Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 2, 2026 · 18:44 UTCOfficial source · JSON
CVE-2024-13160 · CISA Known Exploited Vulnerabilities

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Vendor: Ivanti | Product: Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Ivanti | Product: Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-31
CVE-2024-13159 · CISA Known Exploited Vulnerabilities

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Vendor: Ivanti | Product: Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Ivanti | Product: Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-31
CVE-2024-57968 · CISA Known Exploited Vulnerabilities

Advantive VeraCore Unrestricted File Upload Vulnerability

Vendor: Advantive | Product: VeraCore | Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation…
Read full source summary
Vendor: Advantive | Product: VeraCore | Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-31
CVE-2025-25181 · CISA Known Exploited Vulnerabilities

Advantive VeraCore SQL Injection Vulnerability

Vendor: Advantive | Product: VeraCore | Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation…
Read full source summary
Vendor: Advantive | Product: VeraCore | Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-31
CVE-2025-22226 · CISA Known Exploited Vulnerabilities

VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

Vendor: VMware | Product: ESXi, Workstation, and Fusion | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for…
Read full source summary
Vendor: VMware | Product: ESXi, Workstation, and Fusion | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-25
CVE-2025-22225 · CISA Known Exploited Vulnerabilities

VMware ESXi Arbitrary Write Vulnerability

Vendor: VMware | Product: ESXi | VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are…
Read full source summary
Vendor: VMware | Product: ESXi | VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-25
CVE-2025-22224 · CISA Known Exploited Vulnerabilities

VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

Vendor: VMware | Product: ESXi and Workstation | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. | Required action: Apply mitigations per vendor…
Read full source summary
Vendor: VMware | Product: ESXi and Workstation | VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-25
CVE-2024-50302 · CISA Known Exploited Vulnerabilities

Linux Kernel Use of Uninitialized Resource Vulnerability

Vendor: Linux | Product: Kernel | The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-25
CVE-2024-4885 · CISA Known Exploited Vulnerabilities

Progress WhatsUp Gold Path Traversal Vulnerability

Vendor: Progress | Product: WhatsUp Gold | Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-24
CVE-2018-8639 · CISA Known Exploited Vulnerabilities

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-24
CVE-2022-43769 · CISA Known Exploited Vulnerabilities

Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Vendor: Hitachi Vantara | Product: Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…
Read full source summary
Vendor: Hitachi Vantara | Product: Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-24
CVE-2022-43939 · CISA Known Exploited Vulnerabilities

Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Vendor: Hitachi Vantara | Product: Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are…
Read full source summary
Vendor: Hitachi Vantara | Product: Pentaho Business Analytics (BA) Server | Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-24
CVE-2023-20118 · CISA Known Exploited Vulnerabilities

Cisco Small Business RV Series Routers Command Injection Vulnerability

Vendor: Cisco | Product: Small Business RV Series Routers | Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance…
Read full source summary
Vendor: Cisco | Product: Small Business RV Series Routers | Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-24
CVE-2023-34192 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use…
Read full source summary
Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-18
CVE-2024-49035 · CISA Known Exploited Vulnerabilities

Microsoft Partner Center Improper Access Control Vulnerability

Vendor: Microsoft | Product: Partner Center | Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-18
CVE-2024-20953 · CISA Known Exploited Vulnerabilities

Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Vendor: Oracle | Product: Agile Product Lifecycle Management (PLM) | Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-17
CVE-2017-3066 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Deserialization Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-17
CVE-2025-24989 · CISA Known Exploited Vulnerabilities

Microsoft Power Pages Improper Access Control Vulnerability

Vendor: Microsoft | Product: Power Pages | Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. | Required action: Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |…
Read full source summary
Vendor: Microsoft | Product: Power Pages | Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. | Required action: Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-14
CVE-2025-0111 · CISA Known Exploited Vulnerabilities

Palo Alto Networks PAN-OS File Read Vulnerability

Vendor: Palo Alto Networks | Product: PAN-OS | Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. | Required action: Apply mitigations per vendor instructions or discontinue use of the…
Read full source summary
Vendor: Palo Alto Networks | Product: PAN-OS | Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-13
CVE-2025-23209 · CISA Known Exploited Vulnerabilities

Craft CMS Code Injection Vulnerability

Vendor: Craft CMS | Product: Craft CMS | Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-13
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index