Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2017-11292 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Type Confusion Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2017-0261 · CISA Known Exploited Vulnerabilities

Microsoft Office Use-After-Free Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2017-0001 · CISA Known Exploited Vulnerabilities

Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Graphics Device Interface (GDI) | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-8562 · CISA Known Exploited Vulnerabilities

Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

Vendor: Siemens | Product: SIMATIC CP | An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-7855 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2016-7262 · CISA Known Exploited Vulnerabilities

Microsoft Office Security Feature Bypass Vulnerability

Vendor: Microsoft | Product: Excel | A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-7193 · CISA Known Exploited Vulnerabilities

Microsoft Office Memory Corruption Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-5195 · CISA Known Exploited Vulnerabilities

Linux Kernel Race Condition Vulnerability

Vendor: Linux | Product: Kernel | Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2016-4117 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Arbitrary Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2016-1019 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Arbitrary Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2016-0099 · CISA Known Exploited Vulnerabilities

Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-7645 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Arbitrary Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2015-5119 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2015-4902 · CISA Known Exploited Vulnerabilities

Oracle Java SE Integrity Check Vulnerability

Vendor: Oracle | Product: Java SE | Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-3043 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Memory Corruption Vulnerability

Vendor: Adobe | Product: Flash Player | A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2015-2590 · CISA Known Exploited Vulnerabilities

Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

Vendor: Oracle | Product: Java SE | An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-2545 · CISA Known Exploited Vulnerabilities

Microsoft Office Malformed EPS File Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-2424 · CISA Known Exploited Vulnerabilities

Microsoft PowerPoint Memory Corruption Vulnerability

Vendor: Microsoft | Product: PowerPoint | Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-2387 · CISA Known Exploited Vulnerabilities

Microsoft ATM Font Driver Privilege Escalation Vulnerability

Vendor: Microsoft | Product: ATM Font Driver | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-1701 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index