Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Apple | Product: macOS | macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-25
CVE-2021-45382 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: Multiple Routers | A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-25
CVE-2022-26871 · CISA Known Exploited Vulnerabilities
Vendor: Trend Micro | Product: Apex Central | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2022-1040 · CISA Known Exploited Vulnerabilities
Vendor: Sophos | Product: Firewall | An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-34484 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-28799 · CISA Known Exploited Vulnerabilities
Vendor: QNAP | Product: Network Attached Storage (NAS) | QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2021-21551 · CISA Known Exploited Vulnerabilities
Vendor: Dell | Product: dbutil Driver | Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-21
CVE-2018-10562 · CISA Known Exploited Vulnerabilities
Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2018-10561 · CISA Known Exploited Vulnerabilities
Vendor: Dasan | Product: Gigabit Passive Optical Network (GPON) Routers | Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-21
CVE-2022-1096 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2022-0543 · CISA Known Exploited Vulnerabilities
Vendor: Redis | Product: Debian-specific Redis Servers | Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-38646 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-34486 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-26085 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Confluence Server | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2021-20028 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: Secure Remote Access (SRA) | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-18
CVE-2019-7483 · CISA Known Exploited Vulnerabilities
Vendor: SonicWall | Product: SMA100 | In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8440 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8406 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2018-8405 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: DirectX Graphics Kernel (DXGKRNL) | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
CVE-2017-0213 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-18
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.