Vulnerabilities with evidence of exploitation, including affected products and required actions.
This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
Vendor: Cisco | Product: HyperFlex HX | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1498 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: HyperFlex HX | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2018-0171 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: IOS and IOS XE | Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3118 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: IOS XR | Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3566 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: IOS XR | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Cisco | Product: IOS XR | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3569 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: IOS XR | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Cisco | Product: IOS XR | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-3161 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: Cisco IP Phones | Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-1653 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: Small Business RV320 and RV325 Routers | Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-0296 · CISA Known Exploited Vulnerabilities
Vendor: Cisco | Product: Adaptive Security Appliance (ASA) | Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-13608 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: StoreFront Server | Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8193 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. | Required action: Apply updates per…
Read full source summary
Vendor: Citrix | Product: Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8195 · CISA Known Exploited Vulnerabilities
Vendor: Citrix | Product: Workspace Application and Receiver for Windows | Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-29557 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DIR-825 R1 Devices | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-25506 · CISA Known Exploited Vulnerabilities
Vendor: D-Link | Product: DNS-320 Device | D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-15811 · CISA Known Exploited Vulnerabilities
Vendor: DotNetNuke (DNN) | Product: DotNetNuke (DNN) | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-18325 · CISA Known Exploited Vulnerabilities
Vendor: DotNetNuke (DNN) | Product: DotNetNuke (DNN) | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-9822 · CISA Known Exploited Vulnerabilities
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.