Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 02:48 UTCOfficial source · JSON
CVE-2015-2387 · CISA Known Exploited Vulnerabilities

Microsoft ATM Font Driver Privilege Escalation Vulnerability

Vendor: Microsoft | Product: ATM Font Driver | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-1701 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2015-1642 · CISA Known Exploited Vulnerabilities

Microsoft Office Memory Corruption Vulnerability

Vendor: Microsoft | Product: Office | Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2014-4114 · CISA Known Exploited Vulnerabilities

Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2014-0496 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Use-After-Free Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-5065 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-3897 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Use-After-Free Vulnerability

Vendor: Microsoft | Product: Internet Explorer | A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-3346 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Memory Corruption Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-1675 · CISA Known Exploited Vulnerabilities

Mozilla Firefox Information Disclosure Vulnerability

Vendor: Mozilla | Product: Firefox | Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-1347 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Internet Explorer | This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-0641 · CISA Known Exploited Vulnerabilities

Adobe Reader Buffer Overflow Vulnerability

Vendor: Adobe | Product: Reader | A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-0640 · CISA Known Exploited Vulnerabilities

Adobe Reader and Acrobat Memory Corruption Vulnerability

Vendor: Adobe | Product: Reader and Acrobat | An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2013-0632 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Authentication Bypass Vulnerability

Vendor: Adobe | Product: ColdFusion | An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2012-1856 · CISA Known Exploited Vulnerabilities

Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Office | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2012-1723 · CISA Known Exploited Vulnerabilities

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle | Product: Java SE | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2012-1535 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Arbitrary Code Execution Vulnerability

Vendor: Adobe | Product: Flash Player | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-03-24
CVE-2012-0507 · CISA Known Exploited Vulnerabilities

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle | Product: Java SE | An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2011-3544 · CISA Known Exploited Vulnerabilities

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle | Product: Java SE JDK and JRE | An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
CVE-2011-1889 · CISA Known Exploited Vulnerabilities

Microsoft Forefront TMG Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Forefront Threat Management Gateway (TMG) | A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-03-24
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index