Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2019-13720 · CISA Known Exploited Vulnerabilities

Google Chrome WebAudio Use-After-Free Vulnerability

Vendor: Google | Product: Chrome WebAudio | Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-11707 · CISA Known Exploited Vulnerabilities

Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-11708 · CISA Known Exploited Vulnerabilities

Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

Vendor: Mozilla | Product: Firefox and Thunderbird | Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-8720 · CISA Known Exploited Vulnerabilities

WebKitGTK Memory Corruption Vulnerability

Vendor: WebKitGTK | Product: WebKitGTK | WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-18426 · CISA Known Exploited Vulnerabilities

WhatsApp Cross-Site Scripting Vulnerability

Vendor: Meta Platforms | Product: WhatsApp | A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-1385 · CISA Known Exploited Vulnerabilities

Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2019-1130 · CISA Known Exploited Vulnerabilities

Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2018-5002 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Stack-based Buffer Overflow Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-13
CVE-2018-8589 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-13
CVE-2022-30525 · CISA Known Exploited Vulnerabilities

Zyxel Multiple Firewalls OS Command Injection Vulnerability

Vendor: Zyxel | Product: Multiple Firewalls | A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-06
CVE-2022-22947 · CISA Known Exploited Vulnerabilities

VMware Spring Cloud Gateway Code Injection Vulnerability

Vendor: VMware | Product: Spring Cloud Gateway | Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-06
CVE-2022-1388 · CISA Known Exploited Vulnerabilities

F5 BIG-IP Missing Authentication Vulnerability

Vendor: F5 | Product: BIG-IP | F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-31
CVE-2021-1789 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Type Confusion Vulnerability

Vendor: Apple | Product: Multiple Products | A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2019-8506 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Type Confusion Vulnerability

Vendor: Apple | Product: Multiple Products | A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2014-4113 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2014-0322 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Use-After-Free Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2014-0160 · CISA Known Exploited Vulnerabilities

OpenSSL Information Disclosure Vulnerability

Vendor: OpenSSL | Product: OpenSSL | The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-25
CVE-2022-29464 · CISA Known Exploited Vulnerabilities

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

Vendor: WSO2 | Product: Multiple Products | Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2022-26904 · CISA Known Exploited Vulnerabilities

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2022-21919 · CISA Known Exploited Vulnerabilities

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index