An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2024-48248 NAKIVO · Backup and Replication Added Mar 19, 2025

NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-1316 Edimax · IC-7100 IP Camera Added Mar 19, 2025

Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-30066 tj-actions · changed-files GitHub Action Added Mar 18, 2025

tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24472 Fortinet · FortiOS and FortiProxy Added Mar 18, 2025

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-21590 Juniper · Junos OS Added Mar 13, 2025

Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24201 Apple · Multiple Products Added Mar 13, 2025

Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24993 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24991 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24985 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24984 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24983 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-26633 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-13161 Ivanti · Endpoint Manager (EPM) Added Mar 10, 2025

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-13160 Ivanti · Endpoint Manager (EPM) Added Mar 10, 2025

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-13159 Ivanti · Endpoint Manager (EPM) Added Mar 10, 2025

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-57968 Advantive · VeraCore Added Mar 10, 2025

Advantive VeraCore Unrestricted File Upload Vulnerability

Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-25181 Advantive · VeraCore Added Mar 10, 2025

Advantive VeraCore SQL Injection Vulnerability

Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-22226 VMware · ESXi, Workstation, and Fusion Added Mar 4, 2025

VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-22225 VMware · ESXi Added Mar 4, 2025

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-22224 VMware · ESXi and Workstation Added Mar 4, 2025

VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-50302 Linux · Kernel Added Mar 4, 2025

Linux Kernel Use of Uninitialized Resource Vulnerability

The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-4885 Progress · WhatsUp Gold Added Mar 3, 2025

Progress WhatsUp Gold Path Traversal Vulnerability

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8639 Microsoft · Windows Added Mar 3, 2025

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-43769 Hitachi Vantara · Pentaho Business Analytics (BA) Server Added Mar 3, 2025

Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-43939 Hitachi Vantara · Pentaho Business Analytics (BA) Server Added Mar 3, 2025

Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.