An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2016-4171 Adobe · Flash Player Added Mar 25, 2022

Adobe Flash Player Remote Code Execution Vulnerability

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-1555 NETGEAR · Wireless Access Point (WAP) Devices Added Mar 25, 2022

NETGEAR Multiple WAP Devices Command Injection Vulnerability

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-11021 D-Link · DCS-930L Devices Added Mar 25, 2022

D-Link DCS-930L Devices OS Command Injection Vulnerability

setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-10174 NETGEAR · WNR2000v5 Router Added Mar 25, 2022

NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-0752 Rails · Ruby on Rails Added Mar 25, 2022

Ruby on Rails Directory Traversal Vulnerability

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-4068 Arcserve · Unified Data Protection (UDP) Added Mar 25, 2022

Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-3035 TP-Link · Multiple Archer Devices Added Mar 25, 2022

TP-Link Multiple Archer Devices Directory Traversal Vulnerability

Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-1427 Elastic · Elasticsearch Added Mar 25, 2022

Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-1187 D-Link and TRENDnet · Multiple Devices Added Mar 25, 2022

D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-0666 Cisco · Prime Data Center Network Manager (DCNM) Added Mar 25, 2022

Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-6332 Microsoft · Windows Added Mar 25, 2022

Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-6324 Microsoft · Kerberos Key Distribution Center (KDC) Added Mar 25, 2022

Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-6287 Rejetto · HTTP File Server (HFS) Added Mar 25, 2022

Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-3120 Elastic · Elasticsearch Added Mar 25, 2022

Elasticsearch Remote Code Execution Vulnerability

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-0130 Rails · Ruby on Rails Added Mar 25, 2022

Ruby on Rails Directory Traversal Vulnerability

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2013-5223 D-Link · DSL-2760U Added Mar 25, 2022

D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2013-4810 Hewlett Packard (HP) · ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management Added Mar 25, 2022

HP Multiple Products Remote Code Execution Vulnerability

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2013-2251 Apache · Struts Added Mar 25, 2022

Apache Struts Improper Input Validation Vulnerability

Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-1823 PHP · PHP Added Mar 25, 2022

PHP-CGI Query String Parameter Vulnerability

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-4345 Exim · Exim Added Mar 25, 2022

Exim Privilege Escalation Vulnerability

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-4344 Exim · Exim Added Mar 25, 2022

Exim Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-3035 Cisco · IOS XR Added Mar 25, 2022

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2010-2861 Adobe · ColdFusion Added Mar 25, 2022

Adobe ColdFusion Directory Traversal Vulnerability

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2009-2055 Cisco · IOS XR Added Mar 25, 2022

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2009-1151 phpMyAdmin · phpMyAdmin Added Mar 25, 2022

phpMyAdmin Remote Code Execution Vulnerability

Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.