An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 11, 2026.

1,709 total bulletins 1,709 critical or high severity Source: CISA KEV + NVD
Critical CVE-2019-9874 Sitecore · CMS and Experience Platform (XP) Added Mar 26, 2025

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-30154 reviewdog · action-setup GitHub Action Added Mar 24, 2025

reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-12637 SAP · NetWeaver Added Mar 19, 2025

SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-48248 NAKIVO · Backup and Replication Added Mar 19, 2025

NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-1316 Edimax · IC-7100 IP Camera Added Mar 19, 2025

Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-30066 tj-actions · changed-files GitHub Action Added Mar 18, 2025

tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24472 Fortinet · FortiOS and FortiProxy Added Mar 18, 2025

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-21590 Juniper · Junos OS Added Mar 13, 2025

Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24201 Apple · Multiple Products Added Mar 13, 2025

Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24993 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24991 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24985 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24984 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-24983 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-26633 Microsoft · Windows Added Mar 11, 2025

Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-13161 Ivanti · Endpoint Manager (EPM) Added Mar 10, 2025

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-13160 Ivanti · Endpoint Manager (EPM) Added Mar 10, 2025

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-13159 Ivanti · Endpoint Manager (EPM) Added Mar 10, 2025

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-57968 Advantive · VeraCore Added Mar 10, 2025

Advantive VeraCore Unrestricted File Upload Vulnerability

Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-25181 Advantive · VeraCore Added Mar 10, 2025

Advantive VeraCore SQL Injection Vulnerability

Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-22226 VMware · ESXi, Workstation, and Fusion Added Mar 4, 2025

VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-22225 VMware · ESXi Added Mar 4, 2025

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2025-22224 VMware · ESXi and Workstation Added Mar 4, 2025

VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-50302 Linux · Kernel Added Mar 4, 2025

Linux Kernel Use of Uninitialized Resource Vulnerability

The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-4885 Progress · WhatsUp Gold Added Mar 3, 2025

Progress WhatsUp Gold Path Traversal Vulnerability

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.