISA Known Exploited Vulnerabilities

Oracle JRE Sandbox Bypass Vulnerability

Vendor: Oracle | Product: Java Runtime Environment (JRE) | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-0422 · CISA Known Exploited Vulnerabilities

Oracle JRE Remote Code Execution Vulnerability

Vendor: Oracle | Product: Java Runtime Environment (JRE) | A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2013-0074 · CISA Known Exploited Vulnerabilities

Microsoft Silverlight Double Dereference Vulnerability

Vendor: Microsoft | Product: Silverlight | Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2012-1710 · CISA Known Exploited Vulnerabilities

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle | Product: Fusion Middleware | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2010-1428 · CISA Known Exploited Vulnerabilities

Red Hat JBoss Information Disclosure Vulnerability

Vendor: Red Hat | Product: JBoss | Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2010-0840 · CISA Known Exploited Vulnerabilities

Oracle JRE Unspecified Vulnerability

Vendor: Oracle | Product: Java Runtime Environment (JRE) | Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2010-0738 · CISA Known Exploited Vulnerabilities

Red Hat JBoss Authentication Bypass Vulnerability

Vendor: Red Hat | Product: JBoss | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2018-8611 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2018-19953 · CISA Known Exploited Vulnerabilities

QNAP NAS File Station Cross-Site Scripting Vulnerability

Vendor: QNAP | Product: Network Attached Storage (NAS) | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2018-19949 · CISA Known Exploited Vulnerabilities

QNAP NAS File Station Command Injection Vulnerability

Vendor: QNAP | Product: Network Attached Storage (NAS) | A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2018-19943 · CISA Known Exploited Vulnerabilities

QNAP NAS File Station Cross-Site Scripting Vulnerability

Vendor: QNAP | Product: Network Attached Storage (NAS) | A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0147 · CISA Known Exploited Vulnerabilities

Microsoft Windows SMBv1 Information Disclosure Vulnerability

Vendor: Microsoft | Product: SMBv1 server | The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0022 · CISA Known Exploited Vulnerabilities

Microsoft XML Core Services Information Disclosure Vulnerability

Vendor: Microsoft | Product: XML Core Services | Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0149 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-0210 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Internet Explorer | A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-8291 · CISA Known Exploited Vulnerabilities

Artifex Ghostscript Type Confusion Vulnerability

Vendor: Artifex | Product: Ghostscript | Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-8543 · CISA Known Exploited Vulnerabilities

Microsoft Windows Search Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-14
CVE-2017-18362 · CISA Known Exploited Vulnerabilities

Kaseya VSA SQL Injection Vulnerability

Vendor: Kaseya | Product: Virtual System/Server Administrator (VSA) | ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-14
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index