An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2025-57819 Sangoma · FreePBX Added Aug 29, 2025

Sangoma FreePBX Authentication Bypass Vulnerability

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-7775 Citrix · NetScaler Added Aug 26, 2025

Citrix NetScaler Memory Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-48384 Git · Git Added Aug 25, 2025

Git Link Following Vulnerability

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-8068 Citrix · Session Recording Added Aug 25, 2025

Citrix Session Recording Improper Privilege Management Vulnerability

Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an authenticated user in the same Windows Active Directory domain as the session recording server domain.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-8069 Citrix · Session Recording Added Aug 25, 2025

Citrix Session Recording Deserialization of Untrusted Data Vulnerability

Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Attacker must be an authenticated user on the same intranet as the session recording server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-43300 Apple · iOS, iPadOS, and macOS Added Aug 21, 2025

Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-54948 Trend Micro · Apex One Added Aug 18, 2025

Trend Micro Apex One OS Command Injection Vulnerability

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-8876 N-able · N-Central Added Aug 13, 2025

N-able N-Central Command Injection Vulnerability

N-able N-Central contains a command injection vulnerability via improper sanitization of user input.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-8875 N-able · N-Central Added Aug 13, 2025

N-able N-Central Insecure Deserialization Vulnerability

N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-8088 RARLAB · WinRAR Added Aug 12, 2025

RARLAB WinRAR Path Traversal Vulnerability

RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2007-0671 Microsoft · Office Added Aug 12, 2025

Microsoft Office Excel Remote Code Execution Vulnerability

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2013-3893 Microsoft · Internet Explorer Added Aug 12, 2025

Microsoft Internet Explorer Resource Management Errors Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-25078 D-Link · DCS-2530L and DCS-2670L Devices Added Aug 5, 2025

D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-25079 D-Link · DCS-2530L and DCS-2670L Devices Added Aug 5, 2025

D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-40799 D-Link · DNR-322L Added Aug 5, 2025

D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-2533 PaperCut · NG/MF Added Jul 28, 2025

PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-20337 Cisco · Identity Services Engine Added Jul 28, 2025

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-20281 Cisco · Identity Services Engine Added Jul 28, 2025

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-49706 Microsoft · SharePoint Added Jul 22, 2025

Microsoft SharePoint Improper Authentication Vulnerability

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-49704 Microsoft · SharePoint Added Jul 22, 2025

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-54309 CrushFTP · CrushFTP Added Jul 22, 2025

CrushFTP Unprotected Alternate Channel Vulnerability

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-2776 SysAid · SysAid On-Prem Added Jul 22, 2025

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-2775 SysAid · SysAid On-Prem Added Jul 22, 2025

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-6558 Google · Chromium Added Jul 22, 2025

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-53770 Microsoft · SharePoint Added Jul 20, 2025

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.