An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2023-20118 Cisco · Small Business RV Series Routers Added Mar 3, 2025

Cisco Small Business RV Series Routers Command Injection Vulnerability

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-34192 Synacor · Zimbra Collaboration Suite (ZCS) Added Feb 25, 2025

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-49035 Microsoft · Partner Center Added Feb 25, 2025

Microsoft Partner Center Improper Access Control Vulnerability

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-20953 Oracle · Agile Product Lifecycle Management (PLM) Added Feb 24, 2025

Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-3066 Adobe · ColdFusion Added Feb 24, 2025

Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24989 Microsoft · Power Pages Added Feb 21, 2025

Microsoft Power Pages Improper Access Control Vulnerability

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-0111 Palo Alto Networks · PAN-OS Added Feb 20, 2025

Palo Alto Networks PAN-OS File Read Vulnerability

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-23209 Craft CMS · Craft CMS Added Feb 20, 2025

Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-0108 Palo Alto Networks · PAN-OS Added Feb 18, 2025

Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management web interface to bypass the authentication normally required and invoke certain PHP scripts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-53704 SonicWall · SonicOS Added Feb 18, 2025

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-57727 SimpleHelp · SimpleHelp Added Feb 13, 2025

SimpleHelp Path Traversal Vulnerability

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24200 Apple · iOS and iPadOS Added Feb 12, 2025

Apple iOS and iPadOS Incorrect Authorization Vulnerability

Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-41710 Mitel · SIP Phones Added Feb 12, 2025

Mitel SIP Phones Argument Injection Vulnerability

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-40891 Zyxel · DSL CPE Devices Added Feb 11, 2025

Zyxel DSL CPE OS Command Injection Vulnerability

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-40890 Zyxel · DSL CPE Devices Added Feb 11, 2025

Zyxel DSL CPE OS Command Injection Vulnerability

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-21418 Microsoft · Windows Added Feb 11, 2025

Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-21391 Microsoft · Windows Added Feb 11, 2025

Microsoft Windows Storage Link Following Vulnerability

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-0994 Trimble · Cityworks Added Feb 7, 2025

Trimble Cityworks Deserialization Vulnerability

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-15069 Sophos · XG Firewall Added Feb 6, 2025

Sophos XG Firewall Buffer Overflow Vulnerability

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-29574 Sophos · CyberoamOS Added Feb 6, 2025

CyberoamOS (CROS) SQL Injection Vulnerability

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-21413 Microsoft · Office Outlook Added Feb 6, 2025

Microsoft Outlook Improper Input Validation Vulnerability

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-23748 Audinate · Dante Discovery Added Feb 6, 2025

Dante Discovery Process Control Vulnerability

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-0411 7-Zip · 7-Zip Added Feb 6, 2025

7-Zip Mark of the Web Bypass Vulnerability

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-53104 Linux · Kernel Added Feb 5, 2025

Linux Kernel Out-of-Bounds Write Vulnerability

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-19410 Paessler · PRTG Network Monitor Added Feb 4, 2025

Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.