An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Security Bulletins

Active threat advisories and known exploited vulnerabilities.

Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Sep 16, 2026.

1,713 total bulletins 1,713 critical or high severity Source: CISA KEV + NVD
Critical CVE-2019-0541 Microsoft · MSHTML Added Nov 3, 2021

Microsoft MSHTML Remote Code Execution Vulnerability

Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-11882 Microsoft · Office Added Nov 3, 2021

Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-0674 Microsoft · Internet Explorer Added Nov 3, 2021

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-27059 Microsoft · Office Added Nov 3, 2021

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office contains an unspecified vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1367 Microsoft · Internet Explorer Added Nov 3, 2021

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-0199 Microsoft · Office and WordPad Added Nov 3, 2021

Microsoft Office and WordPad Remote Code Execution Vulnerability

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-1380 Microsoft · Internet Explorer Added Nov 3, 2021

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1429 Microsoft · Internet Explorer Added Nov 3, 2021

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2017-11774 Microsoft · Office Added Nov 3, 2021

Microsoft Office Outlook Security Feature Bypass Vulnerability

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-0968 Microsoft · Internet Explorer Added Nov 3, 2021

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-1472 Microsoft · Netlogon Added Nov 3, 2021

Microsoft Netlogon Privilege Escalation Vulnerability

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-26855 Microsoft · Exchange Server Added Nov 3, 2021

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-26858 Microsoft · Exchange Server Added Nov 3, 2021

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-27065 Microsoft · Exchange Server Added Nov 3, 2021

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-1054 Microsoft · Win32k Added Nov 3, 2021

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-1675 Microsoft · Windows Added Nov 3, 2021

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-34448 Microsoft · Windows Added Nov 3, 2021

Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-0601 Microsoft · Windows Added Nov 3, 2021

Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-0604 Microsoft · SharePoint Added Nov 3, 2021

Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-0646 Microsoft · .NET Framework Added Nov 3, 2021

Microsoft .NET Framework Remote Code Execution Vulnerability

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-0808 Microsoft · Win32k Added Nov 3, 2021

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2021-26857 Microsoft · Exchange Server Added Nov 3, 2021

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2020-1147 Microsoft · .NET Framework, SharePoint, Visual Studio Added Nov 3, 2021

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2019-1214 Microsoft · Windows Added Nov 3, 2021

Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability

Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed
Critical CVE-2016-3235 Microsoft · Office Added Nov 3, 2021

Microsoft Office OLE DLL Side Loading Vulnerability

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution.

NVD Detail ↗ CISA KEV ↗ Patch deadline passed

Need help prioritizing these vulnerabilities?

ThreatGrid can assess your environment and map active CVEs to your monitored assets.