Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 09:01 UTCOfficial source · JSON
CVE-2021-40438 · CISA Known Exploited Vulnerabilities

Apache HTTP Server-Side Request Forgery (SSRF)

Vendor: Apache | Product: Apache | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-15
CVE-2021-44077 · CISA Known Exploited Vulnerabilities

Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

Vendor: Zoho | Product: ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-15
CVE-2021-22204 · CISA Known Exploited Vulnerabilities

ExifTool Remote Code Execution Vulnerability

Vendor: Perl | Product: Exiftool | Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-40449 · CISA Known Exploited Vulnerabilities

Microsoft Windows Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Unspecified vulnerability allows for an authenticated user to escalate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-42321 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Exchange | An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-42292 · CISA Known Exploited Vulnerabilities

Microsoft Excel Security Feature Bypass

Vendor: Microsoft | Product: Office | A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-12-01
CVE-2021-27104 · CISA Known Exploited Vulnerabilities

Accellion FTA OS Command Injection Vulnerability

Vendor: Accellion | Product: FTA | Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27102 · CISA Known Exploited Vulnerabilities

Accellion FTA OS Command Injection Vulnerability

Vendor: Accellion | Product: FTA | Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27101 · CISA Known Exploited Vulnerabilities

Accellion FTA SQL Injection Vulnerability

Vendor: Accellion | Product: FTA | Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-27103 · CISA Known Exploited Vulnerabilities

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Vendor: Accellion | Product: FTA | Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-21017 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-28550 · CISA Known Exploited Vulnerabilities

Adobe Acrobat and Reader Use-After-Free Vulnerability

Vendor: Adobe | Product: Acrobat and Reader | Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2018-4939 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-15961 · CISA Known Exploited Vulnerabilities

Adobe ColdFusion Unrestricted File Upload Vulnerability

Vendor: Adobe | Product: ColdFusion | Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-4878 · CISA Known Exploited Vulnerabilities

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe | Product: Flash Player | Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution. | Required action: The impacted product is end-of-life and should be disconnected if still in use. | Federal remediation due: 2022-05-03
CVE-2020-5735 · CISA Known Exploited Vulnerabilities

Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Vendor: Amcrest | Product: Cameras and Network Video Recorder (NVR) | Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-2215 · CISA Known Exploited Vulnerabilities

Android Kernel Use-After-Free Vulnerability

Vendor: Android | Product: Android Kernel | Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0041 · CISA Known Exploited Vulnerabilities

Android Kernel Out-of-Bounds Write Vulnerability

Vendor: Android | Product: Android Kernel | Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Android | Product: Android Kernel | Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0069 · CISA Known Exploited Vulnerabilities

Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

Vendor: MediaTek | Product: Multiple Chipsets | Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." | Required action: Apply…
Read full source summary
Vendor: MediaTek | Product: Multiple Chipsets | Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu." | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-9805 · CISA Known Exploited Vulnerabilities

Apache Struts Deserialization of Untrusted Data Vulnerability

Vendor: Apache | Product: Struts | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index