Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 05:48 UTCOfficial source · JSON
CVE-2023-22515 · CISA Known Exploited Vulnerabilities

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Vendor: Atlassian | Product: Confluence Data Center and Server | Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence…
Read full source summary
Vendor: Atlassian | Product: Confluence Data Center and Server | Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Check all affected Confluence instances for evidence of compromise per vendor instructions and report any positive findings to CISA. | Federal remediation due: 2023-10-13
CVE-2023-40044 · CISA Known Exploited Vulnerabilities

Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Vendor: Progress | Product: WS_FTP Server | Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due:…
Read full source summary
Vendor: Progress | Product: WS_FTP Server | Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-26
CVE-2023-42824 · CISA Known Exploited Vulnerabilities

Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

Vendor: Apple | Product: iOS and iPadOS | Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-26
CVE-2023-42793 · CISA Known Exploited Vulnerabilities

JetBrains TeamCity Authentication Bypass Vulnerability

Vendor: JetBrains | Product: TeamCity | JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-25
CVE-2023-28229 · CISA Known Exploited Vulnerabilities

Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows CNG Key Isolation Service | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-25
CVE-2023-4211 · CISA Known Exploited Vulnerabilities

Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Vendor: Arm | Product: Mali GPU Kernel Driver | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-24
CVE-2023-5217 · CISA Known Exploited Vulnerabilities

Google Chromium libvpx Heap Buffer Overflow Vulnerability

Vendor: Google | Product: Chromium libvpx | Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome. | Required action: Apply mitigations per vendor instructions or discontinue use of the…
Read full source summary
Vendor: Google | Product: Chromium libvpx | Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-23
CVE-2018-14667 · CISA Known Exploited Vulnerabilities

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Vendor: Red Hat | Product: JBoss RichFaces Framework | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. | Required action: Apply mitigations per vendor instructions…
Read full source summary
Vendor: Red Hat | Product: JBoss RichFaces Framework | Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-19
CVE-2023-41991 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Improper Certificate Validation Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-16
CVE-2023-41992 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Kernel Privilege Escalation Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-16
CVE-2023-41993 · CISA Known Exploited Vulnerabilities

Apple Multiple Products WebKit Code Execution Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply mitigations per…
Read full source summary
Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-16
CVE-2023-41179 · CISA Known Exploited Vulnerabilities

Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

Vendor: Trend Micro | Product: Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. |…
Read full source summary
Vendor: Trend Micro | Product: Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-12
CVE-2023-28434 · CISA Known Exploited Vulnerabilities

MinIO Security Feature Bypass Vulnerability

Vendor: MinIO | Product: MinIO | MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. |…
Read full source summary
Vendor: MinIO | Product: MinIO | MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-10
CVE-2022-22265 · CISA Known Exploited Vulnerabilities

Samsung Mobile Devices Use-After-Free Vulnerability

Vendor: Samsung | Product: Mobile Devices | Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-09
CVE-2014-8361 · CISA Known Exploited Vulnerabilities

Realtek SDK Improper Input Validation Vulnerability

Vendor: Realtek | Product: SDK | Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-09
CVE-2017-6884 · CISA Known Exploited Vulnerabilities

Zyxel EMG2926 Routers Command Injection Vulnerability

Vendor: Zyxel | Product: EMG2926 Routers | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | Required action: Apply mitigations per vendor instructions or…
Read full source summary
Vendor: Zyxel | Product: EMG2926 Routers | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-09
CVE-2021-3129 · CISA Known Exploited Vulnerabilities

Laravel Ignition File Upload Vulnerability

Vendor: Laravel | Product: Ignition | Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents(). | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-09
CVE-2023-26369 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-05
CVE-2023-35674 · CISA Known Exploited Vulnerabilities

Android Framework Privilege Escalation Vulnerability

Vendor: Android | Product: Framework | Android Framework contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | Federal remediation due: 2023-10-04
CVE-2023-20269 · CISA Known Exploited Vulnerabilities

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Vendor: Cisco | Product: Adaptive Security Appliance and Firepower Threat Defense | Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. |…
Read full source summary
Vendor: Cisco | Product: Adaptive Security Appliance and Firepower Threat Defense | Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. | Required action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices. | Federal remediation due: 2023-10-04
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index