Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-01
CVE-2023-28206 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-05-01
CVE-2021-27876 · CISA Known Exploited Vulnerabilities
Vendor: Veritas | Product: Backup Exec Agent | Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-28
CVE-2021-27877 · CISA Known Exploited Vulnerabilities
Vendor: Veritas | Product: Backup Exec Agent | Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-28
CVE-2021-27878 · CISA Known Exploited Vulnerabilities
Vendor: Veritas | Product: Backup Exec Agent | Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-28
CVE-2019-1388 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-28
CVE-2023-26083 · CISA Known Exploited Vulnerabilities
Vendor: Arm | Product: Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-28
CVE-2022-27926 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-24
CVE-2013-3163 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2023-04-20
CVE-2017-7494 · CISA Known Exploited Vulnerabilities
Vendor: Samba | Product: Samba | Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2022-42948 · CISA Known Exploited Vulnerabilities
Vendor: Fortra | Product: Cobalt Strike | Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon configuration, allowing them to execute code remotely. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2021-30900 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple GPU drivers, included in iOS, iPadOS, and macOS, contain an out-of-bounds write vulnerability that may allow a malicious application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2022-38181 · CISA Known Exploited Vulnerabilities
Vendor: Arm | Product: Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2023-0266 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from the system user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2022-3038 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium Network Service | Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Google | Product: Chromium Network Service | Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2022-22706 · CISA Known Exploited Vulnerabilities
Vendor: Arm | Product: Mali Graphics Processing Unit (GPU) | Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-20
CVE-2023-26360 · CISA Known Exploited Vulnerabilities
Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-05
CVE-2023-23397 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-04
CVE-2023-24880 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-04-04
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.