Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.

1,619 total bulletins 1,619 critical or high severity Source: CISA KEV + NVD
Critical CVE-2014-7169 GNU · Bourne-Again Shell (Bash) Added Jan 28, 2022

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2006-1547 Apache · Struts 1 Added Jan 21, 2022

Apache Struts 1 ActionForm Denial-of-Service Vulnerability

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-0391 Apache · Struts 2 Added Jan 21, 2022

Apache Struts 2 Improper Input Validation Vulnerability

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8453 Microsoft · Win32k Added Jan 21, 2022

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-35247 SolarWinds · Serv-U Added Jan 21, 2022

SolarWinds Serv-U Improper Input Validation Vulnerability

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-32648 October CMS · October CMS Added Jan 18, 2022

October CMS Improper Authentication

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25296 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25297 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25298 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-40870 Aviatrix · Aviatrix Controller Added Jan 18, 2022

Aviatrix Controller Unrestricted Upload of File

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-33766 Microsoft · Exchange Server Added Jan 18, 2022

Microsoft Exchange Server Information Disclosure

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21975 VMware · vRealize Operations Manager API Added Jan 18, 2022

VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21315 Npm package · System Information Library for Node.JS Added Jan 18, 2022

System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22991 F5 · BIG-IP Traffic Management Microkernel Added Jan 18, 2022

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-14864 Oracle · Intelligence Enterprise Edition Added Jan 18, 2022

Oracle Business Intelligence Enterprise Edition Path Transversal

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-13671 Drupal · Drupal core Added Jan 18, 2022

Drupal core Un-restricted Upload of File

Improper sanitization in the extension file names is present in Drupal core.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-11978 Apache · Airflow Added Jan 18, 2022

Apache Airflow Command Injection

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-13927 Apache · Airflow's Experimental API Added Jan 18, 2022

Apache Airflow's Experimental API Authentication Bypass

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22017 VMware · vCenter Server Added Jan 10, 2022

VMware vCenter Server Improper Access Control

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-36260 Hikvision · Security cameras web server Added Jan 10, 2022

Hikvision Improper Input Validation

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-6572 Google · Chrome Media Added Jan 10, 2022

Google Chrome Media Use-After-Free Vulnerability

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1458 Microsoft · Win32k Added Jan 10, 2022

Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2013-3900 Microsoft · WinVerifyTrust function Added Jan 10, 2022

Microsoft WinVerifyTrust function Remote Code Execution

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-2725 Oracle · WebLogic Server Added Jan 10, 2022

Oracle WebLogic Server, Injection

Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-9670 Synacor · Zimbra Collaboration Suite (ZCS) Added Jan 10, 2022

Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.