Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Microsoft | Product: Windows | Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-12-09
CVE-2021-25337 · CISA Known Exploited Vulnerabilities
Vendor: Samsung | Product: Mobile Devices | Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-29
CVE-2021-25369 · CISA Known Exploited Vulnerabilities
Vendor: Samsung | Product: Mobile Devices | Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-29
CVE-2021-25370 · CISA Known Exploited Vulnerabilities
Vendor: Samsung | Product: Mobile Devices | Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-29
CVE-2022-3723 · CISA Known Exploited Vulnerabilities
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-18
CVE-2022-42827 · CISA Known Exploited Vulnerabilities
Vendor: Apple | Product: iOS and iPadOS | Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-15
CVE-2020-3433 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Cisco | Product: AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-14
CVE-2020-3153 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. | Required action: Apply updates per vendor instructions.…
Read full source summary
Vendor: Cisco | Product: AnyConnect Secure | Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-14
CVE-2018-19323 · CISA Known Exploited Vulnerabilities
Vendor: GIGABYTE | Product: Multiple Products | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-14
CVE-2018-19322 · CISA Known Exploited Vulnerabilities
Vendor: GIGABYTE | Product: Multiple Products | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-14
CVE-2018-19321 · CISA Known Exploited Vulnerabilities
Vendor: GIGABYTE | Product: Multiple Products | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-14
CVE-2018-19320 · CISA Known Exploited Vulnerabilities
Vendor: GIGABYTE | Product: Multiple Products | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-14
CVE-2022-41352 · CISA Known Exploited Vulnerabilities
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-10
CVE-2021-3493 · CISA Known Exploited Vulnerabilities
Vendor: Linux | Product: Kernel | The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-10
CVE-2022-40684 · CISA Known Exploited Vulnerabilities
Vendor: Fortinet | Product: Multiple Products | Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-01
CVE-2022-41033 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows COM+ Event System Service | Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-11-01
CVE-2022-41082 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-21
CVE-2022-41040 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-21
CVE-2022-36804 · CISA Known Exploited Vulnerabilities
Vendor: Atlassian | Product: Bitbucket Server and Data Center | Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. | Required action: Apply updates per vendor instructions. | Federal remediation…
Read full source summary
Vendor: Atlassian | Product: Bitbucket Server and Data Center | Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-21
CVE-2022-3236 · CISA Known Exploited Vulnerabilities
Vendor: Sophos | Product: Firewall | A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-10-14
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.