Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 05:04 UTCOfficial source · JSON
CVE-2014-4404 · CISA Known Exploited Vulnerabilities

Apple OS X Heap-Based Buffer Overflow Vulnerability

Vendor: Apple | Product: OS X | Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-08-10
CVE-2022-21882 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-18
CVE-2022-22587 · CISA Known Exploited Vulnerabilities

Apple Memory Corruption Vulnerability

Vendor: Apple | Product: iOS and macOS | Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-11
CVE-2021-20038 · CISA Known Exploited Vulnerabilities

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

Vendor: SonicWall | Product: SMA 100 Appliances | SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-11
CVE-2020-5722 · CISA Known Exploited Vulnerabilities

Grandstream Networks UCM6200 Series SQL Injection Vulnerability

Vendor: Grandstream | Product: UCM6200 | Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2020-0787 · CISA Known Exploited Vulnerabilities

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2017-5689 · CISA Known Exploited Vulnerabilities

Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

Vendor: Intel | Product: Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability | Intel products contain a vulnerability which can allow attackers to perform privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2014-1776 · CISA Known Exploited Vulnerabilities

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2014-6271 · CISA Known Exploited Vulnerabilities

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

Vendor: GNU | Product: Bourne-Again Shell (Bash) | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2014-7169 · CISA Known Exploited Vulnerabilities

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

Vendor: GNU | Product: Bourne-Again Shell (Bash) | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-28
CVE-2006-1547 · CISA Known Exploited Vulnerabilities

Apache Struts 1 ActionForm Denial-of-Service Vulnerability

Vendor: Apache | Product: Struts 1 | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-21
CVE-2012-0391 · CISA Known Exploited Vulnerabilities

Apache Struts 2 Improper Input Validation Vulnerability

Vendor: Apache | Product: Struts 2 | The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-21
CVE-2018-8453 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-07-21
CVE-2021-35247 · CISA Known Exploited Vulnerabilities

SolarWinds Serv-U Improper Input Validation Vulnerability

Vendor: SolarWinds | Product: Serv-U | SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-04
CVE-2021-32648 · CISA Known Exploited Vulnerabilities

October CMS Improper Authentication

Vendor: October CMS | Product: October CMS | In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-25296 · CISA Known Exploited Vulnerabilities

Nagios XI OS Command Injection

Vendor: Nagios | Product: Nagios XI | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-25297 · CISA Known Exploited Vulnerabilities

Nagios XI OS Command Injection

Vendor: Nagios | Product: Nagios XI | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-25298 · CISA Known Exploited Vulnerabilities

Nagios XI OS Command Injection

Vendor: Nagios | Product: Nagios XI | Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-40870 · CISA Known Exploited Vulnerabilities

Aviatrix Controller Unrestricted Upload of File

Vendor: Aviatrix | Product: Aviatrix Controller | Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
CVE-2021-33766 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Information Disclosure

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-02-01
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index