Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 00:06 UTCOfficial source · JSON
CVE-2018-8120 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2017-0101 · CISA Known Exploited Vulnerabilities

Microsoft Windows Transaction Manager Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2016-3309 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2015-2546 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Memory Corruption Vulnerability

Vendor: Microsoft | Product: Win32k | The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-04-05
CVE-2022-26486 · CISA Known Exploited Vulnerabilities

Mozilla Firefox Use-After-Free Vulnerability

Vendor: Mozilla | Product: Firefox | Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-21
CVE-2022-26485 · CISA Known Exploited Vulnerabilities

Mozilla Firefox Use-After-Free Vulnerability

Vendor: Mozilla | Product: Firefox | Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-21
CVE-2021-21973 · CISA Known Exploited Vulnerabilities

VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

Vendor: VMware | Product: vCenter Server and Cloud Foundation | VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-21
CVE-2020-8218 · CISA Known Exploited Vulnerabilities

Pulse Connect Secure Code Injection Vulnerability

Vendor: Pulse Secure | Product: Pulse Connect Secure | A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2019-11581 · CISA Known Exploited Vulnerabilities

Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability

Vendor: Atlassian | Product: Jira Server and Data Center | Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2017-6077 · CISA Known Exploited Vulnerabilities

NETGEAR DGN2200 Remote Code Execution Vulnerability

Vendor: NETGEAR | Product: Wireless Router DGN2200 | NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2016-6277 · CISA Known Exploited Vulnerabilities

NETGEAR Multiple Routers Remote Code Execution Vulnerability

Vendor: NETGEAR | Product: Multiple Routers | NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2013-0631 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Information Disclosure Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2013-0629 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Directory Traversal Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2013-0625 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Authentication Bypass Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2009-3960 · CISA Known Exploited Vulnerabilities

Adobe BlazeDS Information Disclosure Vulnerability

Vendor: Adobe | Product: BlazeDS | Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-09-07
CVE-2022-20708 · CISA Known Exploited Vulnerabilities

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).…
Read full source summary
Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2022-20703 · CISA Known Exploited Vulnerabilities

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).…
Read full source summary
Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2022-20701 · CISA Known Exploited Vulnerabilities

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).…
Read full source summary
Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2022-20700 · CISA Known Exploited Vulnerabilities

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).…
Read full source summary
Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
CVE-2022-20699 · CISA Known Exploited Vulnerabilities

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).…
Read full source summary
Vendor: Cisco | Product: Small Business RV160, RV260, RV340, and RV345 Series Routers | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-17
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index