Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Telerik | Product: User Interface (UI) for ASP.NET AJAX | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-16
CVE-2022-47966 · CISA Known Exploited Vulnerabilities
Vendor: CWP | Product: Control Web Panel | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-02-07
CVE-2022-41080 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-31
CVE-2023-21674 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-31
CVE-2018-5430 · CISA Known Exploited Vulnerabilities
Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2018-18809 · CISA Known Exploited Vulnerabilities
Vendor: TIBCO | Product: JasperReports | TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-19
CVE-2022-42856 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS | Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-04
CVE-2022-42475 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: FortiOS | Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-44698 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Defender | Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-27518 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: Application Delivery Controller (ADC) and Gateway | Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability that allows an attacker to execute code as administrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26500 · CISA Known Exploited Vulnerabilities
Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-26501 · CISA Known Exploited Vulnerabilities
Vendor: Veeam | Product: Backup & Replication | The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2023-01-03
CVE-2022-4262 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-26
CVE-2021-35587 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply…
Read full source summary
Vendor: Google | Product: Chromium GPU | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-19
CVE-2022-41049 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41091 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41073 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2022-41125 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.