An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 16, 2026.

1,713 total bulletins 1,713 critical or high severity Source: CISA KEV + NVD
Critical CVE-2018-18325 DotNetNuke (DNN) · DotNetNuke (DNN) Added Nov 3, 2021

DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-9822 DotNetNuke (DNN) · DotNetNuke (DNN) Added Nov 3, 2021

DotNetNuke (DNN) Remote Code Execution Vulnerability

DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-15752 Docker · Desktop Community Edition Added Nov 3, 2021

Docker Desktop Community Edition Privilege Escalation Vulnerability

Docker Desktop Community Edition contains a vulnerability that may allow local users to escalate privileges by placing a trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8515 DrayTek · Multiple Vigor Routers Added Nov 3, 2021

Multiple DrayTek Vigor Routers Web Management Page Vulnerability

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-7600 Drupal · Drupal Core Added Nov 3, 2021

Drupal Core Remote Code Execution Vulnerability

Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22205 GitLab · Community and Enterprise Editions Added Nov 3, 2021

GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-6789 Exim · Exim Added Nov 3, 2021

Exim Buffer Overflow Vulnerability

Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8657 EyesOfNetwork · EyesOfNetwork Added Nov 3, 2021

EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-8655 EyesOfNetwork · EyesOfNetwork Added Nov 3, 2021

EyesOfNetwork Improper Privilege Management Vulnerability

EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-5902 F5 · BIG-IP Added Nov 3, 2021

F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability

F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-22986 F5 · BIG-IP and BIG-IQ Centralized Management Added Nov 3, 2021

F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-35464 ForgeRock · Access Management (AM) Added Nov 3, 2021

ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-5591 Fortinet · FortiOS Added Nov 3, 2021

Fortinet FortiOS Default Configuration Vulnerability

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-12812 Fortinet · FortiOS Added Nov 3, 2021

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2018-13379 Fortinet · FortiOS Added Nov 3, 2021

Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-16010 Google · Chrome for Android UI Added Nov 3, 2021

Google Chrome for Android UI Heap Buffer Overflow Vulnerability

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-15999 Google · Chrome FreeType Added Nov 3, 2021

Google Chrome FreeType Heap Buffer Overflow Vulnerability

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21166 Google · Chromium Added Nov 3, 2021

Google Chromium Race Condition Vulnerability

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-16017 Google · Chrome Added Nov 3, 2021

Google Chrome Use-After-Free Vulnerability

Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-37976 Google · Chromium Added Nov 3, 2021

Google Chromium Information Disclosure Vulnerability

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-16009 Google · Chromium V8 Added Nov 3, 2021

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30632 Google · Chromium V8 Added Nov 3, 2021

Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-16013 Google · Chromium V8 Added Nov 3, 2021

Google Chromium V8 Incorrect Implementation Vulnerabililty

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-30633 Google · Chromium Indexed DB API Added Nov 3, 2021

Google Chromium Indexed DB API Use-After-Free Vulnerability

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-21148 Google · Chromium V8 Added Nov 3, 2021

Google Chromium V8 Heap Buffer Overflow Vulnerability

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.