An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2024-30051 Microsoft · DWM Core Library Added May 14, 2024

Microsoft DWM Core Library Privilege Escalation Vulnerability

Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-4671 Google · Chromium Added May 13, 2024

Google Chromium Visuals Use-After-Free Vulnerability

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-7028 GitLab · GitLab CE/EE Added May 1, 2024

GitLab Community and Enterprise Editions Improper Access Control Vulnerability

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-29988 Microsoft · SmartScreen Prompt Added Apr 30, 2024

Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-4040 CrushFTP · CrushFTP Added Apr 24, 2024

CrushFTP VFS Sandbox Escape Vulnerability

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-20359 Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Added Apr 24, 2024

Cisco ASA and FTD Privilege Escalation Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-20353 Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Added Apr 24, 2024

Cisco ASA and FTD Denial of Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-38028 Microsoft · Windows Added Apr 23, 2024

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-3400 Palo Alto Networks · PAN-OS Added Apr 12, 2024

Palo Alto Networks PAN-OS Command Injection Vulnerability

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-3273 D-Link · Multiple NAS Devices Added Apr 11, 2024

D-Link Multiple NAS Devices Command Injection Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-3272 D-Link · Multiple NAS Devices Added Apr 11, 2024

D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-29748 Android · Pixel Added Apr 4, 2024

Android Pixel Privilege Escalation Vulnerability

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-29745 Android · Pixel Added Apr 4, 2024

Android Pixel Information Disclosure Vulnerability

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-24955 Microsoft · SharePoint Server Added Mar 26, 2024

Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7256 Nice · Linear eMerge E3-Series Added Mar 25, 2024

Nice Linear eMerge E3-Series OS Command Injection Vulnerability

Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-44529 Ivanti · Endpoint Manager Cloud Service Appliance (EPM CSA) Added Mar 25, 2024

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-48788 Fortinet · FortiClient EMS Added Mar 25, 2024

Fortinet FortiClient EMS SQL Injection Vulnerability

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-27198 JetBrains · TeamCity Added Mar 7, 2024

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-23225 Apple · Multiple Products Added Mar 6, 2024

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-23296 Apple · Multiple Products Added Mar 6, 2024

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-21237 Android · Pixel Added Mar 5, 2024

Android Pixel Information Disclosure Vulnerability

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-36380 Sunhillo · SureLine Added Mar 5, 2024

Sunhillo SureLine OS Command Injection Vulnerablity

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-21338 Microsoft · Windows Added Mar 4, 2024

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-29360 Microsoft · Streaming Service Added Feb 29, 2024

Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2024-1709 ConnectWise · ScreenConnect Added Feb 22, 2024

ConnectWise ScreenConnect Authentication Bypass Vulnerability

ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.