An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2021-28799 QNAP · Network Attached Storage (NAS) Added Mar 31, 2022

QNAP NAS Improper Authorization Vulnerability

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21551 Dell · dbutil Driver Added Mar 31, 2022

Dell dbutil Driver Insufficient Access Control Vulnerability

Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service (DoS), or information disclosure.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-10562 Dasan · Gigabit Passive Optical Network (GPON) Routers Added Mar 31, 2022

Dasan GPON Routers Command Injection Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-10561 Dasan · Gigabit Passive Optical Network (GPON) Routers Added Mar 31, 2022

Dasan GPON Routers Authentication Bypass Vulnerability

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-1096 Google · Chromium V8 Added Mar 28, 2022

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-0543 Redis · Debian-specific Redis Servers Added Mar 28, 2022

Debian-specific Redis Server Lua Sandbox Escape Vulnerability

Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-38646 Microsoft · Office Added Mar 28, 2022

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-34486 Microsoft · Windows Added Mar 28, 2022

Microsoft Windows Event Tracing Privilege Escalation Vulnerability

Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-26085 Atlassian · Confluence Server Added Mar 28, 2022

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20028 SonicWall · Secure Remote Access (SRA) Added Mar 28, 2022

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-7483 SonicWall · SMA100 Added Mar 28, 2022

SonicWall SMA100 Directory Traversal Vulnerability

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8440 Microsoft · Windows Added Mar 28, 2022

Microsoft Windows Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8406 Microsoft · DirectX Graphics Kernel (DXGKRNL) Added Mar 28, 2022

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8405 Microsoft · DirectX Graphics Kernel (DXGKRNL) Added Mar 28, 2022

Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0213 Microsoft · Windows Added Mar 28, 2022

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0059 Microsoft · Internet Explorer Added Mar 28, 2022

Microsoft Internet Explorer Information Disclosure Vulnerability

Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0037 Microsoft · Edge and Internet Explorer Added Mar 28, 2022

Microsoft Edge and Internet Explorer Type Confusion Vulnerability

Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-7201 Microsoft · Edge Added Mar 28, 2022

Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-7200 Microsoft · Edge Added Mar 28, 2022

Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-0189 Microsoft · Internet Explorer Added Mar 28, 2022

Microsoft Internet Explorer Memory Corruption Vulnerability

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-0151 Microsoft · Client-Server Run-time Subsystem (CSRSS) Added Mar 28, 2022

Microsoft Windows CSRSS Security Feature Bypass Vulnerability

The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-0040 Microsoft · Windows Added Mar 28, 2022

Microsoft Windows Kernel Privilege Escalation Vulnerability

The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-2426 Microsoft · Windows Added Mar 28, 2022

Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-2419 Microsoft · Internet Explorer Added Mar 28, 2022

Microsoft Internet Explorer Memory Corruption Vulnerability

JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-1770 Microsoft · Office Added Mar 28, 2022

Microsoft Office Uninitialized Memory Use Vulnerability

Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.