An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2014-0322 Microsoft · Internet Explorer Added May 4, 2022

Microsoft Internet Explorer Use-After-Free Vulnerability

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-0160 OpenSSL · OpenSSL Added May 4, 2022

OpenSSL Information Disclosure Vulnerability

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-29464 WSO2 · Multiple Products Added Apr 25, 2022

WSO2 Multiple Products Unrestrictive Upload of File Vulnerability

Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-26904 Microsoft · Windows Added Apr 25, 2022

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-21919 Microsoft · Windows Added Apr 25, 2022

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-0847 Linux · Kernel Added Apr 25, 2022

Linux Kernel Privilege Escalation Vulnerability

Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe."

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-41357 Microsoft · Win32k Added Apr 25, 2022

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-40450 Microsoft · Win32k Added Apr 25, 2022

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1003029 Jenkins · Script Security Plugin Added Apr 25, 2022

Jenkins Script Security Plugin Sandbox Bypass Vulnerability

Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-6882 Synacor · Zimbra Collaboration Suite (ZCS) Added Apr 19, 2022

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-3568 Meta Platforms · WhatsApp Added Apr 19, 2022

WhatsApp VOIP Stack Buffer Overflow Vulnerability

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target phone number.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22718 Microsoft · Windows Added Apr 19, 2022

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22960 VMware · Multiple Products Added Apr 15, 2022

VMware Multiple Products Privilege Escalation Vulnerability

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-1364 Google · Chromium V8 Added Apr 15, 2022

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-3929 Crestron · Multiple Products Added Apr 15, 2022

Crestron Multiple Products Command Injection Vulnerability

Multiple Crestron products are vulnerable to command injection via the file_transfer.cgi HTTP endpoint. A remote, unauthenticated attacker can use this vulnerability to execute operating system commands as root.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-16057 D-Link · DNS-320 Storage Device Added Apr 15, 2022

D-Link DNS-320 Remote Code Execution Vulnerability

The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-7841 Schneider Electric · U.motion Builder Added Apr 15, 2022

Schneider Electric U.motion Builder SQL Injection Vulnerability

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-4523 Trihedral · VTScada (formerly VTS) Added Apr 15, 2022

Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-0780 InduSoft · Web Studio Added Apr 15, 2022

InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-5330 Ubiquiti · AirOS Added Apr 15, 2022

Ubiquiti AirOS Command Injection Vulnerability

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2007-3010 Alcatel · OmniPCX Enterprise Added Apr 15, 2022

Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22954 VMware · Workspace ONE Access and Identity Manager Added Apr 14, 2022

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-24521 Microsoft · Windows Added Apr 13, 2022

Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-7602 Drupal · Core Added Apr 13, 2022

Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-20753 Kaseya · Virtual System/Server Administrator (VSA) Added Apr 13, 2022

Kaseya VSA Remote Code Execution Vulnerability

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.