An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2021-32030 ASUS · Routers Added Jun 2, 2025

ASUS Routers Improper Authentication Vulnerability

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-3935 ConnectWise · ScreenConnect Added Jun 2, 2025

ConnectWise ScreenConnect Improper Authentication Vulnerability

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-35939 Craft CMS · Craft CMS Added Jun 2, 2025

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-56145 Craft CMS · Craft CMS Added Jun 2, 2025

Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-39780 ASUS · RT-AX55 Routers Added Jun 2, 2025

ASUS RT-AX55 Routers OS Command Injection Vulnerability

ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-4632 Samsung · MagicINFO 9 Server Added May 22, 2025

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-38950 ZKTeco · BioTime Added May 19, 2025

ZKTeco BioTime Path Traversal Vulnerability

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-27443 Synacor · Zimbra Collaboration Suite (ZCS) Added May 19, 2025

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-27920 Srimax · Output Messenger Added May 19, 2025

Srimax Output Messenger Directory Traversal Vulnerability

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-11182 MDaemon · Email Server Added May 19, 2025

MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-4428 Ivanti · Endpoint Manager Mobile (EPMM) Added May 19, 2025

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-4427 Ivanti · Endpoint Manager Mobile (EPMM) Added May 19, 2025

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-42999 SAP · NetWeaver Added May 15, 2025

SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-12987 DrayTek · Vigor Routers Added May 15, 2025

DrayTek Vigor Routers OS Command Injection Vulnerability

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-32756 Fortinet · Multiple Products Added May 14, 2025

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-32709 Microsoft · Windows Added May 13, 2025

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-30397 Microsoft · Windows Added May 13, 2025

Microsoft Windows Scripting Engine Type Confusion Vulnerability

Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-32706 Microsoft · Windows Added May 13, 2025

Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-32701 Microsoft · Windows Added May 13, 2025

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-30400 Microsoft · Windows Added May 13, 2025

Microsoft Windows DWM Core Library Use-After-Free Vulnerability

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-47729 TeleMessage · TM SGNL Added May 12, 2025

TeleMessage TM SGNL Hidden Functionality Vulnerability

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-11120 GeoVision · Multiple Devices Added May 7, 2025

GeoVision Devices OS Command Injection Vulnerability

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-6047 GeoVision · Multiple Devices Added May 7, 2025

GeoVision Devices OS Command Injection Vulnerability

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-27363 FreeType · FreeType Added May 6, 2025

FreeType Out-of-Bounds Write Vulnerability

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-3248 Langflow · Langflow Added May 5, 2025

Langflow Missing Authentication Vulnerability

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.