Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 18, 2026.

1,623 total bulletins 1,623 critical or high severity Source: CISA KEV + NVD
Critical CVE-2020-0787 Microsoft · Windows Added Jan 28, 2022

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-5689 Intel · Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Added Jan 28, 2022

Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

Intel products contain a vulnerability which can allow attackers to perform privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-1776 Microsoft · Internet Explorer Added Jan 28, 2022

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-6271 GNU · Bourne-Again Shell (Bash) Added Jan 28, 2022

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-7169 GNU · Bourne-Again Shell (Bash) Added Jan 28, 2022

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2006-1547 Apache · Struts 1 Added Jan 21, 2022

Apache Struts 1 ActionForm Denial-of-Service Vulnerability

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-0391 Apache · Struts 2 Added Jan 21, 2022

Apache Struts 2 Improper Input Validation Vulnerability

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8453 Microsoft · Win32k Added Jan 21, 2022

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-35247 SolarWinds · Serv-U Added Jan 21, 2022

SolarWinds Serv-U Improper Input Validation Vulnerability

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-32648 October CMS · October CMS Added Jan 18, 2022

October CMS Improper Authentication

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25296 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25297 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25298 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-40870 Aviatrix · Aviatrix Controller Added Jan 18, 2022

Aviatrix Controller Unrestricted Upload of File

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-33766 Microsoft · Exchange Server Added Jan 18, 2022

Microsoft Exchange Server Information Disclosure

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21975 VMware · vRealize Operations Manager API Added Jan 18, 2022

VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21315 Npm package · System Information Library for Node.JS Added Jan 18, 2022

System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22991 F5 · BIG-IP Traffic Management Microkernel Added Jan 18, 2022

F5 BIG-IP Traffic Management Microkernel Buffer Overflow

The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-14864 Oracle · Intelligence Enterprise Edition Added Jan 18, 2022

Oracle Business Intelligence Enterprise Edition Path Transversal

Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system file.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-13671 Drupal · Drupal core Added Jan 18, 2022

Drupal core Un-restricted Upload of File

Improper sanitization in the extension file names is present in Drupal core.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-11978 Apache · Airflow Added Jan 18, 2022

Apache Airflow Command Injection

A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-13927 Apache · Airflow's Experimental API Added Jan 18, 2022

Apache Airflow's Experimental API Authentication Bypass

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22017 VMware · vCenter Server Added Jan 10, 2022

VMware vCenter Server Improper Access Control

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-36260 Hikvision · Security cameras web server Added Jan 10, 2022

Hikvision Improper Input Validation

A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-6572 Google · Chrome Media Added Jan 10, 2022

Google Chrome Media Use-After-Free Vulnerability

Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.