An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 14, 2026.

1,710 total bulletins 1,710 critical or high severity Source: CISA KEV + NVD
Critical CVE-2022-29499 Mitel · MiVoice Connect Added Jun 27, 2022

Mitel MiVoice Connect Data Validation Vulnerability

The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30533 Google · Chromium PopupBlocker Added Jun 27, 2022

Google Chromium PopupBlocker Security Bypass Vulnerability

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-4034 Red Hat · Polkit Added Jun 27, 2022

Red Hat Polkit Out-of-Bounds Read and Write Vulnerability

The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30983 Apple · iOS and iPadOS Added Jun 27, 2022

Apple iOS and iPadOS Buffer Overflow Vulnerability

Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3837 Apple · Multiple Products Added Jun 27, 2022

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-9907 Apple · Multiple Products Added Jun 27, 2022

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-8605 Apple · Multiple Products Added Jun 27, 2022

Apple Multiple Products Use-After-Free Vulnerability

A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-4344 Apple · Multiple Products Added Jun 27, 2022

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-30190 Microsoft · Windows Added Jun 14, 2022

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-38163 SAP · NetWeaver Added Jun 9, 2022

SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-2386 SAP · NetWeaver Added Jun 9, 2022

SAP NetWeaver SQL Injection Vulnerability

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-2388 SAP · NetWeaver Added Jun 9, 2022

SAP NetWeaver Information Disclosure Vulnerability

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7195 QNAP · Photo Station Added Jun 8, 2022

QNAP Photo Station Path Traversal Vulnerability

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7194 QNAP · Photo Station Added Jun 8, 2022

QNAP Photo Station Path Traversal Vulnerability

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7193 QNAP · QTS Added Jun 8, 2022

QNAP QTS Improper Input Validation Vulnerability

QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7192 QNAP · Photo Station Added Jun 8, 2022

QNAP Photo Station Improper Access Control Vulnerability

QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-5825 Google · Chromium V8 Added Jun 8, 2022

Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-15271 Cisco · RV Series Routers Added Jun 8, 2022

Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-6065 Google · Chromium V8 Added Jun 8, 2022

Google Chromium V8 Integer Overflow Vulnerability

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-4990 Adobe · Acrobat and Reader Added Jun 8, 2022

Adobe Acrobat and Reader Double Free Vulnerability

Adobe Acrobat and Reader have a double free vulnerability that could lead to remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-17480 Google · Chromium V8 Added Jun 8, 2022

Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-17463 Google · Chromium V8 Added Jun 8, 2022

Google Chromium V8 Remote Code Execution Vulnerability

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-6862 NETGEAR · Multiple Devices Added Jun 8, 2022

NETGEAR Multiple Devices Buffer Overflow Vulnerability

Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-5070 Google · Chromium V8 Added Jun 8, 2022

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-5030 Google · Chromium V8 Added Jun 8, 2022

Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.