An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 14, 2026.

1,710 total bulletins 1,710 critical or high severity Source: CISA KEV + NVD
Critical CVE-2022-22954 VMware · Workspace ONE Access and Identity Manager Added Apr 14, 2022

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-24521 Microsoft · Windows Added Apr 13, 2022

Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-7602 Drupal · Core Added Apr 13, 2022

Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-20753 Kaseya · Virtual System/Server Administrator (VSA) Added Apr 13, 2022

Kaseya VSA Remote Code Execution Vulnerability

Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-5123 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-5122 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player allows remote attackers to execute code or cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-3113 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-2502 Microsoft · Internet Explorer Added Apr 13, 2022

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-0313 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-0311 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-9163 Adobe · Flash Player Added Apr 13, 2022

Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-23176 WatchGuard · Firebox and XTM Added Apr 11, 2022

WatchGuard Firebox and XTM Privilege Escalation Vulnerability

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-42287 Microsoft · Active Directory Added Apr 11, 2022

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-42278 Microsoft · Active Directory Added Apr 11, 2022

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-39793 Google · Pixel Added Apr 11, 2022

Google Pixel Out-of-Bounds Write Vulnerability

Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-27852 Checkbox · Checkbox Survey Added Apr 11, 2022

Checkbox Survey Deserialization of Untrusted Data Vulnerability

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22600 Linux · Kernel Added Apr 11, 2022

Linux Kernel Privilege Escalation Vulnerability

Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-2509 QNAP · QNAP Network-Attached Storage (NAS) Added Apr 11, 2022

QNAP Network-Attached Storage (NAS) Command Injection Vulnerability

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-11317 Telerik · User Interface (UI) for ASP.NET AJAX Added Apr 11, 2022

Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-3156 Sudo · Sudo Added Apr 6, 2022

Sudo Heap-Based Buffer Overflow Vulnerability

Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-31166 Microsoft · HTTP Protocol Stack Added Apr 6, 2022

Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0148 Microsoft · SMBv1 server Added Apr 6, 2022

Microsoft SMBv1 Server Remote Code Execution Vulnerability

The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22965 VMware · Spring Framework Added Apr 4, 2022

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22675 Apple · macOS Added Apr 4, 2022

Apple macOS Out-of-Bounds Write Vulnerability

macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22674 Apple · macOS Added Apr 4, 2022

Apple macOS Out-of-Bounds Read Vulnerability

macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.