An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 16, 2026.

1,713 total bulletins 1,713 critical or high severity Source: CISA KEV + NVD
Critical CVE-2019-3398 Atlassian · Confluence Server and Data Center Added Nov 3, 2021

Atlassian Confluence Server and Data Center Path Traversal Vulnerability

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-26084 Atlassian · Confluence Server and Data Center Added Nov 3, 2021

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-11580 Atlassian · Crowd and Crowd Data Center Added Nov 3, 2021

Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-3396 Atlassian · Confluence Server and Data Server Added Nov 3, 2021

Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-42258 BQE · BillQuick Web Suite Added Nov 3, 2021

BQE BillQuick Web Suite SQL Injection Vulnerability

BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow for unauthenticated, remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3452 Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Added Nov 3, 2021

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3580 Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Added Nov 3, 2021

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1497 Cisco · HyperFlex HX Added Nov 3, 2021

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1498 Cisco · HyperFlex HX Added Nov 3, 2021

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-0171 Cisco · IOS and IOS XE Added Nov 3, 2021

Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3118 Cisco · IOS XR Added Nov 3, 2021

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3566 Cisco · IOS XR Added Nov 3, 2021

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3569 Cisco · IOS XR Added Nov 3, 2021

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-3161 Cisco · Cisco IP Phones Added Nov 3, 2021

Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1653 Cisco · Small Business RV320 and RV325 Routers Added Nov 3, 2021

Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-0296 Cisco · Adaptive Security Appliance (ASA) Added Nov 3, 2021

Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-13608 Citrix · StoreFront Server Added Nov 3, 2021

Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8193 Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Added Nov 3, 2021

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8195 Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Added Nov 3, 2021

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8196 Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Added Nov 3, 2021

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-19781 Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance Added Nov 3, 2021

Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-11634 Citrix · Workspace Application and Receiver for Windows Added Nov 3, 2021

Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability

Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-29557 D-Link · DIR-825 R1 Devices Added Nov 3, 2021

D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-25506 D-Link · DNS-320 Device Added Nov 3, 2021

D-Link DNS-320 Device Command Injection Vulnerability

D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-15811 DotNetNuke (DNN) · DotNetNuke (DNN) Added Nov 3, 2021

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.