Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 3, 2026 · 18:20 UTCOfficial source · JSON
CVE-2022-26904 · CISA Known Exploited Vulnerabilities

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2022-21919 · CISA Known Exploited Vulnerabilities

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2022-0847 · CISA Known Exploited Vulnerabilities

Linux Kernel Privilege Escalation Vulnerability

Vendor: Linux | Product: Kernel | Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2021-41357 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2021-40450 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2019-1003029 · CISA Known Exploited Vulnerabilities

Jenkins Script Security Plugin Sandbox Bypass Vulnerability

Vendor: Jenkins | Product: Script Security Plugin | Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-16
CVE-2018-6882 · CISA Known Exploited Vulnerabilities

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Vendor: Synacor | Product: Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-10
CVE-2019-3568 · CISA Known Exploited Vulnerabilities

WhatsApp VOIP Stack Buffer Overflow Vulnerability

Vendor: Meta Platforms | Product: WhatsApp | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-10
CVE-2022-22718 · CISA Known Exploited Vulnerabilities

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-10
CVE-2022-22960 · CISA Known Exploited Vulnerabilities

VMware Multiple Products Privilege Escalation Vulnerability

Vendor: VMware | Product: Multiple Products | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2022-1364 · CISA Known Exploited Vulnerabilities

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Google | Product: Chromium V8 | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2019-3929 · CISA Known Exploited Vulnerabilities

Crestron Multiple Products Command Injection Vulnerability

Vendor: Crestron | Product: Multiple Products | Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2019-16057 · CISA Known Exploited Vulnerabilities

D-Link DNS-320 Remote Code Execution Vulnerability

Vendor: D-Link | Product: DNS-320 Storage Device | The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-06
CVE-2018-7841 · CISA Known Exploited Vulnerabilities

Schneider Electric U.motion Builder SQL Injection Vulnerability

Vendor: Schneider Electric | Product: U.motion Builder | A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-06
CVE-2016-4523 · CISA Known Exploited Vulnerabilities

Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

Vendor: Trihedral | Product: VTScada (formerly VTS) | The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2014-0780 · CISA Known Exploited Vulnerabilities

InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

Vendor: InduSoft | Product: Web Studio | InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2010-5330 · CISA Known Exploited Vulnerabilities

Ubiquiti AirOS Command Injection Vulnerability

Vendor: Ubiquiti | Product: AirOS | Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2007-3010 · CISA Known Exploited Vulnerabilities

Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

Vendor: Alcatel | Product: OmniPCX Enterprise | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-06
CVE-2022-24521 · CISA Known Exploited Vulnerabilities

Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-04
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index