Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 18, 2026.

1,623 total bulletins 1,623 critical or high severity Source: CISA KEV + NVD
Critical CVE-2021-30657 Apple · macOS Added Nov 3, 2021

Apple macOS Unspecified Vulnerability

Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30665 Apple · Multiple Products Added Nov 3, 2021

Apple Multiple Products WebKit Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30663 Apple · Multiple Products Added Nov 3, 2021

Apple Multiple Products WebKit Integer Overflow Vulnerability

Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30761 Apple · iOS Added Nov 3, 2021

Apple iOS WebKit Memory Corruption Vulnerability

Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30869 Apple · iOS, iPadOS, and macOS Added Nov 3, 2021

Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-9859 Apple · Multiple Products Added Nov 3, 2021

Apple Multiple Products Code Execution Vulnerability

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-20090 Arcadyan · Buffalo Firmware Added Nov 3, 2021

Arcadyan Buffalo Firmware Path Traversal Vulnerability

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-27562 Arm · Trusted Firmware Added Nov 3, 2021

Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-28664 Arm · Mali Graphics Processing Unit (GPU) Added Nov 3, 2021

Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-28663 Arm · Mali Graphics Processing Unit (GPU) Added Nov 3, 2021

Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-3398 Atlassian · Confluence Server and Data Center Added Nov 3, 2021

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-26084 Atlassian · Confluence Server and Data Center Added Nov 3, 2021

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-11580 Atlassian · Crowd and Crowd Data Center Added Nov 3, 2021

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-3396 Atlassian · Confluence Server and Data Server Added Nov 3, 2021

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-42258 BQE · BillQuick Web Suite Added Nov 3, 2021

BQE BillQuick Web Suite SQL Injection Vulnerability

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3452 Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Added Nov 3, 2021

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3580 Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Added Nov 3, 2021

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1497 Cisco · HyperFlex HX Added Nov 3, 2021

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1498 Cisco · HyperFlex HX Added Nov 3, 2021

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-0171 Cisco · IOS and IOS XE Added Nov 3, 2021

Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3118 Cisco · IOS XR Added Nov 3, 2021

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3566 Cisco · IOS XR Added Nov 3, 2021

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3569 Cisco · IOS XR Added Nov 3, 2021

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3161 Cisco · Cisco IP Phones Added Nov 3, 2021

Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1653 Cisco · Small Business RV320 and RV325 Routers Added Nov 3, 2021

Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.