An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2019-6340 Drupal · Core Added Mar 25, 2022

Drupal Core Remote Code Execution Vulnerability

In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-2616 Oracle · BI Publisher (Formerly XML Publisher) Added Mar 25, 2022

Oracle BI Publisher Unauthorized Access Vulnerability

Oracle BI Publisher, formerly XML Publisher, contains an unspecified vulnerability that allows for various unauthorized actions. Open-source reporting attributes this vulnerability to allowing for authentication bypass.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-16920 D-Link · Multiple Routers Added Mar 25, 2022

D-Link Multiple Routers Command Injection Vulnerability

Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-15107 Webmin · Webmin Added Mar 25, 2022

Webmin Command Injection Vulnerability

An issue was discovered in Webmin. The parameter old in password_change.cgi contains a command injection vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-12991 Citrix · SD-WAN and NetScaler Added Mar 25, 2022

Citrix SD-WAN and NetScaler Command Injection Vulnerability

Authenticated Command Injection in Citrix SD-WAN Appliance and NetScaler SD-WAN Appliance.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-12989 Citrix · SD-WAN and NetScaler Added Mar 25, 2022

Citrix SD-WAN and NetScaler SQL Injection Vulnerability

Citrix SD-WAN and NetScaler SD-WAN allow SQL Injection.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-11043 PHP · FastCGI Process Manager (FPM) Added Mar 25, 2022

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-10068 Kentico · Xperience Added Mar 25, 2022

Kentico Xperience Deserialization of Untrusted Data Vulnerability

Kentico contains a failure to validate security headers. This deserialization can led to unauthenticated remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1003030 Jenkins · Matrix Project Plugin Added Mar 25, 2022

Jenkins Matrix Project Plugin Remote Code Execution Vulnerability

Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-0903 Microsoft · Graphics Device Interface (GDI) Added Mar 25, 2022

Microsoft GDI Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8414 Microsoft · Windows Added Mar 25, 2022

Microsoft Windows Shell Remote Code Execution Vulnerability

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8373 Microsoft · Internet Explorer Scripting Engine Added Mar 25, 2022

Microsoft Scripting Engine Memory Corruption Vulnerability

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-6961 VMware · SD-WAN Edge Added Mar 25, 2022

VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-14839 LG · N1A1 NAS Added Mar 25, 2022

LG N1A1 NAS Remote Command Execution Vulnerability

LG N1A1 NAS 3718.510 is affected by a remote code execution vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-1273 VMware Tanzu · Spring Data Commons Added Mar 25, 2022

VMware Tanzu Spring Data Commons Property Binder Vulnerability

Spring Data Commons contains a property binder vulnerability which can allow an attacker to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-11138 Quest · KACE System Management Appliance Added Mar 25, 2022

Quest KACE System Management Appliance Remote Command Execution Vulnerability

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-0147 Cisco · Secure Access Control System (ACS) Added Mar 25, 2022

Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-0125 Cisco · VPN Routers Added Mar 25, 2022

Cisco VPN Routers Remote Code Execution Vulnerability

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-6334 NETGEAR · DGN2200 Devices Added Mar 25, 2022

NETGEAR DGN2200 Devices OS Command Injection Vulnerability

dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-6316 Citrix · NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN, and XenMobile Server Added Mar 25, 2022

Citrix Multiple Products Remote Code Execution Vulnerability

A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthenticated, remote attacker being able to execute arbitrary code as a root user. This vulnerability also affects XenMobile Server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-3881 Cisco · IOS and IOS XE Added Mar 25, 2022

Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-12617 Apache · Tomcat Added Mar 25, 2022

Apache Tomcat Remote Code Execution Vulnerability

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-12615 Apache · Tomcat Added Mar 25, 2022

Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0146 Microsoft · Windows Added Mar 25, 2022

Microsoft Windows SMB Remote Code Execution Vulnerability

The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-7892 Adobe · Flash Player Added Mar 25, 2022

Adobe Flash Player Use-After-Free Vulnerability

Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.