Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2011-2462 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2011-0609 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Unspecified Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2010-2883 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2010-2572 · CISA Known Exploited Vulnerabilities

Microsoft PowerPoint Buffer Overflow Vulnerability

Vendor: Microsoft | Product: PowerPoint | Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2010-1297 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Memory Corruption Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2009-4324 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Use-After-Free Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2009-3953 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2009-1862 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

Vendor: Adobe | Product: Acrobat and Reader, Flash Player | Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). | Required action: For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-22
CVE-2009-0563 · CISA Known Exploited Vulnerabilities

Microsoft Office Buffer Overflow Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2009-0557 · CISA Known Exploited Vulnerabilities

Microsoft Office Object Record Corruption Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2008-0655 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Unspecified Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2007-5659 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Buffer Overflow Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2006-2492 · CISA Known Exploited Vulnerabilities

Microsoft Word Malformed Object Pointer Vulnerability

Vendor: Microsoft | Product: Word | Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-22
CVE-2022-26134 · CISA Known Exploited Vulnerabilities

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Vendor: Atlassian | Product: Confluence Server/Data Center | Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. | Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions…
Read full source summary
Vendor: Atlassian | Product: Confluence Server/Data Center | Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. | Required action: Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules. | Federal remediation due: 2022-06-06
CVE-2019-3010 · CISA Known Exploited Vulnerabilities

Oracle Solaris Privilege Escalation Vulnerability

Vendor: Oracle | Product: Solaris | Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2016-3393 · CISA Known Exploited Vulnerabilities

Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2016-7256 · CISA Known Exploited Vulnerabilities

Microsoft Windows Open Type Font Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-06-15
CVE-2016-1010 · CISA Known Exploited Vulnerabilities

Adobe Flash Player and AIR Integer Overflow Vulnerability

Vendor: Adobe | Product: Flash Player and AIR | Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code. | Required action: The impacted products are end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2016-0984 · CISA Known Exploited Vulnerabilities

Adobe Flash Player and AIR Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player and AIR | Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code. | Required action: The impacted products are end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
CVE-2016-0034 · CISA Known Exploited Vulnerabilities

Microsoft Silverlight Runtime Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Silverlight | Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS). | Required action: The impacted products are end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-06-15
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index