An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2018-14667 Red Hat · JBoss RichFaces Framework Added Sep 28, 2023

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41991 Apple · Multiple Products Added Sep 25, 2023

Apple Multiple Products Improper Certificate Validation Vulnerability

Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41992 Apple · Multiple Products Added Sep 25, 2023

Apple Multiple Products Kernel Privilege Escalation Vulnerability

Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41993 Apple · Multiple Products Added Sep 25, 2023

Apple Multiple Products WebKit Code Execution Vulnerability

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41179 Trend Micro · Apex One and Worry-Free Business Security Added Sep 21, 2023

Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-28434 MinIO · MinIO Added Sep 19, 2023

MinIO Security Feature Bypass Vulnerability

MinIO contains a security feature bypass vulnerability that allows an attacker to use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket` to conduct privilege escalation. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22265 Samsung · Mobile Devices Added Sep 18, 2023

Samsung Mobile Devices Use-After-Free Vulnerability

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-8361 Realtek · SDK Added Sep 18, 2023

Realtek SDK Improper Input Validation Vulnerability

Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-6884 Zyxel · EMG2926 Routers Added Sep 18, 2023

Zyxel EMG2926 Routers Command Injection Vulnerability

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-3129 Laravel · Ignition Added Sep 18, 2023

Laravel Ignition File Upload Vulnerability

Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-26369 Adobe · Acrobat and Reader Added Sep 14, 2023

Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-35674 Android · Framework Added Sep 13, 2023

Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-20269 Cisco · Adaptive Security Appliance and Firepower Threat Defense Added Sep 13, 2023

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-4863 Google · Chromium WebP Added Sep 13, 2023

Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36761 Microsoft · Word Added Sep 12, 2023

Microsoft Word Information Disclosure Vulnerability

Microsoft Word contains an unspecified vulnerability that allows for information disclosure.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-36802 Microsoft · Streaming Service Proxy Added Sep 12, 2023

Microsoft Streaming Service Proxy Privilege Escalation Vulnerability

Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41064 Apple · iOS, iPadOS, and macOS Added Sep 11, 2023

Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

Apple iOS, iPadOS, and macOS contain a buffer overflow vulnerability in ImageIO when processing a maliciously crafted image, which may lead to code execution. This vulnerability was chained with CVE-2023-41061.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-41061 Apple · iOS, iPadOS, and watchOS Added Sep 11, 2023

Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-33246 Apache · RocketMQ Added Sep 6, 2023

Apache RocketMQ Command Execution Vulnerability

Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as or achieve the same effect by forging the RocketMQ protocol content.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-38831 RARLAB · WinRAR Added Aug 24, 2023

RARLAB WinRAR Code Execution Vulnerability

RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-32315 Ignite Realtime · Openfire Added Aug 24, 2023

Ignite Realtime Openfire Path Traversal Vulnerability

Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-38035 Ivanti · Sentry Added Aug 22, 2023

Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-27532 Veeam · Backup & Replication Added Aug 22, 2023

Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-26359 Adobe · ColdFusion Added Aug 21, 2023

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2023-24489 Citrix · Content Collaboration Added Aug 16, 2023

Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.