Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 09:49 UTCOfficial source · JSON
CVE-2021-42013 · CISA Known Exploited Vulnerabilities

Apache HTTP Server Path Traversal Vulnerability

Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. | Required action: Apply updates per vendor instructions. |…
Read full source summary
Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-41773 · CISA Known Exploited Vulnerabilities

Apache HTTP Server Path Traversal Vulnerability

Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. |…
Read full source summary
Vendor: Apache | Product: HTTP Server | Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-0211 · CISA Known Exploited Vulnerabilities

Apache HTTP Server Privilege Escalation Vulnerability

Vendor: Apache | Product: HTTP Server | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Apache | Product: HTTP Server | Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-4437 · CISA Known Exploited Vulnerabilities

Apache Shiro Code Execution Vulnerability

Vendor: Apache | Product: Shiro | Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-17558 · CISA Known Exploited Vulnerabilities

Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability

Vendor: Apache | Product: Solr | The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-17530 · CISA Known Exploited Vulnerabilities

Apache Struts Remote Code Execution Vulnerability

Vendor: Apache | Product: Struts | Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-5638 · CISA Known Exploited Vulnerabilities

Apache Struts Remote Code Execution Vulnerability

Vendor: Apache | Product: Struts | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-11776 · CISA Known Exploited Vulnerabilities

Apache Struts Remote Code Execution Vulnerability

Vendor: Apache | Product: Struts | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same…
Read full source summary
Vendor: Apache | Product: Struts | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30858 · CISA Known Exploited Vulnerabilities

Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-6223 · CISA Known Exploited Vulnerabilities

Apple iOS and macOS Group Facetime Vulnerability

Vendor: Apple | Product: iOS and macOS | Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30860 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Integer Overflow Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-27930 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30807 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-27950 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Memory Initialization Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-27932 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Type Confusion Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-9818 · CISA Known Exploited Vulnerabilities

Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-9819 · CISA Known Exploited Vulnerabilities

Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

Vendor: Apple | Product: iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-30762 · CISA Known Exploited Vulnerabilities

Apple iOS WebKit Use-After-Free Vulnerability

Vendor: Apple | Product: iOS | Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due:…
Read full source summary
Vendor: Apple | Product: iOS | Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1782 · CISA Known Exploited Vulnerabilities

Apple Multiple Products Race Condition Vulnerability

Vendor: Apple | Product: Multiple Products | Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-1870 · CISA Known Exploited Vulnerabilities

Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal…
Read full source summary
Vendor: Apple | Product: iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index