An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jul 29, 2026.

1,656 total bulletins 1,656 critical or high severity Source: CISA KEV + NVD
Critical CVE-2015-2051 D-Link · DIR-645 Router Added Feb 10, 2022

D-Link DIR-645 Router Remote Code Execution Vulnerability

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-1635 Microsoft · HTTP.sys Added Feb 10, 2022

Microsoft HTTP.sys Remote Code Execution Vulnerability

Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2015-1130 Apple · OS X Added Feb 10, 2022

Apple OS X Authentication Bypass Vulnerability

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-4404 Apple · OS X Added Feb 10, 2022

Apple OS X Heap-Based Buffer Overflow Vulnerability

Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-21882 Microsoft · Win32k Added Feb 4, 2022

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2022-22587 Apple · iOS and macOS Added Jan 28, 2022

Apple Memory Corruption Vulnerability

Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20038 SonicWall · SMA 100 Appliances Added Jan 28, 2022

SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-5722 Grandstream · UCM6200 Added Jan 28, 2022

Grandstream Networks UCM6200 Series SQL Injection Vulnerability

Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-0787 Microsoft · Windows Added Jan 28, 2022

Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-5689 Intel · Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Added Jan 28, 2022

Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

Intel products contain a vulnerability which can allow attackers to perform privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-1776 Microsoft · Internet Explorer Added Jan 28, 2022

Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-6271 GNU · Bourne-Again Shell (Bash) Added Jan 28, 2022

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2014-7169 GNU · Bourne-Again Shell (Bash) Added Jan 28, 2022

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2006-1547 Apache · Struts 1 Added Jan 21, 2022

Apache Struts 1 ActionForm Denial-of-Service Vulnerability

ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2012-0391 Apache · Struts 2 Added Jan 21, 2022

Apache Struts 2 Improper Input Validation Vulnerability

The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-8453 Microsoft · Win32k Added Jan 21, 2022

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-35247 SolarWinds · Serv-U Added Jan 21, 2022

SolarWinds Serv-U Improper Input Validation Vulnerability

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-32648 October CMS · October CMS Added Jan 18, 2022

October CMS Improper Authentication

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25296 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25297 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-25298 Nagios · Nagios XI Added Jan 18, 2022

Nagios XI OS Command Injection

Nagios XI contains a vulnerability which can lead to OS command injection on the Nagios XI server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-40870 Aviatrix · Aviatrix Controller Added Jan 18, 2022

Aviatrix Controller Unrestricted Upload of File

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-33766 Microsoft · Exchange Server Added Jan 18, 2022

Microsoft Exchange Server Information Disclosure

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21975 VMware · vRealize Operations Manager API Added Jan 18, 2022

VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21315 Npm package · System Information Library for Node.JS Added Jan 18, 2022

System Information Library for Node.JS Command Injection

In this vulnerability, an attacker can send a malicious payload that will exploit the name parameter. After successful exploitation, attackers can execute remote.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.