An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2015-5123 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-5122 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-3113 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-2502 Microsoft · Internet Explorer Added Apr 13, 2022

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-0313 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-0311 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-9163 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-23176 WatchGuard · Firebox and XTM Added Apr 11, 2022

WatchGuard Firebox and XTM Privilege Escalation Vulnerability

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-42287 Microsoft · Active Directory Added Apr 11, 2022

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-42278 Microsoft · Active Directory Added Apr 11, 2022

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-39793 Google · Pixel Added Apr 11, 2022

Google Pixel Out-of-Bounds Write Vulnerability

Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-27852 Checkbox · Checkbox Survey Added Apr 11, 2022

Checkbox Survey Deserialization of Untrusted Data Vulnerability

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22600 Linux · Kernel Added Apr 11, 2022

Linux Kernel Privilege Escalation Vulnerability

Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-2509 QNAP · QNAP Network-Attached Storage (NAS) Added Apr 11, 2022

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-11317 Telerik · User Interface (UI) for ASP.NET AJAX Added Apr 11, 2022

Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-3156 Sudo · Sudo Added Apr 6, 2022

Sudo Heap-Based Buffer Overflow Vulnerability

Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-31166 Microsoft · HTTP Protocol Stack Added Apr 6, 2022

Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0148 Microsoft · SMBv1 server Added Apr 6, 2022

Microsoft SMBv1 Server Remote Code Execution Vulnerability

The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22965 VMware · Spring Framework Added Apr 4, 2022

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22675 Apple · macOS Added Apr 4, 2022

Apple macOS Out-of-Bounds Write Vulnerability

macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22674 Apple · macOS Added Apr 4, 2022

Apple macOS Out-of-Bounds Read Vulnerability

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-45382 D-Link · Multiple Routers Added Apr 4, 2022

D-Link Multiple Routers Remote Code Execution Vulnerability

A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-26871 Trend Micro · Apex Central Added Mar 31, 2022

Trend Micro Apex Central Arbitrary File Upload Vulnerability

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-1040 Sophos · Firewall Added Mar 31, 2022

Sophos Firewall Authentication Bypass Vulnerability

An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-34484 Microsoft · Windows Added Mar 31, 2022

Microsoft Windows User Profile Service Privilege Escalation Vulnerability

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.