Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2016-4171 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Remote Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-1555 · CISA Known Exploited Vulnerabilities

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Vendor: NETGEAR | Product: Wireless Access Point (WAP) Devices | Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-11021 · CISA Known Exploited Vulnerabilities

D-Link DCS-930L Devices OS Command Injection Vulnerability

Vendor: D-Link | Product: DCS-930L Devices | setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-10174 · CISA Known Exploited Vulnerabilities

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

Vendor: NETGEAR | Product: WNR2000v5 Router | The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-0752 · CISA Known Exploited Vulnerabilities

Ruby on Rails Directory Traversal Vulnerability

Vendor: Rails | Product: Ruby on Rails | Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-4068 · CISA Known Exploited Vulnerabilities

Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Vendor: Arcserve | Product: Unified Data Protection (UDP) | Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-3035 · CISA Known Exploited Vulnerabilities

TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Vendor: TP-Link | Product: Multiple Archer Devices | Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-1427 · CISA Known Exploited Vulnerabilities

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

Vendor: Elastic | Product: Elasticsearch | The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-1187 · CISA Known Exploited Vulnerabilities

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

Vendor: D-Link and TRENDnet | Product: Multiple Devices | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2015-0666 · CISA Known Exploited Vulnerabilities

Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

Vendor: Cisco | Product: Prime Data Center Network Manager (DCNM) | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6324 · CISA Known Exploited Vulnerabilities

Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Kerberos Key Distribution Center (KDC) | The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6287 · CISA Known Exploited Vulnerabilities

Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

Vendor: Rejetto | Product: HTTP File Server (HFS) | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-3120 · CISA Known Exploited Vulnerabilities

Elasticsearch Remote Code Execution Vulnerability

Vendor: Elastic | Product: Elasticsearch | Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-0130 · CISA Known Exploited Vulnerabilities

Ruby on Rails Directory Traversal Vulnerability

Vendor: Rails | Product: Ruby on Rails | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-5223 · CISA Known Exploited Vulnerabilities

D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

Vendor: D-Link | Product: DSL-2760U | A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-4810 · CISA Known Exploited Vulnerabilities

HP Multiple Products Remote Code Execution Vulnerability

Vendor: Hewlett Packard (HP) | Product: ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Hewlett Packard (HP) | Product: ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-2251 · CISA Known Exploited Vulnerabilities

Apache Struts Improper Input Validation Vulnerability

Vendor: Apache | Product: Struts | Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2012-1823 · CISA Known Exploited Vulnerabilities

PHP-CGI Query String Parameter Vulnerability

Vendor: PHP | Product: PHP | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-4345 · CISA Known Exploited Vulnerabilities

Exim Privilege Escalation Vulnerability

Vendor: Exim | Product: Exim | Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index