Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 1, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-1555 · CISA Known Exploited Vulnerabilities
Vendor: NETGEAR | Product: Wireless Access Point (WAP) Devices | Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-11021 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DCS-930L Devices | setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2016-10174 · CISA Known Exploited Vulnerabilities
Vendor: NETGEAR | Product: WNR2000v5 Router | The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2016-0752 · CISA Known Exploited Vulnerabilities
Vendor: Arcserve | Product: Unified Data Protection (UDP) | Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2015-3035 · CISA Known Exploited Vulnerabilities
Vendor: D-Link and TRENDnet | Product: Multiple Devices | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-04-15
CVE-2015-0666 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: Prime Data Center Network Manager (DCNM) | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6332 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6324 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Kerberos Key Distribution Center (KDC) | The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-6287 · CISA Known Exploited Vulnerabilities
Vendor: Rejetto | Product: HTTP File Server (HFS) | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2014-3120 · CISA Known Exploited Vulnerabilities
Vendor: Rails | Product: Ruby on Rails | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2013-5223 · CISA Known Exploited Vulnerabilities
Vendor: PHP | Product: PHP | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
CVE-2010-4345 · CISA Known Exploited Vulnerabilities
Vendor: Exim | Product: Exim | Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-15
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.