Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 2, 2026 · 18:44 UTCOfficial source · JSON
CVE-2025-0108 · CISA Known Exploited Vulnerabilities

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Vendor: Palo Alto Networks | Product: PAN-OS | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts. | Required action: Apply mitigations per vendor instructions or discontinue use…
Read full source summary
Vendor: Palo Alto Networks | Product: PAN-OS | Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-11
CVE-2024-53704 · CISA Known Exploited Vulnerabilities

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

Vendor: SonicWall | Product: SonicOS | SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-11
CVE-2024-57727 · CISA Known Exploited Vulnerabilities

SimpleHelp Path Traversal Vulnerability

Vendor: SimpleHelp | Product: SimpleHelp | SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. | Required action: Apply mitigations per vendor instructions or discontinue use of the…
Read full source summary
Vendor: SimpleHelp | Product: SimpleHelp | SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-06
CVE-2025-24200 · CISA Known Exploited Vulnerabilities

Apple iOS and iPadOS Incorrect Authorization Vulnerability

Vendor: Apple | Product: iOS and iPadOS | Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-05
CVE-2024-41710 · CISA Known Exploited Vulnerabilities

Mitel SIP Phones Argument Injection Vulnerability

Vendor: Mitel | Product: SIP Phones | Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. | Required action: Apply mitigations per vendor instructions…
Read full source summary
Vendor: Mitel | Product: SIP Phones | Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-05
CVE-2024-40891 · CISA Known Exploited Vulnerabilities

Zyxel DSL CPE OS Command Injection Vulnerability

Vendor: Zyxel | Product: DSL CPE Devices | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. | Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is…
Read full source summary
Vendor: Zyxel | Product: DSL CPE Devices | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet. | Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. | Federal remediation due: 2025-03-04
CVE-2024-40890 · CISA Known Exploited Vulnerabilities

Zyxel DSL CPE OS Command Injection Vulnerability

Vendor: Zyxel | Product: DSL CPE Devices | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. | Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is…
Read full source summary
Vendor: Zyxel | Product: DSL CPE Devices | Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request. | Required action: The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable. | Federal remediation due: 2025-03-04
CVE-2025-21418 · CISA Known Exploited Vulnerabilities

Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-04
CVE-2025-21391 · CISA Known Exploited Vulnerabilities

Microsoft Windows Storage Link Following Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-03-04
CVE-2025-0994 · CISA Known Exploited Vulnerabilities

Trimble Cityworks Deserialization Vulnerability

Vendor: Trimble | Product: Cityworks | Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Trimble | Product: Cityworks | Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-28
CVE-2020-15069 · CISA Known Exploited Vulnerabilities

Sophos XG Firewall Buffer Overflow Vulnerability

Vendor: Sophos | Product: XG Firewall | Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-27
CVE-2020-29574 · CISA Known Exploited Vulnerabilities

CyberoamOS (CROS) SQL Injection Vulnerability

Vendor: Sophos | Product: CyberoamOS | CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. | Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. | Federal remediation due: 2025-02-27
CVE-2024-21413 · CISA Known Exploited Vulnerabilities

Microsoft Outlook Improper Input Validation Vulnerability

Vendor: Microsoft | Product: Office Outlook | Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if…
Read full source summary
Vendor: Microsoft | Product: Office Outlook | Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-27
CVE-2022-23748 · CISA Known Exploited Vulnerabilities

Dante Discovery Process Control Vulnerability

Vendor: Audinate | Product: Dante Discovery | Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal…
Read full source summary
Vendor: Audinate | Product: Dante Discovery | Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-27
CVE-2025-0411 · CISA Known Exploited Vulnerabilities

7-Zip Mark of the Web Bypass Vulnerability

Vendor: 7-Zip | Product: 7-Zip | 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-27
CVE-2024-53104 · CISA Known Exploited Vulnerabilities

Linux Kernel Out-of-Bounds Write Vulnerability

Vendor: Linux | Product: Kernel | Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-26
CVE-2018-19410 · CISA Known Exploited Vulnerabilities

Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Vendor: Paessler | Product: PRTG Network Monitor | Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator). | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-25
CVE-2018-9276 · CISA Known Exploited Vulnerabilities

Paessler PRTG Network Monitor OS Command Injection Vulnerability

Vendor: Paessler | Product: PRTG Network Monitor | Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-25
CVE-2024-29059 · CISA Known Exploited Vulnerabilities

Microsoft .NET Framework Information Disclosure Vulnerability

Vendor: Microsoft | Product: .NET Framework | Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-25
CVE-2024-45195 · CISA Known Exploited Vulnerabilities

Apache OFBiz Forced Browsing Vulnerability

Vendor: Apache | Product: OFBiz | Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2025-02-25
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index