An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2023-36845 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability

Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36846 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36847 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36851 Juniper · Junos OS Added Nov 13, 2023

Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability

Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-29552 IETF · Service Location Protocol (SLP) Added Nov 8, 2023

Service Location Protocol (SLP) Denial-of-Service Vulnerability

The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-22518 Atlassian · Confluence Data Center and Server Added Nov 7, 2023

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-46604 Apache · ActiveMQ Added Nov 2, 2023

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-46748 F5 · BIG-IP Configuration Utility Added Oct 31, 2023

F5 BIG-IP Configuration Utility SQL Injection Vulnerability

F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-46747 F5 · BIG-IP Configuration Utility Added Oct 31, 2023

F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-5631 Roundcube · Webmail Added Oct 26, 2023

Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability

Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that allows a remote attacker to run malicious JavaScript code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-20273 Cisco · Cisco IOS XE Web UI Added Oct 23, 2023

Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-4966 Citrix · NetScaler ADC and NetScaler Gateway Added Oct 18, 2023

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-20198 Cisco · IOS XE Web UI Added Oct 16, 2023

Cisco IOS XE Web UI Privilege Escalation Vulnerability

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-21608 Adobe · Acrobat and Reader Added Oct 10, 2023

Adobe Acrobat and Reader Use-After-Free Vulnerability

Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-20109 Cisco · IOS and IOS XE Added Oct 10, 2023

Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41763 Microsoft · Skype for Business Added Oct 10, 2023

Microsoft Skype for Business Privilege Escalation Vulnerability

Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36563 Microsoft · WordPad Added Oct 10, 2023

Microsoft WordPad Information Disclosure Vulnerability

Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-44487 IETF · HTTP/2 Added Oct 10, 2023

HTTP/2 Rapid Reset Attack Vulnerability

HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-22515 Atlassian · Confluence Data Center and Server Added Oct 5, 2023

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-40044 Progress · WS_FTP Server Added Oct 5, 2023

Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-42824 Apple · iOS and iPadOS Added Oct 5, 2023

Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

Apple iOS and iPadOS contain an unspecified vulnerability that allows for local privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-42793 JetBrains · TeamCity Added Oct 4, 2023

JetBrains TeamCity Authentication Bypass Vulnerability

JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-28229 Microsoft · Windows CNG Key Isolation Service Added Oct 4, 2023

Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-4211 Arm · Mali GPU Kernel Driver Added Oct 3, 2023

Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-5217 Google · Chromium libvpx Added Oct 2, 2023

Google Chromium libvpx Heap Buffer Overflow Vulnerability

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.