Public-source reporting · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

1733 records · Collected Oct 4, 2026 · 12:08 UTCOfficial source · JSON
CVE-2018-18325 · CISA Known Exploited Vulnerabilities

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

Vendor: DotNetNuke (DNN) | Product: DotNetNuke (DNN) | DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-9822 · CISA Known Exploited Vulnerabilities

DotNetNuke (DNN) Remote Code Execution Vulnerability

Vendor: DotNetNuke (DNN) | Product: DotNetNuke (DNN) | DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-15752 · CISA Known Exploited Vulnerabilities

Docker Desktop Community Edition Privilege Escalation Vulnerability

Vendor: Docker | Product: Desktop Community Edition | Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8515 · CISA Known Exploited Vulnerabilities

Multiple DrayTek Vigor Routers Web Management Page Vulnerability

Vendor: DrayTek | Product: Multiple Vigor Routers | DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-7600 · CISA Known Exploited Vulnerabilities

Drupal Core Remote Code Execution Vulnerability

Vendor: Drupal | Product: Drupal Core | Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-22205 · CISA Known Exploited Vulnerabilities

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

Vendor: GitLab | Product: Community and Enterprise Editions | GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2018-6789 · CISA Known Exploited Vulnerabilities

Exim Buffer Overflow Vulnerability

Vendor: Exim | Product: Exim | Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8657 · CISA Known Exploited Vulnerabilities

EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

Vendor: EyesOfNetwork | Product: EyesOfNetwork | EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-8655 · CISA Known Exploited Vulnerabilities

EyesOfNetwork Improper Privilege Management Vulnerability

Vendor: EyesOfNetwork | Product: EyesOfNetwork | EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-22986 · CISA Known Exploited Vulnerabilities

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

Vendor: F5 | Product: BIG-IP and BIG-IQ Centralized Management | F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-35464 · CISA Known Exploited Vulnerabilities

ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

Vendor: ForgeRock | Product: Access Management (AM) | ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). | Required action: Apply…
Read full source summary
Vendor: ForgeRock | Product: Access Management (AM) | ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-5591 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS Default Configuration Vulnerability

Vendor: Fortinet | Product: FortiOS | Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-12812 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Vendor: Fortinet | Product: FortiOS | Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2018-13379 · CISA Known Exploited Vulnerabilities

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Vendor: Fortinet | Product: FortiOS | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-16010 · CISA Known Exploited Vulnerabilities

Google Chrome for Android UI Heap Buffer Overflow Vulnerability

Vendor: Google | Product: Chrome for Android UI | Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-15999 · CISA Known Exploited Vulnerabilities

Google Chrome FreeType Heap Buffer Overflow Vulnerability

Vendor: Google | Product: Chrome FreeType | Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. | Required action: Apply updates per vendor instructions.…
Read full source summary
Vendor: Google | Product: Chrome FreeType | Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-21166 · CISA Known Exploited Vulnerabilities

Google Chromium Race Condition Vulnerability

Vendor: Google | Product: Chromium | Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation…
Read full source summary
Vendor: Google | Product: Chromium | Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-16017 · CISA Known Exploited Vulnerabilities

Google Chrome Use-After-Free Vulnerability

Vendor: Google | Product: Chrome | Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-37976 · CISA Known Exploited Vulnerabilities

Google Chromium Information Disclosure Vulnerability

Vendor: Google | Product: Chromium | Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required…
Read full source summary
Vendor: Google | Product: Chromium | Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Archive index